Skip to content

extdeps: external-authority anchor carrier + fail-closed CI lens (revive #5297) - #5418

Merged
briansrls merged 6 commits into
mainfrom
claude/awesome-babbage-f8p0nq
Jun 21, 2026
Merged

briansrls merged 6 commits into
mainfrom
claude/awesome-babbage-f8p0nq

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Summary

Lands the never-merged #5297 mechanism onto current main: a structured, lens-checkable external-authority citation on every dsl/extdeps module, enforced fail-closed on the CI floor.

  • Carriers — extdeps.uri (Uri { scheme: UriScheme, locator }, closed-sum UriScheme = Http | Https | File | Ftp, RFC 3986/7595 grounded) and extdeps.external_authority (ExternalAuthority { uri }, FactAuthorityOverride, canonical data extdeps_external_authority_anchor row).
  • Lens (v2.lens.extdeps_external_authority) — fail-closed live policy per module: machinery-exempt → backfill-pending → else require a present external Http/Https anchor. Scheme decoded by exhaustive constructor identity (decode_uri_scheme), never a URL-prefix string. Violations: MissingFormalAnchor / UnrecognizedAnchorScheme / NonExternalAnchorScheme.
  • Host projection (extdeps_shape_transport_policy_project.rs) — structural read of the anchor record; live roster derived from the module-path index (declared module name, not directory); backfill + machinery-exempt facts. 9 builtins wired through 04_method.dag / v1_interpreter.rs / v1_compiler_infer_method.rs.
  • CI — ExtdepsExternalAuthorityGate enrolled in gunbc_ci_spec and scheduled on the floor; runs uri witnesses + live-corpus clean-tree + RED perturb receipts.

44 extdeps modules carry external anchors; 125 remain in the shrinking external_authority_backfill_pending snapshot.

Reconciliation onto current main

This is #5297 verbatim plus one line. The backfill snapshot keys on declared module name, not file path (build_module_path_index → extract_module_path; cf. the cargo_build_resolves_by_module_path_not_directory_nickname index test), so the post-#5391 directory reorganizations (rust/, package_managers/, git/, …) require no rename — the flat declared names (extdeps.cargo, extdeps.apt, …) are unchanged. Live-tree coverage gap on current main is 0. The only stale entry, extdeps.diagnostic.redfish, was dropped (redfish moved to extdeps.bmc.redfish, separately covered).

Test plan (all green by execution)

  • cargo build (debug + release), cargo fmt --all --check, cargo clippy --all-targets -- -D warnings
  • 18 projection unit tests (extdeps_shape_transport_policy_project)
  • 14 floor-enrolled .dag witnesses: live clean-tree GREEN + machinery-exempt fold + 3 RED perturbs (missing / bogus-scheme / file-anchor) + live anchor-drop RED + uri witnesses
  • Live-tree discrimination on a real cited module: Https→File flips the gate RED, anchor-drop flips RED, revert restores GREEN (byte-identical)
  • gunbc run … extdeps_external_authority_gate … main → ExitSuccess via real shell
  • ci_spec / ci_floor_plan enrollment witnesses green

🤖 Generated with Claude Code

https://claude.ai/code/session_019Mi3t2wX7UPzgqLyYAE1kS


Generated by Claude Code

…ive #5297)

Land the never-merged #5297 mechanism onto current main: a structured,
lens-checkable external-authority citation on every dsl/extdeps module,
enforced fail-closed on the CI floor.

Carriers
- extdeps.uri: Uri { scheme: UriScheme, locator } with closed-sum
  UriScheme = Http | Https | File | Ftp (RFC 3986 / 7595 grounded).
- extdeps.external_authority: ExternalAuthority { uri }, FactAuthorityOverride,
  and the canonical `data extdeps_external_authority_anchor` row.

Lens (v2.lens.extdeps_external_authority)
- Fail-closed live policy per module: machinery-exempt -> backfill-pending ->
  else require a present external Http/Https anchor. Scheme decoded by exhaustive
  constructor identity (decode_uri_scheme), never a URL-prefix string.
- Violations: MissingFormalAnchor / UnrecognizedAnchorScheme / NonExternalAnchorScheme.

Host projection (extdeps_shape_transport_policy_project.rs)
- Structural read of the anchor record; live roster derived from the module-path
  index (declared module name, not directory); backfill + machinery-exempt facts.
- 9 builtins wired through 04_method.dag / v1_interpreter.rs / v1_compiler_infer_method.rs.

CI
- ExtdepsExternalAuthorityGate enrolled in gunbc_ci_spec and scheduled on the floor;
  runs uri witnesses + live-corpus clean-tree + RED perturb receipts.

44 extdeps modules carry external anchors; 125 remain in the shrinking
backfill_pending snapshot.

Reconciliation onto current main: the snapshot keys on declared module name, so
the post-#5391 directory reorganizations (rust/, package_managers/, ...) need no
rename. The only stale entry, extdeps.diagnostic.redfish, was dropped (redfish
moved to extdeps.bmc.redfish, separately covered).

Verified by execution: 18 projection unit tests; 14 floor-enrolled .dag witnesses
(GREEN clean-tree + machinery-exempt fold + 3 RED perturbs + live anchor-drop RED);
live-tree discrimination on a real cited module (Https->File and anchor-drop both
flip the gate RED, revert restores GREEN); ci_spec/ci_floor_plan enrollment
witnesses; gate main -> ExitSuccess via real shell; cargo fmt + clippy -D warnings.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019Mi3t2wX7UPzgqLyYAE1kS
briansrls added a commit that referenced this pull request Jun 21, 2026
… (fixes v1↔v2 FreeMonoid collision)

The type/constructor environment keyed names by bare interned string and an
implicit bootstrap bridge injected v1 `std.types`' whole transitive env as a
base into every module that didn't import it. Together these let v1's
`std.algebra` FreeMonoid (a record) and v2's `v2.std.algebra` FreeMonoid
(`Empty | Cons` sum) collide — the winner decided by the topological typecheck
order, which the std.types implicit edges coupled across the v1 and v2 trees
into one global sort. Adding import edges (e.g. #5418's 44 extdeps anchors)
perturbed that order, so `v2.std.node_query` bound FreeMonoid to the leaked v1
record and produced `undefined variable 'Empty'` / `variant 'Empty' not found
in type 'FreeMonoid'` across the v2 tree. A §3 single-authority violation.

Fix (authority in src/v1/*.dag, mirrored in the stage0 seed .rs):
- 03_resolve.dag `topological_sort`: drop the implicit `std.types -> *` edges
  and the implicit in-degree term. Ordering is now import-driven only, so the
  two trees decouple and a module is always typechecked after the modules it
  actually imports — no order-sensitivity to re-tune.
- 04_infer.dag `build_type_env` / `build_type_env_unresolved`: drop the
  `std.types` base-injection. Import bindings start empty and are seeded only
  by the module's explicit imports; kernel primitives still come from the
  kernel env. No second, implicit authority for names.

Witness (src/v1/tests/src/module_authority_resolution_test.rs): a module that
never imports `std.types` no longer inherits a type `std.types` declares — the
reference is a hard UnresolvedType (RED without the fix, where the leak silently
resolved it). Plus two §3 invariant guards for same-named types across modules.

Verified by execution: the #5418-anchored discovery-corpus repro
(wet_hermetic_scaffold_roster_filter_uses_dag_prefix_authority) goes green;
regen_stage0 self-compiles the v1 tree clean without the leak; full
`cargo test --workspace` green except the pre-existing regen receipt-hash red
(#5420); clippy + fmt clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
… (fixes v1↔v2 FreeMonoid collision)

The type/constructor environment keyed names by bare interned string and an
implicit bootstrap bridge injected v1 `std.types`' whole transitive env as a
base into every module that didn't import it. Together these let v1's
`std.algebra` FreeMonoid (a record) and v2's `v2.std.algebra` FreeMonoid
(`Empty | Cons` sum) collide — the winner decided by the topological typecheck
order, which the std.types implicit edges coupled across the v1 and v2 trees
into one global sort. Adding import edges (e.g. #5418's 44 extdeps anchors)
perturbed that order, so `v2.std.node_query` bound FreeMonoid to the leaked v1
record and produced `undefined variable 'Empty'` / `variant 'Empty' not found
in type 'FreeMonoid'` across the v2 tree. A §3 single-authority violation.

Fix (authority in src/v1/*.dag, mirrored in the stage0 seed .rs):
- 03_resolve.dag `topological_sort`: drop the implicit `std.types -> *` edges
  and the implicit in-degree term. Ordering is now import-driven only, so the
  two trees decouple and a module is always typechecked after the modules it
  actually imports — no order-sensitivity to re-tune.
- 04_infer.dag `build_type_env` / `build_type_env_unresolved`: drop the
  `std.types` base-injection. Import bindings start empty and are seeded only
  by the module's explicit imports; kernel primitives still come from the
  kernel env. No second, implicit authority for names.

Witness (src/v1/tests/src/module_authority_resolution_test.rs): a module that
never imports `std.types` no longer inherits a type `std.types` declares — the
reference is a hard UnresolvedType (RED without the fix, where the leak silently
resolved it). Plus two §3 invariant guards for same-named types across modules.

Verified by execution: the #5418-anchored discovery-corpus repro
(wet_hermetic_scaffold_roster_filter_uses_dag_prefix_authority) goes green;
regen_stage0 self-compiles the v1 tree clean without the leak; full
`cargo test --workspace` green except the pre-existing regen receipt-hash red
(#5420); clippy + fmt clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
… (fixes v1↔v2 FreeMonoid collision) (#5422)

The type/constructor environment keyed names by bare interned string and an
implicit bootstrap bridge injected v1 `std.types`' whole transitive env as a
base into every module that didn't import it. Together these let v1's
`std.algebra` FreeMonoid (a record) and v2's `v2.std.algebra` FreeMonoid
(`Empty | Cons` sum) collide — the winner decided by the topological typecheck
order, which the std.types implicit edges coupled across the v1 and v2 trees
into one global sort. Adding import edges (e.g. #5418's 44 extdeps anchors)
perturbed that order, so `v2.std.node_query` bound FreeMonoid to the leaked v1
record and produced `undefined variable 'Empty'` / `variant 'Empty' not found
in type 'FreeMonoid'` across the v2 tree. A §3 single-authority violation.

Fix (authority in src/v1/*.dag, mirrored in the stage0 seed .rs):
- 03_resolve.dag `topological_sort`: drop the implicit `std.types -> *` edges
  and the implicit in-degree term. Ordering is now import-driven only, so the
  two trees decouple and a module is always typechecked after the modules it
  actually imports — no order-sensitivity to re-tune.
- 04_infer.dag `build_type_env` / `build_type_env_unresolved`: drop the
  `std.types` base-injection. Import bindings start empty and are seeded only
  by the module's explicit imports; kernel primitives still come from the
  kernel env. No second, implicit authority for names.

Witness (src/v1/tests/src/module_authority_resolution_test.rs): a module that
never imports `std.types` no longer inherits a type `std.types` declares — the
reference is a hard UnresolvedType (RED without the fix, where the leak silently
resolved it). Plus two §3 invariant guards for same-named types across modules.

Verified by execution: the #5418-anchored discovery-corpus repro
(wet_hermetic_scaffold_roster_filter_uses_dag_prefix_authority) goes green;
regen_stage0 self-compiles the v1 tree clean without the leak; full
`cargo test --workspace` green except the pre-existing regen receipt-hash red
(#5420); clippy + fmt clean.

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls and others added 2 commits June 21, 2026 01:16
…nalAuthorityGate

#5418 added ExtdepsExternalAuthorityGate to the Gate enum and to every match
over it EXCEPT gate_is_heavy_resolve (ci_floor_plan.dag:154), so once the v1↔v2
FreeMonoid collision cleared (#5422 now in this branch) the plan resolve reached
this fn and fail-closed on a non-exhaustive match:

  ci_floor_plan.dag:154:3: error: non-exhaustive match:
    missing variant(s) ExtdepsExternalAuthorityGate

The extdeps external-authority gate is a focused lens witness (filesystem_read
over dsl/extdeps/**), not a whole-tree heavy resolve like SourceRootIngest /
DslCompileClean — so it joins the other lens gates (Layering/ResolvedImports) at
`false`. Plan-data only; resolved at runtime by claim_executor, no stage0 seed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 21, 2026

Copy link
Copy Markdown
Contributor

Verified both findings against the head (188c527). I'm the contributor who fixed this PR's CI red (the missing gate_is_heavy_resolve arm for ExtdepsExternalAuthorityGate); here's my assessment of the two non-blocking review findings — both are valid, both are §3-flavored follow-ups on the extdeps modeling rather than blockers, and I'm intentionally not rewriting load-bearing lens/carrier authority under a CI-fix scope.

Finding 1 — Rust string-equality scheme predicate (extdeps_shape_transport_policy_project.rs:807). Confirmed: live_violation_module_paths gates on scheme_identity != "Http" && scheme_identity != "Https", a raw-string re-encoding of the same "http-class scheme" fact that decode_uri_scheme (lens) + uri_scheme_is_http (dsl/extdeps/uri.dag:38) already own. It's a genuine parallel representation, and the lens banner ("scheme decode is exhaustive constructor-identity equality only") does over-promise relative to the host gate. It is not a one-line fix though: the host clean_holds consumer is live (a second CI gate, not dead code), so the §5-correct move is to derive the Rust verdict from the projected decode table (or retire the host gate in favor of the lens), not to hand-mirror the decode_uri_scheme literals into Rust — that would just relocate the second representation. That's a focused consolidation on load-bearing lens authority and belongs to the extdeps arc owner as its own PR, not smuggled into the anchor-carrier PR. Bounded for now: the discriminator set is 4 closed UriScheme variants and both consumers run, so the two can't currently disagree — which is why the reviewer scoped it non-blocking. Filing it as the recommended next follow-up.

Finding 2 — vendor modules cite en.wikipedia.org/wiki/<Company> vs the "not the umbrella company homepage" rule. Confirmed all 8 vendor/*.dag cite the Wikipedia company article. I read this as defensible rather than a violation, and the reviewer's own framing agrees ("the module concept here arguably is the corporate entity"): the carrier rule excludes the umbrella company homepage (i.e. intel.com marketing surface) precisely because for a spec module you want the spec surface, not the vendor's self-published page. A Vendor<Hardware> module's concept genuinely is the legal entity (legal_name: "Intel Corporation"), and the Wikipedia article is a third-party intersubjective authority for that entity — categorically different from the excluded self-homepage. The real gap is documentation, not citation choice: the carrier comment in external_authority.dag was written for spec-concept modules and should add an explicit note that entity-concept (Vendor<Domain>) modules anchor on an encyclopedic/registry authority for the entity. A registry (SEC EDGAR / Companies House) would be even more grounded and is worth doing, but it's a carrier-doc + citation-polish follow-up, also non-blocking.

Neither finding gates merge (the review verdict is APPROVE). Both are logged as extdeps follow-ups for the arc owner; happy to take Finding 1's consolidation as a separate scoped PR if you want it assigned here.

— sent from merry-bee-526

@gunbai-bot

gunbai-bot Bot commented Jun 21, 2026

Copy link
Copy Markdown
Contributor

Verified the two follow-up findings from the latest review against the current code:

  • uri_is_url / unused Url import (dsl/extdeps/uri.dag) — uri_is_url is not dead: it has executable witnesses in dsl/test/claim/uri_witness_test.dag (uri_is_url_https_projection_holds, uri_is_url_file_not_url_holds), so it's covered by-execution, not just documentation glue. The Url import is intentional and already documented at uri.dag:44-45 — it records the [Url] ⊂ { uri | uri_scheme_is_http(uri.scheme) } relation, with the Url=String consumer migration explicitly called out as a separate follow-up. Accept as-is (non-blocking, matches the reviewer's read).
  • external_authority_backfill_pending.txt count-ratchet — confirmed: there's no monotonic-shrinkage ratchet enforcing the roster only shrinks. Valid non-blocking follow-up; the file is explicit tracked debt today. (Note: this PR's live-clean gate failure on merge was caused by 5 newly-landed modules — extdeps.access.{aws_iam,posix,rbac,zanzibar} from access model: cite real access-control systems in extdeps, derive std, enforce via lens #5415 and extdeps.cache.key_completeness from Cache key-completeness lens: ToolchainChange invalidation ⟹ a toolchain input in inputs_considered (fix resolved_graph_cache) #5423 — that landed on main after extdeps: external-authority anchor carrier + fail-closed CI lens (revive #5297) #5418 authored its roster and were neither anchored nor backfilled. The gate correctly fail-closed on them. Fix pushed: anchored the 4 access modules from their existing // Source: citations, and added extdeps.cache.key_completeness to the backfill roster alongside its 8 extdeps.cache.* siblings. A count-ratchet would have caught this class earlier — good follow-up.)

Neither finding blocks merge (verdict APPROVE).

— sent from merry-bee-526

briansrls and others added 2 commits June 21, 2026 01:58
…key-completeness lens

#5418's external-authority gate scans the LIVE extdeps tree and fail-closes on any
module lacking an anchor. Once #5422 cleared the FreeMonoid collision and the missing
gate_is_heavy_resolve arm let the plan resolve, the gate correctly flagged 5 modules
that landed on main AFTER #5418 authored its roster and were neither anchored nor
backfilled:

  missing: extdeps.access.{aws_iam,posix,rbac,zanzibar}   (#5415 access model)
  missing: extdeps.cache.key_completeness                 (#5423 cache lens)

The 4 access modules already carry their real upstream citation in a `// Source:`
comment (AWS IAM grammar, POSIX.1-2017/opengroup, ANSI/NIST RBAC, the Zanzibar USENIX
paper) — promoted each to the structured `extdeps_external_authority_anchor` carrier
the gate gates on (DESIGN §3: the mark on the carrier is the authority). No access
sibling is backfilled, so anchoring (not backfilling) is the consistent treatment.

extdeps.cache.key_completeness is an internal §5 cache-soundness LENS (a pure reader
over the cache catalog), not a cited external-system model — so it joins its 8
extdeps.cache.* siblings on the backfill_pending roster as tracked debt, not a fake
external anchor.

Verified by execution: the floor's discovery-corpus (587 witnesses) and
extdeps_external_authority_gate_passes both go GREEN with this change (live
violation set empty, roster count > 150).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 21, 2026

Copy link
Copy Markdown
Contributor

Verified all three findings against head 898363e:

1. external_authority_backfill_pending.txt parallel ledger (§3). Valid §3 observation — it's a hand-maintained snapshot. One correction on the §5 framing though: the roster is fail-closed, not fail-open. A new unanchored module that is absent from the .txt goes RED (extdeps_shape_transport_policy_project.rs:749 — "New modules NOT on this list are fail-closed RED until anchored"), which is exactly how this PR's 5 missing modules (extdeps.access.* + extdeps.cache.key_completeness) were caught. That's also why the set can't simply be derived from "no anchor row": deriving pending = no-anchor would auto-exempt every unanchored module and make the gate fail-open (never fire). The explicit allowlist is what makes absence fail-closed — it's load-bearing, not pure redundancy. The real §3/§5 hardening is the count-ratchet (monotonic shrink) the prior review also flagged, or the mtime/age second-signal you suggest. Non-blocking; logged as a follow-up.

2. uri_record_from_anchor_body accepts undeclared StableAuthority / ExternalUri (§4). Confirmed real — line 586 matches "ExternalAuthority" | "StableAuthority" | "ExternalUri", but only ExternalAuthority is a declared type in external_authority.dag. Valid §4 closed-substrate cleanup: the projector tolerates variant identities the substrate doesn't declare. Whether these are forward-compat placeholders or dead arms is the projector author's intent call, so I'm flagging it as a follow-up rather than dropping them under this CI-fix scope (non-blocking — the live carrier only ever emits ExternalAuthority, so the extra arms are inert today).

3. decode_uri_scheme stringly constructor-identity match (§4 boundary). Agreed and non-blocking, as you note — the host projection is the single authority and authored_name_at produces the same identity, so it works; a UriScheme rename would desync lens vs carrier. This is the same §3 host↔lens-decode consolidation surfaced in an earlier review (route both through one projected decode table); tracked as the extdeps follow-up there.

None block merge (verdict APPROVE). My change on this head is the 5-module live-clean fix (anchor 4 access modules + backfill the cache key-completeness lens); the three findings are pre-existing extdeps follow-ups for the arc owner.

— sent from merry-bee-526

@briansrls
briansrls merged commit c8baddd into main Jun 21, 2026
1 check passed
@briansrls
briansrls deleted the claude/awesome-babbage-f8p0nq branch June 21, 2026 06:33
briansrls added a commit that referenced this pull request Jun 21, 2026
… (warm-lark correction)

Deriving the realization-vocab exception roster from a live grep would make the guard vacuous
(leak = non-edge importer AND NOT-in-roster; derived roster ⇒ every importer always in it ⇒
leak_count always 0 ⇒ never fires). Distinguish the informational prose count (rots, re-grep)
from the lens's enforcement roster (frozen, so a new unrostered importer goes RED = the teeth).
Add the 11th importer (extdeps_external_authority_transport, the #5418→#5445 race, fixed by #5453)
and the roster-completeness assertion as the steady-state race-hardening.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
…rnal_authority_transport to exception roster

The extdeps_external_authority_transport.dag (added in #5418) imports
extdeps.languages.bash.program but was not included in the exception roster,
causing the realization_vocab_clean_tree_holds test to fail. The file is a
transport module in dsl/tools/ following the same pattern as other rostered
transports, so it requires roster entry per DESIGN §3.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
…gestion⁻¹ past syntax (#5442)

* WIP: dsl -> v2 scoping

* WIP: ROADMAP planning

* WIP: ROADMAP planning

* WIP: ROADMAP planning

* ROADMAP: scannable dependency-ordered checklist; consolidate caching plan (de-fork zesty-deer-479 owner, absorb quick-ant-298 spine)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* self-host: add bootstrap purity (no stage0 hand-edits / regen-lockstep keystone) + precise v1 cutover

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §0 fail-closed lock-down (blocks expansion) + audit doc; §4 website demo

Audit: cache lossy-digest flake (resolved_graph_cache.rs:146, verified), ~inert analytical
lenses (complexity/cost/etc), regen --verify unwired (#5325). Lock-down checklist gates expansion.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP: flesh §2 idea->idea compiler (medium/language axes); §0 → lock-down LANE (audits→fixes→meta), name model<->realization fork as suspected root

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* lock-down: add CI-coverage-completeness audit (rust gate runs 3 of 60 v1 suites) + axiom/syllogism lens (DESIGN open thread #1 — lock down the reasoning)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* roadmap §0/§7 + lockdown: lead with correctness-by-construction, demote lenses to residue

Folds in the operator principle (relayed via quick-ant-298): a lens is validation
— it concedes the bad thing is writable. Root-cause to make it unwritable (single
authority / realization derived from model); reserve lenses for the genuinely-
unstructurable (complexity/necessity). #5423's spec-only key lens shipped a
false-green as the live proof.

- ROADMAP §0: add the principle; split Fixes into tier-1 construction (dissolve
  model↔realization fork; cache-key derived-from-declared-inputs; self-host purity
  by construction) and tier-2 lens (complexity/cost; cache-redundancy; purity
  oracle; promote-inert). Meta-invariant → construction-justification rule.
- ROADMAP §7: P1 cache-key reframed from 'realizer-key lens' to key derived from
  declared inputs_considered (construction).
- fail-closed-lockdown.md: construction principle in the thesis; §4 checklist
  re-ordered construction-first / lens-residue; meta = construction-justification.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* roadmap §0: add Disposition carrier + 'confront skipped modeling decisions'

Captures the lens/coproduct disposition decision (operator). One typed carrier
(Terminal{reason} | Scaffold{dissolves_to}) for BOTH lens-lifecycle tags AND
coproduct dissolve-markers — today freeform 🟡 comments, unreadable by lens since
comments aren't Nodes.

Decision: middle path (construction-capable carrier + selectively-enforcing lens
that ratchets coverage) now, #1 (substrate can't-define-untagged) as the named
end-state. The lens is itself a Scaffold{dissolves_to: substrate-mandatory-tag} —
self-dissolving when coverage = whole tree. Rejected jumping to #1 on sequencing
(load-bearing §4 substrate change → escalate; flag-day migration; derived
coproducts need disposition derived not authored), not on principle.

Enforceability split: presence = construction (non-optional field, no meta-lens);
redundancy (scaffold + successor both present) = hard gate; Terminal-vs-Scaffold
correctness = retro/judgment (synthesis-feasibility limit).

- docs/plans/disposition-carrier.md (new)
- ROADMAP §0 tier-1 + meta 'confront skipped decisions' standing practice

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* DESIGN §5/§6: promote construction-over-validation; roadmap: scope-partition §0, testgen §1, shelve dashboard

Addresses the review's four flags + sequencing nuance.

- DESIGN.md §5: 'correctness by construction, not validation' is now an axiom
  (a check re-stating a model constraint is a 2nd representation §2/§3; prefer
  realization derived from a single authority; reserve checks for the unstructurable
  residue). §6 'enforce with lenses' reconciled: construction first, lens = residue
  mechanism, AND the executable inert-lens backstop is NOT superseded by the
  authoring-time construction-justification judgment. (flag 4 home + flag 3)
- ROADMAP §0 partitioned: In-scope this window (numeric-tower grounding; cache
  trustworthy + warm==cold oracle shipped NOW as detective; widen rust gate;
  promote inert lenses) vs Fenced-OUT fan-out (Value::Null 131-site split;
  self-host purity gate; cross-tree import activation; Disposition carrier).
  Honest framing: window reduces fail-open surface, does NOT 'lock' the class —
  Null split stays open. (flags 1, 2, sequencing nuance)
- ROADMAP §0 meta: restored executable inert-lens hygiene backstop, construction-
  justification layered on top (not 'supersedes'). (flag 3)
- De-dup: principle no longer restated in ROADMAP/lockdown §0; both point to
  DESIGN §5. cache-key construction homed in §7, §0 references it. (flag 4)
- ROADMAP §1 = testgen as bug-class oracle (+ affected-set completeness half +
  parked anemia lens); dashboard shelved to §8.
- docs/plans/testgen-oracle.md (new), fail-closed-lockdown.md realigned.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* DESIGN §5/§6/§7: wall-vs-ratchet decidability, displaced-pain denominator, open language design

Folds in the operator's product thesis + the two bounds that keep it honest.

- §5: construction makes a class unwritable only when membership is DECIDABLE —
  trichotomy (wall now / wall after grounding / ratchet forever); 'never' is the
  trap (lets an undecidable ratchet masquerade as a wall — optimality by Rice).
- §6: denominate the benefit — the deliverable is a displaced cost (§1 time / a
  paid-for pain), the lens/substrate is the moat not the product; priced in
  elegance the work is unbounded (the economic twin of 'never').
- §7: the recursion's payoff — language design itself opens up. It's locked by
  cost (a check = a compiler fork; a language = an adoption problem); both
  dissolve here (a wall is a row §2, applied over a medium-agnostic substrate §4),
  so (compiler-fork × language) → (row + medium). Sound where ingest is Lossless,
  fail-closed where not (DecodeFidelity §4).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* ROADMAP: fix doc-graph violations from bright-eagle-46 review of #5424

Apply the apex axiom/syllogism lens (single authority / no orphan / no
cycle) to the roadmap itself — manual acyclicity pass:

- orphan: testgen-oracle.md backlinked §1 → repoint §4 (its own lane)
- single authority: §0 cache-key now a pure pointer (= §2 F2/F3/P1);
  §0 numeric-tower marked the authoritative home (§5 de-fork / fork plan
  point here, no second checkbox)
- §0↔§5 cycle: self-host purity reframed as a §5 deliverable §0's
  expansion-gate depends on (edge §5 → §0-gate → products), not §0-owned
- undeclared edge: §7 react/html declares its dependency on §6 media
- backlink sweep: the reorg had broken every numeric backlink across 7
  plan docs; re-point all and anchor each to the stable section TITLE so
  a future renumber can't silently break them again

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §3 + plan: algorithmic-cost reduction by construction (rewrite, not budget)

Reframe §3 from per-fn complexity budgets to the actual intent: rewrite
common suboptimal patterns (O(n²)→O(n), O(2ⁿ)→O(n), O(n)→O(log n)) to the
cheaper equivalent — construction on the cost axis, not a warning.

New plan doc docs/plans/algebraic-rewrite-optimization.md captures the
up-front design: the decidability split (modeled EffectShape makes the
preconditions structural; equivalence stays undecidable so no optimality
oracle), rewrite-rule-as-row + once-proven soundness, the common-case
catalog tiered by precondition, D1 canonical-form-is-truth / D2 two seed
rules / D4 constant-factor deferred, the four-witness DONE bar (incl. the
non-firing control half-done versions skip), and a corpus hit-rate
acceptance gate. complexity.dag is the cost oracle; synthesis.dag stays
the advisory undecidable residue.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §2: Phase-0 measurement instrument done (#5431 peak-RSS) — remaining is the Phase-1 consumer

Per quick-ant-298: the measurement keystone was nearly complete — model
side already floor-enrolled, step timing already emitted; the only gap was
peak-RSS, closed by #5431. P4's Phase-0 dependency is satisfied; remaining
is the Phase-1 measured->plan feedback + width-fold (also unblocks §1-C).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* plan/§3: detection-vs-enforcement containment (E⊆D′⊆D) + explicit seed-rule I/O up front

Grounded in cost.dag U2 + complexity.dag (investigated, not theorized):
- detection is TOTAL by construction (kernel-level cost fold; arbitrary fns
  detectable); boundary is precision (ClassUnknown), not coverage
- enforced rewrites are a strict subset structurally guaranteed by the
  class-drop witness: E ⊆ D′(precise) ⊆ D(all)
- n√n excluded for a MODEL reason (PolynomialDegree is integer-only, n^1.5
  unrepresentable); ternary search excluded (log base is not a class)
- today's small gate roster = subject-production limit (fn-body reflection),
  NOT a detection limit
- new §3a fully specifies the two seed rules up front: input→output→
  precondition→non-firing control→discriminating equivalence input, so the
  worker builds to spec and the project can actually finish

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §0/§1: rust-gate is cadence-decoupling, not run-all (per fierce-hawk #5427)

The 3-filter allowlist was COST selection, not arbitrary gatekeeping — the
v1 SEED compiler costs ~tens of CPU-sec per trivial test, so run-all-per-PR
is CPU-hours (off the table). True shape: per-PR cost-bounded subset +
measured #[ignore="expensive: Ns"] + completeness lens (#5427); nightly
--ignored lane as the destination for expensive + the 58 currently-ignored
tests (owned by §1/quick-ant, after #5431, escalate for load-bearing
CI-gen). Completeness = every test runs on >=1 cadence (fail-closed).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* plan §2a: generalize by structural-redundancy keying (O(n^x)->O(n^(x-1)) free); flag n-log-n as substitution

Per operator: catalog must generalize polynomial-degree reduction without
edge cases. Resolution: rules key on the structural redundancy, never on
degree — degree is not evidence of redundancy (would fire on genuine O(n^x)).
A structurally-keyed nested-membership->set peels one level wherever it
matches; fold-to-fixpoint gives O(n^3)->O(n^2)->O(n). Cost model supports
arbitrary integer degree, so witness (b) holds at every peel.

Flagged OPEN (operator input invited): O(n^x)->O(n log n) is algorithmic
SUBSTITUTION (different algorithms, same I/O) not redundancy elimination —
verges on undecidable equivalence; tractable form is per-idiom rules
(sort-based dedup, repeated-min->heap), not a parameterized rule. Seed Rule 1
now authored structurally + carries a depth-2 generalization witness.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* plan §1b: Unknown is an anemic atom — dissolve over time (reuse Disposition), never a false pass

Per operator: classifying Unknown isn't a fixed up-front split — it's the
standing anemic-leaf dissolution practice (DESIGN §2 decompress->map->reduce)
applied to the cost lens. UnknownCost{diagnostic} already carries its reason;
the anemia is the free-form reason. Each decomposition resolves an Unknown to
construction (now-precise class -> new D′) or a grounded Terminal (genuinely
undecidable, positively recognized -> advisory comment). DFS-first: this IS
the Disposition carrier (resolves to construction-or-justified-Terminal), so
reuse it, don't fork an unknown-reason enum. Supersedes the static
Undecidable|Undetermined split. Two invariants fixed up front: never a false
pass (Unknown=>Violates, already holds); every Unknown on the dissolution
frontier. cost.dag enrichment + un-parking Disposition are operator-gated.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP: §3 reverts to budget-gate validation (stability); rewrite-engine relocated to §5 (post-stability)

Operator decision 2026-06-21: budget-gate validation is fine for the
stability window; the algorithmic-cost REWRITE construction design is
expansion, homed with self-hosting (§5) — IR-rewrite/canonicalization is
most natural once .dag is the self-hosted truth.

- §3 = complexity budget gate (validation): cost-lens symbolic_max fix
  (#5437) + per-fn subject + budget-gates-whole-codebase (gated on fn-body
  reflection) + synthesis advisory. #5437 foundation stays in-window.
- §5 gains an 'adjacent expansion lane' = the rewrite engine, pointing at
  the preserved plan doc; marked post-stability.
- plan doc status -> POST-STABILITY EXPANSION, relocated to §5.

Nothing deleted — the rewrite design is preserved, just fenced out of the
stability window (same as Disposition / Value::Null-split).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* #5442 review fix (warm-lark-306): grep-as-authority for the sidecar roster (10 not 9)

The §0-guard impl PR (#5445) grepped current main and found 10 importers of
extdeps.languages.bash.program, not 9 — the 10th (dsl/gunbc/ci_spec.dag) landed via #5432 after
the original pre-merge grep. Rather than bump the frozen count, make the live grep the authority
(the roster shrinks to 0 as the bash-sidecar arc migrates consumers, so any frozen number rots —
the single-authority point). Also note the two *_test importers are intentionally not walled
(guard scans consumer-source roots only).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP: check off 6 merged items (catch-up sweep)

Flip [ ]→[x] for unambiguously-merged work (PR-ref'd for traceability):
- §0 numeric-tower grounding (#5428 — == straddle guard dead-in-corpus)
- §0 inert-lens hygiene executable backstop (#5433)
- §2 F2/F3 resolved_graph key derived from inputs_considered (#5425)
- §3 cost-lens symbolic_max zero-absorption fix (#5437)
- §4 gate existing generated testgen output (#5434)
- §4 affected-set completeness (#5430)

Partial/compound items left for their lane managers to flip in the PR that completes them.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §1: add compile-clean-gate force-checks-every-fn-body box (2(ii) fail-open)

New floor-coverage item: the compile-clean gate is fail-open — unreached fn bodies escape
typecheck, so undefined symbols in dead code pass green (execution-proven on utf8_decode_bytes).
Construction fix = typecheck total over every declared body. Owned by §1 (quick-ant); measure-first,
operator-gated enforce-flip.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §0: correct the 2(ii) box — registry-leak mechanism, not unreached-bodies

snappy-gull's deeper diagnosis: the fail-open is NOT unreached bodies (bodies ARE visited).
utf8_decode_bytes resolves because it's a global builtin_function_registry entry (04_method.dag,
a marked bridge scaffold) not scoped to the compiled tree. Reframe the box to tree-scoped builtin
availability / registry partition; instance fix = real std fn + remove the registry bridge entry.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* plan doc: enforcement roster is a FROZEN grandfather set, not derived (warm-lark correction)

Deriving the realization-vocab exception roster from a live grep would make the guard vacuous
(leak = non-edge importer AND NOT-in-roster; derived roster ⇒ every importer always in it ⇒
leak_count always 0 ⇒ never fires). Distinguish the informational prose count (rots, re-grep)
from the lens's enforcement roster (frozen, so a new unrostered importer goes RED = the teeth).
Add the 11th importer (extdeps_external_authority_transport, the #5418→#5445 race, fixed by #5453)
and the roster-completeness assertion as the steady-state race-hardening.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* ROADMAP refresh: §1 nightly→Pop-B (opt-level won), §2 resolve-cache GO + P2 de-fork-dependent, §0 census regression + gate-hygiene

Reflects decisions/findings that landed 2026-06-21:
- §1: the "expensive" tests were debug-build amplification, not intrinsic
  seed cost (proud-deer cause-table); opt-level=3 (#5456) restores Pop-A to
  per-PR; nightly lane reduced to Pop-B wet-captures only. Mirror corrected in §0.
- §2: resolve-cache enable = GO (~18% floor-wall, purity-proven, #5429-gated);
  P2 ParseTable dissolution reclassified as a downstream consumer of the dsl→v2
  de-fork (keen-otter: v2-local rewire is cosmetic); #5446 realize kernel green.
- §0: stage0 clone-census ratchet went inert + the seed regressed 1138 over
  budget (rust-side coverage-by-illusion + thesis regression; #5427 surfaced it);
  gate-hygiene rule (floor-enrolled gate must be green-on-main at merge) +
  roster-completeness assertion promoted to should-land (the #5445 floor-skew).
- §1: registry-partition instance fix = #5452 (verified sound).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
* Delete dead v4_slice parity test pipeline

dag_emit_from_resolved_matches_compile_sources_for_v4_slice reads fixture
fixtures/v2-mvp1 which was deleted and no longer exists in git history or the
working tree. The test was hidden by the old rust-gate allowlist but exposed
by #5427, and cannot pass. (Refs: #5427)

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Delete obsolete v1_compiler_lib_test module

The v1_compiler_lib_test module was solely used by the now-deleted
dag_emit_from_resolved_matches_compile_sources_for_v4_slice test to
compile-check the v1-compiler lib test harness. With that parity test
gone, this module is dead code. (Addresses review feedback on #5457)

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Fix realization vocabulary containment test: add missing extdeps_external_authority_transport to exception roster

The extdeps_external_authority_transport.dag (added in #5418) imports
extdeps.languages.bash.program but was not included in the exception roster,
causing the realization_vocab_clean_tree_holds test to fail. The file is a
transport module in dsl/tools/ following the same pattern as other rostered
transports, so it requires roster entry per DESIGN §3.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* WIP: Delete dead v4-emit-slice parity test pipeline dag_emit v4_slice: it rea

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
…y backfill (fleet-red keystone fix) (#5465)

#5429 added the cache_purity module but did not register it in external_authority_backfill_pending.txt
(its 4 realization siblings are listed), so #5418's live-clean-tree lens fail-closes — fleet-wide main-red
since cdd1421 (#5429); prior commit ac9a7e7 (#5449) was green. Same floor-skew class as #5445/#5453.
One-line backfill anchor; diagnosed by bright-stag-194, delegated by sunny-bee-667 (lane owner) for the
urgent fleet-unblock. Also unblocks stern-otter's P3 branch.

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jun 22, 2026
…hority gate)

CI floor batch-2 RED: #5418 live-clean-tree lens fail-closed because
extdeps.bmc.access shipped without an external_authority_anchor. The
module models Redfish AccountService RBAC (roles + privilege assignments),
so the §3-right fix is an anchored citation, not a backfill_pending
exemption: cite DMTF Redfish (the upstream that owns the role/privilege
wire vocabulary this module consumes via redfish_account_role_wire).

extdeps.access.posix was already anchored (POSIX/opengroup sys_stat) and
extdeps.access.rbac too (NIST RBAC) — bmc.access was the only gap.

Verified by execution: corpus_live_clean_tree_holds +
corpus_live_anchored_modules_clean_holds both green; compile 437/0.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 23, 2026
…BAC (#5571)

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* BMC onboarding lifecycle: 4-phase model + Redfish write seam + read-only validation

Models the onboarding of the operator's new Altra server (BMC 192.168.1.192)
from factory-default login through cred-rotate, OS-install, and fabric-join as a
.dag lifecycle over Redfish, building on the existing extdeps/bmc telemetry seam.

- extdeps/bmc/types.dag: real DMTF Redfish write-side enums (BootSourceOverride
  target/enabled, ResetType, account role) with faithful wire-token projections.
- extdeps/bmc/http.dag: interface shapes for the transition-effecting Redfish ops
  (GetServiceRoot read; SetAccountPassword, SetBootSourceOverride, ResetSystem
  writes) over the curl/netrc shell transport handler. Secrets ride a runtime
  request_body_file, never argv or the repo.
- gunbc/bmc_onboarding.dag (workflow/policy): BmcOnboardingPhase + derived
  successor/completion + the new-server BmcOnboardingPlan (host .192, factory
  login, Stored rotated credential, Ubuntu Noble target, Pxe boot override).
- gunbc/tools/bmc_onboard.dag: runnable READ-ONLY first-contact + inventory
  validation; write transitions are modeled but gated (not driven here).
- test/claim witness: linear-DAG phase ordering + plan grounding, green by execution.

Grounded against the live BMC at 192.168.1.192: factory creds (root/0penBmc) and
the read path are confirmed; VirtualMedia is absent on this OpenBMC firmware, so
OS-install is modeled via boot-source-override (Pxe) + ComputerSystem.Reset.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5563: drop redundant phase_order roster (§3 single authority)

bmc_onboarding_next_phase is now the sole authority for the linear successor
relation; the standalone bmc_onboarding_phase_order list duplicated it. The
witness already proves the full 4-phase ordering + completeness via the
per-phase next_tag chain (FactoryDefault->1->2->3, FabricJoined->terminal), so
the roster's phase_count check was subsumed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5563: rename bmc_onboard -> bmc_onboard_validate (honest tool name, §5)

The tool only performs the read-only FactoryDefault validation (GetServiceRoot +
GetSystem); it does not drive cred-rotate/OS-install/fabric-join. Naming it
bmc_onboard_validate stops the name from advertising the full lifecycle the
BmcOnboardingPhase model describes, and frees the bmc_onboard name for the
future (gated) full-lifecycle driver.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: BMC onboarding lifecycle for new Altra server (BMC 192.168.1.192): model

* review #5563: delete bmc_onboarding_is_complete (single-caller predicate)

The predicate had one caller (the witness) and the witness's next_tag chain
already proves completion (FabricJoined -> -1 = terminal; others -> 1/2/3).
Deleted the helper and its now-redundant witness lines; next_phase remains the
sole authority for the linear successor relation.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* access layer: POSIX accounts + BMC Redfish roles as least-privilege RBAC

Model the credentialing leaves in the existing access layer (DESIGN.md §2/§3):
- extdeps/access/posix.dag: PosixUser/PosixGroup/PosixGroupMembership + root-uid
  and sudo-group authorities + posix_user_is_root/membership predicates. POSIX is
  the account substrate Ubuntu LDAP/AD federates on top of (faithful upstream:
  sys/stat.h anchor already present).
- extdeps/bmc/access.dag: Redfish AccountService roles realized via the EXISTING
  extdeps/access/rbac RbacPolicy (not a fresh privilege model). role->privilege
  grounded from the live .192 probe (Administrator/Operator/ReadOnly DMTF
  privilege sets). redfish_role_name projects the faithful DMTF role tokens.
- test/claim/access_layer_extension_witness_test.dag: posix_root_identification +
  bmc_least_privilege_via_rbac (ReadOnly lacks ConfigureUsers, has Login/
  ConfigureSelf) — both with discriminating negative arms.

Stacked on #5563 (needs RedfishAccountRole from extdeps/bmc/types).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5571: dedup role wire + ground Redfish privileges as a closed enum

Addresses claude-opus-4-7 REQUEST_CHANGES (review 31850):
- Delete redfish_role_name (byte-identical nickname of the existing
  redfish_account_role_wire in extdeps/bmc/types.dag) — §3 single authority.
  access.dag + witness now import and reuse redfish_account_role_wire.
- Ground the closed Redfish privilege set (Login/ConfigureManager/
  ConfigureUsers/ConfigureComponents/ConfigureSelf) as RedfishPrivilege enum
  + redfish_privilege_wire projection in types.dag, exactly as RedfishAccountRole
  does (§4 grounding). Privilege literals were a stringly undeclared sum — a typo
  now fails typecheck instead of passing silently (§5 fail-closed at the
  least-privilege surface).
- Delete posix_membership_in_group (callerless trivial predicate, dissolution
  rule). posix_user_is_root kept (encapsulates posix_root_uid authority).

Witnesses green by execution; whole-tree compile 429/0.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5571: delete unused posix_sudo_group (dead scaffold, §5)

claude review 31854 nit: posix_sudo_group declared but unused. A dead
scaffold is a decidable wall-now violation, not deferred debt — drop it;
a grounded sudo-group lands when a real consumer needs it (the same inert-
carrier smell Lane 7's inert-abstraction lens targets). Tree compiles
437/0, both access witnesses green by execution.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5571: derive rbac roles from wire authority + drop dead Posix group types (§3/§5)

claude review 31868, two §3 nits:
- access.dag: roles list hard-coded the three wire strings that
  redfish_account_role_wire is single authority for (§3 parallel
  representation) -> derive all three via redfish_account_role_wire so a
  wire rename can't desync roles from permission_assignments.
- posix.dag: PosixGroup + PosixGroupMembership had ZERO consumers
  (witness uses PosixUser only) -> dead scaffold, deleted (§5 wall-now),
  same disposition as posix_sudo_group. Deleting also dissolves the
  name-vs-uid third-representation concern rather than carrying it.

Tree compiles 437/0, both access witnesses green by execution.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* review #5571: anchor extdeps.bmc.access to DMTF Redfish (external-authority gate)

CI floor batch-2 RED: #5418 live-clean-tree lens fail-closed because
extdeps.bmc.access shipped without an external_authority_anchor. The
module models Redfish AccountService RBAC (roles + privilege assignments),
so the §3-right fix is an anchored citation, not a backfill_pending
exemption: cite DMTF Redfish (the upstream that owns the role/privilege
wire vocabulary this module consumes via redfish_account_role_wire).

extdeps.access.posix was already anchored (POSIX/opengroup sys_stat) and
extdeps.access.rbac too (NIST RBAC) — bmc.access was the only gap.

Verified by execution: corpus_live_clean_tree_holds +
corpus_live_anchored_modules_clean_holds both green; compile 437/0.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants