Skip to content

Cursor/lane b workflow 2281 - #53

Closed
briansrls wants to merge 13 commits into
mainfrom
cursor/lane-b-workflow-2281
Closed

briansrls wants to merge 13 commits into
mainfrom
cursor/lane-b-workflow-2281

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

No description provided.

cursoragent and others added 13 commits February 19, 2026 20:19
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 36af3d61de

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread gunbc-dag/src/workflow/planner.rs
@briansrls briansrls closed this Feb 20, 2026
briansrls added a commit that referenced this pull request May 7, 2026
Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 7, 2026
…2116)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 7, 2026
…briefs (#2117)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 7, 2026
…reate) (#2158)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
…nded + Q-Cost-Composition-Layering ε) (#2181)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at #2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at #2181 (sha 00551a8): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at #2181 (sha 4209eb7) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at #2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at #2181 (sha be9a9c9): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at #2181 (sha be9a9c9): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
…ined as context) (#2193)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at #2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at #2181 (sha 00551a8): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at #2181 (sha 4209eb7) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at #2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at #2181 (sha be9a9c9): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at #2181 (sha be9a9c9): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
…precedent does NOT apply) (#2197)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at #2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at #2181 (sha 00551a8): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at #2181 (sha 4209eb7) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at #2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at #2181 (sha be9a9c9): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at #2181 (sha be9a9c9): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Complexity-Composition-Layering canvas — DRAFT (factoring tested, ε precedent does NOT apply)

Director authorized canvas authoring at #828 c#4402669133 as
parallel structure to Q-Cost-Composition-Layering (ε RATIFIED). Substrate-
grep on src/v3/lenses/complexity.dag at HEAD shows the factoring claim
DIFFERS from cost-lens:

- Cost-lens needed (target-agnostic shape × target-specific values)
  factoring → Rust-side composition (ε)
- Complexity-lens has NO target-specific axis; output is structural
  property of DAG topology + algebra-instance composition; substrate-
  native fully-on-.dag-side completion

Mgr provisional reading: ε precedent does NOT apply; complexity-lens
BEHAVIORAL COMPLETION is direct slice-tier substrate authoring (carrier
introduction follows SymbolicCost precedent + T-E-P P1 carrier
consumption). Director ratification ask: Q1 (factoring finding correct),
Q2 (slice-tier directly bypassing canvas), Q3 (fresh worker pin).

Cross-Mgr: Verification Mgr (#2075) pinged on v2-oracle snapshot capture
status (cross-cutting prerequisite for #1950/#1951 cementing dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at #2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at #2181 (sha 00551a8): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at #2181 (sha 4209eb7) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at #2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at #2181 (sha be9a9c9): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at #2181 (sha be9a9c9): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Complexity-Composition-Layering canvas — DRAFT (factoring tested, ε precedent does NOT apply)

Director authorized canvas authoring at #828 c#4402669133 as
parallel structure to Q-Cost-Composition-Layering (ε RATIFIED). Substrate-
grep on src/v3/lenses/complexity.dag at HEAD shows the factoring claim
DIFFERS from cost-lens:

- Cost-lens needed (target-agnostic shape × target-specific values)
  factoring → Rust-side composition (ε)
- Complexity-lens has NO target-specific axis; output is structural
  property of DAG topology + algebra-instance composition; substrate-
  native fully-on-.dag-side completion

Mgr provisional reading: ε precedent does NOT apply; complexity-lens
BEHAVIORAL COMPLETION is direct slice-tier substrate authoring (carrier
introduction follows SymbolicCost precedent + T-E-P P1 carrier
consumption). Director ratification ask: Q1 (factoring finding correct),
Q2 (slice-tier directly bypassing canvas), Q3 (fresh worker pin).

Cross-Mgr: Verification Mgr (#2075) pinged on v2-oracle snapshot capture
status (cross-cutting prerequisite for #1950/#1951 cementing dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LBP complexity-lens substrate-completion worker brief (Q1/Q2/Q3 RATIFIED)

Pre-authored brief for complexity-lens BEHAVIORAL COMPLETION substrate
work per Director Q1/Q2/Q3 ratification at #828 c#4402714255.

Three deliverables: carrier introduction (ComplexityCost / WorkSpan /
AsymptoticClass following SymbolicCost precedent) + lens widening
(complexity.dag PROXY → COMPLETE) + T-E-P P1 carrier consumption
(DescentEvidence / CallPattern / SubValueRelation for asymptotic
classification of recursive-call behavior).

Indirect-variant dependency surfaced as worker-grep concern at slice-
authoring time (T-E-P P1 Slice 5+ pending; eager-bat-178 stream).

Cementing test (#1950) is separate downstream brief; v2-oracle snapshot
ownership pending Q4 cross-Mgr ratification.

Worker pin: fresh-pool pick at dispatch time (NOT eager-bat-178 per
Director Q3 framing; NOT fierce-ram-21 busy with cost-lens ε).

Same-window-dispatch discipline applies post-canvas-merge (PR #2197).

Pre-authored vs pre-known discipline applied per
feedback_pre_known_vs_pre_authored_briefs.md memorialized 2026-05-08.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): rewrite complexity-lens brief consuming live design authority (codex BLOCKING fix)

Codex BLOCKING (3 findings) at #2199 sha 7a8bb6d:
1. Brief authored against missing canvas instead of reconciling with
   docs/design-complexity-lens-behavioral-completeness.md (which exists
   at HEAD with comprehensive substrate spec)
2. Producer coverage treated as optional corpus scope; should be hard
   T-E-P-Producer-Broadening prerequisite
3. Stale/non-in-repo planning authority cited; should be r3-structure.md
   row 146 (T-LBP slice 1)

All three BLOCKING findings VALID — substrate-grep-before-authoring
discipline failure on my part (feedback_substrate_grep_before_authoring
already memorialized; violated own discipline).

Rewrite delegates carrier shape, dimension wiring, and consumer rewrite
to live design doc §§1.1-1.6 verbatim:
- §1.1 SymbolicCost — already at algebra.dag; no change
- §1.2 SizeVariable — display_name enrichment
- §1.3 work_dimension + span_dimension — two AnalysisDimension instances
- §1.4 AsymptoticClass + BoundedLattice instance
- §1.5 Certainty (cost-aware composition; no lattice)
- §1.6 cost_bound_to_symbolic projection
- §1.7 ComplexitySummary record + lens widening

T-E-P P1 hard prerequisite per design's authority discipline + r3-
structure.md row 146; STOP-and-PING if T-E-P P1 not COMPLETE at slice
authoring time. Authority cites updated to live r3-structure.md row 146.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
…per Q6 RATIFIED) (#2209)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at #2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at #2181 (sha 00551a8): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at #2181 (sha 4209eb7) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at #2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at #2181 (sha be9a9c9): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at #2181 (sha be9a9c9): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Complexity-Composition-Layering canvas — DRAFT (factoring tested, ε precedent does NOT apply)

Director authorized canvas authoring at #828 c#4402669133 as
parallel structure to Q-Cost-Composition-Layering (ε RATIFIED). Substrate-
grep on src/v3/lenses/complexity.dag at HEAD shows the factoring claim
DIFFERS from cost-lens:

- Cost-lens needed (target-agnostic shape × target-specific values)
  factoring → Rust-side composition (ε)
- Complexity-lens has NO target-specific axis; output is structural
  property of DAG topology + algebra-instance composition; substrate-
  native fully-on-.dag-side completion

Mgr provisional reading: ε precedent does NOT apply; complexity-lens
BEHAVIORAL COMPLETION is direct slice-tier substrate authoring (carrier
introduction follows SymbolicCost precedent + T-E-P P1 carrier
consumption). Director ratification ask: Q1 (factoring finding correct),
Q2 (slice-tier directly bypassing canvas), Q3 (fresh worker pin).

Cross-Mgr: Verification Mgr (#2075) pinged on v2-oracle snapshot capture
status (cross-cutting prerequisite for #1950/#1951 cementing dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LBP complexity-lens substrate-completion worker brief (Q1/Q2/Q3 RATIFIED)

Pre-authored brief for complexity-lens BEHAVIORAL COMPLETION substrate
work per Director Q1/Q2/Q3 ratification at #828 c#4402714255.

Three deliverables: carrier introduction (ComplexityCost / WorkSpan /
AsymptoticClass following SymbolicCost precedent) + lens widening
(complexity.dag PROXY → COMPLETE) + T-E-P P1 carrier consumption
(DescentEvidence / CallPattern / SubValueRelation for asymptotic
classification of recursive-call behavior).

Indirect-variant dependency surfaced as worker-grep concern at slice-
authoring time (T-E-P P1 Slice 5+ pending; eager-bat-178 stream).

Cementing test (#1950) is separate downstream brief; v2-oracle snapshot
ownership pending Q4 cross-Mgr ratification.

Worker pin: fresh-pool pick at dispatch time (NOT eager-bat-178 per
Director Q3 framing; NOT fierce-ram-21 busy with cost-lens ε).

Same-window-dispatch discipline applies post-canvas-merge (PR #2197).

Pre-authored vs pre-known discipline applied per
feedback_pre_known_vs_pre_authored_briefs.md memorialized 2026-05-08.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): rewrite complexity-lens brief consuming live design authority (codex BLOCKING fix)

Codex BLOCKING (3 findings) at #2199 sha 7a8bb6d:
1. Brief authored against missing canvas instead of reconciling with
   docs/design-complexity-lens-behavioral-completeness.md (which exists
   at HEAD with comprehensive substrate spec)
2. Producer coverage treated as optional corpus scope; should be hard
   T-E-P-Producer-Broadening prerequisite
3. Stale/non-in-repo planning authority cited; should be r3-structure.md
   row 146 (T-LBP slice 1)

All three BLOCKING findings VALID — substrate-grep-before-authoring
discipline failure on my part (feedback_substrate_grep_before_authoring
already memorialized; violated own discipline).

Rewrite delegates carrier shape, dimension wiring, and consumer rewrite
to live design doc §§1.1-1.6 verbatim:
- §1.1 SymbolicCost — already at algebra.dag; no change
- §1.2 SizeVariable — display_name enrichment
- §1.3 work_dimension + span_dimension — two AnalysisDimension instances
- §1.4 AsymptoticClass + BoundedLattice instance
- §1.5 Certainty (cost-aware composition; no lattice)
- §1.6 cost_bound_to_symbolic projection
- §1.7 ComplexitySummary record + lens widening

T-E-P P1 hard prerequisite per design's authority discipline + r3-
structure.md row 146; STOP-and-PING if T-E-P P1 not COMPLETE at slice
authoring time. Authority cites updated to live r3-structure.md row 146.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas — DRAFT (canvas-tier P1 procedure per Q6 RATIFIED)

Director Q6 RATIFIED canvas-tier-required at #828 c#4403163639
for PerfWithinBaseline TestPredicate variant authoring. Three substantive
substrate-shape questions resolved:

Q1 baseline shape: (a) literal-Int rejected as strict-mirror-of-CostBounded
defeats semantic load; (b) DeclarationRef-to-stored-data composes
LensOutputEquals + data X: SymbolicCost precedent at HEAD; (c) runtime-
fixture-injection over-authors. Mgr lean (b).

Q2 ComparisonOp composition: (i) reuse existing ComparisonOp via test-
runner-side resolution matches LensOutputEquals path; (ii) new relative-
op-set introduces parallel-representation debt. Mgr lean (i).

Q3 baseline-storage scope: (α) in-scope slice authors example data; (β)
out-of-scope variant-only slice + PB consumer authors baseline data
matches existing layering. Mgr lean (β).

Combined Mgr lean: Q1(b) + Q2(i) + Q3(β) — variant authored as
compositional extension; baseline-storage is PB consumer-tier work.

Cross-Mgr: PB Mgr #2138 worker (crisp-swift-433) holds dispatch on #2204
land; T-Tier3-Dissolution #2085 R-4 prereq encoded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
…g-shape original) (#2210)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at #2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at #2181 (sha 00551a8): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at #2181 (sha 4209eb7) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at #2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at #2181 (sha be9a9c9): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at #2181 (sha be9a9c9): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Complexity-Composition-Layering canvas — DRAFT (factoring tested, ε precedent does NOT apply)

Director authorized canvas authoring at #828 c#4402669133 as
parallel structure to Q-Cost-Composition-Layering (ε RATIFIED). Substrate-
grep on src/v3/lenses/complexity.dag at HEAD shows the factoring claim
DIFFERS from cost-lens:

- Cost-lens needed (target-agnostic shape × target-specific values)
  factoring → Rust-side composition (ε)
- Complexity-lens has NO target-specific axis; output is structural
  property of DAG topology + algebra-instance composition; substrate-
  native fully-on-.dag-side completion

Mgr provisional reading: ε precedent does NOT apply; complexity-lens
BEHAVIORAL COMPLETION is direct slice-tier substrate authoring (carrier
introduction follows SymbolicCost precedent + T-E-P P1 carrier
consumption). Director ratification ask: Q1 (factoring finding correct),
Q2 (slice-tier directly bypassing canvas), Q3 (fresh worker pin).

Cross-Mgr: Verification Mgr (#2075) pinged on v2-oracle snapshot capture
status (cross-cutting prerequisite for #1950/#1951 cementing dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LBP complexity-lens substrate-completion worker brief (Q1/Q2/Q3 RATIFIED)

Pre-authored brief for complexity-lens BEHAVIORAL COMPLETION substrate
work per Director Q1/Q2/Q3 ratification at #828 c#4402714255.

Three deliverables: carrier introduction (ComplexityCost / WorkSpan /
AsymptoticClass following SymbolicCost precedent) + lens widening
(complexity.dag PROXY → COMPLETE) + T-E-P P1 carrier consumption
(DescentEvidence / CallPattern / SubValueRelation for asymptotic
classification of recursive-call behavior).

Indirect-variant dependency surfaced as worker-grep concern at slice-
authoring time (T-E-P P1 Slice 5+ pending; eager-bat-178 stream).

Cementing test (#1950) is separate downstream brief; v2-oracle snapshot
ownership pending Q4 cross-Mgr ratification.

Worker pin: fresh-pool pick at dispatch time (NOT eager-bat-178 per
Director Q3 framing; NOT fierce-ram-21 busy with cost-lens ε).

Same-window-dispatch discipline applies post-canvas-merge (PR #2197).

Pre-authored vs pre-known discipline applied per
feedback_pre_known_vs_pre_authored_briefs.md memorialized 2026-05-08.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): rewrite complexity-lens brief consuming live design authority (codex BLOCKING fix)

Codex BLOCKING (3 findings) at #2199 sha 7a8bb6d:
1. Brief authored against missing canvas instead of reconciling with
   docs/design-complexity-lens-behavioral-completeness.md (which exists
   at HEAD with comprehensive substrate spec)
2. Producer coverage treated as optional corpus scope; should be hard
   T-E-P-Producer-Broadening prerequisite
3. Stale/non-in-repo planning authority cited; should be r3-structure.md
   row 146 (T-LBP slice 1)

All three BLOCKING findings VALID — substrate-grep-before-authoring
discipline failure on my part (feedback_substrate_grep_before_authoring
already memorialized; violated own discipline).

