Repository navigation
extdeps: external-authority anchor carrier + fail-closed CI lens (revive #5297) - #5418
Conversation
…ive #5297) Land the never-merged #5297 mechanism onto current main: a structured, lens-checkable external-authority citation on every dsl/extdeps module, enforced fail-closed on the CI floor. Carriers - extdeps.uri: Uri { scheme: UriScheme, locator } with closed-sum UriScheme = Http | Https | File | Ftp (RFC 3986 / 7595 grounded). - extdeps.external_authority: ExternalAuthority { uri }, FactAuthorityOverride, and the canonical `data extdeps_external_authority_anchor` row. Lens (v2.lens.extdeps_external_authority) - Fail-closed live policy per module: machinery-exempt -> backfill-pending -> else require a present external Http/Https anchor. Scheme decoded by exhaustive constructor identity (decode_uri_scheme), never a URL-prefix string. - Violations: MissingFormalAnchor / UnrecognizedAnchorScheme / NonExternalAnchorScheme. Host projection (extdeps_shape_transport_policy_project.rs) - Structural read of the anchor record; live roster derived from the module-path index (declared module name, not directory); backfill + machinery-exempt facts. - 9 builtins wired through 04_method.dag / v1_interpreter.rs / v1_compiler_infer_method.rs. CI - ExtdepsExternalAuthorityGate enrolled in gunbc_ci_spec and scheduled on the floor; runs uri witnesses + live-corpus clean-tree + RED perturb receipts. 44 extdeps modules carry external anchors; 125 remain in the shrinking backfill_pending snapshot. Reconciliation onto current main: the snapshot keys on declared module name, so the post-#5391 directory reorganizations (rust/, package_managers/, ...) need no rename. The only stale entry, extdeps.diagnostic.redfish, was dropped (redfish moved to extdeps.bmc.redfish, separately covered). Verified by execution: 18 projection unit tests; 14 floor-enrolled .dag witnesses (GREEN clean-tree + machinery-exempt fold + 3 RED perturbs + live anchor-drop RED); live-tree discrimination on a real cited module (Https->File and anchor-drop both flip the gate RED, revert restores GREEN); ci_spec/ci_floor_plan enrollment witnesses; gate main -> ExitSuccess via real shell; cargo fmt + clippy -D warnings. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019Mi3t2wX7UPzgqLyYAE1kS
… (fixes v1↔v2 FreeMonoid collision) The type/constructor environment keyed names by bare interned string and an implicit bootstrap bridge injected v1 `std.types`' whole transitive env as a base into every module that didn't import it. Together these let v1's `std.algebra` FreeMonoid (a record) and v2's `v2.std.algebra` FreeMonoid (`Empty | Cons` sum) collide — the winner decided by the topological typecheck order, which the std.types implicit edges coupled across the v1 and v2 trees into one global sort. Adding import edges (e.g. #5418's 44 extdeps anchors) perturbed that order, so `v2.std.node_query` bound FreeMonoid to the leaked v1 record and produced `undefined variable 'Empty'` / `variant 'Empty' not found in type 'FreeMonoid'` across the v2 tree. A §3 single-authority violation. Fix (authority in src/v1/*.dag, mirrored in the stage0 seed .rs): - 03_resolve.dag `topological_sort`: drop the implicit `std.types -> *` edges and the implicit in-degree term. Ordering is now import-driven only, so the two trees decouple and a module is always typechecked after the modules it actually imports — no order-sensitivity to re-tune. - 04_infer.dag `build_type_env` / `build_type_env_unresolved`: drop the `std.types` base-injection. Import bindings start empty and are seeded only by the module's explicit imports; kernel primitives still come from the kernel env. No second, implicit authority for names. Witness (src/v1/tests/src/module_authority_resolution_test.rs): a module that never imports `std.types` no longer inherits a type `std.types` declares — the reference is a hard UnresolvedType (RED without the fix, where the leak silently resolved it). Plus two §3 invariant guards for same-named types across modules. Verified by execution: the #5418-anchored discovery-corpus repro (wet_hermetic_scaffold_roster_filter_uses_dag_prefix_authority) goes green; regen_stage0 self-compiles the v1 tree clean without the leak; full `cargo test --workspace` green except the pre-existing regen receipt-hash red (#5420); clippy + fmt clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… (fixes v1↔v2 FreeMonoid collision) The type/constructor environment keyed names by bare interned string and an implicit bootstrap bridge injected v1 `std.types`' whole transitive env as a base into every module that didn't import it. Together these let v1's `std.algebra` FreeMonoid (a record) and v2's `v2.std.algebra` FreeMonoid (`Empty | Cons` sum) collide — the winner decided by the topological typecheck order, which the std.types implicit edges coupled across the v1 and v2 trees into one global sort. Adding import edges (e.g. #5418's 44 extdeps anchors) perturbed that order, so `v2.std.node_query` bound FreeMonoid to the leaked v1 record and produced `undefined variable 'Empty'` / `variant 'Empty' not found in type 'FreeMonoid'` across the v2 tree. A §3 single-authority violation. Fix (authority in src/v1/*.dag, mirrored in the stage0 seed .rs): - 03_resolve.dag `topological_sort`: drop the implicit `std.types -> *` edges and the implicit in-degree term. Ordering is now import-driven only, so the two trees decouple and a module is always typechecked after the modules it actually imports — no order-sensitivity to re-tune. - 04_infer.dag `build_type_env` / `build_type_env_unresolved`: drop the `std.types` base-injection. Import bindings start empty and are seeded only by the module's explicit imports; kernel primitives still come from the kernel env. No second, implicit authority for names. Witness (src/v1/tests/src/module_authority_resolution_test.rs): a module that never imports `std.types` no longer inherits a type `std.types` declares — the reference is a hard UnresolvedType (RED without the fix, where the leak silently resolved it). Plus two §3 invariant guards for same-named types across modules. Verified by execution: the #5418-anchored discovery-corpus repro (wet_hermetic_scaffold_roster_filter_uses_dag_prefix_authority) goes green; regen_stage0 self-compiles the v1 tree clean without the leak; full `cargo test --workspace` green except the pre-existing regen receipt-hash red (#5420); clippy + fmt clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… (fixes v1↔v2 FreeMonoid collision) (#5422) The type/constructor environment keyed names by bare interned string and an implicit bootstrap bridge injected v1 `std.types`' whole transitive env as a base into every module that didn't import it. Together these let v1's `std.algebra` FreeMonoid (a record) and v2's `v2.std.algebra` FreeMonoid (`Empty | Cons` sum) collide — the winner decided by the topological typecheck order, which the std.types implicit edges coupled across the v1 and v2 trees into one global sort. Adding import edges (e.g. #5418's 44 extdeps anchors) perturbed that order, so `v2.std.node_query` bound FreeMonoid to the leaked v1 record and produced `undefined variable 'Empty'` / `variant 'Empty' not found in type 'FreeMonoid'` across the v2 tree. A §3 single-authority violation. Fix (authority in src/v1/*.dag, mirrored in the stage0 seed .rs): - 03_resolve.dag `topological_sort`: drop the implicit `std.types -> *` edges and the implicit in-degree term. Ordering is now import-driven only, so the two trees decouple and a module is always typechecked after the modules it actually imports — no order-sensitivity to re-tune. - 04_infer.dag `build_type_env` / `build_type_env_unresolved`: drop the `std.types` base-injection. Import bindings start empty and are seeded only by the module's explicit imports; kernel primitives still come from the kernel env. No second, implicit authority for names. Witness (src/v1/tests/src/module_authority_resolution_test.rs): a module that never imports `std.types` no longer inherits a type `std.types` declares — the reference is a hard UnresolvedType (RED without the fix, where the leak silently resolved it). Plus two §3 invariant guards for same-named types across modules. Verified by execution: the #5418-anchored discovery-corpus repro (wet_hermetic_scaffold_roster_filter_uses_dag_prefix_authority) goes green; regen_stage0 self-compiles the v1 tree clean without the leak; full `cargo test --workspace` green except the pre-existing regen receipt-hash red (#5420); clippy + fmt clean. Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…nalAuthorityGate #5418 added ExtdepsExternalAuthorityGate to the Gate enum and to every match over it EXCEPT gate_is_heavy_resolve (ci_floor_plan.dag:154), so once the v1↔v2 FreeMonoid collision cleared (#5422 now in this branch) the plan resolve reached this fn and fail-closed on a non-exhaustive match: ci_floor_plan.dag:154:3: error: non-exhaustive match: missing variant(s) ExtdepsExternalAuthorityGate The extdeps external-authority gate is a focused lens witness (filesystem_read over dsl/extdeps/**), not a whole-tree heavy resolve like SourceRootIngest / DslCompileClean — so it joins the other lens gates (Layering/ResolvedImports) at `false`. Plan-data only; resolved at runtime by claim_executor, no stage0 seed. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Verified both findings against the head ( Finding 1 — Rust string-equality scheme predicate ( Finding 2 — vendor modules cite Neither finding gates merge (the review verdict is APPROVE). Both are logged as extdeps follow-ups for the arc owner; happy to take Finding 1's consolidation as a separate scoped PR if you want it assigned here. — sent from merry-bee-526 |
|
Verified the two follow-up findings from the latest review against the current code:
Neither finding blocks merge (verdict APPROVE). — sent from merry-bee-526 |
…key-completeness lens #5418's external-authority gate scans the LIVE extdeps tree and fail-closes on any module lacking an anchor. Once #5422 cleared the FreeMonoid collision and the missing gate_is_heavy_resolve arm let the plan resolve, the gate correctly flagged 5 modules that landed on main AFTER #5418 authored its roster and were neither anchored nor backfilled: missing: extdeps.access.{aws_iam,posix,rbac,zanzibar} (#5415 access model) missing: extdeps.cache.key_completeness (#5423 cache lens) The 4 access modules already carry their real upstream citation in a `// Source:` comment (AWS IAM grammar, POSIX.1-2017/opengroup, ANSI/NIST RBAC, the Zanzibar USENIX paper) — promoted each to the structured `extdeps_external_authority_anchor` carrier the gate gates on (DESIGN §3: the mark on the carrier is the authority). No access sibling is backfilled, so anchoring (not backfilling) is the consistent treatment. extdeps.cache.key_completeness is an internal §5 cache-soundness LENS (a pure reader over the cache catalog), not a cited external-system model — so it joins its 8 extdeps.cache.* siblings on the backfill_pending roster as tracked debt, not a fake external anchor. Verified by execution: the floor's discovery-corpus (587 witnesses) and extdeps_external_authority_gate_passes both go GREEN with this change (live violation set empty, roster count > 150). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Verified all three findings against head 1. 2. 3. None block merge (verdict APPROVE). My change on this head is the 5-module live-clean fix (anchor 4 access modules + backfill the cache key-completeness lens); the three findings are pre-existing extdeps follow-ups for the arc owner. — sent from merry-bee-526 |
… (warm-lark correction) Deriving the realization-vocab exception roster from a live grep would make the guard vacuous (leak = non-edge importer AND NOT-in-roster; derived roster ⇒ every importer always in it ⇒ leak_count always 0 ⇒ never fires). Distinguish the informational prose count (rots, re-grep) from the lens's enforcement roster (frozen, so a new unrostered importer goes RED = the teeth). Add the 11th importer (extdeps_external_authority_transport, the #5418→#5445 race, fixed by #5453) and the roster-completeness assertion as the steady-state race-hardening. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…rnal_authority_transport to exception roster The extdeps_external_authority_transport.dag (added in #5418) imports extdeps.languages.bash.program but was not included in the exception roster, causing the realization_vocab_clean_tree_holds test to fail. The file is a transport module in dsl/tools/ following the same pattern as other rostered transports, so it requires roster entry per DESIGN §3. Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
…gestion⁻¹ past syntax (#5442) * WIP: dsl -> v2 scoping * WIP: ROADMAP planning * WIP: ROADMAP planning * WIP: ROADMAP planning * ROADMAP: scannable dependency-ordered checklist; consolidate caching plan (de-fork zesty-deer-479 owner, absorb quick-ant-298 spine) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * self-host: add bootstrap purity (no stage0 hand-edits / regen-lockstep keystone) + precise v1 cutover Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP §0 fail-closed lock-down (blocks expansion) + audit doc; §4 website demo Audit: cache lossy-digest flake (resolved_graph_cache.rs:146, verified), ~inert analytical lenses (complexity/cost/etc), regen --verify unwired (#5325). Lock-down checklist gates expansion. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP: flesh §2 idea->idea compiler (medium/language axes); §0 → lock-down LANE (audits→fixes→meta), name model<->realization fork as suspected root Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * lock-down: add CI-coverage-completeness audit (rust gate runs 3 of 60 v1 suites) + axiom/syllogism lens (DESIGN open thread #1 — lock down the reasoning) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * roadmap §0/§7 + lockdown: lead with correctness-by-construction, demote lenses to residue Folds in the operator principle (relayed via quick-ant-298): a lens is validation — it concedes the bad thing is writable. Root-cause to make it unwritable (single authority / realization derived from model); reserve lenses for the genuinely- unstructurable (complexity/necessity). #5423's spec-only key lens shipped a false-green as the live proof. - ROADMAP §0: add the principle; split Fixes into tier-1 construction (dissolve model↔realization fork; cache-key derived-from-declared-inputs; self-host purity by construction) and tier-2 lens (complexity/cost; cache-redundancy; purity oracle; promote-inert). Meta-invariant → construction-justification rule. - ROADMAP §7: P1 cache-key reframed from 'realizer-key lens' to key derived from declared inputs_considered (construction). - fail-closed-lockdown.md: construction principle in the thesis; §4 checklist re-ordered construction-first / lens-residue; meta = construction-justification. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * roadmap §0: add Disposition carrier + 'confront skipped modeling decisions' Captures the lens/coproduct disposition decision (operator). One typed carrier (Terminal{reason} | Scaffold{dissolves_to}) for BOTH lens-lifecycle tags AND coproduct dissolve-markers — today freeform 🟡 comments, unreadable by lens since comments aren't Nodes. Decision: middle path (construction-capable carrier + selectively-enforcing lens that ratchets coverage) now, #1 (substrate can't-define-untagged) as the named end-state. The lens is itself a Scaffold{dissolves_to: substrate-mandatory-tag} — self-dissolving when coverage = whole tree. Rejected jumping to #1 on sequencing (load-bearing §4 substrate change → escalate; flag-day migration; derived coproducts need disposition derived not authored), not on principle. Enforceability split: presence = construction (non-optional field, no meta-lens); redundancy (scaffold + successor both present) = hard gate; Terminal-vs-Scaffold correctness = retro/judgment (synthesis-feasibility limit). - docs/plans/disposition-carrier.md (new) - ROADMAP §0 tier-1 + meta 'confront skipped decisions' standing practice Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * DESIGN §5/§6: promote construction-over-validation; roadmap: scope-partition §0, testgen §1, shelve dashboard Addresses the review's four flags + sequencing nuance. - DESIGN.md §5: 'correctness by construction, not validation' is now an axiom (a check re-stating a model constraint is a 2nd representation §2/§3; prefer realization derived from a single authority; reserve checks for the unstructurable residue). §6 'enforce with lenses' reconciled: construction first, lens = residue mechanism, AND the executable inert-lens backstop is NOT superseded by the authoring-time construction-justification judgment. (flag 4 home + flag 3) - ROADMAP §0 partitioned: In-scope this window (numeric-tower grounding; cache trustworthy + warm==cold oracle shipped NOW as detective; widen rust gate; promote inert lenses) vs Fenced-OUT fan-out (Value::Null 131-site split; self-host purity gate; cross-tree import activation; Disposition carrier). Honest framing: window reduces fail-open surface, does NOT 'lock' the class — Null split stays open. (flags 1, 2, sequencing nuance) - ROADMAP §0 meta: restored executable inert-lens hygiene backstop, construction- justification layered on top (not 'supersedes'). (flag 3) - De-dup: principle no longer restated in ROADMAP/lockdown §0; both point to DESIGN §5. cache-key construction homed in §7, §0 references it. (flag 4) - ROADMAP §1 = testgen as bug-class oracle (+ affected-set completeness half + parked anemia lens); dashboard shelved to §8. - docs/plans/testgen-oracle.md (new), fail-closed-lockdown.md realigned. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * DESIGN §5/§6/§7: wall-vs-ratchet decidability, displaced-pain denominator, open language design Folds in the operator's product thesis + the two bounds that keep it honest. - §5: construction makes a class unwritable only when membership is DECIDABLE — trichotomy (wall now / wall after grounding / ratchet forever); 'never' is the trap (lets an undecidable ratchet masquerade as a wall — optimality by Rice). - §6: denominate the benefit — the deliverable is a displaced cost (§1 time / a paid-for pain), the lens/substrate is the moat not the product; priced in elegance the work is unbounded (the economic twin of 'never'). - §7: the recursion's payoff — language design itself opens up. It's locked by cost (a check = a compiler fork; a language = an adoption problem); both dissolve here (a wall is a row §2, applied over a medium-agnostic substrate §4), so (compiler-fork × language) → (row + medium). Sound where ingest is Lossless, fail-closed where not (DecodeFidelity §4). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * ROADMAP: fix doc-graph violations from bright-eagle-46 review of #5424 Apply the apex axiom/syllogism lens (single authority / no orphan / no cycle) to the roadmap itself — manual acyclicity pass: - orphan: testgen-oracle.md backlinked §1 → repoint §4 (its own lane) - single authority: §0 cache-key now a pure pointer (= §2 F2/F3/P1); §0 numeric-tower marked the authoritative home (§5 de-fork / fork plan point here, no second checkbox) - §0↔§5 cycle: self-host purity reframed as a §5 deliverable §0's expansion-gate depends on (edge §5 → §0-gate → products), not §0-owned - undeclared edge: §7 react/html declares its dependency on §6 media - backlink sweep: the reorg had broken every numeric backlink across 7 plan docs; re-point all and anchor each to the stable section TITLE so a future renumber can't silently break them again Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP §3 + plan: algorithmic-cost reduction by construction (rewrite, not budget) Reframe §3 from per-fn complexity budgets to the actual intent: rewrite common suboptimal patterns (O(n²)→O(n), O(2ⁿ)→O(n), O(n)→O(log n)) to the cheaper equivalent — construction on the cost axis, not a warning. New plan doc docs/plans/algebraic-rewrite-optimization.md captures the up-front design: the decidability split (modeled EffectShape makes the preconditions structural; equivalence stays undecidable so no optimality oracle), rewrite-rule-as-row + once-proven soundness, the common-case catalog tiered by precondition, D1 canonical-form-is-truth / D2 two seed rules / D4 constant-factor deferred, the four-witness DONE bar (incl. the non-firing control half-done versions skip), and a corpus hit-rate acceptance gate. complexity.dag is the cost oracle; synthesis.dag stays the advisory undecidable residue. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP §2: Phase-0 measurement instrument done (#5431 peak-RSS) — remaining is the Phase-1 consumer Per quick-ant-298: the measurement keystone was nearly complete — model side already floor-enrolled, step timing already emitted; the only gap was peak-RSS, closed by #5431. P4's Phase-0 dependency is satisfied; remaining is the Phase-1 measured->plan feedback + width-fold (also unblocks §1-C). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * plan/§3: detection-vs-enforcement containment (E⊆D′⊆D) + explicit seed-rule I/O up front Grounded in cost.dag U2 + complexity.dag (investigated, not theorized): - detection is TOTAL by construction (kernel-level cost fold; arbitrary fns detectable); boundary is precision (ClassUnknown), not coverage - enforced rewrites are a strict subset structurally guaranteed by the class-drop witness: E ⊆ D′(precise) ⊆ D(all) - n√n excluded for a MODEL reason (PolynomialDegree is integer-only, n^1.5 unrepresentable); ternary search excluded (log base is not a class) - today's small gate roster = subject-production limit (fn-body reflection), NOT a detection limit - new §3a fully specifies the two seed rules up front: input→output→ precondition→non-firing control→discriminating equivalence input, so the worker builds to spec and the project can actually finish Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP §0/§1: rust-gate is cadence-decoupling, not run-all (per fierce-hawk #5427) The 3-filter allowlist was COST selection, not arbitrary gatekeeping — the v1 SEED compiler costs ~tens of CPU-sec per trivial test, so run-all-per-PR is CPU-hours (off the table). True shape: per-PR cost-bounded subset + measured #[ignore="expensive: Ns"] + completeness lens (#5427); nightly --ignored lane as the destination for expensive + the 58 currently-ignored tests (owned by §1/quick-ant, after #5431, escalate for load-bearing CI-gen). Completeness = every test runs on >=1 cadence (fail-closed). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * plan §2a: generalize by structural-redundancy keying (O(n^x)->O(n^(x-1)) free); flag n-log-n as substitution Per operator: catalog must generalize polynomial-degree reduction without edge cases. Resolution: rules key on the structural redundancy, never on degree — degree is not evidence of redundancy (would fire on genuine O(n^x)). A structurally-keyed nested-membership->set peels one level wherever it matches; fold-to-fixpoint gives O(n^3)->O(n^2)->O(n). Cost model supports arbitrary integer degree, so witness (b) holds at every peel. Flagged OPEN (operator input invited): O(n^x)->O(n log n) is algorithmic SUBSTITUTION (different algorithms, same I/O) not redundancy elimination — verges on undecidable equivalence; tractable form is per-idiom rules (sort-based dedup, repeated-min->heap), not a parameterized rule. Seed Rule 1 now authored structurally + carries a depth-2 generalization witness. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * plan §1b: Unknown is an anemic atom — dissolve over time (reuse Disposition), never a false pass Per operator: classifying Unknown isn't a fixed up-front split — it's the standing anemic-leaf dissolution practice (DESIGN §2 decompress->map->reduce) applied to the cost lens. UnknownCost{diagnostic} already carries its reason; the anemia is the free-form reason. Each decomposition resolves an Unknown to construction (now-precise class -> new D′) or a grounded Terminal (genuinely undecidable, positively recognized -> advisory comment). DFS-first: this IS the Disposition carrier (resolves to construction-or-justified-Terminal), so reuse it, don't fork an unknown-reason enum. Supersedes the static Undecidable|Undetermined split. Two invariants fixed up front: never a false pass (Unknown=>Violates, already holds); every Unknown on the dissolution frontier. cost.dag enrichment + un-parking Disposition are operator-gated. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP: §3 reverts to budget-gate validation (stability); rewrite-engine relocated to §5 (post-stability) Operator decision 2026-06-21: budget-gate validation is fine for the stability window; the algorithmic-cost REWRITE construction design is expansion, homed with self-hosting (§5) — IR-rewrite/canonicalization is most natural once .dag is the self-hosted truth. - §3 = complexity budget gate (validation): cost-lens symbolic_max fix (#5437) + per-fn subject + budget-gates-whole-codebase (gated on fn-body reflection) + synthesis advisory. #5437 foundation stays in-window. - §5 gains an 'adjacent expansion lane' = the rewrite engine, pointing at the preserved plan doc; marked post-stability. - plan doc status -> POST-STABILITY EXPANSION, relocated to §5. Nothing deleted — the rewrite design is preserved, just fenced out of the stability window (same as Disposition / Value::Null-split). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * #5442 review fix (warm-lark-306): grep-as-authority for the sidecar roster (10 not 9) The §0-guard impl PR (#5445) grepped current main and found 10 importers of extdeps.languages.bash.program, not 9 — the 10th (dsl/gunbc/ci_spec.dag) landed via #5432 after the original pre-merge grep. Rather than bump the frozen count, make the live grep the authority (the roster shrinks to 0 as the bash-sidecar arc migrates consumers, so any frozen number rots — the single-authority point). Also note the two *_test importers are intentionally not walled (guard scans consumer-source roots only). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP: check off 6 merged items (catch-up sweep) Flip [ ]→[x] for unambiguously-merged work (PR-ref'd for traceability): - §0 numeric-tower grounding (#5428 — == straddle guard dead-in-corpus) - §0 inert-lens hygiene executable backstop (#5433) - §2 F2/F3 resolved_graph key derived from inputs_considered (#5425) - §3 cost-lens symbolic_max zero-absorption fix (#5437) - §4 gate existing generated testgen output (#5434) - §4 affected-set completeness (#5430) Partial/compound items left for their lane managers to flip in the PR that completes them. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP §1: add compile-clean-gate force-checks-every-fn-body box (2(ii) fail-open) New floor-coverage item: the compile-clean gate is fail-open — unreached fn bodies escape typecheck, so undefined symbols in dead code pass green (execution-proven on utf8_decode_bytes). Construction fix = typecheck total over every declared body. Owned by §1 (quick-ant); measure-first, operator-gated enforce-flip. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP §0: correct the 2(ii) box — registry-leak mechanism, not unreached-bodies snappy-gull's deeper diagnosis: the fail-open is NOT unreached bodies (bodies ARE visited). utf8_decode_bytes resolves because it's a global builtin_function_registry entry (04_method.dag, a marked bridge scaffold) not scoped to the compiled tree. Reframe the box to tree-scoped builtin availability / registry partition; instance fix = real std fn + remove the registry bridge entry. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * plan doc: enforcement roster is a FROZEN grandfather set, not derived (warm-lark correction) Deriving the realization-vocab exception roster from a live grep would make the guard vacuous (leak = non-edge importer AND NOT-in-roster; derived roster ⇒ every importer always in it ⇒ leak_count always 0 ⇒ never fires). Distinguish the informational prose count (rots, re-grep) from the lens's enforcement roster (frozen, so a new unrostered importer goes RED = the teeth). Add the 11th importer (extdeps_external_authority_transport, the #5418→#5445 race, fixed by #5453) and the roster-completeness assertion as the steady-state race-hardening. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * ROADMAP refresh: §1 nightly→Pop-B (opt-level won), §2 resolve-cache GO + P2 de-fork-dependent, §0 census regression + gate-hygiene Reflects decisions/findings that landed 2026-06-21: - §1: the "expensive" tests were debug-build amplification, not intrinsic seed cost (proud-deer cause-table); opt-level=3 (#5456) restores Pop-A to per-PR; nightly lane reduced to Pop-B wet-captures only. Mirror corrected in §0. - §2: resolve-cache enable = GO (~18% floor-wall, purity-proven, #5429-gated); P2 ParseTable dissolution reclassified as a downstream consumer of the dsl→v2 de-fork (keen-otter: v2-local rewire is cosmetic); #5446 realize kernel green. - §0: stage0 clone-census ratchet went inert + the seed regressed 1138 over budget (rust-side coverage-by-illusion + thesis regression; #5427 surfaced it); gate-hygiene rule (floor-enrolled gate must be green-on-main at merge) + roster-completeness assertion promoted to should-land (the #5445 floor-skew). - §1: registry-partition instance fix = #5452 (verified sound). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Delete dead v4_slice parity test pipeline dag_emit_from_resolved_matches_compile_sources_for_v4_slice reads fixture fixtures/v2-mvp1 which was deleted and no longer exists in git history or the working tree. The test was hidden by the old rust-gate allowlist but exposed by #5427, and cannot pass. (Refs: #5427) Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com> * Delete obsolete v1_compiler_lib_test module The v1_compiler_lib_test module was solely used by the now-deleted dag_emit_from_resolved_matches_compile_sources_for_v4_slice test to compile-check the v1-compiler lib test harness. With that parity test gone, this module is dead code. (Addresses review feedback on #5457) Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com> * Fix realization vocabulary containment test: add missing extdeps_external_authority_transport to exception roster The extdeps_external_authority_transport.dag (added in #5418) imports extdeps.languages.bash.program but was not included in the exception roster, causing the realization_vocab_clean_tree_holds test to fail. The file is a transport module in dsl/tools/ following the same pattern as other rostered transports, so it requires roster entry per DESIGN §3. Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com> * WIP: Delete dead v4-emit-slice parity test pipeline dag_emit v4_slice: it rea --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>
…y backfill (fleet-red keystone fix) (#5465) #5429 added the cache_purity module but did not register it in external_authority_backfill_pending.txt (its 4 realization siblings are listed), so #5418's live-clean-tree lens fail-closes — fleet-wide main-red since cdd1421 (#5429); prior commit ac9a7e7 (#5449) was green. Same floor-skew class as #5445/#5453. One-line backfill anchor; diagnosed by bright-stag-194, delegated by sunny-bee-667 (lane owner) for the urgent fleet-unblock. Also unblocks stern-otter's P3 branch. Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…hority gate) CI floor batch-2 RED: #5418 live-clean-tree lens fail-closed because extdeps.bmc.access shipped without an external_authority_anchor. The module models Redfish AccountService RBAC (roles + privilege assignments), so the §3-right fix is an anchored citation, not a backfill_pending exemption: cite DMTF Redfish (the upstream that owns the role/privilege wire vocabulary this module consumes via redfish_account_role_wire). extdeps.access.posix was already anchored (POSIX/opengroup sys_stat) and extdeps.access.rbac too (NIST RBAC) — bmc.access was the only gap. Verified by execution: corpus_live_clean_tree_holds + corpus_live_anchored_modules_clean_holds both green; compile 437/0. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…BAC (#5571) * WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model * BMC onboarding lifecycle: 4-phase model + Redfish write seam + read-only validation Models the onboarding of the operator's new Altra server (BMC 192.168.1.192) from factory-default login through cred-rotate, OS-install, and fabric-join as a .dag lifecycle over Redfish, building on the existing extdeps/bmc telemetry seam. - extdeps/bmc/types.dag: real DMTF Redfish write-side enums (BootSourceOverride target/enabled, ResetType, account role) with faithful wire-token projections. - extdeps/bmc/http.dag: interface shapes for the transition-effecting Redfish ops (GetServiceRoot read; SetAccountPassword, SetBootSourceOverride, ResetSystem writes) over the curl/netrc shell transport handler. Secrets ride a runtime request_body_file, never argv or the repo. - gunbc/bmc_onboarding.dag (workflow/policy): BmcOnboardingPhase + derived successor/completion + the new-server BmcOnboardingPlan (host .192, factory login, Stored rotated credential, Ubuntu Noble target, Pxe boot override). - gunbc/tools/bmc_onboard.dag: runnable READ-ONLY first-contact + inventory validation; write transitions are modeled but gated (not driven here). - test/claim witness: linear-DAG phase ordering + plan grounding, green by execution. Grounded against the live BMC at 192.168.1.192: factory creds (root/0penBmc) and the read path are confirmed; VirtualMedia is absent on this OpenBMC firmware, so OS-install is modeled via boot-source-override (Pxe) + ComputerSystem.Reset. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * review #5563: drop redundant phase_order roster (§3 single authority) bmc_onboarding_next_phase is now the sole authority for the linear successor relation; the standalone bmc_onboarding_phase_order list duplicated it. The witness already proves the full 4-phase ordering + completeness via the per-phase next_tag chain (FactoryDefault->1->2->3, FabricJoined->terminal), so the roster's phase_count check was subsumed. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * review #5563: rename bmc_onboard -> bmc_onboard_validate (honest tool name, §5) The tool only performs the read-only FactoryDefault validation (GetServiceRoot + GetSystem); it does not drive cred-rotate/OS-install/fabric-join. Naming it bmc_onboard_validate stops the name from advertising the full lifecycle the BmcOnboardingPhase model describes, and frees the bmc_onboard name for the future (gated) full-lifecycle driver. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model * review #5563: delete bmc_onboarding_is_complete (single-caller predicate) The predicate had one caller (the witness) and the witness's next_tag chain already proves completion (FabricJoined -> -1 = terminal; others -> 1/2/3). Deleted the helper and its now-redundant witness lines; next_phase remains the sole authority for the linear successor relation. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * access layer: POSIX accounts + BMC Redfish roles as least-privilege RBAC Model the credentialing leaves in the existing access layer (DESIGN.md §2/§3): - extdeps/access/posix.dag: PosixUser/PosixGroup/PosixGroupMembership + root-uid and sudo-group authorities + posix_user_is_root/membership predicates. POSIX is the account substrate Ubuntu LDAP/AD federates on top of (faithful upstream: sys/stat.h anchor already present). - extdeps/bmc/access.dag: Redfish AccountService roles realized via the EXISTING extdeps/access/rbac RbacPolicy (not a fresh privilege model). role->privilege grounded from the live .192 probe (Administrator/Operator/ReadOnly DMTF privilege sets). redfish_role_name projects the faithful DMTF role tokens. - test/claim/access_layer_extension_witness_test.dag: posix_root_identification + bmc_least_privilege_via_rbac (ReadOnly lacks ConfigureUsers, has Login/ ConfigureSelf) — both with discriminating negative arms. Stacked on #5563 (needs RedfishAccountRole from extdeps/bmc/types). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * review #5571: dedup role wire + ground Redfish privileges as a closed enum Addresses claude-opus-4-7 REQUEST_CHANGES (review 31850): - Delete redfish_role_name (byte-identical nickname of the existing redfish_account_role_wire in extdeps/bmc/types.dag) — §3 single authority. access.dag + witness now import and reuse redfish_account_role_wire. - Ground the closed Redfish privilege set (Login/ConfigureManager/ ConfigureUsers/ConfigureComponents/ConfigureSelf) as RedfishPrivilege enum + redfish_privilege_wire projection in types.dag, exactly as RedfishAccountRole does (§4 grounding). Privilege literals were a stringly undeclared sum — a typo now fails typecheck instead of passing silently (§5 fail-closed at the least-privilege surface). - Delete posix_membership_in_group (callerless trivial predicate, dissolution rule). posix_user_is_root kept (encapsulates posix_root_uid authority). Witnesses green by execution; whole-tree compile 429/0. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * review #5571: delete unused posix_sudo_group (dead scaffold, §5) claude review 31854 nit: posix_sudo_group declared but unused. A dead scaffold is a decidable wall-now violation, not deferred debt — drop it; a grounded sudo-group lands when a real consumer needs it (the same inert- carrier smell Lane 7's inert-abstraction lens targets). Tree compiles 437/0, both access witnesses green by execution. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * review #5571: derive rbac roles from wire authority + drop dead Posix group types (§3/§5) claude review 31868, two §3 nits: - access.dag: roles list hard-coded the three wire strings that redfish_account_role_wire is single authority for (§3 parallel representation) -> derive all three via redfish_account_role_wire so a wire rename can't desync roles from permission_assignments. - posix.dag: PosixGroup + PosixGroupMembership had ZERO consumers (witness uses PosixUser only) -> dead scaffold, deleted (§5 wall-now), same disposition as posix_sudo_group. Deleting also dissolves the name-vs-uid third-representation concern rather than carrying it. Tree compiles 437/0, both access witnesses green by execution. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * review #5571: anchor extdeps.bmc.access to DMTF Redfish (external-authority gate) CI floor batch-2 RED: #5418 live-clean-tree lens fail-closed because extdeps.bmc.access shipped without an external_authority_anchor. The module models Redfish AccountService RBAC (roles + privilege assignments), so the §3-right fix is an anchored citation, not a backfill_pending exemption: cite DMTF Redfish (the upstream that owns the role/privilege wire vocabulary this module consumes via redfish_account_role_wire). extdeps.access.posix was already anchored (POSIX/opengroup sys_stat) and extdeps.access.rbac too (NIST RBAC) — bmc.access was the only gap. Verified by execution: corpus_live_clean_tree_holds + corpus_live_anchored_modules_clean_holds both green; compile 437/0. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
Summary
Lands the never-merged #5297 mechanism onto current
main: a structured, lens-checkable external-authority citation on everydsl/extdepsmodule, enforced fail-closed on the CI floor.extdeps.uri(Uri { scheme: UriScheme, locator }, closed-sumUriScheme = Http | Https | File | Ftp, RFC 3986/7595 grounded) andextdeps.external_authority(ExternalAuthority { uri },FactAuthorityOverride, canonicaldata extdeps_external_authority_anchorrow).v2.lens.extdeps_external_authority) — fail-closed live policy per module: machinery-exempt → backfill-pending → else require a present externalHttp/Httpsanchor. Scheme decoded by exhaustive constructor identity (decode_uri_scheme), never a URL-prefix string. Violations:MissingFormalAnchor/UnrecognizedAnchorScheme/NonExternalAnchorScheme.extdeps_shape_transport_policy_project.rs) — structural read of the anchor record; live roster derived from the module-path index (declared module name, not directory); backfill + machinery-exempt facts. 9 builtins wired through04_method.dag/v1_interpreter.rs/v1_compiler_infer_method.rs.ExtdepsExternalAuthorityGateenrolled ingunbc_ci_specand scheduled on the floor; runs uri witnesses + live-corpus clean-tree + RED perturb receipts.44 extdeps modules carry external anchors; 125 remain in the shrinking
external_authority_backfill_pendingsnapshot.Reconciliation onto current
mainThis is #5297 verbatim plus one line. The backfill snapshot keys on declared module name, not file path (
build_module_path_index→extract_module_path; cf. thecargo_build_resolves_by_module_path_not_directory_nicknameindex test), so the post-#5391 directory reorganizations (rust/,package_managers/,git/, …) require no rename — the flat declared names (extdeps.cargo,extdeps.apt, …) are unchanged. Live-tree coverage gap on currentmainis 0. The only stale entry,extdeps.diagnostic.redfish, was dropped (redfish moved toextdeps.bmc.redfish, separately covered).Test plan (all green by execution)
cargo build(debug + release),cargo fmt --all --check,cargo clippy --all-targets -- -D warningsextdeps_shape_transport_policy_project).dagwitnesses: live clean-tree GREEN + machinery-exempt fold + 3 RED perturbs (missing / bogus-scheme / file-anchor) + live anchor-drop RED + uri witnessesHttps→Fileflips the gate RED, anchor-drop flips RED, revert restores GREEN (byte-identical)gunbc run … extdeps_external_authority_gate … main→ExitSuccessvia real shellci_spec/ci_floor_planenrollment witnesses green🤖 Generated with Claude Code
https://claude.ai/code/session_019Mi3t2wX7UPzgqLyYAE1kS
Generated by Claude Code