Rewrite delegates carrier shape, dimension wiring, and consumer rewrite
to live design doc §§1.1-1.6 verbatim:
- §1.1 SymbolicCost — already at algebra.dag; no change
- §1.2 SizeVariable — display_name enrichment
- §1.3 work_dimension + span_dimension — two AnalysisDimension instances
- §1.4 AsymptoticClass + BoundedLattice instance
- §1.5 Certainty (cost-aware composition; no lattice)
- §1.6 cost_bound_to_symbolic projection
- §1.7 ComplexitySummary record + lens widening

T-E-P P1 hard prerequisite per design's authority discipline + r3-
structure.md row 146; STOP-and-PING if T-E-P P1 not COMPLETE at slice
authoring time. Authority cites updated to live r3-structure.md row 146.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas — DRAFT (canvas-tier P1 procedure per Q6 RATIFIED)

Director Q6 RATIFIED canvas-tier-required at #828 c#4403163639
for PerfWithinBaseline TestPredicate variant authoring. Three substantive
substrate-shape questions resolved:

Q1 baseline shape: (a) literal-Int rejected as strict-mirror-of-CostBounded
defeats semantic load; (b) DeclarationRef-to-stored-data composes
LensOutputEquals + data X: SymbolicCost precedent at HEAD; (c) runtime-
fixture-injection over-authors. Mgr lean (b).

Q2 ComparisonOp composition: (i) reuse existing ComparisonOp via test-
runner-side resolution matches LensOutputEquals path; (ii) new relative-
op-set introduces parallel-representation debt. Mgr lean (i).

Q3 baseline-storage scope: (α) in-scope slice authors example data; (β)
out-of-scope variant-only slice + PB consumer authors baseline data
matches existing layering. Mgr lean (β).

Combined Mgr lean: Q1(b) + Q2(i) + Q3(β) — variant authored as
compositional extension; baseline-storage is PB consumer-tier work.

Cross-Mgr: PB Mgr #2138 worker (crisp-swift-433) holds dispatch on #2204
land; T-Tier3-Dissolution #2085 R-4 prereq encoded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas REVISED (supersedes wrong-shape original)

Director disposition at #828 c#4403265220 authorized
supersession after BLOCKING at PR #2209 c#4403246233 verified VALID:
original canvas conflated symbolic SymbolicCost (cost-lens substrate)
with wall-clock measured median/p99 baseline (T-Tier3 perf gate
substrate per docs/r3-structure.md:225 + :461 Director-locked 2026-04-28).

Revised canvas frames as two-path ratification:
- P1 author full perf-budget substrate in-R3 (multi-slice; pattern-5
  genuinely-novel substrate-fact-introduction)
- P2 explicitly post-R3 per Director-locked recommendation (zero in-R3
  effort; structural close per r3-structure.md:461 'R3 deliverable is
  structural close; perf is downstream')

Mgr lean: P2 — Director-locked recommendation explicit; trigger-
condition ('someone authors perf-budget claim with concrete numbers
and tooling') not met; R3 horizon constraint argues against multi-
slice perf-budget substrate adding to 5-orthogonal-dependency picture.

Original canvas at q-perf-within-baseline-canvas.md retained with
SUPERSEDED-BY header per durable-decision-record discipline.

5th discipline-failure of 2026-05-08 cycle: substrate-grep verified
substrate-precedent but missed consumer-side requirement at canonical
authority doc; Director self-flagged symmetric two-axis verification
gap; canvas-finding-taxonomy needs precondition 'consumer-side
requirement grep-verified at canonical authority doc'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas-revised — correct trigger-condition framing per Director c#4403297623

Director caught second-axis grep failure on revised canvas: my P2
reasoning #1 ("path-trigger condition for P1 is not met") was
structurally wrong. Existing tooling at HEAD substantially meets the
Director-locked 2026-04-28 trigger-condition ("someone authors the
perf-budget claim with concrete numbers and tooling"):

- docs/briefs/r3-pb-tier3-perf-budget-worker.md
- docs/audit/c1-tier3-perf-budget-readiness-matrix.md
- src/v3/compiler/benches/tier3_mirror_perf.rs
- docs/audit/c1-tier3-baseline-capture-procedure.md
- docs/audit/c1-r3-canonical-bench-host-decision-matrix.md

Plus thresholds (≤2× median, ≤5× p99) + capture discipline (N=3 min,
N=5 preferred) + canonical bench host option matrix.

P1 is bridging existing tooling to substrate (compositional-extension),
NOT multi-slice greenfield genuinely-novel pattern-5 as originally
framed. Smaller scope than canvas-finding-taxonomy pattern 5 implies.

Path-call genuinely depends on PB Mgr's R-3 (canonical CI bench host)
+ R-7 (tier3_baseline.json baseline-capture path) decisions per their
audit response at c#4403059897. Path-call DEFERRED to cross-Mgr
coordination outcome with PB Mgr (#2074); Substrate Mgr surfaces with
corrected framing this turn.

Sixth discipline-failure of cycle (mine, second-axis grep gap on
existing-tooling state); same-class as Director's first-axis grep gap
on consumer-side requirement at the prior turn. Memorialized as
two-axis verification discipline anchor.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at #2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at #2181 (sha 00551a8): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at #2181 (sha 4209eb7) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at #2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at #2181 (sha be9a9c9): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at #2181 (sha be9a9c9): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Complexity-Composition-Layering canvas — DRAFT (factoring tested, ε precedent does NOT apply)

Director authorized canvas authoring at #828 c#4402669133 as
parallel structure to Q-Cost-Composition-Layering (ε RATIFIED). Substrate-
grep on src/v3/lenses/complexity.dag at HEAD shows the factoring claim
DIFFERS from cost-lens:

- Cost-lens needed (target-agnostic shape × target-specific values)
  factoring → Rust-side composition (ε)
- Complexity-lens has NO target-specific axis; output is structural
  property of DAG topology + algebra-instance composition; substrate-
  native fully-on-.dag-side completion

Mgr provisional reading: ε precedent does NOT apply; complexity-lens
BEHAVIORAL COMPLETION is direct slice-tier substrate authoring (carrier
introduction follows SymbolicCost precedent + T-E-P P1 carrier
consumption). Director ratification ask: Q1 (factoring finding correct),
Q2 (slice-tier directly bypassing canvas), Q3 (fresh worker pin).

Cross-Mgr: Verification Mgr (#2075) pinged on v2-oracle snapshot capture
status (cross-cutting prerequisite for #1950/#1951 cementing dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LBP complexity-lens substrate-completion worker brief (Q1/Q2/Q3 RATIFIED)

Pre-authored brief for complexity-lens BEHAVIORAL COMPLETION substrate
work per Director Q1/Q2/Q3 ratification at #828 c#4402714255.

Three deliverables: carrier introduction (ComplexityCost / WorkSpan /
AsymptoticClass following SymbolicCost precedent) + lens widening
(complexity.dag PROXY → COMPLETE) + T-E-P P1 carrier consumption
(DescentEvidence / CallPattern / SubValueRelation for asymptotic
classification of recursive-call behavior).

Indirect-variant dependency surfaced as worker-grep concern at slice-
authoring time (T-E-P P1 Slice 5+ pending; eager-bat-178 stream).

Cementing test (#1950) is separate downstream brief; v2-oracle snapshot
ownership pending Q4 cross-Mgr ratification.

Worker pin: fresh-pool pick at dispatch time (NOT eager-bat-178 per
Director Q3 framing; NOT fierce-ram-21 busy with cost-lens ε).

Same-window-dispatch discipline applies post-canvas-merge (PR #2197).

Pre-authored vs pre-known discipline applied per
feedback_pre_known_vs_pre_authored_briefs.md memorialized 2026-05-08.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): rewrite complexity-lens brief consuming live design authority (codex BLOCKING fix)

Codex BLOCKING (3 findings) at #2199 sha 7a8bb6d:
1. Brief authored against missing canvas instead of reconciling with
   docs/design-complexity-lens-behavioral-completeness.md (which exists
   at HEAD with comprehensive substrate spec)
2. Producer coverage treated as optional corpus scope; should be hard
   T-E-P-Producer-Broadening prerequisite
3. Stale/non-in-repo planning authority cited; should be r3-structure.md
   row 146 (T-LBP slice 1)

All three BLOCKING findings VALID — substrate-grep-before-authoring
discipline failure on my part (feedback_substrate_grep_before_authoring
already memorialized; violated own discipline).

Rewrite delegates carrier shape, dimension wiring, and consumer rewrite
to live design doc §§1.1-1.6 verbatim:
- §1.1 SymbolicCost — already at algebra.dag; no change
- §1.2 SizeVariable — display_name enrichment
- §1.3 work_dimension + span_dimension — two AnalysisDimension instances
- §1.4 AsymptoticClass + BoundedLattice instance
- §1.5 Certainty (cost-aware composition; no lattice)
- §1.6 cost_bound_to_symbolic projection
- §1.7 ComplexitySummary record + lens widening

T-E-P P1 hard prerequisite per design's authority discipline + r3-
structure.md row 146; STOP-and-PING if T-E-P P1 not COMPLETE at slice
authoring time. Authority cites updated to live r3-structure.md row 146.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas — DRAFT (canvas-tier P1 procedure per Q6 RATIFIED)

Director Q6 RATIFIED canvas-tier-required at #828 c#4403163639
for PerfWithinBaseline TestPredicate variant authoring. Three substantive
substrate-shape questions resolved:

Q1 baseline shape: (a) literal-Int rejected as strict-mirror-of-CostBounded
defeats semantic load; (b) DeclarationRef-to-stored-data composes
LensOutputEquals + data X: SymbolicCost precedent at HEAD; (c) runtime-
fixture-injection over-authors. Mgr lean (b).

Q2 ComparisonOp composition: (i) reuse existing ComparisonOp via test-
runner-side resolution matches LensOutputEquals path; (ii) new relative-
op-set introduces parallel-representation debt. Mgr lean (i).

Q3 baseline-storage scope: (α) in-scope slice authors example data; (β)
out-of-scope variant-only slice + PB consumer authors baseline data
matches existing layering. Mgr lean (β).

Combined Mgr lean: Q1(b) + Q2(i) + Q3(β) — variant authored as
compositional extension; baseline-storage is PB consumer-tier work.

Cross-Mgr: PB Mgr #2138 worker (crisp-swift-433) holds dispatch on #2204
land; T-Tier3-Dissolution #2085 R-4 prereq encoded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas REVISED (supersedes wrong-shape original)

Director disposition at #828 c#4403265220 authorized
supersession after BLOCKING at PR #2209 c#4403246233 verified VALID:
original canvas conflated symbolic SymbolicCost (cost-lens substrate)
with wall-clock measured median/p99 baseline (T-Tier3 perf gate
substrate per docs/r3-structure.md:225 + :461 Director-locked 2026-04-28).

Revised canvas frames as two-path ratification:
- P1 author full perf-budget substrate in-R3 (multi-slice; pattern-5
  genuinely-novel substrate-fact-introduction)
- P2 explicitly post-R3 per Director-locked recommendation (zero in-R3
  effort; structural close per r3-structure.md:461 'R3 deliverable is
  structural close; perf is downstream')

Mgr lean: P2 — Director-locked recommendation explicit; trigger-
condition ('someone authors perf-budget claim with concrete numbers
and tooling') not met; R3 horizon constraint argues against multi-
slice perf-budget substrate adding to 5-orthogonal-dependency picture.

Original canvas at q-perf-within-baseline-canvas.md retained with
SUPERSEDED-BY header per durable-decision-record discipline.

5th discipline-failure of 2026-05-08 cycle: substrate-grep verified
substrate-precedent but missed consumer-side requirement at canonical
authority doc; Director self-flagged symmetric two-axis verification
gap; canvas-finding-taxonomy needs precondition 'consumer-side
requirement grep-verified at canonical authority doc'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas-revised — correct trigger-condition framing per Director c#4403297623

Director caught second-axis grep failure on revised canvas: my P2
reasoning #1 ("path-trigger condition for P1 is not met") was
structurally wrong. Existing tooling at HEAD substantially meets the
Director-locked 2026-04-28 trigger-condition ("someone authors the
perf-budget claim with concrete numbers and tooling"):

- docs/briefs/r3-pb-tier3-perf-budget-worker.md
- docs/audit/c1-tier3-perf-budget-readiness-matrix.md
- src/v3/compiler/benches/tier3_mirror_perf.rs
- docs/audit/c1-tier3-baseline-capture-procedure.md
- docs/audit/c1-r3-canonical-bench-host-decision-matrix.md

Plus thresholds (≤2× median, ≤5× p99) + capture discipline (N=3 min,
N=5 preferred) + canonical bench host option matrix.

P1 is bridging existing tooling to substrate (compositional-extension),
NOT multi-slice greenfield genuinely-novel pattern-5 as originally
framed. Smaller scope than canvas-finding-taxonomy pattern 5 implies.

Path-call genuinely depends on PB Mgr's R-3 (canonical CI bench host)
+ R-7 (tier3_baseline.json baseline-capture path) decisions per their
audit response at c#4403059897. Path-call DEFERRED to cross-Mgr
coordination outcome with PB Mgr (#2074); Substrate Mgr surfaces with
corrected framing this turn.

Sixth discipline-failure of cycle (mine, second-axis grep gap on
existing-tooling state); same-class as Director's first-axis grep gap
on consumer-side requirement at the prior turn. Memorialized as
two-axis verification discipline anchor.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-ValueBody-Drift-Resolution canvas — DRAFT (codegen-generation lean)

D1 substrate-shape question per Q-ValueBody-Isomorphism RATIFIED at
#828 c#4403972737. Variant-inventory readiness input from
PR #2218 (merged 2026-05-08) confirms drift: Rust 5 variants vs
substrate 3 constructors; asymmetry on Scalar+List Rust-only +
Map payload-parity-with-semantic-gap.

Two-axis verification at HEAD:
- Substrate-precedent: codegen tooling exists (regen_bootstrap_emit;
  5 _generated.rs files; regen_bootstrap binary). Pattern-3 strict-
  mirror codegen extension applies; no pattern-5 P1 procedure.
- Consumer-side requirement: V1 worker brief explicitly names mirror-
  parity-vs-codegen-generation as D1 path-pair.

Mgr lean: (b) codegen-generation. Path (a) mirror-parity perpetuates
parallel-representation debt; (b) dissolves the dual-taxonomy class
by construction (substrate canonical, Rust codegens). Map dup-key gap
handled via (ii) Rust-side post-codegen wrapping (substrate stays
minimal).

Director ratification ask: D1 (b) + D1-followup (ii).

Carrier slice path post-ratification: extend regen_bootstrap_emit;
add Scalar+List constructors to substrate; regen + remove hand-Rust
enum; handle Map dup-key per ratified followup. Worker pin fresh-pool
per same-window-dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
…cite (#2226)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at #2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at #2181 (sha 00551a8): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at #2181 (sha 4209eb7) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at #2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at #2181 (sha be9a9c9): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at #2181 (sha be9a9c9): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Complexity-Composition-Layering canvas — DRAFT (factoring tested, ε precedent does NOT apply)

Director authorized canvas authoring at #828 c#4402669133 as
parallel structure to Q-Cost-Composition-Layering (ε RATIFIED). Substrate-
grep on src/v3/lenses/complexity.dag at HEAD shows the factoring claim
DIFFERS from cost-lens:

- Cost-lens needed (target-agnostic shape × target-specific values)
  factoring → Rust-side composition (ε)
- Complexity-lens has NO target-specific axis; output is structural
  property of DAG topology + algebra-instance composition; substrate-
  native fully-on-.dag-side completion

Mgr provisional reading: ε precedent does NOT apply; complexity-lens
BEHAVIORAL COMPLETION is direct slice-tier substrate authoring (carrier
introduction follows SymbolicCost precedent + T-E-P P1 carrier
consumption). Director ratification ask: Q1 (factoring finding correct),
Q2 (slice-tier directly bypassing canvas), Q3 (fresh worker pin).

Cross-Mgr: Verification Mgr (#2075) pinged on v2-oracle snapshot capture
status (cross-cutting prerequisite for #1950/#1951 cementing dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LBP complexity-lens substrate-completion worker brief (Q1/Q2/Q3 RATIFIED)

Pre-authored brief for complexity-lens BEHAVIORAL COMPLETION substrate
work per Director Q1/Q2/Q3 ratification at #828 c#4402714255.

Three deliverables: carrier introduction (ComplexityCost / WorkSpan /
AsymptoticClass following SymbolicCost precedent) + lens widening
(complexity.dag PROXY → COMPLETE) + T-E-P P1 carrier consumption
(DescentEvidence / CallPattern / SubValueRelation for asymptotic
classification of recursive-call behavior).

Indirect-variant dependency surfaced as worker-grep concern at slice-
authoring time (T-E-P P1 Slice 5+ pending; eager-bat-178 stream).

Cementing test (#1950) is separate downstream brief; v2-oracle snapshot
ownership pending Q4 cross-Mgr ratification.

Worker pin: fresh-pool pick at dispatch time (NOT eager-bat-178 per
Director Q3 framing; NOT fierce-ram-21 busy with cost-lens ε).

Same-window-dispatch discipline applies post-canvas-merge (PR #2197).

Pre-authored vs pre-known discipline applied per
feedback_pre_known_vs_pre_authored_briefs.md memorialized 2026-05-08.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): rewrite complexity-lens brief consuming live design authority (codex BLOCKING fix)

Codex BLOCKING (3 findings) at #2199 sha 7a8bb6d:
1. Brief authored against missing canvas instead of reconciling with
   docs/design-complexity-lens-behavioral-completeness.md (which exists
   at HEAD with comprehensive substrate spec)
2. Producer coverage treated as optional corpus scope; should be hard
   T-E-P-Producer-Broadening prerequisite
3. Stale/non-in-repo planning authority cited; should be r3-structure.md
   row 146 (T-LBP slice 1)

All three BLOCKING findings VALID — substrate-grep-before-authoring
discipline failure on my part (feedback_substrate_grep_before_authoring
already memorialized; violated own discipline).

Rewrite delegates carrier shape, dimension wiring, and consumer rewrite
to live design doc §§1.1-1.6 verbatim:
- §1.1 SymbolicCost — already at algebra.dag; no change
- §1.2 SizeVariable — display_name enrichment
- §1.3 work_dimension + span_dimension — two AnalysisDimension instances
- §1.4 AsymptoticClass + BoundedLattice instance
- §1.5 Certainty (cost-aware composition; no lattice)
- §1.6 cost_bound_to_symbolic projection
- §1.7 ComplexitySummary record + lens widening

T-E-P P1 hard prerequisite per design's authority discipline + r3-
structure.md row 146; STOP-and-PING if T-E-P P1 not COMPLETE at slice
authoring time. Authority cites updated to live r3-structure.md row 146.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas — DRAFT (canvas-tier P1 procedure per Q6 RATIFIED)

Director Q6 RATIFIED canvas-tier-required at #828 c#4403163639
for PerfWithinBaseline TestPredicate variant authoring. Three substantive
substrate-shape questions resolved:

Q1 baseline shape: (a) literal-Int rejected as strict-mirror-of-CostBounded
defeats semantic load; (b) DeclarationRef-to-stored-data composes
LensOutputEquals + data X: SymbolicCost precedent at HEAD; (c) runtime-
fixture-injection over-authors. Mgr lean (b).

Q2 ComparisonOp composition: (i) reuse existing ComparisonOp via test-
runner-side resolution matches LensOutputEquals path; (ii) new relative-
op-set introduces parallel-representation debt. Mgr lean (i).

Q3 baseline-storage scope: (α) in-scope slice authors example data; (β)
out-of-scope variant-only slice + PB consumer authors baseline data
matches existing layering. Mgr lean (β).

Combined Mgr lean: Q1(b) + Q2(i) + Q3(β) — variant authored as
compositional extension; baseline-storage is PB consumer-tier work.

Cross-Mgr: PB Mgr #2138 worker (crisp-swift-433) holds dispatch on #2204
land; T-Tier3-Dissolution #2085 R-4 prereq encoded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas REVISED (supersedes wrong-shape original)

Director disposition at #828 c#4403265220 authorized
supersession after BLOCKING at PR #2209 c#4403246233 verified VALID:
original canvas conflated symbolic SymbolicCost (cost-lens substrate)
with wall-clock measured median/p99 baseline (T-Tier3 perf gate
substrate per docs/r3-structure.md:225 + :461 Director-locked 2026-04-28).

Revised canvas frames as two-path ratification:
- P1 author full perf-budget substrate in-R3 (multi-slice; pattern-5
  genuinely-novel substrate-fact-introduction)
- P2 explicitly post-R3 per Director-locked recommendation (zero in-R3
  effort; structural close per r3-structure.md:461 'R3 deliverable is
  structural close; perf is downstream')

Mgr lean: P2 — Director-locked recommendation explicit; trigger-
condition ('someone authors perf-budget claim with concrete numbers
and tooling') not met; R3 horizon constraint argues against multi-
slice perf-budget substrate adding to 5-orthogonal-dependency picture.

Original canvas at q-perf-within-baseline-canvas.md retained with
SUPERSEDED-BY header per durable-decision-record discipline.

5th discipline-failure of 2026-05-08 cycle: substrate-grep verified
substrate-precedent but missed consumer-side requirement at canonical
authority doc; Director self-flagged symmetric two-axis verification
gap; canvas-finding-taxonomy needs precondition 'consumer-side
requirement grep-verified at canonical authority doc'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas-revised — correct trigger-condition framing per Director c#4403297623

Director caught second-axis grep failure on revised canvas: my P2
reasoning #1 ("path-trigger condition for P1 is not met") was
structurally wrong. Existing tooling at HEAD substantially meets the
Director-locked 2026-04-28 trigger-condition ("someone authors the
perf-budget claim with concrete numbers and tooling"):

- docs/briefs/r3-pb-tier3-perf-budget-worker.md
- docs/audit/c1-tier3-perf-budget-readiness-matrix.md
- src/v3/compiler/benches/tier3_mirror_perf.rs
- docs/audit/c1-tier3-baseline-capture-procedure.md
- docs/audit/c1-r3-canonical-bench-host-decision-matrix.md

Plus thresholds (≤2× median, ≤5× p99) + capture discipline (N=3 min,
N=5 preferred) + canonical bench host option matrix.

P1 is bridging existing tooling to substrate (compositional-extension),
NOT multi-slice greenfield genuinely-novel pattern-5 as originally
framed. Smaller scope than canvas-finding-taxonomy pattern 5 implies.

Path-call genuinely depends on PB Mgr's R-3 (canonical CI bench host)
+ R-7 (tier3_baseline.json baseline-capture path) decisions per their
audit response at c#4403059897. Path-call DEFERRED to cross-Mgr
coordination outcome with PB Mgr (#2074); Substrate Mgr surfaces with
corrected framing this turn.

Sixth discipline-failure of cycle (mine, second-axis grep gap on
existing-tooling state); same-class as Director's first-axis grep gap
on consumer-side requirement at the prior turn. Memorialized as
two-axis verification discipline anchor.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-ValueBody-Drift-Resolution canvas — DRAFT (codegen-generation lean)

D1 substrate-shape question per Q-ValueBody-Isomorphism RATIFIED at
#828 c#4403972737. Variant-inventory readiness input from
PR #2218 (merged 2026-05-08) confirms drift: Rust 5 variants vs
substrate 3 constructors; asymmetry on Scalar+List Rust-only +
Map payload-parity-with-semantic-gap.

Two-axis verification at HEAD:
- Substrate-precedent: codegen tooling exists (regen_bootstrap_emit;
  5 _generated.rs files; regen_bootstrap binary). Pattern-3 strict-
  mirror codegen extension applies; no pattern-5 P1 procedure.
- Consumer-side requirement: V1 worker brief explicitly names mirror-
  parity-vs-codegen-generation as D1 path-pair.

Mgr lean: (b) codegen-generation. Path (a) mirror-parity perpetuates
parallel-representation debt; (b) dissolves the dual-taxonomy class
by construction (substrate canonical, Rust codegens). Map dup-key gap
handled via (ii) Rust-side post-codegen wrapping (substrate stays
minimal).

Director ratification ask: D1 (b) + D1-followup (ii).

Carrier slice path post-ratification: extend regen_bootstrap_emit;
add Scalar+List constructors to substrate; regen + remove hand-Rust
enum; handle Map dup-key per ratified followup. Worker pin fresh-pool
per same-window-dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-ValueBody-Drift-Resolution canvas amend authority cite (codex BLOCKING fix)

Director ratified (α) amendment-PR at #828 c#4404398425
post-codex-BLOCKING at PR #2222 c#4404360699.

Canvas originally cited regen_bootstrap_emit.rs as codegen authority
for ValueBody runtime mirror; corrected to scripts/regen_runtime_mirrors.py
which is the substrate→Rust runtime-mirror generator (reads substrate.dag,
emits dag_scalar_generated.rs etc.). regen_bootstrap_emit.rs is a
separate codegen system that generates bootstrap_generated.rs (bootstrap
parser/lower compile snapshot).

D1 (b) codegen-generation ratification UNCHANGED; only authority-path
cites corrected. Carrier slice path at canvas §6-step plan now references
correct runtime-mirror generator. Canvas inline notes mark amendment
location for future-reader audit trail.

8th cycle-tier framing-failure (Mgr-tier; same fine-granularity gap
parallel to Director-tier failure at c#4404256128). Two-axis verification
discipline applied at insufficient granularity (verified codegen-tooling-
exists but didn't disambiguate against bootstrap-vs-runtime-mirror systems).

Discipline anchor refinement: when canvas cites a codegen system /
tooling / authority path, identify the SPECIFIC generator/handler for
the target-file-class. Don't accept 'tooling exists' at coarse granularity.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 9, 2026
…om cluster-analysis audit + today's merges (#2399)

Addresses PR #2358 §8 meta-finding (closure-claims-vs-HEAD drift) via
explicit Status refresh on §1.8 rows. Cluster-analysis audit on main
(PR #2300 / docs/audit/r3-cluster-analysis-2026-05-09.md §1) identified
9 gates likely-promotable from DECLARED → CONSUMER_LANDED + named
specific PRs as evidence. Today's session adds 1 more (#92 via PR #2340).

Per cluster-analysis audit §1 closing note: "PM surface, not authoring:
ledger refresh is Mgr-owned per docs/r3-program-plan.md §10 cadence.
This list is input to next refresh cycle."

PM (deep-wolf-155) interpretation: Mgr-cadence-discipline holds, but
the cluster-analysis was published 2026-05-09T03:25Z + at least 9 gates
are mechanically derivable from PR-history. Authoring this sweep as
PM-tier signal-into-next-refresh; lane Mgrs review their lane's rows
in this PR before merge.

**Updates** (10 candidates):

| Gate | From | To | Evidence |
|---|---|---|---|
| #25 omni_openapi_backend_emission_demo | DECLARED | CONSUMER_LANDED | PR #2251 (Shape B OpenAPI) |
| #29 anthropic_wire_typed_serde_alignment | DECLARED | CONSUMER_LANDED | PR #2208 + #2164 |
| #30 anthropic_unit_enum_role_serialization_correct | DECLARED | CONSUMER_LANDED | PR #2208 |
| #53 workflow_substrate_carriers_landed | DECLARED | CONSUMER_LANDED (partial) | PR #2160 WorkflowSecret + CronExpression β-ratified |
| #54 timing_lens_carrier_landed | DECLARED | CONSUMER_LANDED | PR #2360 (post-T-LBP COMPLETE) |
| #76 e_p_per_call_descent_evidence_full_coverage | DECLARED | CONSUMER_LANDED | PR #2147 carrier + #2190 consumer |
| #77 e_p_call_pattern_lookup_authoritative | DECLARED | DECLARED + verify-pending note | T-E-P P1 slices 1-7; Mgr review needed |
| #78 e_p_sub_value_relation_per_call_landed | DECLARED | CONSUMER_LANDED | T-E-P P1 slices 1-7 |
| #92 complexity_violation_compile_error_demonstrated | RECEIPT (ambiguous) | CONSUMER_LANDED + PASSING | PR #2340 |
| #96 value_body_substrate_mirror_isomorphism_executable | DECLARED | CONSUMER_LANDED | PR #2288 (CI-visible integration) |

Each cite includes PR# + brief evidence summary. #77 retained as
DECLARED with verify-pending note (cluster-analysis audit said
"verify"; Mgr review recommended before promotion).

**Verification**: R4-carve dissolution discipline ratchet still passes
(32 citations, all properly annotated). No new drift introduced.

**Mgr review path**: Substrate Mgr (warm-wolf-698) reviews #29/#30/#53/
#54/#76/#77/#78/#96 lane rows. Verification Mgr (wise-bear-525) reviews
#92/#96 lane rows. Grounding Mgr (sunny-koi-893) reviews #25 lane row.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 9, 2026
…population drift (#2333)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec869202): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d26.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85a — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at gunb-ai/gunbc#2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at gunb-ai/gunbc#2181 (sha 00551a80): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at gunb-ai/gunbc#2181 (sha 4209eb7f) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at gunb-ai/gunbc#2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at gunb-ai/gunbc#2181 (sha be9a9c94): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at gunb-ai/gunbc#2181 (sha be9a9c94): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426de5 ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at gunb-ai/gunbc#2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Complexity-Composition-Layering canvas — DRAFT (factoring tested, ε precedent does NOT apply)

Director authorized canvas authoring at gunb-ai/gunbc#828 c#4402669133 as
parallel structure to Q-Cost-Composition-Layering (ε RATIFIED). Substrate-
grep on src/v3/lenses/complexity.dag at HEAD shows the factoring claim
DIFFERS from cost-lens:

- Cost-lens needed (target-agnostic shape × target-specific values)
  factoring → Rust-side composition (ε)
- Complexity-lens has NO target-specific axis; output is structural
  property of DAG topology + algebra-instance composition; substrate-
  native fully-on-.dag-side completion

Mgr provisional reading: ε precedent does NOT apply; complexity-lens
BEHAVIORAL COMPLETION is direct slice-tier substrate authoring (carrier
introduction follows SymbolicCost precedent + T-E-P P1 carrier
consumption). Director ratification ask: Q1 (factoring finding correct),
Q2 (slice-tier directly bypassing canvas), Q3 (fresh worker pin).

Cross-Mgr: Verification Mgr (#2075) pinged on v2-oracle snapshot capture
status (cross-cutting prerequisite for #1950/#1951 cementing dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LBP complexity-lens substrate-completion worker brief (Q1/Q2/Q3 RATIFIED)

Pre-authored brief for complexity-lens BEHAVIORAL COMPLETION substrate
work per Director Q1/Q2/Q3 ratification at gunb-ai/gunbc#828 c#4402714255.

Three deliverables: carrier introduction (ComplexityCost / WorkSpan /
AsymptoticClass following SymbolicCost precedent) + lens widening
(complexity.dag PROXY → COMPLETE) + T-E-P P1 carrier consumption
(DescentEvidence / CallPattern / SubValueRelation for asymptotic
classification of recursive-call behavior).

Indirect-variant dependency surfaced as worker-grep concern at slice-
authoring time (T-E-P P1 Slice 5+ pending; eager-bat-178 stream).

Cementing test (#1950) is separate downstream brief; v2-oracle snapshot
ownership pending Q4 cross-Mgr ratification.

Worker pin: fresh-pool pick at dispatch time (NOT eager-bat-178 per
Director Q3 framing; NOT fierce-ram-21 busy with cost-lens ε).

Same-window-dispatch discipline applies post-canvas-merge (PR #2197).

Pre-authored vs pre-known discipline applied per
feedback_pre_known_vs_pre_authored_briefs.md memorialized 2026-05-08.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): rewrite complexity-lens brief consuming live design authority (codex BLOCKING fix)

Codex BLOCKING (3 findings) at #2199 sha 7a8bb6dc:
1. Brief authored against missing canvas instead of reconciling with
   docs/design-complexity-lens-behavioral-completeness.md (which exists
   at HEAD with comprehensive substrate spec)
2. Producer coverage treated as optional corpus scope; should be hard
   T-E-P-Producer-Broadening prerequisite
3. Stale/non-in-repo planning authority cited; should be r3-structure.md
   row 146 (T-LBP slice 1)

All three BLOCKING findings VALID — substrate-grep-before-authoring
discipline failure on my part (feedback_substrate_grep_before_authoring
already memorialized; violated own discipline).

Rewrite delegates carrier shape, dimension wiring, and consumer rewrite
to live design doc §§1.1-1.6 verbatim:
- §1.1 SymbolicCost — already at algebra.dag; no change
- §1.2 SizeVariable — display_name enrichment
- §1.3 work_dimension + span_dimension — two AnalysisDimension instances
- §1.4 AsymptoticClass + BoundedLattice instance
- §1.5 Certainty (cost-aware composition; no lattice)
- §1.6 cost_bound_to_symbolic projection
- §1.7 ComplexitySummary record + lens widening

T-E-P P1 hard prerequisite per design's authority discipline + r3-
structure.md row 146; STOP-and-PING if T-E-P P1 not COMPLETE at slice
authoring time. Authority cites updated to live r3-structure.md row 146.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas — DRAFT (canvas-tier P1 procedure per Q6 RATIFIED)

Director Q6 RATIFIED canvas-tier-required at gunb-ai/gunbc#828 c#4403163639
for PerfWithinBaseline TestPredicate variant authoring. Three substantive
substrate-shape questions resolved:

Q1 baseline shape: (a) literal-Int rejected as strict-mirror-of-CostBounded
defeats semantic load; (b) DeclarationRef-to-stored-data composes
LensOutputEquals + data X: SymbolicCost precedent at HEAD; (c) runtime-
fixture-injection over-authors. Mgr lean (b).

Q2 ComparisonOp composition: (i) reuse existing ComparisonOp via test-
runner-side resolution matches LensOutputEquals path; (ii) new relative-
op-set introduces parallel-representation debt. Mgr lean (i).

Q3 baseline-storage scope: (α) in-scope slice authors example data; (β)
out-of-scope variant-only slice + PB consumer authors baseline data
matches existing layering. Mgr lean (β).

Combined Mgr lean: Q1(b) + Q2(i) + Q3(β) — variant authored as
compositional extension; baseline-storage is PB consumer-tier work.

Cross-Mgr: PB Mgr #2138 worker (crisp-swift-433) holds dispatch on #2204
land; T-Tier3-Dissolution #2085 R-4 prereq encoded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas REVISED (supersedes wrong-shape original)

Director disposition at gunb-ai/gunbc#828 c#4403265220 authorized
supersession after BLOCKING at PR #2209 c#4403246233 verified VALID:
original canvas conflated symbolic SymbolicCost (cost-lens substrate)
with wall-clock measured median/p99 baseline (T-Tier3 perf gate
substrate per docs/r3-structure.md:225 + :461 Director-locked 2026-04-28).

Revised canvas frames as two-path ratification:
- P1 author full perf-budget substrate in-R3 (multi-slice; pattern-5
  genuinely-novel substrate-fact-introduction)
- P2 explicitly post-R3 per Director-locked recommendation (zero in-R3
  effort; structural close per r3-structure.md:461 'R3 deliverable is
  structural close; perf is downstream')

Mgr lean: P2 — Director-locked recommendation explicit; trigger-
condition ('someone authors perf-budget claim with concrete numbers
and tooling') not met; R3 horizon constraint argues against multi-
slice perf-budget substrate adding to 5-orthogonal-dependency picture.

Original canvas at q-perf-within-baseline-canvas.md retained with
SUPERSEDED-BY header per durable-decision-record discipline.

5th discipline-failure of 2026-05-08 cycle: substrate-grep verified
substrate-precedent but missed consumer-side requirement at canonical
authority doc; Director self-flagged symmetric two-axis verification
gap; canvas-finding-taxonomy needs precondition 'consumer-side
requirement grep-verified at canonical authority doc'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas-revised — correct trigger-condition framing per Director c#4403297623

Director caught second-axis grep failure on revised canvas: my P2
reasoning #1 ("path-trigger condition for P1 is not met") was
structurally wrong. Existing tooling at HEAD substantially meets the
Director-locked 2026-04-28 trigger-condition ("someone authors the
perf-budget claim with concrete numbers and tooling"):

- docs/briefs/r3-pb-tier3-perf-budget-worker.md
- docs/audit/c1-tier3-perf-budget-readiness-matrix.md
- src/v3/compiler/benches/tier3_mirror_perf.rs
- docs/audit/c1-tier3-baseline-capture-procedure.md
- docs/audit/c1-r3-canonical-bench-host-decision-matrix.md

Plus thresholds (≤2× median, ≤5× p99) + capture discipline (N=3 min,
N=5 preferred) + canonical bench host option matrix.

P1 is bridging existing tooling to substrate (compositional-extension),
NOT multi-slice greenfield genuinely-novel pattern-5 as originally
framed. Smaller scope than canvas-finding-taxonomy pattern 5 implies.

Path-call genuinely depends on PB Mgr's R-3 (canonical CI bench host)
+ R-7 (tier3_baseline.json baseline-capture path) decisions per their
audit response at c#4403059897. Path-call DEFERRED to cross-Mgr
coordination outcome with PB Mgr (#2074); Substrate Mgr surfaces with
corrected framing this turn.

Sixth discipline-failure of cycle (mine, second-axis grep gap on
existing-tooling state); same-class as Director's first-axis grep gap
on consumer-side requirement at the prior turn. Memorialized as
two-axis verification discipline anchor.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-ValueBody-Drift-Resolution canvas — DRAFT (codegen-generation lean)

D1 substrate-shape question per Q-ValueBody-Isomorphism RATIFIED at
gunb-ai/gunbc#828 c#4403972737. Variant-inventory readiness input from
PR #2218 (merged 2026-05-08) confirms drift: Rust 5 variants vs
substrate 3 constructors; asymmetry on Scalar+List Rust-only +
Map payload-parity-with-semantic-gap.

Two-axis verification at HEAD:
- Substrate-precedent: codegen tooling exists (regen_bootstrap_emit;
  5 _generated.rs files; regen_bootstrap binary). Pattern-3 strict-
  mirror codegen extension applies; no pattern-5 P1 procedure.
- Consumer-side requirement: V1 worker brief explicitly names mirror-
  parity-vs-codegen-generation as D1 path-pair.

Mgr lean: (b) codegen-generation. Path (a) mirror-parity perpetuates
parallel-representation debt; (b) dissolves the dual-taxonomy class
by construction (substrate canonical, Rust codegens). Map dup-key gap
handled via (ii) Rust-side post-codegen wrapping (substrate stays
minimal).

Director ratification ask: D1 (b) + D1-followup (ii).

Carrier slice path post-ratification: extend regen_bootstrap_emit;
add Scalar+List constructors to substrate; regen + remove hand-Rust
enum; handle Map dup-key per ratified followup. Worker pin fresh-pool
per same-window-dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-ValueBody-Drift-Resolution canvas amend authority cite (codex BLOCKING fix)

Director ratified (α) amendment-PR at gunb-ai/gunbc#828 c#4404398425
post-codex-BLOCKING at PR #2222 c#4404360699.

Canvas originally cited regen_bootstrap_emit.rs as codegen authority
for ValueBody runtime mirror; corrected to scripts/regen_runtime_mirrors.py
which is the substrate→Rust runtime-mirror generator (reads substrate.dag,
emits dag_scalar_generated.rs etc.). regen_bootstrap_emit.rs is a
separate codegen system that generates bootstrap_generated.rs (bootstrap
parser/lower compile snapshot).

D1 (b) codegen-generation ratification UNCHANGED; only authority-path
cites corrected. Carrier slice path at canvas §6-step plan now references
correct runtime-mirror generator. Canvas inline notes mark amendment
location for future-reader audit trail.

8th cycle-tier framing-failure (Mgr-tier; same fine-granularity gap
parallel to Director-tier failure at c#4404256128). Two-axis verification
discipline applied at insufficient granularity (verified codegen-tooling-
exists but didn't disambiguate against bootstrap-vs-runtime-mirror systems).

Discipline anchor refinement: when canvas cites a codegen system /
tooling / authority path, identify the SPECIFIC generator/handler for
the target-file-class. Don't accept 'tooling exists' at coarse granularity.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: reconcile cross_target_coverage emission_path_projections post-population drift

cross_target_coverage.dag:179 + sg0_census_test.rs:355 still described
emission_path_projections as `(empty data state)` / `== []`, but the
data block at cross_target_coverage.dag:186 is populated with 41 Phase-1
rows (Rust 13 / Python 16 / Go 12). Update both comment sites to reflect
the populated state. P1 Modeling Faithfulness — comment-drift only, no
behavior change.

Surfaced by gentle-newt-665 R3 Debt-Paydown ROADMAP audit at gunb-ai/gunbc#2062;
absorbed into Substrate lane (#1939) per L6 emission_path_projections
carrier ownership.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix: pad cross_target_coverage.dag comment to preserve byte offsets

Previous comment edit changed line 179 length 76→75, shifting
SourceSpan byte offsets in bootstrap_generated.rs by 1 and breaking
regen_bootstrap --verify in CI. Pad with one extra dash to restore
original 76-char length; comment text intent unchanged.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* fix(canvas): clarify Source param doesn't carry subject identity (P2)

Reviewer flagged on PR #2333 inline review: parametric form
WorkflowObservationAnchor<BehaviorId, TimingMeasurement> would create
redundant subject-identity authority if TimingMeasurement carries
subject identity (P2 violation). Clarify Q-WAD-S2-Anchor (b) so Source
parameter is observed-payload-only; subject identity is owned solely
by Subject parameter.

In worker's actual PR #2360 shape, TimingMeasurement is variant-typed
report state (Observed { nanoseconds } | Missing | ...) and does NOT
carry subject identity — concern is theoretical there but worth
clarifying canvas language for clean Director ratification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): correct fail-closed analysis for LensEnforcement.violates signature

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:90):
LensEnforcement.violates signature is (Budget, Budget) -> Bool per
src/v3/std/lens_application.dag:100 — does NOT see raw Output.
Original canvas claim 'fail-closed: violates = Output != Observed'
was structurally wrong. Updated:

- (a) clarified: projection step (Output → Budget) must fabricate
  violating Budget for non-Observed variants (option (a)(i)) OR
  substrate-extend the violates signature (option (a)(ii)) which is
  canvas-tier and cascades across all lens consumers.
- Added option (c) reflecting worker tidy-raven-610 PR #2360 shape:
  Output folded into TimingMeasurement carrier directly, Budget
  projection handles fabrication naturally.

Status: shape ratification still pending Director per #828 c#4412018726.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): add 🟢 dissolution classification to TimingObservationOutcome variants

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:86):
proposed sum has no 🟢/🟡/🔴 dissolution receipt per INVARIANTS P5 /
modeling-discipline.md §coproduct dissolution. Worker could land
unclassified coproduct.

Added 🟢 GREEN (terminal) classification to both option (a)
TimingObservationOutcome and option (c) folded TimingMeasurement —
four variants exhaust externally-attested observation states; no
richer-source-extraction path exists at the workflow-observation
boundary. Worker .dag declarations MUST carry the 🟢 marker comment
per modeling-discipline.md:132.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): correct Q-WAD-S2-Placement to src/v3/std/ (not dsl/std/)

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:108):
recommending dsl/std/timing_lens.dag conflicts with src/v3/std/lens.dag:17-21
v3-only-carriers convention. Worker would land substrate in wrong layer.

Earlier canvas claim 'T-LBP / T-CostLens / T-LAS lens carriers all live in
dsl/std/' was factually wrong — they live in src/v3/std/ and src/v3/lenses/.
Corrected to src/v3/std/timing_lens.dag throughout. Worker PR #2360 already
placed at correct path; canvas now matches.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): make six gate #55 invariants concrete fields on anchor (P2)

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:75): the
recommended <Subject, Source> parametric shape only named type params
and didn't assign digest/producer/observer/prover/timestamp/run-id/
report-state to a single carrier — gate #55 facts wouldn't flow forward
under P2 boundary discipline.

Fixed: Q-WAD-S2-Anchor (b) now shows explicit six-invariant field
schema as concrete fields (subject/artifact_digest/producer_id/
observer_id/prover_id/attached_at/workflow_run_id/observation_outcome)
with Subject + Source as type parameters for variable parts only.
Notes worker tidy-raven-610 PR #2360 flat shape is already
gate-#55-compliant at the field level; convergence path is adding
type parameters to the flat shape (minimal rework).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): correct convergence assessment — invariant 5 split-authority in worker shape

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:96): claiming
worker's flat anchor shape gate-#55-compliant drops invariant 5
(observation_outcome / report-state) from the anchor. Worker's
TimingMeasurement variants carry report-state on the payload, not on
the anchor — splits P2 single-authority for invariant 5.

Fixed: convergence assessment now correctly identifies 5/6 invariants
on anchor + invariant 5 split. Path requires TWO edits not one:
(1) add <Subject, Source> type parameters to anchor; (2) add
observation_outcome: ObservationOutcome<Source> field to anchor itself.
This collapses Q-WAD-S2-Output (c) folded shape back to (a)(i)
separate-projection — trade-off documented (single-authority preserved
at cost of one extra type).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): reject (a)(i) Budget fabrication per P3/C-8 fail-closed (canvas:118)

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:118):
recommending projection fabricates violating Budget for non-Observed
states violates INVARIANTS P3/C-8 fail-closed discipline — erases
typed Missing/Ambiguous/Stale failure evidence into a plausible budget
value. Consumers downstream of violates can't distinguish 'budget
exceeded by observed value' from 'no observation existed'.

Fixed: (a)(i) REJECTED with explicit P3/C-8 rationale. Added (a)(iii)
Result-typed projection with auto_violate_on_left bit — smaller
substrate change than (ii) full-signature-extension. Director-tier
disposition still required for (ii) or (iii); (i) no longer a viable
path.

Convergence implications for worker PR #2360 + canvas (c) folded
shape need re-assessment in next pass — (c) sidesteps the violates
signature collision but invariant 5 split-authority (per canvas:96
fix in 960a03f98) means observation_outcome belongs on anchor not
payload, which then re-introduces the violates-Output-visibility
question via ObservationOutcome typing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): propagate (a)(i) rejection across all recommendation/status refs

Earlier commit 594a4df9c rejected (a)(i) Budget fabrication per
P3/C-8 inline review. Updated remaining 3 refs to reflect:
- Q-WAD-S2-Anchor convergence trade-off line
- Q-WAD-S2-Output recommendation: now (a)(ii)/(a)(iii) pending Director
- Q3 (c) Status line: Director call is (a)(ii)/(a)(iii) vs (c)

(a)(i) is REJECTED throughout; Director-tier LensEnforcement substrate
change unavoidable for fail-closed-correct anchor-side report-state
carriage.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): correct invariant-6 claim — fail-closed needs LensEnforcement substrate-extension

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:91): claim
'all six invariants concrete fields on anchor' was wrong — invariant 6
(fail-closed) explicitly lives at LensEnforcement.violates layer, not
on the anchor. Without Q-WAD-S2-Output (a)(ii)/(a)(iii) substrate-
extension landing, gate #55 cannot close on 5/6 — would let consumers
attach observation facts without fail-closed evidence (P2/P3 violation).

Fixed: clarified 5/6 invariants on anchor + invariant 6 dependency on
Director-tier LensEnforcement substrate-extension. Gate #55 closure
explicitly cross-linked to canvas:118 escalation thread.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): Output (a) variants wrap Source not TimingMeasurement (P2)

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:112):
Output (a) Observed{value: TimingMeasurement} would wrap the
report-state-bearing TimingMeasurement type, duplicating
identity/attestation/report-state with the anchor's invariant 5
authority. Reopens P2 split-authority.

Fixed: Observed wraps payload-only Source (e.g., TimingPayload {
nanoseconds: Int }), NOT TimingMeasurement. Per Q-WAD-S2-Anchor
revised convergence: subject identity / attestation / report-state
on anchor; payload carries only observed-value-when-present.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): split gate #55 + canonicalize TimingPayload (parent BLOCKING b526a26f)

Reviewer flagged 2 BLOCKING on PR #2333 parent review at sha b526a26f:

Finding 1 (gate #55 mixes anchor-fact + fail-closed): added gate #55a/#55b
split — #55a = anchor carrier landed (worker scope); #55b = LensEnforcement
substrate-extension landed across all lens consumers (canvas-tier separate
dispatch, owner: Substrate Mgr).

Finding 2 (TimingMeasurement overload): added Naming canonicalization
section to Carrier inventory. TimingPayload = observed-value-only;
WorkflowObservationAnchor = observation record; ObservationOutcome = report
state; TimingObservationSet = lens C (per Q1 ratification). Earlier
TimingMeasurement references deprecated.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): rewrite Carrier inventory to reflect Director ratification of worker shape

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:35): old
carrier inventory still said TimingMeasurement owns subject identity +
observer attestation, contradicting revised anchor authority. Same-day
Director re-ratification at #828 c#4412301889 reversed the canvas (b)
recommendations and ratified worker tidy-raven-610's shape as-shipped:

- TimingMeasurement = Observed | Missing | Ambiguous | Stale
  (carrier-as-report-state; owns invariant 5 via variants)
- WorkflowObservationAnchor = timing-specific concrete fields
  (Q-WAD-S2-Anchor (a) ratified; owns invariants 1-4)
- TimingObservationSet = aggregation collection
- Lens<TimingMeasurement> per-observation

Fixed: rewrote Carrier inventory to reflect Director-ratified shape;
explicit invariant ownership (anchor: 1-5; LensEnforcement: 6 via
gate #55b separate dispatch). TimingPayload canonicalization (which
contradicted Director ratification) removed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): resolve option (c) Pro/Con contradiction on signature collision

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:137):
option (c) Pro line said 'avoids violates signature collision entirely'
but lines 135/139 routed back to (a)(ii)/(a)(iii) — internal
contradiction; fail-closed obligation under P3/C-8 still ambiguous.

Fixed: rewrote (c) Pro/Con honestly — Pro = state-space discipline
(per Director's ratification reasoning); Con = does NOT sidestep
violates signature collision, still requires substrate-extension
path. Status updated to reflect Director ratification at #828
c#4412301889: (c) carrier shape ratified for worker scope (#55a);
LensEnforcement substrate-extension disposition (#55b) still pending
between (a)(ii) and (a)(iii).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(v3): LensEnforcement.auto_violate_on_left for observation-driven lenses

Per Director ratification at gunb-ai/gunbc#828 c#4412884371 + re-confirmation
at c#4413159089: extend LensEnforcement<Output, Budget> with additive
auto_violate_on_left: Bool field for observation-driven lens classes
(T-Workflow-As-Data Slice 2 timing-lens et seq.).

Substrate semantics: when Output is Result-typed (e.g.,
Result<Observed, ObservationFailure> for timing), runtime checks the
bit before calling project; on Result-Left + bit=true, enforcement
violates without fabricating a Budget value at the projection
boundary. Preserves typed failure evidence (Missing/Ambiguous/Stale/
Unobserved) per INVARIANTS P3/C-8 fail-closed discipline.

Backward-compatible additive: existing structural-static lenses
(complexity, cost, T-LAS) set the bit to false; bit is inert when
Output is not Result-typed. Updated complexity_enforcement
declaration + hand-Rust LensEnforcement struct mirror.

Closes §1.8 ledger #55 sub-gate b (LensEnforcement substrate-extension
prerequisite for fail-closed-correct enforcement on non-Observed
report states); enables T-Workflow-As-Data Slice 2 worker
(tidy-raven-610 #2359) to revise PR #2360 against the ratified
Result-typed Output shape.

Canvas authority: docs/briefs/r3-substrate-t-wad-slice-2-timing-lens-canvas.md
§"Question 3 (Q-WAD-S2-Output)" + Gate #55 closure-predicate split.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Revert "feat(v3): LensEnforcement.auto_violate_on_left for observation-driven lenses"

This reverts commit 5ec59209d1c561788a4f6f686d8d1f62daf086ef.

* fix(canvas): Q-WAD-S2-Anchor recommendation aligned to Director ratification of (a)

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:99): canvas
still recommended (b) generic anchor after Director ratified (a)
timing-specific. Competing WorkflowObservationAnchor authorities = P2
violation.

Fixed: Q-WAD-S2-Anchor recommendation rewritten to reflect Director
RATIFIED (a) per #828 c#4412301889 + c#4413322671. Mgr-tier preliminary
(b) was over-engineered (chased hypothetical second-consumer
parameterization). Invariant 5 split-authority concern resolved at
LensEnforcement layer per (a)(ii) full-signature extension (Director
c#4413284764) — violates pattern-matches Output variants directly,
no observation_outcome projection wrapper needed.

Co-Authored-By: Claude Opus 4.7 …
briansrls added a commit that referenced this pull request May 13, 2026
Director ratified Candidate (b) on PR #2820 — workflow-substrate
FileAttachment carrier extending #53 — per PM msg_52c4a707. This
sub-canvas surfaces carrier internals (type def + fields + workflow
coupling + Practice 4 + lazy-vs-eager) for next-tier ratification
per recursive feedback_substrate_shape_belongs_in_mgr_canvas.

Three candidate shapes (B-1 minimal / B-2 path-keyed / B-3 anchor+entry
pair) anchored against gate #55 WorkflowObservationAnchor precedent at
src/v3/std/timing_lens.dag:98 (already CONSUMER_LANDED).

Director anti-patterns encoded for worker review enforcement.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
* docs(briefs): S6 brief fix-forward — authority chain corrected per codex BLOCKING review on PR #2782 sha b28cf88

Earlier brief mis-cited high-level T-WAD substrate-shape framing; codex caught that the actual implementation authority for affected-set selection is:
- PR #2713 (upstream affected-set lens substrate; merged) per docs/design-affected-set-lens.md §2
- docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md in main (§1 BinaryShim consumption / §3 fail-closed / §4 selection algorithm / §5 path-regex removal invariant)
- PR #2766 harness contract + Layer 2 path-regex inventory ratchet

§0 + §1 rewritten to encode the correct authority chain, canvas §4 algorithm verbatim, and canvas §5 path-regex removal invariant. STOP conditions tightened to the actual fail-closed surfaces (PR #2713 serialization form, path-regex inventory drift).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S6 brief — surface 2-layer decomposition per canvas §6-§7 staging (substrate prerequisite + BinaryShim consumer/runner) — swift-wren-365 msg_29f68109

Earlier draft compressed both layers into one PR. swift-wren-365 surfaced (correctly) that PR #2798 in-flight is Layer 1 substrate (closure+topo over CIWorkflowDag + CiWorkflowDiff) — Layer 2 (BinaryShim consumer of PR #2713 lens output + TestClaim D(t)/Δ(t) mapping + canvas §5 path-regex removal) is a follow-on PR depending on Slice 5 BinaryShim hook per canvas §6-§7.

§1 reframed as two-layer decomposition with explicit scope boundaries. Phase A-C explicitly scoped to Layer 2. Layer 1 in-flight under PR #2798 not in this brief's scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S6 brief §4 PR-body framing + §6 reference list harmonized with §1 canvas-vs-PR-#2766-harness split — cursor APPROVE 10477 exploratory note

§4 PR body framing now distinguishes three authority types: canvas (BinaryShim consumption + selection algorithm + path-regex removal) + upstream lens (PR #2713 / design-affected-set-lens.md) + harness/ratchet (PR #2766). §6 reference list expanded similarly. Removes the residual 'PR #2766 substrate authority' phrasing that conflicted with §1's three-source split.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #62 file-ingestion substrate-shape canvas

Surfaces the substrate-shape question for §1.8 row #62
substrate_gap_file_ingestion_closed before brief authoring.

bright-otter-731 was auto-spawned on this gate without an
authored brief and surfaced a clean audit (no include_str! at
HEAD in dsl/; PR #2819 read_utf8_file candidate shape held in
draft). §4.3 line 505 frames closure as workflow_substrate
extension to file-attachment (Candidate B), but PR #2819 implements
compile-time UTF-8 read (Candidate A) — parallel-authority risk.

This canvas frames the candidate shapes (A/B/C/d) for Director-or-
Substrate-Mgr-tier ratification before brief authoring proceeds.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #62 FileAttachment carrier-internals sub-canvas

Director ratified Candidate (b) on PR #2820 — workflow-substrate
FileAttachment carrier extending #53 — per PM msg_52c4a707. This
sub-canvas surfaces carrier internals (type def + fields + workflow
coupling + Practice 4 + lazy-vs-eager) for next-tier ratification
per recursive feedback_substrate_shape_belongs_in_mgr_canvas.

Three candidate shapes (B-1 minimal / B-2 path-keyed / B-3 anchor+entry
pair) anchored against gate #55 WorkflowObservationAnchor precedent at
src/v3/std/timing_lens.dag:98 (already CONSUMER_LANDED).

Director anti-patterns encoded for worker review enforcement.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #62 FileAttachment worker brief (Refined-B-1 ratified)

Director ratified Refined-B-1 carrier shape with full §8 Q1-Q6
dispositions + 7 anti-patterns per PM msg_bc8c23f6 (relaying Director
msg_61e302c6). Worker brief authored with:

- Exact 5-field carrier (subject_node + content_digest + producer_id +
  workflow_run_id + attached_at_ns) — strict 5-of-7-subset of #55
  WorkflowObservationAnchor
- Q1-Q6 dispositions encoded verbatim for reviewer enforcement
- 7 anti-patterns receipt-of-compliance requirement
- Phase A (carrier) / Phase B (ratchet test) / Phase C (existence-proof
  use case) / Phase D (ledger update) staging
- 5 STOP conditions including consumer-evidence-blob-store gap
- Workflow blob-store substrate flagged as Wave-2 sub-canvas-2 trigger
  (forward-looking, NOT blocking this brief)

Brief is DISPATCH-READY. PR #2819 stays held as Candidate A drift
(anti-pattern #1).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
…ape (b) FileAttachment extending #53 per Director msg_09df44c6 (#2821)

* docs(r3): fix shell-escape artifact + arithmetic drift (cursor #10531 APPROVE_WITH_COMMENTS)

cursor review #10531 (APPROVE_WITH_COMMENTS) caught 2 small fixes:

1. **:330 Origin field** — literal `Director'\''s` shell-escape artifact (leaked from heredoc authoring) → corrected to `Director's`. P1 documentation-faithfulness.

2. **:205 parenthetical** — "was 97; +6 T-WAD FULL R3 elevation" only sums to 103, not the headline 104. Added "+1 Miss-class dissolution 2026-05-12" so arithmetic reconciles: 97 + 6 + 1 = 104. P2 single-authority consistency.

Both small fixes; no scope change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): row #104 — codex BLOCKING #4276876807 scope-gap fix (Part A predicate 64→70 across 6 files)

codex BLOCKING on merged PR #2804 (review 4276876807 @ 23:10:31Z):
"The row scopes the migration from a relayed count instead of deriving
it from its own terminal grep predicate → include every current Part A
match in the phase plan, or explicitly narrow the predicate and route
the excluded Lookup< sites to a separate gate. ⚠️ One blocking scope
gap in the new closure gate would leave the terminal predicate red
after the documented migration."

Verified at `7a7c19d3` HEAD: `git grep -nE "Lookup<" src/v3/lenses/
src/v3/std/` = 70 matches (NOT 64 as Director's relay msg_cefcbe05 had it):
- cost.dag: 25
- complexity.dag: 25
- infer_helpers.dag: 3 (incl. active `-> Lookup<DeclarationId>` :141)
- algebra.dag: 3 (incl. canonical `miss_symbolic_cost_lookup()` :225
  + `hit_symbolic_cost_lookup` :229)
- substrate.dag: 3
- lookup.dag: 11

Critical: `algebra.dag:225 miss_symbolic_cost_lookup()` is THE
constructor at the bind layer that emits the 15 Miss returns
Director's complexity-lens dump (msg_32a3775e) originally surfaced —
it being out-of-scope contradicted the row's own Origin statement.

Fixes:
1. Scope at HEAD: 64 → 70 across 6 files (was 4); added
   `algebra.dag` 3 + `infer_helpers.dag` 3.
2. Bundled-migration Phase 2 reframed as "monomorphized accessor
   sweep" (substrate 3 + algebra 3 + infer_helpers 3 = 9 sites; line
   anchors added).
3. Origin trailer: appended PR #2807 scope-correction note + codex
   BLOCKING #4276876807 attribution; flagged msg_cefcbe05 as superseded.

Part A terminal predicate unchanged; the migration plan now matches it.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §1.8 row #62 status refinement — gate #62 file-ingestion ratified shape (b) FileAttachment carrier extending #53

Director ratification msg_09df44c6 on canvas PR #2820 + §4.3 line 505 verbatim authority. Disposition (b) wins per:
- §4.3 line 505 explicitly names "T-Workflow-As-Data file-ingestion substrate (workflow_substrate_carriers_landed extended to file-attachment)" as closure path
- Lane fit: gate #62 is T-WAD per §1.8; carrier extension is canonical T-WAD pattern
- Sibling-carrier precedent: WorkflowSecret + CronExpression in #53 establish the pattern
- Construction-first: model workflow concept, not compile-time intrinsic
- No parallel-authority: (a)+(b) coexistence violates §P1 single-authority

Status: DECLARED → DECLARED-with-ratified-shape-and-sub-canvas-pending. Sub-canvas (FileAttachment carrier-shape: type def + fields + workflow-context coupling) queued for Substrate Mgr per recursive feedback_substrate_shape_belongs_in_mgr_canvas. Worker dispatch follows sub-shape ratification.

PR #2819 STAND DOWN per Director disposition (msg_09df44c6); bright-otter-731 audit (msg_e85224dc) preserved as diagnostic-trail input.

Anti-patterns enumerated for post-ratification reviewers:
- Compile-time read_utf8_file-equivalent (Candidate A drift)
- FileAttachment landed without #53 sibling-carrier alignment
- Legacy include_str! bridges preserved alongside FileAttachment (§P5 atomic-migration violation)

include_str! audit at HEAD (Director-verified): no matches — gate is forward-looking, not retire-existing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §1.8 row #62 — carrier-internals Refined-B-1 ratified (Director sub-canvas disposition msg_61e302c6)

Director-ratified FileAttachment carrier-internals shape per msg_61e302c6 on PR #2820 sub-canvas (commit 4a96d33). Status: DECLARED-with-ratified-shape-and-sub-canvas-pending → DECLARED-with-ratified-shape-and-carrier-internals-ratified.

Refined-B-1 carrier (5-of-7 strict subset of #55 WorkflowObservationAnchor):
  FileAttachment {
    subject_node:    NodeId
    content_digest:  ContentHash
    producer_id:     WorkflowProducerId
    workflow_run_id: WorkflowRunId
    attached_at_ns:  Nanoseconds
  }

Drops observer_id + prover_id (timing-observation-specific epistemological roles; not applicable to file attachment).

Q1-Q6 dispositions verbatim from Director:
- Q1 carrier shape: Refined-B-1 (B-2 + B-3 disqualified)
- Q2 encoding field: ABSENT default; if needed use `Encoding` from `dsl/std/encoding.dag`
- Q3 `WorkflowAssetPath` branded nominal: NOT introduced (digest-only canonical)
- Q4 workflow-coupling: deferred to worker brief / consumer evidence (#55 List analogy)
- Q5 eager-vs-lazy: EAGER confirmed
- Q6 `AttachmentEncoding`: Practice-4 RED — dissolved to existing `Encoding` lattice

Director grep-verified at HEAD: #55 anchor structure at timing_lens.dag:98-106, 5 branded nominals at dsl/std/types.dag:324-331, dsl/std/encoding.dag exists with 6-variant `Encoding` BoundedLattice, no FileAttachment/AttachmentEncoding/WorkflowAssetPath at HEAD (no parallel-authority risk).

Anti-patterns extended from 3 (top-level) to 7 (sub-canvas additions):
- (4) AttachmentEncoding duplicating dsl/std/encoding.dag — Practice-4 RED dissolution
- (5) path field on FileAttachment — parallel-rep vs canonical digest
- (6) List<FileAttachment> on Job/Step preemptively — consumer-evidence-required
- (7) Carrier deviation from Refined-B-1 5-field structure — strict subset of #55

Cascade:
- Sub-canvas closure: carrier-internals ratified
- Worker brief authoring: 5-field carrier + sibling-alignment receipt + bootstrap ratchet test + existence-proof use case
- Sub-canvas-2 trigger (forward-looking): workflow blob-store substrate (content_digest -> bytes resolution); Substrate Mgr authors after Refined-B-1 lands; NOT blocking carrier-internals ratification

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
* docs(briefs): S6 brief fix-forward — authority chain corrected per codex BLOCKING review on PR #2782 sha b28cf88

Earlier brief mis-cited high-level T-WAD substrate-shape framing; codex caught that the actual implementation authority for affected-set selection is:
- PR #2713 (upstream affected-set lens substrate; merged) per docs/design-affected-set-lens.md §2
- docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md in main (§1 BinaryShim consumption / §3 fail-closed / §4 selection algorithm / §5 path-regex removal invariant)
- PR #2766 harness contract + Layer 2 path-regex inventory ratchet

§0 + §1 rewritten to encode the correct authority chain, canvas §4 algorithm verbatim, and canvas §5 path-regex removal invariant. STOP conditions tightened to the actual fail-closed surfaces (PR #2713 serialization form, path-regex inventory drift).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S6 brief — surface 2-layer decomposition per canvas §6-§7 staging (substrate prerequisite + BinaryShim consumer/runner) — swift-wren-365 msg_29f68109

Earlier draft compressed both layers into one PR. swift-wren-365 surfaced (correctly) that PR #2798 in-flight is Layer 1 substrate (closure+topo over CIWorkflowDag + CiWorkflowDiff) — Layer 2 (BinaryShim consumer of PR #2713 lens output + TestClaim D(t)/Δ(t) mapping + canvas §5 path-regex removal) is a follow-on PR depending on Slice 5 BinaryShim hook per canvas §6-§7.

§1 reframed as two-layer decomposition with explicit scope boundaries. Phase A-C explicitly scoped to Layer 2. Layer 1 in-flight under PR #2798 not in this brief's scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S6 brief §4 PR-body framing + §6 reference list harmonized with §1 canvas-vs-PR-#2766-harness split — cursor APPROVE 10477 exploratory note

§4 PR body framing now distinguishes three authority types: canvas (BinaryShim consumption + selection algorithm + path-regex removal) + upstream lens (PR #2713 / design-affected-set-lens.md) + harness/ratchet (PR #2766). §6 reference list expanded similarly. Removes the residual 'PR #2766 substrate authority' phrasing that conflicted with §1's three-source split.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #62 file-ingestion substrate-shape canvas

Surfaces the substrate-shape question for §1.8 row #62
substrate_gap_file_ingestion_closed before brief authoring.

bright-otter-731 was auto-spawned on this gate without an
authored brief and surfaced a clean audit (no include_str! at
HEAD in dsl/; PR #2819 read_utf8_file candidate shape held in
draft). §4.3 line 505 frames closure as workflow_substrate
extension to file-attachment (Candidate B), but PR #2819 implements
compile-time UTF-8 read (Candidate A) — parallel-authority risk.

This canvas frames the candidate shapes (A/B/C/d) for Director-or-
Substrate-Mgr-tier ratification before brief authoring proceeds.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #62 FileAttachment carrier-internals sub-canvas

Director ratified Candidate (b) on PR #2820 — workflow-substrate
FileAttachment carrier extending #53 — per PM msg_52c4a707. This
sub-canvas surfaces carrier internals (type def + fields + workflow
coupling + Practice 4 + lazy-vs-eager) for next-tier ratification
per recursive feedback_substrate_shape_belongs_in_mgr_canvas.

Three candidate shapes (B-1 minimal / B-2 path-keyed / B-3 anchor+entry
pair) anchored against gate #55 WorkflowObservationAnchor precedent at
src/v3/std/timing_lens.dag:98 (already CONSUMER_LANDED).

Director anti-patterns encoded for worker review enforcement.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #62 FileAttachment worker brief (Refined-B-1 ratified)

Director ratified Refined-B-1 carrier shape with full §8 Q1-Q6
dispositions + 7 anti-patterns per PM msg_bc8c23f6 (relaying Director
msg_61e302c6). Worker brief authored with:

- Exact 5-field carrier (subject_node + content_digest + producer_id +
  workflow_run_id + attached_at_ns) — strict 5-of-7-subset of #55
  WorkflowObservationAnchor
- Q1-Q6 dispositions encoded verbatim for reviewer enforcement
- 7 anti-patterns receipt-of-compliance requirement
- Phase A (carrier) / Phase B (ratchet test) / Phase C (existence-proof
  use case) / Phase D (ledger update) staging
- 5 STOP conditions including consumer-evidence-blob-store gap
- Workflow blob-store substrate flagged as Wave-2 sub-canvas-2 trigger
  (forward-looking, NOT blocking this brief)

Brief is DISPATCH-READY. PR #2819 stays held as Candidate A drift
(anti-pattern #1).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 SymbolicCost Tier 1 carrier-extension canvas

Director ratified Path A Tier 1 on 2026-05-13 (PM msg_4fd650b7
relaying msg_ad5e934d) with 5 sub-canvas questions Q1-Q5 routed
to Mgr. This canvas surfaces dispositions on each for next-tier
ratification before worker brief authoring.

Mgr recommendations:
- Q1 Rational ordering: c (layered OrderedField + lazy migration)
- Q2 Linear-vs-Polynomial: Y (collapse to PolynomialCost(degree=1)
  per §P5; net 10 variants not 11)
- Q3 algebra rules: tabulated 10 new interaction rules; PolyLog
  reserved for log^k only (n log n stays composite); Factorial²
  = UnknownCost (Tier-2 R4-deferral receipt)
- Q4 STOP SIGNAL: re-resets at 11th variant (or 12th if Tier-2)
- Q5 carrier-shape canvas: this document
- §8 Tier-2 mechanism: defer to R4 (InverseAckermann doesn't
  fit IteratedAlgebra; no uniform compositional surface)

5 Director anti-patterns encoded + 2 Mgr-derived for worker review.

Gates on §1.8 row #105 PR #2824 landing + Director ratification of
§12 questions before worker dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 SymbolicCost Tier 1 worker brief (canvas ratified)

Director ratified canvas PR #2828 Q1-Q5 + §8 Tier-2 disposition per
PM msg_a055c38b relaying msg_d86a5987. Worker brief encodes ratified
shape as single coordinated PR with 7 sub-phases:

- Phase A: OrderedField<T> witness landing + Rational re-declaration
- Phase B: STOP SIGNAL rewrite (cap at 11)
- Phase C: SymbolicCost carrier reshape (Q2-Y collapse Linear)
- Phase D: algebra interaction rules (13-rule table; §5.1 composite
  for poly·log; §5.2 (n!)² → UnknownCost verbatim)
- Phase E: bootstrap ratchet test
- Phase F: cost-lens consumer migration (LinearCost → PolyCost(d=1))
- Phase G: §1.8 row #105 ledger update

7 anti-patterns + 5 reviewer ratchets + 6 STOP conditions encoded.
DISPATCH GATES on PR #2824 (row anchor) AND PR #2828 (canvas) both
merged; brief is ready when cascade clears.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — encode invariants in type carriers (codex BLOCKING fix)

codex BLOCKING #10726 on PR #2828 (Practice 2 + Practice 6 violations):
1. Worker brief moved invariants (degree>0, exponent≥1, base≥2) into
   fold normalizer instead of carrier — admits illegal states
2. Canvas §187 said 'Rational ≥ 0' while worker said 'degree > 0' —
   split authority on the invariant

Both findings valid. Fix:

Canvas §6 STOP-SIGNAL text:
- Replaced 'PolynomialCost(Rational ≥ 0)' with 'PolynomialCost { degree:
  PositiveRational }' + adds PolyLogCost { exponent: PositiveInt } +
  ExponentialCost { base: IntAtLeastTwo } verbatim
- Adds new "Type-level refinement carriers" subsection citing
  DegreeAtLeastTwo precedent (algebra.dag:171-173)

Worker brief §5:
- New §5.0 introduces PositiveRational, PositiveInt, IntAtLeastTwo as
  Peano-style inductive carriers (strict-mirror of DegreeAtLeastTwo)
- §5.1 SymbolicCost now uses these refinement types for fields:
  PolynomialCost.degree: PositiveRational
  PolyLogCost.exponent: PositiveInt
  ExponentialCost.base: IntAtLeastTwo
- Removed the "refinements live in fold normalizer" paragraph

Illegal states (degree≤0, exponent≤0, base≤1) now structurally
unrepresentable per Practice 2 + Practice 6.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — fix variant arithmetic 10 → 9 per operator BLOCKING

Operator BLOCKING on PR #2828 canvas:135 caught real arithmetic error:
Q2-Y removes LinearCost (-1) and adds 3 NEW variants (PolyLogCost +
ExponentialCost + FactorialCost), so net is 7 - 1 + 3 = 9, not 10.
PolynomialCost is PROMOTED (degree type changed Rational), NOT added as
a new variant — that was the counting mistake.

Confirmed variant set per canvas §6 + worker §5.1:
1. ConstantCost
2. PolynomialCost { degree: PositiveRational }
3. PolyLogCost { exponent: PositiveInt }
4. LogCost
5. ProductCost
6. SumCost
7. ExponentialCost { base: IntAtLeastTwo }
8. FactorialCost
9. UnknownCost

Total: 9 variants. Confirmed.

All references updated:
- "10 variants" → "9 variants"
- "11th variant" → "10th variant" (STOP-SIGNAL trigger threshold)
- "Net 7 → 10/11" → "Net 7 → 9"
- "variant cap at 11" → "variant cap at 10"
- "10 ratified + 1 trigger" → "9 ratified + 1 trigger"
- "STOP-SIGNAL re-reset to 11" → "STOP-SIGNAL re-reset to 10"

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — Q1 premise correction per operator BLOCKING canvas:48

Operator BLOCKING #2 on PR #2828 canvas:48 caught real authority error:
Field<T> at dsl/std/algebra.dag:294 ALREADY has compare: fn(T,T)->Ordering.
The canvas claim "Rational supports add+mul+inverse, NOT order" was wrong —
Field carries the foundational order primitive. Introducing OrderedField<T>
would create parallel order authority.

This invalidates the original Q1-c ratification premise (PM msg_a055c38b).
Q1 disposition needs RE-RATIFICATION:

Revised candidate set (canvas §3 REVISED):
- Q1-α (Mgr-rec): use existing Field.compare via Rational; lt/le/gt/ge as
  cost-lens-local free functions. Zero new substrate.
- Q1-β: extend Field<T> in-place with 6 derived predicate fields. Larger
  blast radius; mirrors OrderedRing predicate set on Field directly.
- Q1-γ: OrderedField as Field-superset via type-level inheritance. Requires
  DSL grammar prerequisite (worker grep-verifies).

Worker brief Phase A regenerated under Q1-α assumption (smallest scope):
- NO OrderedField type introduction
- NO Rational re-declaration
- Cost-lens-local rational_lt/le/gt/ge/max helpers derived from
  rational.compare (existing Field operation)

Anti-pattern #6 reworded: "Parallel order authority — adding any new
OrderedField or equivalent witness when Field.compare already exists at
algebra.dag:294 (Q1 premise-corrected anti-pattern)".

Canvas + worker brief both note re-ratification required; if Director
prefers Q1-β or Q1-γ, Phase A regenerates.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — fix unsound multiplicative absorption rules per operator BLOCKING worker:140

Operator BLOCKING caught real asymptotic-analysis error: multiplicative
absorption rules like `PolyCost(d) · ExpCost(c, v) = ExpCost(c, v)` are
UNSOUND. n^d · c^n / c^n = n^d is unbounded as n → ∞, so n^d · c^n is
NOT O(c^n) strictly. Same problem with FactorialCost · PolyCost and
FactorialCost · ExpCost.

Fix: multiplicative absorption rules removed; replaced with composite
ProductCost retention:
- PolyCost(d) · ExpCost(c, v) → ProductCost([PolyCost(d), ExpCost(c, v)])
- FactorialCost(v) · PolyCost(d) → ProductCost([FactorialCost, PolyCost(d)])
- FactorialCost(v) · ExpCost(c, v) → ProductCost([FactorialCost, ExpCost])

ADDITIVE dominance rules unchanged (those ARE sound — n^d + c^n = O(c^n)
because dominant term wins; only multiplicative absorption is unsound).

Both canvas §5 + worker brief §6 rule tables updated.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — Q1-α Director-RATIFIED; add 6th anti-pattern

Director re-ratified Q1 to Q1-α per msg_676ad4e7 (supersedes
msg_d86a5987 Q1-c), retraction explicit. Updates:

Canvas + worker brief §3:
- "PENDING re-ratification" framing removed
- Q1-c rejection cites INVARIANTS P1 + row #24 + Q-MachineConstraint-Carrier
- Q1-β + Q1-γ rejections documented (Director rationale verbatim)

Anti-patterns:
- NEW Director-ratified #6: "Introducing parallel ordered-algebraic-structure
  carriers (Ordered<X>) when underlying carrier already provides compare:
  fn(T,T) -> Ordering"
- NEW Mgr-derived #7: "Multiplicative absorption rules where one variant
  absorbs another asymptotically" (operator BLOCKING worker:140 retained as
  permanent anti-pattern receipt)

Canvas: 6 Director + 2 Mgr-derived = 8 total
Worker brief: 8 anti-patterns total (matches canvas)
PR body framing template + reviewer ratchet count updated 7 → 8

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — refinement types for PolyLogExponent + ExponentialBase per operator BLOCKING PR #2824:333

Operator BLOCKING #4 on PR #2824 (relayed via PM msg_92bc8538):
- PolyLogCost { exponent: Int } admits exponent=0 (ConstantCost dup),
  exponent=1 (LogCost dup), negative; cannot represent log^7.5 (AKS
  Tier-1 case)
- ExponentialCost { base: Int } admits base=0/1 (degenerate/ConstantCost)
- Same Practice 2/6 illegal-states-unrepresentable class as prior codex
  BLOCKING (commit 3d21cb7)

Fix:
- NEW refinement carrier ExponentialBase (Int ≥ 2; renames IntAtLeastTwo
  to PM-ledger naming per row #105 commit 8049ccd)
- NEW refinement carrier PolyLogExponent (Rational > 1; admits 7.5/AKS)
- PolyLogCost.exponent: PositiveInt → PolyLogExponent
- ExponentialCost.base: IntAtLeastTwo → ExponentialBase
- PositiveRational unchanged (PolynomialCost.degree already correctly
  bounded > 0 by this carrier)

7th Director-pending anti-pattern added: "Tier-1 variant constructed
with raw Int/Rational bypassing refinement type" (matches PM's row #105
ledger 7th anti-pattern per PR #2824:8049ccde4).

Updated counts:
- Canvas §10: 6→7 Director + 2 Mgr-derived
- Worker brief §11: 8→9 anti-patterns total

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 worker brief — pre-wire P5 receipt requirement per claude APPROVE 10773

claude review 10773 exploratory observation (non-blocking): when worker
authors symbolic_cost_tier1_carrier_test.rs, INVARIANTS P5 requires
explicit single checkable receipt (deletion / SG-0 census shrink /
named-lane deferral) in PR body. Pre-wire so worker doesn't re-derive.

Added §13 verification bullet: canonical receipt is Phase F cost-lens
consumer migration (deletes LinearCost variant + collapses fallback
dispatch paths) — that net hand-Rust deletion is the P5 receipt for the
new test file.

Also corrected refinement carrier name list (was: PositiveRational/
PositiveInt/IntAtLeastTwo; now: PositiveRational/PositiveInt/
ExponentialBase/PolyLogExponent matching the post-d93e2eaffe naming).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 worker brief — address codex BLOCKING 014544f findings 2/3/4

codex review 014544f surfaced 4 BLOCKING findings (sha pre-d93e2eaffe).
Findings 1 + partial-2 covered by intervening d93e2ea (refinement
types). Residual findings 2/3/4 addressed in this commit:

Finding 2 — refinement-mixed-with-product on PolyLogExponent:
- Previous shape was `{ numerator, denominator }` with textual "numerator
  > denominator" invariant — exact refinement-mixed-with-product pattern
  codex forbids
- New inductive shape: PolyLogExponentSuccessor | PolyLogExponentFractional
  with FractionalPart in (0, 1] structurally; whole ≥ 1 + fraction > 0
  yields value > 1 by carrier shape
- HARD STOP added: do NOT author as record-with-comment-invariant
- Worker grep-verifies DSL refinement support; if not available, ratify
  inductive shape pre-authoring

Finding 3 — cross-variable dominance gap:
- §6 algebra rules table prefaced with explicit "Variable-scoping
  precondition" — rules assume same-variable operands; different-variable
  operations preserve as SumCost/ProductCost composite, not folded by
  dominance
- Cross-variable dominance explicitly named undefined within Tier-1
  substrate (Tier-2 / polynomial-multivariate scope post-R3)

Finding 4 — P5 receipt category specificity:
- §13 verification bullet now requires "exactly ONE P5 receipt category
  with concrete path + LOC count" (not narrative)
- 3 categories enumerated: (a) hand-Rust deletion + LOC; (b) SG-0 census
  shrink + delta; (c) T-PB-B ROADMAP row + dissolution-trigger
- Phase F LinearCost removal noted as LIKELY (a) source but worker MUST
  measure actual numbers, not assume narrative-equivalence

Finding 1 (refinement-over-existing-Rational vs fresh records) surfaces a
refinement-mechanism canvas question; routed to PM/Director (no fix in
this commit; the residual product-shape for PositiveRational is preserved
pending Director disposition on substrate-refinement-mechanism).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — fix FactorialCost dominance over-reach per operator BLOCKING worker:158

Operator BLOCKING: 'FactorialCost(v) + anything = FactorialCost(v)' rule
would erase UnknownCost (conservative-top) and incomparable SizeVariable
dimensions, violating P2/P3.

Fix: expand FactorialCost addition rule from single 'anything' catch-all
to per-variant explicit enumeration:
- FactorialCost + same-variable cost (Factorial/Exp/Poly/PolyLog/Log/
  Constant) → FactorialCost (absorption valid)
- FactorialCost + UnknownCost → SumCost composite (UnknownCost is
  conservative-top per algebra.dag; NEVER absorbed)
- FactorialCost + FactorialCost different-variable → SumCost composite
  (cross-variable undefined per §6 precondition)

Same-variable precondition from prior commit (c787f75 finding #3 fix)
now explicitly applied per-rule for the FactorialCost row.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — refinement mechanism IS ratified; reshape carriers per PM msg_a52ed981

PM-grep correction (msg_a52ed981): substrate refinement-mechanism `type
X = Y where predicate` is ALREADY RATIFIED at HEAD per gunbc#828
issuecomment-4390333451 Path 3 + Director Option 2. Mgr missed grep-
verifying this when authoring path (i)/(ii) framing — same discipline
class as feedback_grep_substrate_before_naming_ratification.

Precedent: dsl/std/integer.dag:181 (`PositiveInt = Nat where gt_zero`).
KNOWN_PREDICATES registry at lower.rs:798-862:
  range / non_empty / brand / gt_zero / unicode_scalar

Reshape (worker brief §5.0 + canvas §6):
- PositiveRational = Rational where gt_zero (REQUIRES gt_zero
  allowed_carriers extension to include Rational — Phase A atomic)
- ExponentialBase = Int where range(min: 2) (IMMEDIATELY available;
  range predicate has Int in allowed_carriers)
- PolyLogExponent = Rational where gt_one (REQUIRES NEW gt_one
  predicate; allowed_carriers Rational + Int; mirrors gt_zero shape;
  Phase A atomic)
- PositiveInt reuses existing dsl/std/integer.dag:181 declaration

ZERO new authority introduced. P1 single-authority + Practice 4 + Q-
MachineConstraint-Carrier "no dual representations" all satisfied via
refinement over canonical Rational/Int carriers.

NEW Mgr-derived anti-pattern #8 added: parallel rational-number
carriers when refinement-mechanism is available (PM-grep-corrected per
msg_a52ed981 + codex 014544f finding #1).

Phase A KNOWN_PREDICATES extensions:
1. gt_zero allowed_carriers + Rational
2. New gt_one predicate (Rational + Int; Bare arg)
Both atomic with carrier landing per §P5.

HARD STOP added: do NOT author fresh records/inductive sums when
refinement is available.

Anti-pattern counts: canvas §10 → 7 Director + 3 Mgr-derived = 10;
worker brief §11 → 10 anti-patterns total.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 canvas/worker — cursor 10801 stale-cite cleanup

Cursor review 10801 (PR #2828) — 6 stale-ratification cites cleaned to
the Q1-α / 9-variant ratified state:

Canvas (PR #2828):
- L13-14 front matter: Field<T>/Rational "no order" → carries compare
  (Director ratified Q1-α via existing Field.compare; line ref :287→:294)
- §6 L216 variant count: "10 post-Q2-Y" → "9 post-Q2-Y" (matches §5 L153
  and Q2-Y disposition; PolynomialCost.degree promotion is not a new
  variant)
- §6 algebra bullets: Q1-c OrderedField.add/compare → Field.add/compare
  on Rational + rational_max lens-local helper (Q1-α)
- §12 Q1 Mgr-rec: stale "c — OrderedField" replaced with full ratified
  Q1-α/Q2-Y/Q3/Q4/Q5/§8 disposition block as audit trail
- §13 reference list: Field<T> "no order" + Q1-c cite → Q1-α via compare

Worker brief:
- §7 phase E receipt: "10 variant count" / "All 10 variant names" → 9
- §10 STOP #3: "Q1-c re-declaration target" → "Q1-α refinement target"
- §14 out-of-scope: "Q1-c lazy migration" → Q1-α (Field unchanged)
- §15 PR body template: "Companion substrate (Q1-c)" → (Q1-α)
- §11 anti-patterns: duplicate #8 numbering fixed → renumber to 1-10
- §16 reference: feedback_strict_mirror Q1-c → Q1-α discipline

INVARIANTS P2 single-authority restored across both briefs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 canvas — fix §10 Mgr-derived duplicate #8 numbering

Per claude/claude-opus-4-7 review 10819 cosmetic note: Mgr-derived
anti-patterns had 7,8,8 → renumber to 8,9,10 (continuing from
Director-enumerated 1-7). Matches the §11 worker brief enumeration.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 worker — fix Phase E sample-test multiplicative absorption

Codex REQUEST_CHANGES review 10837: worker brief §7 line 225 sample test
asserted ExpCost(2,n) · PolyCost(d) collapses to ExpCost(2,n), which
contradicts §6 algebra + anti-pattern #9 (multiplicative cross-class
absorption is unsound; only ProductCost composite is correct).

Fix-forward: corrected sample to assert ProductCost composite under
multiplication; added the additive-sound sibling test (ExpCost + PolyCost
DOES absorb to ExpCost) so both directions of the SUM-sound vs
PRODUCT-unsound asymmetry are receipt-tested.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 canvas — codex 10852 two contradictions in dispatch artifact

Codex REQUEST_CHANGES review 10852 — both findings load-bearing:

1. §5 L172 FactorialCost rule: "FactorialCost(v) + anything = FactorialCost(v)"
   contradicted worker brief's per-variant rules (preserve composites for
   UnknownCost + cross-variable FactorialCost(w)). Expanded canvas table
   to match worker:
   - Same-variable Tier-1-below: absorb to FactorialCost(v)
   - Cross-variable FactorialCost(w): SumCost composite
   - + UnknownCost: SumCost composite (conservative-top, never absorbed)
   - + SumCost/ProductCost composites: distribute and re-fold per §6
   Mirrors operator BLOCKING #5 fix to worker brief (commit adb8417).

2. §5.1 L183 n log n shape: "ProductCost([LinearCost(n), LogCost(n)])"
   reintroduced the LinearCost variant dissolved by ratified Q2-Y.
   Corrected to "ProductCost([PolynomialCost { var: n, degree: 1 },
   LogCost(n)])" — post-Q2-Y collapse via PolynomialCost(degree=1).

INVARIANTS P2 single-authority restored across canvas + worker for both
fold rules. Anti-pattern §11 #10 (LinearCost-consumer paths preserved)
no longer self-violated by the canvas guidance.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 worker — reconcile authority chain (codex 48328e4)

Codex BLOCKING review sha 48328e4: worker brief frontmatter / authority
chain / §9 ledger update / §15 PR body template cited the pre-Q1-α
ratification msg_d86a5987 alone, without msg_676ad4e7 (Q1-α supersession)
reconciliation. The substantive carrier + algebra fixes were clean but
the authority chain leaked the superseded shape.

Fix-forward: every load-bearing authority cite (frontmatter, §0 status,
§2 inputs ratification line, §4 cite-in-comment-block, §9 row-#105 ledger
update text, §13 PR body cite list, §15 PR template, §16 reference) now
cites the **composite ratification**:

  PM msg_a055c38b relaying Director msg_d86a5987 (Q2-Q5 + §8 base)
  RECONCILED BY Director msg_676ad4e7 (Q1-α supersedes prior Q1-c)

Worker dispatches on this composite — not the pre-Q1-α msg_d86a5987 alone.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — Director scope-extension msg_2c1bfb0e (signed Rational)

Director RATIFIED scope-extension on PR #2828 (msg_2c1bfb0e via PM
msg_e5ed6db8 2026-05-13) per operator directive: PolynomialCost.degree
admits signed Rational (arbitrary roots + inverse/decay coverage), no
where-refinement. Q6 dominance ordering + Q7 SymbolicCost preserves full
expression both ratified; new anti-pattern #11 forbidding parallel
InverseCost/ReciprocalCost variants.

Canvas (PR #2828) updates:
- §1 PROMOTE: PolynomialCost.degree = signed Rational (no refinement);
  subsumes negative degrees for asymptotic-decay
- §4 Q2-Y candidate: drop "where degree > 0"; plain Rational
- §6 refinement-carriers: PositiveRational DROPPED (struck-through with
  Director cite); ExponentialBase + PolyLogExponent unchanged
- NEW §6.1 Q6 asymptotic-dominance ordering verbatim Director conjecture
  (reverse-sign-convention via Field.compare; Q1-α authority)
- NEW §6.2 Q7 SymbolicCost preserves full expression; Big-O is derived
  operation (dominant_term / asymptotic_class)
- §10 anti-pattern #11: no parallel InverseCost/ReciprocalCost when
  carrier-extension dissolves question
- §12 ratifications Q6 + Q7 added; Practice 4 GREEN per Director
  pre-emption

Worker brief updates:
- §1 PROMOTE: signed Rational, no refinement
- §5.0 PositiveRational refinement DROPPED with struck-through comment
- §5.1 PolynomialCost.degree: Rational (Q6 signed)
- NEW §6.0 Q7 canonical-form preservation: SymbolicCost preserves all
  terms; canonicalize ≠ dominant_term; mixed-sign canonicalization test
- NEW §6.1 Q6 dominance rule encoded via Field.compare reverse-sign
- §6.2 same-variable algebra fold rules header
- §11 anti-pattern #11 mirrored
- §16 Director msg_2c1bfb0e reference added

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — purge stale PositiveRational refs (cursor 10886)

Cursor APPROVE_WITH_COMMENTS review 10886: post-Q6 scope-extension
(243fd63), several PositiveRational / degree≤0 refinement references
remained in canvas STOP-SIGNAL prose + worker brief verbatim STOP block,
"zero new authority" line, hard-stop directive, STOP condition #4,
anti-pattern #7, and §13 verification axis listing. Worker could follow
the verbatim STOP/anti-pattern text and encode wrong carrier shape
relative to ratified Q6/Q2-Y signed-Rational.

Fix-forward:
- Canvas §6 STOP-SIGNAL prose: PolynomialCost { degree: PositiveRational } → { degree: Rational } (signed per Q6)
- Canvas §10 anti-pattern #7: drop degree≤0/PositiveRational requirement on PolynomialCost; explicit exclusion citing Q6
- Worker §4 verbatim STOP block: same PolynomialCost.degree text fix
- Worker §5.0 "ZERO new authority": drop PositiveRational from refinement list; note PolynomialCost.degree plain signed
- Worker §5.0 hard-stop directive: drop PositiveRational; add Q6 carve-out note
- Worker §10 STOP #4 variant collision: drop PositiveRational from de-dup list; add anti-pattern-#7-fires note
- Worker §11 anti-pattern #7: degree≤0 dropped; explicit PolynomialCost.degree exclusion per Q6
- Worker §13 verification axis: PositiveRational removed from refinement-carriers test list

INVARIANTS P1/P2 single-authority restored across both briefs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — STOP-SIGNAL line range :60-72 → :69-72

Cursor REQUEST_CHANGES 10904: brief cited STOP-SIGNAL as :60-72 across
7 surfaces but the live file has STOP at :69-72 and Pattern 3/4
dissolution receipt at :49-67. A literal Phase B "replace :60-72" would
delete part of the dissolution receipt — INVARIANTS P1 (dispatch prose
must ground in identifiable file facts) + P2 (single edit locus).

Fix-forward:
- Canvas L10 / L46 / L325 STOP-cite: :60-72 → :69-72
- Worker L42 / L90 (Phase B replace) / L261 / L350 / L373: :60-72 → :69-72
- Worker §4 Phase B: explicit DO-NOT-TOUCH callout on :49-67 dissolution
  receipt; replacement is surgical 4-line STOP block only

Brief is now internally consistent with canvas:204 ("Current
src/v3/std/algebra.dag:69-72") which was already correct.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 worker — drop stale gt_zero extension from Phase A list

Cursor APPROVE_WITH_COMMENTS 10920: §5.0 KNOWN_PREDICATES extension list
still required extending gt_zero's allowed_carriers to Rational, but
PositiveRational was dropped in the Q6 scope-extension (243fd63) —
no in-scope refinement uses gt_zero on Rational anymore. Conflicting
dispatch vs the comment block above.

Fix-forward: Phase A list now has only the gt_one addition (genuinely
required for PolyLogExponent = Rational where gt_one). Explicit
parenthetical: gt_zero extension NOT required; range allowed_carriers
already includes Int for ExponentialBase. Only gt_one is new.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — Q6 zero-degree collision + Q7 worker semantics + AP count

Codex BLOCKING review 4bd0cb5 — 2 BLOCKING + 1 non-blocking:

1. Q6 carrier admits degree=0 colliding with ConstantCost (n^0 ≡ 1):
   Fix-forward: keep ratified plain signed Rational carrier; add explicit
   canonicalize-fold rule canvas §6.1 + worker §6 algebra:
   `canonicalize(PolyCost(_, 0)) ⇒ ConstantCost(1)`. Same dissolution
   discipline class as Q2-Y LinearCost ≡ PolyCost(d=1) collapse. Single
   authority for "value=1 constant" via ConstantCost, not parallel via
   PolyCost(_, 0).

2. Q7 output-semantics drift between canvas + worker §14:
   Fix-forward: worker §14 reframed — symbolic_cost_of returns EXACT
   canonical SymbolicCost (Q7 contract change, not backwards-compatible
   reduction). Big-O is derived via dominant_term projection. Legacy
   single-term consumers MUST wrap with dominant_term; canonical-form
   change is expected and ratified.

3. Anti-pattern off-by-one (non-blocking): worker §11 enumerated 11
   items but header + §12 + §13 + §15 PR template said 10. Fix-forward:
   updated all 4 cite-list surfaces to 11 (7 Director-enumerated + 4
   Mgr-derived).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — Q6 Option B Practice-2 carrier refinement (msg_b80bcaa8)

Director RATIFIED Option B on Q6 zero-degree Practice-2 tension via
msg_b80bcaa8 (relayed by PM msg_9d248cbd 2026-05-13). Practice-2
carrier-level `where nonzero` refinement preferred over Practice-4
canonicalize-fold dissolution; sign-admission intent preserved.

Director-distilled discipline rule (NEW, load-bearing):
> Same-variant redundancy → Practice-4 collapse (Q2-Y LinearCost ≡
> PolyCost(d=1)). Cross-variant redundancy → Practice-2 carrier
> refinement (PolyCost(d=0) ≡ ConstantCost(1)). Type-level state-space
> tightening beats API-level normalization when redundant state crosses
> variant boundaries.

Canvas + worker fix-forward:
- §1 PROMOTE / §3 Q2-Y candidate / §6 STOP-SIGNAL / §6.1 dissolution
  text: `Rational` → `Rational where nonzero` (sign-admission via msg_2c1bfb0e
  preserved; only degree=0 excluded)
- Canvas §6.1: reframed from canonicalize-fold to carrier-level
  refinement; Practice-2 vs Practice-4 disambiguation rule encoded
- Worker §5 Phase A KNOWN_PREDICATES list: add `nonzero` predicate
  (allowed_carriers: Rational; arg_shape: Bare); now 2 new predicates
  (gt_one + nonzero), not 1
- Worker §5 "ZERO new authority" line: cite cross-variant vs
  same-variant rule
- Worker §6 algebra table: canonicalize-fold rule REMOVED (type prevents
  construction); multiplicative cancellation rule split into d1+d2≠0
  and d1+d2=0 cases (=0 maps to ConstantCost(1) directly without
  PolyCost(d=0) intermediate which is type-rejected)
- Worker §7 bootstrap ratchet: type-rejection negative test added
  (PolyCost(_, Rational(0)) must be structurally rejected; ±n admits)
- §11 anti-pattern #12 (new, Director-added): forbid canonicalize-fold
  for cross-variant redundancy when carrier refinement available
- AP cite-list counts: 11 → 12 across §11 header / §12 / §13 / §15

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 canvas — reconcile Q2-Y refinement + variant arithmetic

Cursor APPROVE_WITH_COMMENTS 10980 — 2 internal-consistency findings:

1. Q2-Y parenthetical "no where refinement" contradicted the snippet
   directly above showing `where nonzero` (post msg_b80bcaa8 Option B).
   Reconciled: explicit "no positivity / gt_zero refinement" framing
   per Director msg_2c1bfb0e sign-admission intent, AND explicit
   acknowledgment that `where nonzero` IS present per msg_b80bcaa8
   Practice-2 carrier-level Option B (sign-orthogonal, excludes only 0).

2. Q2-Y Pros bullet "11 → 10 net" contradicted §4 closing "**9** net
   under Q2-Y". Reconciled: corrected to "7 → 9 net" matching §1
   ratified scope (+3 new variants -1 collapsed = +3 net over existing
   7) and §4 closing reconciliation pointer.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — codex 77088ff non-blocking wording hygiene

Codex no-blocking + 2 non-blocking improvements (77088ff review):

- worker L156: "no such refinement" → "no positivity refinement, but
  DOES carry where nonzero" (clarifies sign-admission vs zero-exclusion
  distinction for downstream readers).
- canvas L285: §10 anti-pattern header "7 Director + 3 Mgr-derived"
  → "7 Director + 5 Mgr-derived; 12 total" (matches actual 12-item
  list per worker §11 cite-list).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(r3): gate #105 — named NonZeroRational alias (codex worker:167)

Codex BLOCKING worker:167: inline `Rational where nonzero` in struct
field types is unsupported by HEAD parser/lowerer — `where` refinements
attach only to type aliases / parameters (precedent
`type PositiveInt = Nat where gt_zero` at dsl/std/integer.dag:181).
Inline use would require unsupported substrate syntax instead of
making illegal degree=0 unrepresentable through a proper named
refinement carrier.

Fix-forward: introduce `type NonZeroRational = Rational where nonzero`
at the type-alias layer (alongside existing
`PolyLogExponent = Rational where gt_one` +
`ExponentialBase = Int where range(min: 2)`). PolynomialCost.degree
field type references the named alias: `degree: NonZeroRational`.

Updates across both briefs:
- All `degree: Rational where nonzero` → `degree: NonZeroRational`
  (5 canvas occurrences + 10 worker occurrences)
- Worker §5.0 dag block: NonZeroRational alias declaration added with
  rationale comment citing codex worker:167 + HEAD parser constraint
- Canvas §6 refinement-carriers list: NonZeroRational row added with
  named-alias note
- Worker §5.0 HARD STOP directive: NonZeroRational added to the
  hard-stop list (named alias, not fresh record); HEAD parser
  constraint cited
- Worker §10 STOP #4 variant-collision list: NonZeroRational added
- Worker §5.0 P1/P2 narrative: clarified "DOES carry NonZeroRational
  named-alias" framing
- Worker §7 bootstrap ratchet test: type-rejection test asserts both
  the type-alias declaration AND the degree=0 rejection at carrier
  level
- Worker §13 verification axis: NonZeroRational added to refinement-
  carriers test list

INVARIANTS P2 + Practice 2 carrier-level illegal-states-unrepresentable
satisfied via named alias (P5 / parser-supported substrate syntax).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 canvas — fix §6 'no refinement' stale text (codex canvas:218)

Canvas §6 closing paragraph still said "PolynomialCost.degree intentionally
has no refinement" — pre-msg_b80bcaa8 framing that contradicts the
NonZeroRational alias declared 3 lines above + ratified by msg_b80bcaa8.

Fix-forward: reframe as "no positivity refinement, but DOES carry
NonZeroRational named alias for zero-exclusion". Sign-admission
preserved (msg_2c1bfb0e); zero-exclusion enforced (msg_b80bcaa8).
Also added explicit reference to degree=0 alongside exponent≤1 / base≤1
in the structurally-unrepresentable set.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(r3): gate #105 canvas — STOP-SIGNAL Tier-2 cite msg_ad5e934d → msg_d86a5987 (cursor 11087)

Cursor APPROVE_WITH_COMMENTS 11087: canvas §6 STOP-SIGNAL cited
msg_ad5e934d for Tier-2 R4-deferral, but the worker brief §4 verbatim
STOP block cited msg_d86a5987 for the same sentence. msg_ad5e934d was
the original Path A Tier-1 ratification; the §8 Tier-2-deferral
disposition was ratified in msg_d86a5987 (per composite-ratification
text already used elsewhere in worker §0/§2/§9/§13/§15). Canvas
STOP-SIGNAL aligned to msg_d86a5987 for single-authority trace.

INVARIANTS P2 single authoritative trace restored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 14, 2026
* R3 gate #53: workflow substrate carrier ratchet receipt

Adds `workflow_substrate_carriers_test.rs` locking the Slice 1
β-ratified carriers (`WorkflowSecret { name: SecretName, scope:
SecretScope }`, `SecretScope = StepScope | JobScope | WorkflowScope`,
`CronSchedule` 5-field record, `CronField` 5-variant sum) against
the full bootstrap Dag.

Sibling-carrier shape with gate #62
`file_attachment_substrate_carrier_test.rs`; STOP+PING discipline on
field-count drift per
`docs/briefs/r3-substrate-t-workflow-as-data-slice-1-worker.md`.

Updates §1.8 row #53 to cite the structural ratchet receipt.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Add workflow_substrate_carriers_test.rs to SG-0 census

Addresses cursor/composer-2 BLOCKING review on #3104: every new
hand-authored test path must be listed in EXPECTED_HAND_AUTHORED_TEST
per INVARIANTS.md §P5 Mechanism (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* ci: retrigger workflow after PR body SG-0 pairing update

Adds the `SG-0 hand-path delta: +1` + `SG-0 pairing: (c)` lines to the
PR body (citing the worker brief as the dispatch evidence) so the
`check-pr-sg0-net-shrink-discipline.sh` step picks up the discipline
receipt on the next pull_request event.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(invariants): add gate #53 SG-0 receipt row

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
@briansrls
briansrls deleted the cursor/lane-b-workflow-2281 branch June 1, 2026 18:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants