Skip to content

Widen the rust gate by construction (§1): invert the hand-picked 3-filter allowlist (29 of 792 green tests) → run-all-unless-#[ignore]d-with-written-reason; add CI-coverage-completeness so a new test is covered by default (fail-closed); measure CI-time impact before committing the full set - #5427

Merged
briansrls merged 47 commits into
mainfrom
session/fierce-hawk-540
Jun 22, 2026

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jun 21, 2026 •

Copy link
Copy Markdown
Contributor

DRAFT — flips ready once CI is green on the full run-all gate.

Why this PR exists (the strongest motivation)

The hand-picked 3-test allowlist meant coverage was by enumeration — a test was gated only if someone remembered to add it to the filter. That is fail-OPEN by construction: a test could sit green-by-never-running indefinitely. This PR proves the hazard was real, twice by execution:

  1. The new coverage-completeness lens caught a silently-unrun test on its first input: resolve_typed_cache_equivalence_test.rs (landed via Phase 1: ExecutionMode{Hermetic|Wet} for interpreter + claim_batch --wet #5071, never declared in lib.rs → never compiled/ran — a coverage hole on main). The lens went RED fail-closed; declaring the module fixed it.
  2. Inverting the allowlist (run-all) surfaced 27 deterministic reds the allowlist had hidden — including interpreted_parse_termination, parse_table_memo_amortization, and target_model_runtime_import_repro, which resolve compiler-CORE entries. They broke when v2-core started importing extdeps.communication.medium (a layer-legal compiler←extdeps dep in dsl/) but the test helper's roots were never updated — and the allowlist hid it for a whole release.

Coverage-by-construction (run-all-except-#[ignore]d) makes both classes impossible: a new test is gated the moment it lands; an under-scoped helper that breaks real tests goes loud.

What this PR does

  • Inverts the rust gate: drops the hand-picked 3-filter allowlist → cargo test -p v1-compiler-tests (run-all-EXCEPT-#[ignore]d) in dsl/gunbc/ci_spec.dag ci_rust_gate_test_command. Coverage holds by construction.
  • Adds the CI-coverage-completeness lens (coverage_completeness_lens_test, runs inside the gate over its own suite): fail-closed residue keeping every #[ignore] reasoned and every *.rs test file mod-declared in lib.rs. It is itself a test in the widened suite, so it covers its own completeness — no separate wiring to drift.

The honest tally — 27 reds surfaced by the widening

  • 14 FIXED BY CONSTRUCTION (zero ignores): the under-scoped v2_source_roots() = [src/v2] was a §3 fork of the canonical layer-roots authority gunbc.ci_layer_roots = [src/v2, dsl] — it dropped dsl, so v2-core's extdeps.communication.medium import was unresolvable. The 4 affected files' local copies now funnel through one helpers::v2_layer_roots() = [src/v2, dsl] authority, with a §6 dissolution marker (derive from the .dag fact when a Rust-reachable accessor exists; cf. neat-ibex-867's roster-drift de-fork). All 14 verified green.
  • 13 IGNORED-WITH-REASON + routed (pre-existing emit/inference reds, never run in CI): each #[ignore = "failing: <real symptom>; … surfaced by #5427; bucket=…"], bucketed emit / inference / lang-go / lang-python for per-bucket fix follow-ups. The asymmetry is the win: the allowlist HID these; ignore-with-reason SURFACES them, fail-closed and tracked, even before they're fixed.

(The original 16 #[ignore=failing] — 15 self_gen8_* self-host emit regressions + the ownership_stage0_census clone ratchet, do-NOT-bump-the-cap per project spirit — remain; total reasoned ignores = 29.)

Feasibility / affordability

Post-#5454 (the module-index decl-scan), run-all completes in ~32min (down from a parse-heavy ~65–71min) — feasible, no nightly fallback needed. Whether ~32min/PR (vs the old allowlist's ~13min) is worth full-coverage-per-PR, or warrants affected-set selection (run affected per-PR, full suite nightly — ROADMAP child1 step-2, the existing v2.lens.affected_set), is a separate decision after this lands; the eval cost (not parse) is the residue to weigh then.


Update — operator Tasks 1+2 + nextest absorbed (carried since the affordability section above)

This PR now also carries three things the affordability discussion above is superseded by:

  1. §3 cargo modeling (operator Task 1): the rust gate no longer hand-types "cargo …" command Strings — run_gates calls the modeled cargo.Build.Fmt/Clippy/Nextest ops (extdeps.cargo_build); the argv lives once, in the cargo model's shell transport. The dead ci_rust_gate_{fmt,clippy,test}_command() String fns are removed.
  2. Separate parallel rust_tests CI job (operator Task 2): the long v1 cargo gate is split out of the floor (gunbc_ci_gates is now the partition floor ∪ rust_job by construction) into its own GHA job, so PR wall-clock is max(ci, rust_tests), not their sum. ci.yml regenerated; drift gate green; new witness_rust_gate_split_is_real proves the split is real (floor excludes rust, rust-job runs it — no double-run, no drop).
  3. nextest run backend (the direct "CI is too long" answer): the test op is cargo nextest run (process-per-test isolation), measured 26m11s → 5m41s (4.6×), same set, full coverage (nextest honors #[ignore], so run-all-unless-#[ignore] is unchanged). This dissolves the affordability question above: the widening is no longer a coverage-vs-time tradeoff — it's full coverage and fast.

Separate next lever (NOT bundled here): nextest exposes a ~16m single-threaded compile tentpole (the CARGO_BUILD_JOBS=1 sccache spawn/pids clamp). That's the derive-jobs-from-the-model lever, owned by sleek-cat-446 under neat-dove-397 via the cargo.Build env→transport seam — a follow-on PR, gated on its own design sign-off.

briansrls added a commit that referenced this pull request Jun 21, 2026
…ce-hawk #5427)

The 3-filter allowlist was COST selection, not arbitrary gatekeeping — the
v1 SEED compiler costs ~tens of CPU-sec per trivial test, so run-all-per-PR
is CPU-hours (off the table). True shape: per-PR cost-bounded subset +
measured #[ignore="expensive: Ns"] + completeness lens (#5427); nightly
--ignored lane as the destination for expensive + the 58 currently-ignored
tests (owned by §1/quick-ant, after #5431, escalate for load-bearing
CI-gen). Completeness = every test runs on >=1 cadence (fail-closed).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
…budgets) + plan doc (#5436)

* WIP: dsl -> v2 scoping

* WIP: ROADMAP planning

* WIP: ROADMAP planning

* WIP: ROADMAP planning

* ROADMAP: scannable dependency-ordered checklist; consolidate caching plan (de-fork zesty-deer-479 owner, absorb quick-ant-298 spine)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* self-host: add bootstrap purity (no stage0 hand-edits / regen-lockstep keystone) + precise v1 cutover

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §0 fail-closed lock-down (blocks expansion) + audit doc; §4 website demo

Audit: cache lossy-digest flake (resolved_graph_cache.rs:146, verified), ~inert analytical
lenses (complexity/cost/etc), regen --verify unwired (#5325). Lock-down checklist gates expansion.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP: flesh §2 idea->idea compiler (medium/language axes); §0 → lock-down LANE (audits→fixes→meta), name model<->realization fork as suspected root

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* lock-down: add CI-coverage-completeness audit (rust gate runs 3 of 60 v1 suites) + axiom/syllogism lens (DESIGN open thread #1 — lock down the reasoning)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* roadmap §0/§7 + lockdown: lead with correctness-by-construction, demote lenses to residue

Folds in the operator principle (relayed via quick-ant-298): a lens is validation
— it concedes the bad thing is writable. Root-cause to make it unwritable (single
authority / realization derived from model); reserve lenses for the genuinely-
unstructurable (complexity/necessity). #5423's spec-only key lens shipped a
false-green as the live proof.

- ROADMAP §0: add the principle; split Fixes into tier-1 construction (dissolve
  model↔realization fork; cache-key derived-from-declared-inputs; self-host purity
  by construction) and tier-2 lens (complexity/cost; cache-redundancy; purity
  oracle; promote-inert). Meta-invariant → construction-justification rule.
- ROADMAP §7: P1 cache-key reframed from 'realizer-key lens' to key derived from
  declared inputs_considered (construction).
- fail-closed-lockdown.md: construction principle in the thesis; §4 checklist
  re-ordered construction-first / lens-residue; meta = construction-justification.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* roadmap §0: add Disposition carrier + 'confront skipped modeling decisions'

Captures the lens/coproduct disposition decision (operator). One typed carrier
(Terminal{reason} | Scaffold{dissolves_to}) for BOTH lens-lifecycle tags AND
coproduct dissolve-markers — today freeform 🟡 comments, unreadable by lens since
comments aren't Nodes.

Decision: middle path (construction-capable carrier + selectively-enforcing lens
that ratchets coverage) now, #1 (substrate can't-define-untagged) as the named
end-state. The lens is itself a Scaffold{dissolves_to: substrate-mandatory-tag} —
self-dissolving when coverage = whole tree. Rejected jumping to #1 on sequencing
(load-bearing §4 substrate change → escalate; flag-day migration; derived
coproducts need disposition derived not authored), not on principle.

Enforceability split: presence = construction (non-optional field, no meta-lens);
redundancy (scaffold + successor both present) = hard gate; Terminal-vs-Scaffold
correctness = retro/judgment (synthesis-feasibility limit).

- docs/plans/disposition-carrier.md (new)
- ROADMAP §0 tier-1 + meta 'confront skipped decisions' standing practice

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* DESIGN §5/§6: promote construction-over-validation; roadmap: scope-partition §0, testgen §1, shelve dashboard

Addresses the review's four flags + sequencing nuance.

- DESIGN.md §5: 'correctness by construction, not validation' is now an axiom
  (a check re-stating a model constraint is a 2nd representation §2/§3; prefer
  realization derived from a single authority; reserve checks for the unstructurable
  residue). §6 'enforce with lenses' reconciled: construction first, lens = residue
  mechanism, AND the executable inert-lens backstop is NOT superseded by the
  authoring-time construction-justification judgment. (flag 4 home + flag 3)
- ROADMAP §0 partitioned: In-scope this window (numeric-tower grounding; cache
  trustworthy + warm==cold oracle shipped NOW as detective; widen rust gate;
  promote inert lenses) vs Fenced-OUT fan-out (Value::Null 131-site split;
  self-host purity gate; cross-tree import activation; Disposition carrier).
  Honest framing: window reduces fail-open surface, does NOT 'lock' the class —
  Null split stays open. (flags 1, 2, sequencing nuance)
- ROADMAP §0 meta: restored executable inert-lens hygiene backstop, construction-
  justification layered on top (not 'supersedes'). (flag 3)
- De-dup: principle no longer restated in ROADMAP/lockdown §0; both point to
  DESIGN §5. cache-key construction homed in §7, §0 references it. (flag 4)
- ROADMAP §1 = testgen as bug-class oracle (+ affected-set completeness half +
  parked anemia lens); dashboard shelved to §8.
- docs/plans/testgen-oracle.md (new), fail-closed-lockdown.md realigned.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* DESIGN §5/§6/§7: wall-vs-ratchet decidability, displaced-pain denominator, open language design

Folds in the operator's product thesis + the two bounds that keep it honest.

- §5: construction makes a class unwritable only when membership is DECIDABLE —
  trichotomy (wall now / wall after grounding / ratchet forever); 'never' is the
  trap (lets an undecidable ratchet masquerade as a wall — optimality by Rice).
- §6: denominate the benefit — the deliverable is a displaced cost (§1 time / a
  paid-for pain), the lens/substrate is the moat not the product; priced in
  elegance the work is unbounded (the economic twin of 'never').
- §7: the recursion's payoff — language design itself opens up. It's locked by
  cost (a check = a compiler fork; a language = an adoption problem); both
  dissolve here (a wall is a row §2, applied over a medium-agnostic substrate §4),
  so (compiler-fork × language) → (row + medium). Sound where ingest is Lossless,
  fail-closed where not (DecodeFidelity §4).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* ROADMAP: fix doc-graph violations from bright-eagle-46 review of #5424

Apply the apex axiom/syllogism lens (single authority / no orphan / no
cycle) to the roadmap itself — manual acyclicity pass:

- orphan: testgen-oracle.md backlinked §1 → repoint §4 (its own lane)
- single authority: §0 cache-key now a pure pointer (= §2 F2/F3/P1);
  §0 numeric-tower marked the authoritative home (§5 de-fork / fork plan
  point here, no second checkbox)
- §0↔§5 cycle: self-host purity reframed as a §5 deliverable §0's
  expansion-gate depends on (edge §5 → §0-gate → products), not §0-owned
- undeclared edge: §7 react/html declares its dependency on §6 media
- backlink sweep: the reorg had broken every numeric backlink across 7
  plan docs; re-point all and anchor each to the stable section TITLE so
  a future renumber can't silently break them again

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §3 + plan: algorithmic-cost reduction by construction (rewrite, not budget)

Reframe §3 from per-fn complexity budgets to the actual intent: rewrite
common suboptimal patterns (O(n²)→O(n), O(2ⁿ)→O(n), O(n)→O(log n)) to the
cheaper equivalent — construction on the cost axis, not a warning.

New plan doc docs/plans/algebraic-rewrite-optimization.md captures the
up-front design: the decidability split (modeled EffectShape makes the
preconditions structural; equivalence stays undecidable so no optimality
oracle), rewrite-rule-as-row + once-proven soundness, the common-case
catalog tiered by precondition, D1 canonical-form-is-truth / D2 two seed
rules / D4 constant-factor deferred, the four-witness DONE bar (incl. the
non-firing control half-done versions skip), and a corpus hit-rate
acceptance gate. complexity.dag is the cost oracle; synthesis.dag stays
the advisory undecidable residue.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §2: Phase-0 measurement instrument done (#5431 peak-RSS) — remaining is the Phase-1 consumer

Per quick-ant-298: the measurement keystone was nearly complete — model
side already floor-enrolled, step timing already emitted; the only gap was
peak-RSS, closed by #5431. P4's Phase-0 dependency is satisfied; remaining
is the Phase-1 measured->plan feedback + width-fold (also unblocks §1-C).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* plan/§3: detection-vs-enforcement containment (E⊆D′⊆D) + explicit seed-rule I/O up front

Grounded in cost.dag U2 + complexity.dag (investigated, not theorized):
- detection is TOTAL by construction (kernel-level cost fold; arbitrary fns
  detectable); boundary is precision (ClassUnknown), not coverage
- enforced rewrites are a strict subset structurally guaranteed by the
  class-drop witness: E ⊆ D′(precise) ⊆ D(all)
- n√n excluded for a MODEL reason (PolynomialDegree is integer-only, n^1.5
  unrepresentable); ternary search excluded (log base is not a class)
- today's small gate roster = subject-production limit (fn-body reflection),
  NOT a detection limit
- new §3a fully specifies the two seed rules up front: input→output→
  precondition→non-firing control→discriminating equivalence input, so the
  worker builds to spec and the project can actually finish

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §0/§1: rust-gate is cadence-decoupling, not run-all (per fierce-hawk #5427)

The 3-filter allowlist was COST selection, not arbitrary gatekeeping — the
v1 SEED compiler costs ~tens of CPU-sec per trivial test, so run-all-per-PR
is CPU-hours (off the table). True shape: per-PR cost-bounded subset +
measured #[ignore="expensive: Ns"] + completeness lens (#5427); nightly
--ignored lane as the destination for expensive + the 58 currently-ignored
tests (owned by §1/quick-ant, after #5431, escalate for load-bearing
CI-gen). Completeness = every test runs on >=1 cadence (fail-closed).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* plan §2a: generalize by structural-redundancy keying (O(n^x)->O(n^(x-1)) free); flag n-log-n as substitution

Per operator: catalog must generalize polynomial-degree reduction without
edge cases. Resolution: rules key on the structural redundancy, never on
degree — degree is not evidence of redundancy (would fire on genuine O(n^x)).
A structurally-keyed nested-membership->set peels one level wherever it
matches; fold-to-fixpoint gives O(n^3)->O(n^2)->O(n). Cost model supports
arbitrary integer degree, so witness (b) holds at every peel.

Flagged OPEN (operator input invited): O(n^x)->O(n log n) is algorithmic
SUBSTITUTION (different algorithms, same I/O) not redundancy elimination —
verges on undecidable equivalence; tractable form is per-idiom rules
(sort-based dedup, repeated-min->heap), not a parameterized rule. Seed Rule 1
now authored structurally + carries a depth-2 generalization witness.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* plan §1b: Unknown is an anemic atom — dissolve over time (reuse Disposition), never a false pass

Per operator: classifying Unknown isn't a fixed up-front split — it's the
standing anemic-leaf dissolution practice (DESIGN §2 decompress->map->reduce)
applied to the cost lens. UnknownCost{diagnostic} already carries its reason;
the anemia is the free-form reason. Each decomposition resolves an Unknown to
construction (now-precise class -> new D′) or a grounded Terminal (genuinely
undecidable, positively recognized -> advisory comment). DFS-first: this IS
the Disposition carrier (resolves to construction-or-justified-Terminal), so
reuse it, don't fork an unknown-reason enum. Supersedes the static
Undecidable|Undetermined split. Two invariants fixed up front: never a false
pass (Unknown=>Violates, already holds); every Unknown on the dissolution
frontier. cost.dag enrichment + un-parking Disposition are operator-gated.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP: §3 reverts to budget-gate validation (stability); rewrite-engine relocated to §5 (post-stability)

Operator decision 2026-06-21: budget-gate validation is fine for the
stability window; the algorithmic-cost REWRITE construction design is
expansion, homed with self-hosting (§5) — IR-rewrite/canonicalization is
most natural once .dag is the self-hosted truth.

- §3 = complexity budget gate (validation): cost-lens symbolic_max fix
  (#5437) + per-fn subject + budget-gates-whole-codebase (gated on fn-body
  reflection) + synthesis advisory. #5437 foundation stays in-window.
- §5 gains an 'adjacent expansion lane' = the rewrite engine, pointing at
  the preserved plan doc; marked post-stability.
- plan doc status -> POST-STABILITY EXPANSION, relocated to §5.

Nothing deleted — the rewrite design is preserved, just fenced out of the
stability window (same as Disposition / Value::Null-split).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls and others added 4 commits June 21, 2026 07:07
…e pre-existing fixture red

The coverage-completeness lens (this PR's residue) fired on its first real
input after merging main: resolve_typed_cache_equivalence_test.rs landed via
#5071 but was never declared in lib.rs, so it would silently not run — exactly
the gap the lens exists to close (fail-closed, working as designed). Declared it.

dag_emit_from_resolved_matches_compile_sources_for_v4_slice reads a removed
fixture (fixtures/v2-mvp1, absent from the tree and every git ref) — a
pre-existing red hidden by the old 3-filter allowlist, surfaced by the widening.
Flagged with a written #[ignore] reason (FLAG-DON'T-FIX); the lens keeps the
excuse reviewable.

The ~20 interp_recorded_fixture/dry_run local failures were a build-ordering
artifact (claim_batch bin not built locally); they pass once the floor's
release --bins build is present, so they are NOT ignored (ignoring them would
have been a fail-open).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…rmanent

Parent note: a test whose fixture is gone from every git ref is DEAD — it can
never pass, so a permanent ignore would calcify a coverage hole. Sharpened the
reason to name the resolution (delete the dead parity receipt OR restore/retarget
the fixture at a live v2 source set) and the owner routing (v2 emit slice, via
bright-stag), so the completeness lens keeps it visible as work-to-drain.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
briansrls and others added 2 commits June 21, 2026 09:09
My own lens (every_ignore_carries_a_written_reason) went RED on the v4_slice
ignore I'd just added: the detector required the closing quote on the same line
as #[ignore = "..."], so a long reason wrapped with \ line-continuation left
the opening line with an unterminated string and was misread as reasonless — a
false-positive that fails-closed on legitimately-reasoned input.

Detector now recognizes a multi-line reason: opening quote + non-empty content
(sans a trailing \ continuation) is reasoned even when the string closes on a
later line; an opener with no content before the break is still empty → flagged.
Added detector_accepts_a_multiline_reason as the discriminating control (both the
valid wrap and the empty-multiline edge), fed through the same authority.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…es (#[ignore=failing])

The widened gate runs the self_gen8 + census families that the old 3-filter
allowlist never ran. warm-ram's opt-level run listed 32 candidates; running them
to completion (--no-fail-fast, claim_batch built) confirms only 16 actually FAIL
— the other 16 self_gen8 PASS (e.g. kernel_type_import). Ignoring warm-ram's
superset would have excluded 16 GREEN tests (fail-open); only the execution-
confirmed failures are flagged.

  • ownership_stage0_census (1): clone-census ratchet RED on main (non-emit
    .clone() 21540 > 20200+202, ~1138 over) — inert under the old allowlist while
    the seed drifted UP against "Rust shrinks toward zero". Do NOT bump the cap
    (project spirit); route to a census/substrate-migration owner.
  • self_gen8_* (15): pre-existing self-host emit regression (parametric-alias-RHS
    / reexported-type-import module resolution); route to the v2 self-host Route-A
    owner.

All draining-worklist, not permanent; the completeness lens keeps each reason
visible and reviewable. fmt-clean (rust gate runs fmt --check); parse.rs picked
up a pre-existing fmt fix from the earlier ignore conversion.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
…O + P2 de-fork-dependent, §0 census regression + gate-hygiene

Reflects decisions/findings that landed 2026-06-21:
- §1: the "expensive" tests were debug-build amplification, not intrinsic
  seed cost (proud-deer cause-table); opt-level=3 (#5456) restores Pop-A to
  per-PR; nightly lane reduced to Pop-B wet-captures only. Mirror corrected in §0.
- §2: resolve-cache enable = GO (~18% floor-wall, purity-proven, #5429-gated);
  P2 ParseTable dissolution reclassified as a downstream consumer of the dsl→v2
  de-fork (keen-otter: v2-local rewire is cosmetic); #5446 realize kernel green.
- §0: stage0 clone-census ratchet went inert + the seed regressed 1138 over
  budget (rust-side coverage-by-illusion + thesis regression; #5427 surfaced it);
  gate-hygiene rule (floor-enrolled gate must be green-on-main at merge) +
  roster-completeness assertion promoted to should-land (the #5445 floor-skew).
- §1: registry-partition instance fix = #5452 (verified sound).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 21, 2026

Copy link
Copy Markdown
Contributor Author

Intentionally held in draft — not abandoned. Status for the draft-nudge:

This PR (the §1 rust-gate widening: invert the allowlist → run-all-unless-#[ignore]d + CI-coverage-completeness lens) is structurally complete and frozen at merge-ready (commit 9ac2032). It is deliberately kept draft pending two upstream merges, in this order:

  1. Fix main-red: roster the 11th bash-sidecar importer (floor-skew from #5445) #5453 ("Fix main-red: roster the 11th bash-sidecar importer") — clears the live realization_vocab_clean_tree_holds main-red that every PR currently inherits. Until it lands, this branch's CI is red for a reason unrelated to this PR's content.
  2. Add profile.test.package.v1-compiler opt-level=3 to cut debug-build amplification #5456 (opt-level=3 for the v1-compiler test profile) — without it the widened rust gate runs in debug and times out (~65min, node-killed) rather than test-failing; with it the gate completes in ~13-16min.

The flip-to-ready is a deliberate post-merge step, not a rubber stamp: after both land → sync main → CI gives a real completed run that (a) positively confirms "the only reds are exactly the 16 execution-confirmed #[ignore=failing]" and (b) yields the real post-opt-level gate wall number. Flipping ready now would put it up for review/merge while CI is red on an inherited main-red and the gate can't even complete — that's not a meaningful "ready."

Owner fierce-hawk-540 is holding warm to do that reactive sync+flip the instant #5453+#5456 are on main. No churn in the meantime (push-to-retrigger under the current 2nd-provider approval outage would only burn the lone approval). Tracked; will flip on the merge signal.

— sent from quick-ant-298

briansrls added a commit that referenced this pull request Jun 21, 2026
…gestion⁻¹ past syntax (#5442)

* WIP: dsl -> v2 scoping

* WIP: ROADMAP planning

* WIP: ROADMAP planning

* WIP: ROADMAP planning

* ROADMAP: scannable dependency-ordered checklist; consolidate caching plan (de-fork zesty-deer-479 owner, absorb quick-ant-298 spine)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* self-host: add bootstrap purity (no stage0 hand-edits / regen-lockstep keystone) + precise v1 cutover

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §0 fail-closed lock-down (blocks expansion) + audit doc; §4 website demo

Audit: cache lossy-digest flake (resolved_graph_cache.rs:146, verified), ~inert analytical
lenses (complexity/cost/etc), regen --verify unwired (#5325). Lock-down checklist gates expansion.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP: flesh §2 idea->idea compiler (medium/language axes); §0 → lock-down LANE (audits→fixes→meta), name model<->realization fork as suspected root

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* lock-down: add CI-coverage-completeness audit (rust gate runs 3 of 60 v1 suites) + axiom/syllogism lens (DESIGN open thread #1 — lock down the reasoning)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* roadmap §0/§7 + lockdown: lead with correctness-by-construction, demote lenses to residue

Folds in the operator principle (relayed via quick-ant-298): a lens is validation
— it concedes the bad thing is writable. Root-cause to make it unwritable (single
authority / realization derived from model); reserve lenses for the genuinely-
unstructurable (complexity/necessity). #5423's spec-only key lens shipped a
false-green as the live proof.

- ROADMAP §0: add the principle; split Fixes into tier-1 construction (dissolve
  model↔realization fork; cache-key derived-from-declared-inputs; self-host purity
  by construction) and tier-2 lens (complexity/cost; cache-redundancy; purity
  oracle; promote-inert). Meta-invariant → construction-justification rule.
- ROADMAP §7: P1 cache-key reframed from 'realizer-key lens' to key derived from
  declared inputs_considered (construction).
- fail-closed-lockdown.md: construction principle in the thesis; §4 checklist
  re-ordered construction-first / lens-residue; meta = construction-justification.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* roadmap §0: add Disposition carrier + 'confront skipped modeling decisions'

Captures the lens/coproduct disposition decision (operator). One typed carrier
(Terminal{reason} | Scaffold{dissolves_to}) for BOTH lens-lifecycle tags AND
coproduct dissolve-markers — today freeform 🟡 comments, unreadable by lens since
comments aren't Nodes.

Decision: middle path (construction-capable carrier + selectively-enforcing lens
that ratchets coverage) now, #1 (substrate can't-define-untagged) as the named
end-state. The lens is itself a Scaffold{dissolves_to: substrate-mandatory-tag} —
self-dissolving when coverage = whole tree. Rejected jumping to #1 on sequencing
(load-bearing §4 substrate change → escalate; flag-day migration; derived
coproducts need disposition derived not authored), not on principle.

Enforceability split: presence = construction (non-optional field, no meta-lens);
redundancy (scaffold + successor both present) = hard gate; Terminal-vs-Scaffold
correctness = retro/judgment (synthesis-feasibility limit).

- docs/plans/disposition-carrier.md (new)
- ROADMAP §0 tier-1 + meta 'confront skipped decisions' standing practice

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* DESIGN §5/§6: promote construction-over-validation; roadmap: scope-partition §0, testgen §1, shelve dashboard

Addresses the review's four flags + sequencing nuance.

- DESIGN.md §5: 'correctness by construction, not validation' is now an axiom
  (a check re-stating a model constraint is a 2nd representation §2/§3; prefer
  realization derived from a single authority; reserve checks for the unstructurable
  residue). §6 'enforce with lenses' reconciled: construction first, lens = residue
  mechanism, AND the executable inert-lens backstop is NOT superseded by the
  authoring-time construction-justification judgment. (flag 4 home + flag 3)
- ROADMAP §0 partitioned: In-scope this window (numeric-tower grounding; cache
  trustworthy + warm==cold oracle shipped NOW as detective; widen rust gate;
  promote inert lenses) vs Fenced-OUT fan-out (Value::Null 131-site split;
  self-host purity gate; cross-tree import activation; Disposition carrier).
  Honest framing: window reduces fail-open surface, does NOT 'lock' the class —
  Null split stays open. (flags 1, 2, sequencing nuance)
- ROADMAP §0 meta: restored executable inert-lens hygiene backstop, construction-
  justification layered on top (not 'supersedes'). (flag 3)
- De-dup: principle no longer restated in ROADMAP/lockdown §0; both point to
  DESIGN §5. cache-key construction homed in §7, §0 references it. (flag 4)
- ROADMAP §1 = testgen as bug-class oracle (+ affected-set completeness half +
  parked anemia lens); dashboard shelved to §8.
- docs/plans/testgen-oracle.md (new), fail-closed-lockdown.md realigned.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* DESIGN §5/§6/§7: wall-vs-ratchet decidability, displaced-pain denominator, open language design

Folds in the operator's product thesis + the two bounds that keep it honest.

- §5: construction makes a class unwritable only when membership is DECIDABLE —
  trichotomy (wall now / wall after grounding / ratchet forever); 'never' is the
  trap (lets an undecidable ratchet masquerade as a wall — optimality by Rice).
- §6: denominate the benefit — the deliverable is a displaced cost (§1 time / a
  paid-for pain), the lens/substrate is the moat not the product; priced in
  elegance the work is unbounded (the economic twin of 'never').
- §7: the recursion's payoff — language design itself opens up. It's locked by
  cost (a check = a compiler fork; a language = an adoption problem); both
  dissolve here (a wall is a row §2, applied over a medium-agnostic substrate §4),
  so (compiler-fork × language) → (row + medium). Sound where ingest is Lossless,
  fail-closed where not (DecodeFidelity §4).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* ROADMAP: fix doc-graph violations from bright-eagle-46 review of #5424

Apply the apex axiom/syllogism lens (single authority / no orphan / no
cycle) to the roadmap itself — manual acyclicity pass:

- orphan: testgen-oracle.md backlinked §1 → repoint §4 (its own lane)
- single authority: §0 cache-key now a pure pointer (= §2 F2/F3/P1);
  §0 numeric-tower marked the authoritative home (§5 de-fork / fork plan
  point here, no second checkbox)
- §0↔§5 cycle: self-host purity reframed as a §5 deliverable §0's
  expansion-gate depends on (edge §5 → §0-gate → products), not §0-owned
- undeclared edge: §7 react/html declares its dependency on §6 media
- backlink sweep: the reorg had broken every numeric backlink across 7
  plan docs; re-point all and anchor each to the stable section TITLE so
  a future renumber can't silently break them again

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §3 + plan: algorithmic-cost reduction by construction (rewrite, not budget)

Reframe §3 from per-fn complexity budgets to the actual intent: rewrite
common suboptimal patterns (O(n²)→O(n), O(2ⁿ)→O(n), O(n)→O(log n)) to the
cheaper equivalent — construction on the cost axis, not a warning.

New plan doc docs/plans/algebraic-rewrite-optimization.md captures the
up-front design: the decidability split (modeled EffectShape makes the
preconditions structural; equivalence stays undecidable so no optimality
oracle), rewrite-rule-as-row + once-proven soundness, the common-case
catalog tiered by precondition, D1 canonical-form-is-truth / D2 two seed
rules / D4 constant-factor deferred, the four-witness DONE bar (incl. the
non-firing control half-done versions skip), and a corpus hit-rate
acceptance gate. complexity.dag is the cost oracle; synthesis.dag stays
the advisory undecidable residue.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §2: Phase-0 measurement instrument done (#5431 peak-RSS) — remaining is the Phase-1 consumer

Per quick-ant-298: the measurement keystone was nearly complete — model
side already floor-enrolled, step timing already emitted; the only gap was
peak-RSS, closed by #5431. P4's Phase-0 dependency is satisfied; remaining
is the Phase-1 measured->plan feedback + width-fold (also unblocks §1-C).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* plan/§3: detection-vs-enforcement containment (E⊆D′⊆D) + explicit seed-rule I/O up front

Grounded in cost.dag U2 + complexity.dag (investigated, not theorized):
- detection is TOTAL by construction (kernel-level cost fold; arbitrary fns
  detectable); boundary is precision (ClassUnknown), not coverage
- enforced rewrites are a strict subset structurally guaranteed by the
  class-drop witness: E ⊆ D′(precise) ⊆ D(all)
- n√n excluded for a MODEL reason (PolynomialDegree is integer-only, n^1.5
  unrepresentable); ternary search excluded (log base is not a class)
- today's small gate roster = subject-production limit (fn-body reflection),
  NOT a detection limit
- new §3a fully specifies the two seed rules up front: input→output→
  precondition→non-firing control→discriminating equivalence input, so the
  worker builds to spec and the project can actually finish

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §0/§1: rust-gate is cadence-decoupling, not run-all (per fierce-hawk #5427)

The 3-filter allowlist was COST selection, not arbitrary gatekeeping — the
v1 SEED compiler costs ~tens of CPU-sec per trivial test, so run-all-per-PR
is CPU-hours (off the table). True shape: per-PR cost-bounded subset +
measured #[ignore="expensive: Ns"] + completeness lens (#5427); nightly
--ignored lane as the destination for expensive + the 58 currently-ignored
tests (owned by §1/quick-ant, after #5431, escalate for load-bearing
CI-gen). Completeness = every test runs on >=1 cadence (fail-closed).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* plan §2a: generalize by structural-redundancy keying (O(n^x)->O(n^(x-1)) free); flag n-log-n as substitution

Per operator: catalog must generalize polynomial-degree reduction without
edge cases. Resolution: rules key on the structural redundancy, never on
degree — degree is not evidence of redundancy (would fire on genuine O(n^x)).
A structurally-keyed nested-membership->set peels one level wherever it
matches; fold-to-fixpoint gives O(n^3)->O(n^2)->O(n). Cost model supports
arbitrary integer degree, so witness (b) holds at every peel.

Flagged OPEN (operator input invited): O(n^x)->O(n log n) is algorithmic
SUBSTITUTION (different algorithms, same I/O) not redundancy elimination —
verges on undecidable equivalence; tractable form is per-idiom rules
(sort-based dedup, repeated-min->heap), not a parameterized rule. Seed Rule 1
now authored structurally + carries a depth-2 generalization witness.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* plan §1b: Unknown is an anemic atom — dissolve over time (reuse Disposition), never a false pass

Per operator: classifying Unknown isn't a fixed up-front split — it's the
standing anemic-leaf dissolution practice (DESIGN §2 decompress->map->reduce)
applied to the cost lens. UnknownCost{diagnostic} already carries its reason;
the anemia is the free-form reason. Each decomposition resolves an Unknown to
construction (now-precise class -> new D′) or a grounded Terminal (genuinely
undecidable, positively recognized -> advisory comment). DFS-first: this IS
the Disposition carrier (resolves to construction-or-justified-Terminal), so
reuse it, don't fork an unknown-reason enum. Supersedes the static
Undecidable|Undetermined split. Two invariants fixed up front: never a false
pass (Unknown=>Violates, already holds); every Unknown on the dissolution
frontier. cost.dag enrichment + un-parking Disposition are operator-gated.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP: §3 reverts to budget-gate validation (stability); rewrite-engine relocated to §5 (post-stability)

Operator decision 2026-06-21: budget-gate validation is fine for the
stability window; the algorithmic-cost REWRITE construction design is
expansion, homed with self-hosting (§5) — IR-rewrite/canonicalization is
most natural once .dag is the self-hosted truth.

- §3 = complexity budget gate (validation): cost-lens symbolic_max fix
  (#5437) + per-fn subject + budget-gates-whole-codebase (gated on fn-body
  reflection) + synthesis advisory. #5437 foundation stays in-window.
- §5 gains an 'adjacent expansion lane' = the rewrite engine, pointing at
  the preserved plan doc; marked post-stability.
- plan doc status -> POST-STABILITY EXPANSION, relocated to §5.

Nothing deleted — the rewrite design is preserved, just fenced out of the
stability window (same as Disposition / Value::Null-split).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* #5442 review fix (warm-lark-306): grep-as-authority for the sidecar roster (10 not 9)

The §0-guard impl PR (#5445) grepped current main and found 10 importers of
extdeps.languages.bash.program, not 9 — the 10th (dsl/gunbc/ci_spec.dag) landed via #5432 after
the original pre-merge grep. Rather than bump the frozen count, make the live grep the authority
(the roster shrinks to 0 as the bash-sidecar arc migrates consumers, so any frozen number rots —
the single-authority point). Also note the two *_test importers are intentionally not walled
(guard scans consumer-source roots only).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP: check off 6 merged items (catch-up sweep)

Flip [ ]→[x] for unambiguously-merged work (PR-ref'd for traceability):
- §0 numeric-tower grounding (#5428 — == straddle guard dead-in-corpus)
- §0 inert-lens hygiene executable backstop (#5433)
- §2 F2/F3 resolved_graph key derived from inputs_considered (#5425)
- §3 cost-lens symbolic_max zero-absorption fix (#5437)
- §4 gate existing generated testgen output (#5434)
- §4 affected-set completeness (#5430)

Partial/compound items left for their lane managers to flip in the PR that completes them.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §1: add compile-clean-gate force-checks-every-fn-body box (2(ii) fail-open)

New floor-coverage item: the compile-clean gate is fail-open — unreached fn bodies escape
typecheck, so undefined symbols in dead code pass green (execution-proven on utf8_decode_bytes).
Construction fix = typecheck total over every declared body. Owned by §1 (quick-ant); measure-first,
operator-gated enforce-flip.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §0: correct the 2(ii) box — registry-leak mechanism, not unreached-bodies

snappy-gull's deeper diagnosis: the fail-open is NOT unreached bodies (bodies ARE visited).
utf8_decode_bytes resolves because it's a global builtin_function_registry entry (04_method.dag,
a marked bridge scaffold) not scoped to the compiled tree. Reframe the box to tree-scoped builtin
availability / registry partition; instance fix = real std fn + remove the registry bridge entry.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* plan doc: enforcement roster is a FROZEN grandfather set, not derived (warm-lark correction)

Deriving the realization-vocab exception roster from a live grep would make the guard vacuous
(leak = non-edge importer AND NOT-in-roster; derived roster ⇒ every importer always in it ⇒
leak_count always 0 ⇒ never fires). Distinguish the informational prose count (rots, re-grep)
from the lens's enforcement roster (frozen, so a new unrostered importer goes RED = the teeth).
Add the 11th importer (extdeps_external_authority_transport, the #5418→#5445 race, fixed by #5453)
and the roster-completeness assertion as the steady-state race-hardening.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* ROADMAP refresh: §1 nightly→Pop-B (opt-level won), §2 resolve-cache GO + P2 de-fork-dependent, §0 census regression + gate-hygiene

Reflects decisions/findings that landed 2026-06-21:
- §1: the "expensive" tests were debug-build amplification, not intrinsic
  seed cost (proud-deer cause-table); opt-level=3 (#5456) restores Pop-A to
  per-PR; nightly lane reduced to Pop-B wet-captures only. Mirror corrected in §0.
- §2: resolve-cache enable = GO (~18% floor-wall, purity-proven, #5429-gated);
  P2 ParseTable dissolution reclassified as a downstream consumer of the dsl→v2
  de-fork (keen-otter: v2-local rewire is cosmetic); #5446 realize kernel green.
- §0: stage0 clone-census ratchet went inert + the seed regressed 1138 over
  budget (rust-side coverage-by-illusion + thesis regression; #5427 surfaced it);
  gate-hygiene rule (floor-enrolled gate must be green-on-main at merge) +
  roster-completeness assertion promoted to should-land (the #5445 floor-skew).
- §1: registry-partition instance fix = #5452 (verified sound).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
* Delete dead v4_slice parity test pipeline

dag_emit_from_resolved_matches_compile_sources_for_v4_slice reads fixture
fixtures/v2-mvp1 which was deleted and no longer exists in git history or the
working tree. The test was hidden by the old rust-gate allowlist but exposed
by #5427, and cannot pass. (Refs: #5427)

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Delete obsolete v1_compiler_lib_test module

The v1_compiler_lib_test module was solely used by the now-deleted
dag_emit_from_resolved_matches_compile_sources_for_v4_slice test to
compile-check the v1-compiler lib test harness. With that parity test
gone, this module is dead code. (Addresses review feedback on #5457)

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Fix realization vocabulary containment test: add missing extdeps_external_authority_transport to exception roster

The extdeps_external_authority_transport.dag (added in #5418) imports
extdeps.languages.bash.program but was not included in the exception roster,
causing the realization_vocab_clean_tree_holds test to fail. The file is a
transport module in dsl/tools/ following the same pattern as other rostered
transports, so it requires roster entry per DESIGN §3.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* WIP: Delete dead v4-emit-slice parity test pipeline dag_emit v4_slice: it rea

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>
briansrls and others added 2 commits June 21, 2026 14:46
…tion of dead v4_slice test

main moved again (#5449 etc.) after my first sync. Conflict in pipeline.rs:
main DELETED dag_emit_from_resolved_matches_compile_sources_for_v4_slice (the dead
parity receipt reading the removed fixtures/v2-mvp1) — exactly the delete-or-restore
resolution I'd flagged and routed. Accepted main's deletion; my interim #[ignore]
on it is now moot and gone. The 16 self_gen8/census failing-ignores stay intact;
completeness lens green (no undeclared test file from the merge); crate compiles.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
… (§1 cost) two-axes

- parent: name the seam, cost informs scheduling never selection
- per-PR = sound baseline (#5427 run-all) shrunk to affected set (v2.lens.affected_set)
- nightly = full-corpus selector-backstop + non-hermetic residue, NOT a slow-test dump
- +docs/plans/ci-selection-vs-scheduling.md (framing; warm-lark-306 analysis, quick-ant §1-lead)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
…frame (#5463)

* ROADMAP §1: opt-level #5456 MERGED → flip Pop-A restore done (squash title mislabeled Pop-B; content verified on main)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* ROADMAP §1 nightly reframe: selection (§4 affected-set) vs scheduling (§1 cost) two-axes

- parent: name the seam, cost informs scheduling never selection
- per-PR = sound baseline (#5427 run-all) shrunk to affected set (v2.lens.affected_set)
- nightly = full-corpus selector-backstop + non-hermetic residue, NOT a slow-test dump
- +docs/plans/ci-selection-vs-scheduling.md (framing; warm-lark-306 analysis, quick-ant §1-lead)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* WIP: ROADMAP planning

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls and others added 4 commits June 21, 2026 16:44
…r B ignore-with-reason; fix doc-lazy-continuation

27 reds surfaced by the run-all widening:
- 14 fixed-by-construction: under-scoped v2_source_roots()=[src/v2] dropped dsl, so
  v2-core's extdeps.communication.medium import was unresolvable. Funnel the 4 files'
  local copies through one helpers::v2_layer_roots()=[src/v2,dsl] authority (mirrors
  gunbc.ci_layer_roots; §6 dissolution marker to derive from the .dag fact later).
- 13 pre-existing emit/inference reds: #[ignore=failing] with written symptom + bucket
  (emit/inference/lang-go/lang-python), routed as follow-ups.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
briansrls and others added 7 commits June 22, 2026 19:09
…comment-ban

The auto-committer pushed an unresolved-conflict state (<<<<<<< markers in
cargo_build.dag:3,8,9) which fails to parse — fixes the BLOCKING review and the
red dsl_compile_clean_gate.

main's comment-ban sweep (#5537/#5543/#5539) left dsl/std, dsl/extdeps,
dsl/gunbc, dsl/tools, src/v2/test/claim comment-free; this PR's new/rewritten
files in those dirs re-introduced comments. Strip them to conform (code
unchanged) so we match already-merged state and avoid a future re-sweep.

ci.yml emit is byte-identical (comments don't affect output); drift gate green,
ci_spec_witnesses green, rust gate + floor_effect_gate_witness resolve clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…urfaced)

The run-all widening (#5427) surfaced source_audit::compile_gate_keeps_infer_errors_blocking_in_stage0,
red because main refactored compile.dag's emission gate from
is_error_diagnostic to is_resolved_pipeline_typecheck_blocking (discovery-corpus
advisory typecheck) without updating this brittle string-audit literal. The
audit never ran under the 3-filter allowlist, so the drift went unseen — exactly
the class this widening exists to catch. Intent is unchanged (emission is gated
on type errors); update the literal to the current predicate so the audit stays
live and green. Fix, not #[ignore]: a stale literal is cheaply correctable, not
deep work to route.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…s comment-ban

The auto-committer committed an unresolved merge (3052ecd, markers in 5 test
.rs files) bringing main's .rs comment-ban sweep (#5544). Resolution: restore my
pre-merge versions (preserving every #[ignore = "<reason>"] — the single
authority my coverage-completeness lens requires; main's bare #[ignore] would
red that lens) then strip full-line // comments to conform to the ban. Code
unchanged; 17 self_gen8 + diagnostics reasoned ignores intact; zero reasonless
#[ignore] introduced.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…s caught it)

body_producer_infer_profile_test.rs is a manual timing-profiling scaffold
(std::time::Instant, profile_* fns, bare #[ignore], never declared in lib.rs).
My widening deliberately deleted it (26beeee); the auto-committer's merge
(3052ecd) left main's copy in the tree via the unresolved deleted-in-HEAD/
modified-in-main conflict. The new coverage-completeness lens correctly fired on
it twice — orphan file (every_test_file_is_declared_in_lib) + bare reasonless
#[ignore] (every_ignore_carries_a_written_reason) — a live proof the lens has
teeth. Re-delete to honor the original deletion; both lenses green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
wet_hermetic_scaffold_roster_outcomes_agree passes isolated (~110s) but fails
under the 766-test parallel load (~335s). nextest process-isolates each test, so
this is resource/timing contention on the wet-execution path, not a logic bug —
a non-deterministic test can't gate a merge (§5 fail-open-by-noise). Pre-existing
(#5276), never run under the old 3-filter allowlist. #[ignore=reason] + route to
the wet==hermetic / hermetic-testing owner; the coverage lens keeps it visible.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The comment-strip in f05415d left double-blank-lines where comments had been;
cargo fmt --all --check rejected them (the rust gate's Fmt op would red). Pure
blank-line removal (105 lines), zero code change, all #[ignore]s intact. Also
addresses the blank-line noise the 19:42 review flagged.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 22, 2026

Copy link
Copy Markdown
Contributor Author

Resolved the conflict-marker REQUEST_CHANGES and the follow-on CI reds. Pushed through 08c5b481f7.

Root cause: main landed two back-to-back comment-ban sweeps (#5544 .rs seed, #5540/#5537/#5543/#5539 .dag) while this branch was open, and the session auto-committer pushed two unresolved merge states before I could resolve them (it commits any working-tree delta). That's the 3052ecd / f05415d the bots reviewed. Resolved cleanly:

  • Conflict markers (the RC): restored the HEAD-side #[ignore = "<reason>"] across every conflicted test file — main's bare #[ignore] from the .rs sweep would have red the new coverage lens — then stripped // comments to conform to that same ban. 17 self_gen8 + diagnostics reasoned ignores intact; zero reasonless #[ignore].
  • cargo fmt: the strip left double-blank-lines (fmt --check rejected them — the rust gate's Fmt op would red). 08c5b481f7 is a pure blank-line collapse (105 lines, no code change) — also clears the blank-line noise the 19:42 review flagged.
  • Orphan resurrection: the merge resurrected body_producer_infer_profile_test.rs (a manual timing-profiling scaffold this PR had deleted) via the deleted-in-HEAD/modified-in-main conflict. The new coverage lens fired on it twice — orphan-not-in-lib.rs + bare #[ignore] — a live proof it has teeth. Re-deleted.
  • Stale source-audit literal: source_audit::compile_gate_keeps_infer_errors_blocking_in_stage0 was red because main refactored compile.dag's gate predicate (is_error_diagnostic → is_resolved_pipeline_typecheck_blocking) without updating this string-audit. Intent unchanged; updated the literal (fix, not #[ignore] — a stale literal is cheaply correctable).
  • Contention-flaky wet test: wet_hermetic_scaffold_roster_outcomes_agree passes isolated (~110s) but fails under full-suite parallel load (~335s). nextest process-isolates each test, so this is resource/timing contention on the wet-execution path, not a logic bug — a non-deterministic test can't gate a merge (§5). Pre-existing (P3c: wet==hermetic equivalence gate + flip CI discovery default to Hermetic #5276), never run under the old 3-filter allowlist. #[ignore = "<reason>"] + routed to the wet==hermetic / hermetic-testing owner; the lens keeps it visible.

Verified on the merged tree: cargo fmt --all --check ✓, cargo clippy --all-targets -D warnings ✓, cargo nextest run -p v1-compiler-tests → 765 passed, 0 failed, 92 skipped ✓, ci.yml drift gate ExitSuccess (ci.yml stays generated from ci_workflow.dag, byte-identical), ci_spec_witnesses() + floor_effect_gate_witness ✓.

On the flat-tree declared_modules note: confirmed accepted residue — documented in the doc comment; a nested-mod refactor would need it to recurse, flagged there.

— sent from fierce-hawk-540

@gunbai-bot

gunbai-bot Bot commented Jun 22, 2026

Copy link
Copy Markdown
Contributor Author

Thanks — all three are addressed/clean, no code change warranted:

  1. declared_modules flat-tree caveat — yes, that's the intended unstructurable-residue boundary, and your note closes the doc-comment loop. The promise is deliberate: if anyone nests a *_test.rs under a mod foo { … } / foo/mod.rs, every_test_file_is_declared_in_lib must grow to recurse into nested mod blocks (the docstring is the named dissolution trigger). Today's tree is flat, so it holds; flagged for the future refactor, exactly as you read it.
  2. Nextest transport — agreed, thin shape (["cargo","nextest","run",extra_args]), no business literal; -p v1-compiler-tests lives at the caller in rust_gates_ci.dag, matching the sibling ops under the §3 carve-out.
  3. ci_spec split — correct: spec.gates == floor_gates (asserted by witness_rust_gate_split_is_real), and the concat(floor, rust_job) union stays referenced by the roster-completeness witnesses (ci_spec_witness + affected_set_universe), so no orphan.

CI is green-equivalent on this head: the freshness-merge to cd649fb37c brought only docs/planning commits (#5550/#5547/#5545) — zero .rs/rust changes — over the 08c5b481f7 I verified cargo nextest run -p v1-compiler-tests = 765 passed / 0 failed / 92 skipped, fmt/clippy/drift/witnesses all green. CI run in_progress confirms.

— sent from fierce-hawk-540

briansrls added a commit that referenced this pull request Jun 22, 2026
…stones

Surgical ROADMAP.md updates from the 2026-06-22 session (short lines, density in
docs per the roadmap's own no-dual-rep rule):
- §5 de-fork: grounding cluster UNPARKED (operator ruled FreeMonoid/algebra single
  authority — coproduct structural authority, record-surface derived, grounded-
  realization wins); de-fork + self-host fused into one grounding lane (Root A
  emit-seam / Root B keystone), v1-coupled coercion/node fenced to v1-delete.
- ✦ ergonomics: generic-inference keystone landed (#5552, green-by-execution).
- §1 CI: rust-gate run-all at nextest speed CI-green-proven (#5427).
- §1 G2: cross-host placement dispatched (proud-tern-439), live apply fenced.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@briansrls
briansrls merged commit eff64e4 into main Jun 22, 2026
2 checks passed
@briansrls
briansrls deleted the session/fierce-hawk-540 branch June 22, 2026 20:47
briansrls added a commit that referenced this pull request Jun 22, 2026
…content review; re-homes into .dag after #5535] (#5560)

* WIP: ROADMAP planning

* docs(roadmap): reflect FreeMonoid grounding ruling + keystone/CI milestones

Surgical ROADMAP.md updates from the 2026-06-22 session (short lines, density in
docs per the roadmap's own no-dual-rep rule):
- §5 de-fork: grounding cluster UNPARKED (operator ruled FreeMonoid/algebra single
  authority — coproduct structural authority, record-surface derived, grounded-
  realization wins); de-fork + self-host fused into one grounding lane (Root A
  emit-seam / Root B keystone), v1-coupled coercion/node fenced to v1-delete.
- ✦ ergonomics: generic-inference keystone landed (#5552, green-by-execution).
- §1 CI: rust-gate run-all at nextest speed CI-green-proven (#5427).
- §1 G2: cross-host placement dispatched (proud-tern-439), live apply fenced.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 22, 2026
…r, coherence blocker

- self-host: cargo-green is a CHECKPOINT; the bit-identical self-emit merkle fixed-point
  (Stage C) is the GATE (the "compiles but miscompiles" §5 trap). Stage C owner = open decision.
- verification standard: discriminating red-witness + non-growing #[ignore] roster, not counts.
- CI: one cgroup-peak measurement / three consumers; the self-RSS-vs-cgroup-peak §5 bug.
- coherence gate head-independently broken (ctrl-side) may block keystone #5427 (decision C7).
- extdeps anchor lane blocked on 28 mis-homed modules operator decision (C8).
- new Lane 3b: CI inline-shell de-fork (transport-fusion debt) candidate (C9).
- Section A marked snapshot-not-authority (derive from dashboard-ops; no §6 parallel ledger).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jun 22, 2026
#5535)

#5560 hand-edited ROADMAP.md on main (FreeMonoid grounding ruling + keystone/CI
milestones) with intent to "re-home into .dag after #5535" — but it landed BEFORE
#5535, so transcribe its content into the authority now or the generated ROADMAP.md
would drop/drift it (zero-content-loss). Folded all 5 edits:
- §0 rust-gate: run-all-at-nextest-speed CI-green line (#5427)
- ✦ Milestones + generic-inference fix: #5552 keystone green
- §1 G2: + cross-host placement (proud-tern-439)
- §5 de-fork restructure: grounding cluster UNPARKED → Root A / Root B / v1-coupled

All 8 #5560 phrases present + matching; 2 superseded items removed; whole-doc audit
zero missing refs/paths; 5 witnesses green; gate drift-clean + red-receipt intact.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 22, 2026
…n flagship capstone) (#5535)

* WIP: Continue the ROADMAP inversion lane - successor to archived quiet-hawk-4

* WIP: Continue the ROADMAP inversion lane - successor to archived quiet-hawk-4

* wip: roadmap gate floor wiring (gate_is_heavy_resolve arm)

* roadmap gate: comply with #5534 comment-ban (strip gunbc/tools comments; boundary lives in gate reason-string + witness)

* WIP: Continue the ROADMAP inversion lane - successor to archived quiet-hawk-4

* WIP: Continue the ROADMAP inversion lane - successor to archived quiet-hawk-4

* WIP: Continue the ROADMAP inversion lane - successor to archived quiet-hawk-4

* ROADMAP authority: re-transcribe faithfully from current main + carriers(List<Pointer>) + lead_lanes machinery

Fixes the stale-base lossiness (warm-lark/bright-stag): re-transcribe §1-§8 from
current main (245 ln) with ZERO content loss, applying only C1-C5 + benign rewrap.

Model:
- PlanDocCarrier -> List<Pointer{label,path}> (dissolves NoCarrier/PlanDoc 2-state;
  label is data, varies per ROADMAP; multi-pointer items supported)
- RoadmapDocument gains lead_lanes: List<RoadmapSection>, rendered with a
  projection-derived ✦ sigil (sigil-from-position); ✦ Ergonomics LANE content HELD
  pending #5545 merge (transcribe post-#5545 bytes natively)
- emit no longer force-bolds derivable titles; bold is authored in the title string
  (the §5 fence, consistent with AuthoredLine) -> matches main's per-item bolding

Restored: §1 (was entirely stale: title reverted, host-op band G1-G5, shared
abstractions), §2 P1/P2/M4.1/M5/P3 cache subtree, §3 subject-producer/gates-whole,
§4 anemia-lens, §5 adjacent-lane + de-fork children + emitted-crate subtree, §6
Medium<A><->Medium<B>, preamble clauses, §0 dropped descriptions + cardinality item
+ all dropped pointers (incl gate-hygiene merge-freshness + DESIGN §6 + axiom scope).

All 5 roadmap witnesses green by execution; gate drift-clean + red-receipt teeth.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Continue the ROADMAP inversion lane - successor to archived quiet-hawk-4

* revert §2 to flat authored (temp green) — awaiting owner call on plain-bullet approach

bright-stag+warm-lark want byte-exact plain bullets for the 2 compact lines
(hermetic, blockers). The SectionGroup restructure (real nested checkboxes) was
withdrawn (7th delta). But byte-exact mixed task/plain lists need a std.markdown
heterogeneous-list capability — out of brief, escalating to owners. Holding the 2
lines at flat-authored (green) until they rule std-change vs roadmap-layer-plain.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* §6 roadmap-inversion: option (B) — plain-bullet RoadmapItem (no phantom checkbox)

The two compact §2 bullets (hermetic, blockers) carry inline [x]/[ ] glyphs that
a TaskListBlock would falsely wrap in a leading checkbox — a §5 mixed-state
fail-open. Add a PlainLine RoadmapItem variant + roadmap-layer run-partitioning
(consecutive task/plain nodes → adjacent TaskListBlock/UnorderedListBlock) so they
render as faithful plain bullets. No std.markdown touch (the heterogeneous-list
unification is a separate parked defect per owner ruling).

hermetic (nested under P2) is byte-exact (md_item joins nested blocks with "\n");
blockers (top-level) gets one structural blank line (block_separator "\n\n") —
classified [benign-rewrap], the std-heterogeneous-list fix deferred.

5 witnesses green; gate drift-clean + red-receipt intact.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* docs: reclassify the 2 compact bullets as option (B) implemented

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* §6 roadmap-inversion: transcribe ✦ Ergonomics lane natively + §5 required-facts pointer

- ✦ Ergonomics lane authored into lead_lanes (renders upstream of §0 per both owners'
  lead-lane ruling; ✦ sigil from projection position). Content byte-faithful to
  post-#5545 main modulo accepted benign-rewraps (line-wrap, blank-after-heading,
  uniform-blank-after-sub-group-label).
- §5 "dissolve seed hand-patches": fold in the required-facts pointer + emit_rust
  hand-sync caveat text that a recent merge added to main (was dropped on regen).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* docs: ✦ lane transcribed natively — update completeness diff (placement + §5 catch)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* §6 roadmap-inversion: remove the review artifact — capstone finalized

Both owners signed (warm-lark gate-integrity + independent faithfulness verify;
bright-stag content+placement). The completeness-diff was a review aid; the
authority + gate are the durable record. ROADMAP.md is now a CI-enforced
projection of gunbc.roadmap_authority — drift unwritable via RoadmapGate.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* §6 roadmap-inversion: fold #5560 content into authority (re-home before #5535)

#5560 hand-edited ROADMAP.md on main (FreeMonoid grounding ruling + keystone/CI
milestones) with intent to "re-home into .dag after #5535" — but it landed BEFORE
#5535, so transcribe its content into the authority now or the generated ROADMAP.md
would drop/drift it (zero-content-loss). Folded all 5 edits:
- §0 rust-gate: run-all-at-nextest-speed CI-green line (#5427)
- ✦ Milestones + generic-inference fix: #5552 keystone green
- §1 G2: + cross-host placement (proud-tern-439)
- §5 de-fork restructure: grounding cluster UNPARKED → Root A / Root B / v1-coupled

All 8 #5560 phrases present + matching; 2 superseded items removed; whole-doc audit
zero missing refs/paths; 5 witnesses green; gate drift-clean + red-receipt intact.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 22, 2026
…ak (per-job placement divisor) (#5574)

* WIP: ci is slow investiation

* docs/plans: ci-merge-freshness decision record (stale-green root of the 3× fleet-red)

Pins the 3× fleet-red to stale-green (PR validated against a pre-gate base,
merged without re-validating current main) via the #5429 timeline receipts;
ranks the merge-policy fixes (merge-queue >> require-up-to-date under the
approval outage); scopes neat-ibex's reverse-staleness lens as complementary,
not the 3×-red killer. Decision record for the operator's merge-policy call.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* docs/plans: scoped edge-(b) brief — rust-test↔consumed-.dag provenance (the §1 coverage keystone)

Scoping artifact for the operator greenlight call. One declared fact (rust-test→
consumed-.dag closure on the existing NodeArtifactProvenance carrier) read in two
directions: FIRE-when-consumed (coverage wall, fail-closed) and SKIP-when-unaffected
(affordability selector) — DESIGN §4 one grammar both directions. Shared
testgen-reflection blocker; first vertical slice; honest multi-day estimate. Build
HELD for operator nod; decoupled from #5427.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* docs/plans: edge-(b) brief — fold in the coverage-completeness asymmetry (closure ⊇ reads)

bright-stag's load-bearing sharpening: coverage (fire-on-change) is fail-OPEN to
under-declaration (declaration drift re-opens the .dag→rust hole), while affordability
(skip) is fail-safe to over-declaration. So (1) the completeness lens must check
closure ⊇ actual-.dag-reads (CORRECTNESS), not mere presence — presence is the §5
faked-cache-key trap; (2) structural closure discovery IS the soundness, not optional
polish — a hand-authored closure is the §3/§5 fork that silently re-opens the hole;
(3) slice-1 must state whether its closure is structurally derived (proves the wall) or
hand-listed (proves only the wiring).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* ROADMAP: anchor the edge-(b) keystone brief from the rust-gate-coverage item (doc reachability)

The new docs/plans/edge-b-rust-dag-provenance-brief.md was an orphan doc → the
floor witness doc_graph_has_no_orphan_docs (dsl/test/claim/doc_reachability_witness_test.dag)
RED on #5526. Fix per the rule (every docs/**/*.md reachable from a ROADMAP/DESIGN
root): add a terse pointer on the existing §1 rust-gate-coverage line, its correct
semantic home — edge-(b) is the .dag→rust coverage wall that #5427 (the .rs-hole-closer)
does not close.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* ROADMAP: trim edge-(b) line 36 to short summary + status (bright-stag refinement)

Per the operator short-lines rule (bright-stag enforces): move the mechanism density
(rust-test↔consumed-.dag closure, fail-closed both directions) into the brief; keep the
ROADMAP line a short scannable summary + pointer + explicit no-overclaim status
('SCOPED / pending operator greenlight'). Build is NOT greenlit; the line now says so.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: ci is slow investiation

* fmt: rustfmt the cgroup-peak measurement additions (claim_executor)

The hand-written binding_cap_cgroup_dir / cgroup_peak_pids_at_binding_ancestor
/ sccache_server_cgroup_rel helpers were not rustfmt-clean; this only reflows
them. No logic change. Fixes the rust_tests fmt failure on the held draft #5564.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* CI measurement: rust_tests-job leaf cgroup peak + --measure-cgroup-peak (per-job placement divisor)

Second half of the whole-tree CI memory measurement (companion to #5564's ci-job
emit): a claim_executor --measure-cgroup-peak standalone mode + a rust_tests-job
ci.yml step that calls it, so the rust_tests job (the binding ~16-23 GiB per-job
constraint, measured live on srv1) emits its own cgroup peak.

Corrects #5564's cap-ancestor read for the real fleet. Live srv1 inspection
(operator-granted) shows the runner units run MemoryMax=infinity (UNCAPPED), so
binding_cap_cgroup_dir returns None and the cap-ancestor read emits "unavailable".
The measurement now reads memory.peak at the LEAF runner cgroup (the ephemeral
per-job cgroup, always present) and reports capped-vs-uncapped + host MemTotal.

One walk, all reads (single authority): the emit line carries memory.peak (usage)
+ memory.max (budget, =uncapped on the fleet) + host_ram + pids.current/max + the
sccache server cgroup classified descendant-vs-sibling (the "accounted exactly
once" decision) — consumed by the compile-jobs divisor (#5546) and the placement
model (#5559).

Stacked on #5564 (reuses its binding_cap_cgroup_dir / sccache scan). ci.yml
regenerated via main_wet; drift gate green; fmt + clippy -D warnings + release
build clean; --measure-cgroup-peak verified by execution.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* Review fix (#5574): path-component prefix for sccache descendant check

claude-opus-4-7 flagged that sccache_under_leaf used a bare string prefix, so a
sibling like <leaf>-other.service would misclassify as a descendant (under-counts
host_fixed_overhead — the fail-OPEN direction). Compare on path components: leaf
itself, or a strict <leaf>/ prefix. Comment updated to match.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 4, 2026
* CI witness opt-in inversion: zero witnesses by default, enrollment by declared roster row

Operator decision 2026-07-04: the tree-wide glob roster (543 files / ~1,551
test fns, growing quadratically - a witness is definable between any two
pipeline segments) pushed both CI jobs to the 90-min timeout: maximum cost,
zero delivered signal, every merge effectively fail-open. Existence no longer
enrolls a witness in CI.

- CiSpec.witness_entries: the opt-in roster, projected from CommitWitnessClaim
  rows on the GithubActionsCiJob surface of commit_gate_roster (the existing
  enrollment authority - no new mechanism). Empty today.
- ci_floor_plan: an empty roster puts NO witness-corpus node in the plan
  (structural omission, not an empty glob - the executor's empty-corpus
  fail-closed diagnostic stays meaningful); a non-empty roster becomes
  explicit-entries discovery batches (scan_dirs/discovery_scope_dirs empty, so
  the glob path is unreachable from CI), partitioned corpus vs execution by
  path prefix, still compile-gated and heavy-serialized. The dedicated
  grounding whole-tree node dissolved into the roster.
- claim_executor: when a plan carries no DiscoveryBatch, run the naming-
  hygiene tree walk (test fn outside *_test.dag, __ basenames) once,
  fail-closed - a witness must stay nameable even when not enrolled.
- Witness tests inverted: live plan asserts discovery tracks the roster
  (zero today); the enrollment machinery is proven on synthetic rosters
  (presence, partition, gating after compile, heavy serialization, exclusion
  edges) with red discrimination.
- Rust lane, same inversion: the two whole-tree tests (func_env whole-tree
  ptr-count, whole-corpus semantic oracle) are now #[ignore] with written
  reasons per the #5427 discipline; run via -- --ignored.
- Found and fixed two files the v1 interpreter grammar could not parse
  (top-level // comments): affected_set_floor_runner.dag - which made
  resolve_floor_runner_context fail and silently disabled the affected-set
  skip, falling back to full corpus on every floor run - and
  phase_profile_proof_plan.dag. Comments converted to data-string markers.
- Local tree-wide discovery unchanged (claim_batch --roster-from-discovery).
- Dissolve-on: affected-set selection + floor memoization make per-PR
  selection-by-affectedness affordable; enrollment returns to discovery
  shrunk by the affected set.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Enroll the first opt-in CI witness: variant_owner_expected_type (single pure-fn canary)

Per operator intent: exactly one witness in CI for now, to observe the floor's
behavior around a known-tiny payload. The canary is
dag/test/claim/variant_owner_expected_type_test.dag ::
expected_type_picks_variant_owner_not_alpha_order - a single test fn over
self-contained pure functions (no host intrinsics, one std.logic import;
measured locally: 3ms resolve / 2-module closure, ~0ms eval), so whatever time
the CI witness lane now costs is the floor's fixed overhead, not the witness.

Also: run the witness naming-hygiene walk unconditionally in claim_executor's
plan path, BEFORE plan evaluation - explicit-entries discovery batches skip
the glob scan that used to carry the placement checks, and pre-plan ordering
makes a naming violation the cheapest possible failure. Verified by execution:
red probe (planted test fn in a non-_test.dag file) fails closed with the
placement diagnostic in seconds; green probe on the live tree passes the walk
and proceeds to plan eval; the enrolled canary runs green via claim_batch.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Fix clippy absurd_extreme_comparisons on the emitted-Rust error ratchet (pre-existing on main; surfaces on any .rs-touching PR)

The ratchet constant deliberately sits at its minimum (0); scoped allow with
justification keeps raising the ceiling a one-constant edit instead of
hardcoding == 0.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Eliminate every degradation arm in floor selection: declared machinery fails immediately

Operator decision: 'fail closed' here means DON'T PROCEED, never 'silently run
more'. skip_unaffected_node_frontier: true is a declared capability, so every
input it needs is required - a failure is a loud typed error:

- git diff observation failed -> error (was: run full corpus). The
  FloorGitDiffOutcome degradation enum is deleted; an absent diff is no longer
  a representable input state to selection. To run without selection, declare
  skip_unaffected_node_frontier: false - an explicit bit, not a silent state.
- diff->declaration attribution failed -> error (was: run full corpus)
- affected-set runner unresolvable -> error naming the declared entry
  (was: run full corpus - the arm that hid the broken runner for weeks)
- same per shard -> error through the shard join (was: run all rows in shard)
- precompute_would_skip / per-witness would_skip / frontier-touch fns
  erroring -> error naming the witness (was: run anyway)
- roster row file unreadable -> error (was: silently reclassify as
  host-scaffold)

Rationale: the 'safe' superset fallback conflated broken artifacts with
missing observations, hid the defect permanently (no consumer of the eprintln),
and at corpus scale 'run more' inverted into fail-open-by-timeout. The runner
provisioning, fetch step, and observers are all declared by this repo's own
spec, so there is no 'environment' excuse category: a missing input is a bug
in a declared step and stops the floor.

cargo build green, clippy -D warnings green, fmt clean; floor-scoped lib unit
tests and a live red/green probe through a discovery batch are running and any
regression they surface lands as a follow-up.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Floor prelude: resolve the plan entry once, stamp every phase with wall-clock marks

The 'gunbc ci' step went silent for 35+ minutes after the release build on the
self-hosted runner - all of it pre-witness prelude: naming walk, output-policy
install, plan-entry resolve, interpreted scheduler eval (gunbc_ci_floor_batches),
then a SECOND resolve of the same plan entry for spawn-width, then another
interpreted eval. Nothing printed until all of it finished, so a 30-minute
prelude was indistinguishable from a hang.

- resolve_entry_graph(plan_entry) now runs once; the hermetic plan eval and the
  wet spawn-width eval share the resolved graph (the double-paid-compute trap
  from the floor memoization thread, paid at minutes per resolve).
- claim_executor stamps [t+Xs] phase marks: hygiene walk, policy install, plan
  resolved, plan evaluated, width evaluated / walk starting. The floor log now
  itemizes its own prelude.

eval_plan stays as a resolve+eval wrapper for the --perturb-check path.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* CI job timeout: 90 -> 10 minutes (operator inversion of the timeout ratchet)

The prior ratchet went 30 -> 50 -> 90, each raise buying headroom for the
unfixed resolve cost; at 90 the queue backed up and runs still died at the
cap having delivered zero signal. The budget is now a forcing function: the
floor must fit it, and the [t+Xs] phase marks itemize exactly which phase
does not. Jobs stay red-by-timeout until resolve memoization lands - an
honest red, unlike a 90-minute lane that never completed.

ci.yml hand-synced with the ci_workflow.dag authority (3 job sites); the
generated-artifact drift gate byte-verifies the pairing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Resolver graph-major design doc: once-per-node module evaluation (operator session 2026-07-04)

Names the target architecture for the resolve problem measured during the CI
dig-out: request-major private universes -> cheap edge graph + reverse-reachable
minimal set + forward once-per-node evaluation (construction, not cache lookup),
windowed-frontier memory (interface vs body artifacts), isolation-as-purity, and
the full v1/v2 change surface. Staged S1 (union resolve, in-process, ships in
the current PR line) / S2a (module nodes + Merkle keys) / S2b (persistence,
gated on determinism #5941) / S3 (shared store) so it is not a 10-PR arc.
Cross-linked from the M1/M2 memoization doc it supersedes (that doc's own M1
dissolution trigger anticipated exactly this design).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Hand-sync generated docs to their edited authorities (DESIGN.md CI bullet, ci-selection-vs-scheduling section 7)

The interpreted main_wet regeneration was killed twice by container restarts
(~2 CPU-hours each attempt, itself a receipt for the resolver-graph-major
design). The generated outputs are hand-applied to byte-match what the
emitters produce from the already-committed authorities
(dag/gunbc/design_document.dag, dag/gunbc/plans/ci_selection_vs_scheduling.dag);
the GeneratedArtifactDriftGate adjudicates exactness once the floor fits its
10-minute budget.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* claim_batch: honor GUNBC_FLOOR_PHASE_PROFILE (same install as claim_executor)

Without it, claim_batch diagnostics cannot attribute time to
resolve/typecheck/eval phases - a 20-minute silent resolve is
uninterpretable, and the resolver investigation needs per-phase receipts.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Resolver design: phase verdict (typecheck-dominant) + one-scheduler-no-special-cases section; per-module typecheck attribution

Instrumented, isolated measurement: the 11-module closure finishes
parse+resolve+normalize in ~1.1s then sits in typecheck 13+ minutes -
inference is ~99.9% of cold resolve cost. Reprioritizes the plan: pathology
lane first (per-module [typecheck-attribution] lines now name any module
over 2s), unification (module obligations under the existing executor)
second, union-of-global-passes demoted to a ~1s-class cut.

Adds the operator's formulation as design section 1b: resolution is the
system's one special case - the Bazel-shaped executor schedules eleven
coarse gates while the dominant work hides in one opaque recursive host
call; module resolution IS dependency execution over the same substrate.
Maps the external witness-frontier-cursor vocabulary onto existing
authorities (Runnable/RunnableCompile, Realization content-hash key +
EffectShape, executor batches, receipts) per the section-3 anti-nickname
discipline, and adopts the four-terminal-state invariant.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* S1a: process-level resolve store - fixed-entry machinery resolves once per process

First implementation increment of the resolver graph-major design (and of
the stratification rule: resolution is declared shared work, not ambient
per-consumer control flow). A thread-local store keyed by (source_roots,
entry) now serves the floor runner context, the diff observer, the output
policy, the group syntax, the wet-hermetic roster prefix, and the
executor's plan entry - each was previously a private resolve, re-paid per
consumer and per discovery batch within one process. Failure semantics
unchanged: a miss resolves exactly as before, including the typed error
path; the store never converts an error into a fallback.

Receipt: process_resolve_store_dedupes_repeat_resolve - Rc identity on the
second resolve proves zero recompute (0.00s, fixture tree under target/).
Thread-local by design: resolved graphs are Rc-based (not Send); shard
threads keep their own store rather than smuggling Rc across threads.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* typecheck attribution: start markers (profile-gated) name the pathological module

Verdict from the instrumented run: all std modules in the closure -
including std.algebra and std.realization_schedule themselves - typecheck
in under 2s each; the call that runs 17+ minutes is typecheck_module on
the 80-line CONSUMER module (test.claim.realization_schedule_witness).
The inference pathology is at generic use sites, not definition sites.
Next lane: the existing type-env lookup profiler (text_lookup_work_counter
feature, reset_type_env_lookup_profile) pointed at that one module.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Phase heartbeat: live type-env amplification counters; pathology named

Heartbeats now carry env_flatten/env_builds/env_merges/env_rewires from the
existing v1_compiler_infer_env atomics. First live capture on the
pathological entry: env_flatten grows ~80k/sec unbounded (9.7M by t=120s)
while builds=11, merges=37, rewires=0 stay flat.

Root site: record_lit_variant_fields_from_visible_env
(v1_compiler_infer.rs, generated from v1.compiler.infer) - every VARIANT
LITERAL flattens the entire visible environment (recursive parent fold; the
counter) and then scans every visible binding with
expand_type_for_field_access per candidate to find the variant's owner.
Cost = variant literals x |visible env| x expansion - definitions cheap,
consumers explode. 04_env.dag:35 carries an invariant expecting
flatten_visible_parent_recurses==0 on import chains; live count says 9.7M
in 2 minutes. Fix shape (next block, dag source + regen): a variant-name ->
owner index built once per env, and expected-type short-circuit before any
global scan.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Resolver design: operator ruling - constructor ambiguity is an ERROR; resolution follows the binding edge

The ambiguity support (bare constructor names legal across coproducts,
expected-type tie-break, whole-env owner scan as fallback) is itself the
bug - accidental semantics, never intended. The DAG already provides the
namespace: imports bind arm names to arm nodes; the parent edge names the
owner; resolution is following the edge already held. Rules: bound-name
resolution via parent edge; unbound constructor literal = typed error
(today a silent undeclared-dependency fail-open via the scan); double
binding = collision error at env build; patterns resolve via scrutinee
type; expected-type owner-picking deleted. The pathological scan is
removed, not memoized.

Census: 5,526 arm names, 221 global collisions (uniqueness must be scoped
to co-visibility); <=4,572 unbound arm-name uses upper bound, dominated by
legal pattern positions. Control run killed at 60+ min still inside one
typecheck_module call on the 80-line module.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Resolver design: operator sequencing - union resolve first as interim with explicit contract; flat name visibility refinement

Union resolve leads the resolve lane with a recorded contract: minimum
upper bound (resolve cost <= 1x union closure, receipt-enforced), successor
must be maximally parallel (topo-antichain module typecheck, budget-tree
width) and frontier-window efficient; it dissolves into S2a and must not
grow features that delay that. Namespacing ruling refined per operator:
visibility is FLAT - locals + direct imports only, never transitive -
making collision detection per-file with zero graph traversal; types
propagate by graph identity underneath.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

---------

Co-authored-by: Claude <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 4, 2026
…ll, scan deleted — the engine PR (#6235)

* CI witness opt-in inversion: zero witnesses by default, enrollment by declared roster row

Operator decision 2026-07-04: the tree-wide glob roster (543 files / ~1,551
test fns, growing quadratically - a witness is definable between any two
pipeline segments) pushed both CI jobs to the 90-min timeout: maximum cost,
zero delivered signal, every merge effectively fail-open. Existence no longer
enrolls a witness in CI.

- CiSpec.witness_entries: the opt-in roster, projected from CommitWitnessClaim
  rows on the GithubActionsCiJob surface of commit_gate_roster (the existing
  enrollment authority - no new mechanism). Empty today.
- ci_floor_plan: an empty roster puts NO witness-corpus node in the plan
  (structural omission, not an empty glob - the executor's empty-corpus
  fail-closed diagnostic stays meaningful); a non-empty roster becomes
  explicit-entries discovery batches (scan_dirs/discovery_scope_dirs empty, so
  the glob path is unreachable from CI), partitioned corpus vs execution by
  path prefix, still compile-gated and heavy-serialized. The dedicated
  grounding whole-tree node dissolved into the roster.
- claim_executor: when a plan carries no DiscoveryBatch, run the naming-
  hygiene tree walk (test fn outside *_test.dag, __ basenames) once,
  fail-closed - a witness must stay nameable even when not enrolled.
- Witness tests inverted: live plan asserts discovery tracks the roster
  (zero today); the enrollment machinery is proven on synthetic rosters
  (presence, partition, gating after compile, heavy serialization, exclusion
  edges) with red discrimination.
- Rust lane, same inversion: the two whole-tree tests (func_env whole-tree
  ptr-count, whole-corpus semantic oracle) are now #[ignore] with written
  reasons per the #5427 discipline; run via -- --ignored.
- Found and fixed two files the v1 interpreter grammar could not parse
  (top-level // comments): affected_set_floor_runner.dag - which made
  resolve_floor_runner_context fail and silently disabled the affected-set
  skip, falling back to full corpus on every floor run - and
  phase_profile_proof_plan.dag. Comments converted to data-string markers.
- Local tree-wide discovery unchanged (claim_batch --roster-from-discovery).
- Dissolve-on: affected-set selection + floor memoization make per-PR
  selection-by-affectedness affordable; enrollment returns to discovery
  shrunk by the affected set.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Enroll the first opt-in CI witness: variant_owner_expected_type (single pure-fn canary)

Per operator intent: exactly one witness in CI for now, to observe the floor's
behavior around a known-tiny payload. The canary is
dag/test/claim/variant_owner_expected_type_test.dag ::
expected_type_picks_variant_owner_not_alpha_order - a single test fn over
self-contained pure functions (no host intrinsics, one std.logic import;
measured locally: 3ms resolve / 2-module closure, ~0ms eval), so whatever time
the CI witness lane now costs is the floor's fixed overhead, not the witness.

Also: run the witness naming-hygiene walk unconditionally in claim_executor's
plan path, BEFORE plan evaluation - explicit-entries discovery batches skip
the glob scan that used to carry the placement checks, and pre-plan ordering
makes a naming violation the cheapest possible failure. Verified by execution:
red probe (planted test fn in a non-_test.dag file) fails closed with the
placement diagnostic in seconds; green probe on the live tree passes the walk
and proceeds to plan eval; the enrolled canary runs green via claim_batch.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Fix clippy absurd_extreme_comparisons on the emitted-Rust error ratchet (pre-existing on main; surfaces on any .rs-touching PR)

The ratchet constant deliberately sits at its minimum (0); scoped allow with
justification keeps raising the ceiling a one-constant edit instead of
hardcoding == 0.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Eliminate every degradation arm in floor selection: declared machinery fails immediately

Operator decision: 'fail closed' here means DON'T PROCEED, never 'silently run
more'. skip_unaffected_node_frontier: true is a declared capability, so every
input it needs is required - a failure is a loud typed error:

- git diff observation failed -> error (was: run full corpus). The
  FloorGitDiffOutcome degradation enum is deleted; an absent diff is no longer
  a representable input state to selection. To run without selection, declare
  skip_unaffected_node_frontier: false - an explicit bit, not a silent state.
- diff->declaration attribution failed -> error (was: run full corpus)
- affected-set runner unresolvable -> error naming the declared entry
  (was: run full corpus - the arm that hid the broken runner for weeks)
- same per shard -> error through the shard join (was: run all rows in shard)
- precompute_would_skip / per-witness would_skip / frontier-touch fns
  erroring -> error naming the witness (was: run anyway)
- roster row file unreadable -> error (was: silently reclassify as
  host-scaffold)

Rationale: the 'safe' superset fallback conflated broken artifacts with
missing observations, hid the defect permanently (no consumer of the eprintln),
and at corpus scale 'run more' inverted into fail-open-by-timeout. The runner
provisioning, fetch step, and observers are all declared by this repo's own
spec, so there is no 'environment' excuse category: a missing input is a bug
in a declared step and stops the floor.

cargo build green, clippy -D warnings green, fmt clean; floor-scoped lib unit
tests and a live red/green probe through a discovery batch are running and any
regression they surface lands as a follow-up.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Floor prelude: resolve the plan entry once, stamp every phase with wall-clock marks

The 'gunbc ci' step went silent for 35+ minutes after the release build on the
self-hosted runner - all of it pre-witness prelude: naming walk, output-policy
install, plan-entry resolve, interpreted scheduler eval (gunbc_ci_floor_batches),
then a SECOND resolve of the same plan entry for spawn-width, then another
interpreted eval. Nothing printed until all of it finished, so a 30-minute
prelude was indistinguishable from a hang.

- resolve_entry_graph(plan_entry) now runs once; the hermetic plan eval and the
  wet spawn-width eval share the resolved graph (the double-paid-compute trap
  from the floor memoization thread, paid at minutes per resolve).
- claim_executor stamps [t+Xs] phase marks: hygiene walk, policy install, plan
  resolved, plan evaluated, width evaluated / walk starting. The floor log now
  itemizes its own prelude.

eval_plan stays as a resolve+eval wrapper for the --perturb-check path.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* CI job timeout: 90 -> 10 minutes (operator inversion of the timeout ratchet)

The prior ratchet went 30 -> 50 -> 90, each raise buying headroom for the
unfixed resolve cost; at 90 the queue backed up and runs still died at the
cap having delivered zero signal. The budget is now a forcing function: the
floor must fit it, and the [t+Xs] phase marks itemize exactly which phase
does not. Jobs stay red-by-timeout until resolve memoization lands - an
honest red, unlike a 90-minute lane that never completed.

ci.yml hand-synced with the ci_workflow.dag authority (3 job sites); the
generated-artifact drift gate byte-verifies the pairing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Resolver graph-major design doc: once-per-node module evaluation (operator session 2026-07-04)

Names the target architecture for the resolve problem measured during the CI
dig-out: request-major private universes -> cheap edge graph + reverse-reachable
minimal set + forward once-per-node evaluation (construction, not cache lookup),
windowed-frontier memory (interface vs body artifacts), isolation-as-purity, and
the full v1/v2 change surface. Staged S1 (union resolve, in-process, ships in
the current PR line) / S2a (module nodes + Merkle keys) / S2b (persistence,
gated on determinism #5941) / S3 (shared store) so it is not a 10-PR arc.
Cross-linked from the M1/M2 memoization doc it supersedes (that doc's own M1
dissolution trigger anticipated exactly this design).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Hand-sync generated docs to their edited authorities (DESIGN.md CI bullet, ci-selection-vs-scheduling section 7)

The interpreted main_wet regeneration was killed twice by container restarts
(~2 CPU-hours each attempt, itself a receipt for the resolver-graph-major
design). The generated outputs are hand-applied to byte-match what the
emitters produce from the already-committed authorities
(dag/gunbc/design_document.dag, dag/gunbc/plans/ci_selection_vs_scheduling.dag);
the GeneratedArtifactDriftGate adjudicates exactness once the floor fits its
10-minute budget.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* claim_batch: honor GUNBC_FLOOR_PHASE_PROFILE (same install as claim_executor)

Without it, claim_batch diagnostics cannot attribute time to
resolve/typecheck/eval phases - a 20-minute silent resolve is
uninterpretable, and the resolver investigation needs per-phase receipts.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Resolver design: phase verdict (typecheck-dominant) + one-scheduler-no-special-cases section; per-module typecheck attribution

Instrumented, isolated measurement: the 11-module closure finishes
parse+resolve+normalize in ~1.1s then sits in typecheck 13+ minutes -
inference is ~99.9% of cold resolve cost. Reprioritizes the plan: pathology
lane first (per-module [typecheck-attribution] lines now name any module
over 2s), unification (module obligations under the existing executor)
second, union-of-global-passes demoted to a ~1s-class cut.

Adds the operator's formulation as design section 1b: resolution is the
system's one special case - the Bazel-shaped executor schedules eleven
coarse gates while the dominant work hides in one opaque recursive host
call; module resolution IS dependency execution over the same substrate.
Maps the external witness-frontier-cursor vocabulary onto existing
authorities (Runnable/RunnableCompile, Realization content-hash key +
EffectShape, executor batches, receipts) per the section-3 anti-nickname
discipline, and adopts the four-terminal-state invariant.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* S1a: process-level resolve store - fixed-entry machinery resolves once per process

First implementation increment of the resolver graph-major design (and of
the stratification rule: resolution is declared shared work, not ambient
per-consumer control flow). A thread-local store keyed by (source_roots,
entry) now serves the floor runner context, the diff observer, the output
policy, the group syntax, the wet-hermetic roster prefix, and the
executor's plan entry - each was previously a private resolve, re-paid per
consumer and per discovery batch within one process. Failure semantics
unchanged: a miss resolves exactly as before, including the typed error
path; the store never converts an error into a fallback.

Receipt: process_resolve_store_dedupes_repeat_resolve - Rc identity on the
second resolve proves zero recompute (0.00s, fixture tree under target/).
Thread-local by design: resolved graphs are Rc-based (not Send); shard
threads keep their own store rather than smuggling Rc across threads.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* typecheck attribution: start markers (profile-gated) name the pathological module

Verdict from the instrumented run: all std modules in the closure -
including std.algebra and std.realization_schedule themselves - typecheck
in under 2s each; the call that runs 17+ minutes is typecheck_module on
the 80-line CONSUMER module (test.claim.realization_schedule_witness).
The inference pathology is at generic use sites, not definition sites.
Next lane: the existing type-env lookup profiler (text_lookup_work_counter
feature, reset_type_env_lookup_profile) pointed at that one module.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Phase heartbeat: live type-env amplification counters; pathology named

Heartbeats now carry env_flatten/env_builds/env_merges/env_rewires from the
existing v1_compiler_infer_env atomics. First live capture on the
pathological entry: env_flatten grows ~80k/sec unbounded (9.7M by t=120s)
while builds=11, merges=37, rewires=0 stay flat.

Root site: record_lit_variant_fields_from_visible_env
(v1_compiler_infer.rs, generated from v1.compiler.infer) - every VARIANT
LITERAL flattens the entire visible environment (recursive parent fold; the
counter) and then scans every visible binding with
expand_type_for_field_access per candidate to find the variant's owner.
Cost = variant literals x |visible env| x expansion - definitions cheap,
consumers explode. 04_env.dag:35 carries an invariant expecting
flatten_visible_parent_recurses==0 on import chains; live count says 9.7M
in 2 minutes. Fix shape (next block, dag source + regen): a variant-name ->
owner index built once per env, and expected-type short-circuit before any
global scan.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Resolver design: operator ruling - constructor ambiguity is an ERROR; resolution follows the binding edge

The ambiguity support (bare constructor names legal across coproducts,
expected-type tie-break, whole-env owner scan as fallback) is itself the
bug - accidental semantics, never intended. The DAG already provides the
namespace: imports bind arm names to arm nodes; the parent edge names the
owner; resolution is following the edge already held. Rules: bound-name
resolution via parent edge; unbound constructor literal = typed error
(today a silent undeclared-dependency fail-open via the scan); double
binding = collision error at env build; patterns resolve via scrutinee
type; expected-type owner-picking deleted. The pathological scan is
removed, not memoized.

Census: 5,526 arm names, 221 global collisions (uniqueness must be scoped
to co-visibility); <=4,572 unbound arm-name uses upper bound, dominated by
legal pattern positions. Control run killed at 60+ min still inside one
typecheck_module call on the 80-line module.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Resolver design: operator sequencing - union resolve first as interim with explicit contract; flat name visibility refinement

Union resolve leads the resolve lane with a recorded contract: minimum
upper bound (resolve cost <= 1x union closure, receipt-enforced), successor
must be maximally parallel (topo-antichain module typecheck, budget-tree
width) and frontier-window efficient; it dissolves into S2a and must not
grow features that delay that. Namespacing ruling refined per operator:
visibility is FLAT - locals + direct imports only, never transitive -
making collision detection per-file with zero graph traversal; types
propagate by graph identity underneath.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Union-resolve follow-up: main-thread discovery rides the thread's shared index

run_discovery_corpus_with_options now takes process_shared_index(source_roots)
instead of building a private MultiEntryIndex, so when the executor prelude
already resolved on this thread, discovery reuses its parse/typed caches
(one union per thread, not per consumer). Shards keep their own index
(Rc !Send, per-shard contract in resolver-graph-major-design §7 S1).

Also: resolve_typed_cache_equivalence_test fixtures move from
std::env::temp_dir() to the workspace target/ dir — build_module_path_index
fails closed on out-of-workspace paths, so the /tmp fixture could never
resolve in a workspace-guarded environment (union_resolve_receipts_test
precedent).

Gates run: cargo build -p v1-compiler; cargo test -p v1-compiler-tests
resolve_typed_cache + union_resolve (green); source_identity guard (green).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Resolver design: three-layer executor framing (scheduler / runner+store / content keys) + realization tower

Supersedes the 'artifact-bearing executor' framing (operator, 2026-07-04:
artifacting is a separate concern, opaque to scheduling). §1b/§5/§7 now
state the split: the scheduler is payload-agnostic and unchanged; dataflow
lives in a runner + node-keyed store (typed_module_cache is its embryo);
S2b only swaps the store's key function to content hashes. The S2a open
decisions are settled by the split (results in the store, jobs reference
by node identity; gates stay unit-result; .dag-authority schedule).

New §5b: the realization tower — Rust is the bootstrap row, not the floor;
the intrinsic kernel is the declared HAND_MAINTAINED surface + registered
builtins; realization-scoped decisions (Rc !Send) carry dissolve-ons.

Post-fix timing receipts are placeholders by design, filled at the
receipts commit of this PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Constructor-owner ruling (§1c): binding-edge resolution, per-file collision wall, scans deleted — dag sources

Implements the operator ruling in the .dag authority (v1.compiler.infer /
infer_resolve). This commit is step 1 of the seed two-step: the checked-in
generated Rust still realizes the OLD semantics; the next commit hand-patches
the seed functionally, and the regen commit replaces the hand-patch with this
source's true emission (RegenVerifyGate byte-identity + bootstrap fixed point).

- infer_record_lit: the unconditional whole-env scan-first rung is DELETED
  (record_lit_variant_fields_from_visible_env and both call sites). The
  ladder is now instantiate -> expected -> declaration/binding-edge only.
- variant_owner_node: O(1) owner lookup — scope.locals binds arm name to its
  owning coproduct NODE; no name round-trip, owner need not be name-visible.
- build_module_context: constructor namespace is FLAT — local coproduct arms
  + direct imports' contributions (is_all covered; specific enum or arm
  names covered; owner node carried on the binding). The transitive
  ancestry fold and the unique-owner-or-nothing import map are deleted.
- Collision wall: one arm name -> two different owners in one file appends
  VariantCollision at env construction (insert_variant_owner_checked); the
  same declaration via two import paths is one owner, not a collision.
  Kernel coproduct arms keep low-priority prelude merge.
- expected_type_override_enum (expected-type-as-owner-picker) DELETED;
  ExprVar variant bindings resolve by binding edge alone.
- field_in_any_variant_named re-scoped to the resolved owner's arms.
- Unbound constructor literal now reports UnresolvedType (was a generic
  InternalError message); no new diagnostic variants minted — VariantCollision
  and UnresolvedType already existed in 00_core.
- collect_unit_variant_phantom_matches (04_resolve): flat one-level search
  (own + direct parents' str_bindings), no recursive ancestry flatten.
- Dead code deleted: unique_imported_variant_owner,
  enum_parents_for_variant_in_items, is_imported_variant_owned_by,
  union_parent_variant_locals, fold_local_coproduct_variant_locals
  (kernel path inlined), variant_locals_from_items.

Note: v2.std.determinism roster rows ^unique_imported_variant_owner /
^alpha_sorted_variant_fold are quoted symbols and still compile, but now
name superseded fns — flagged for operator re-signing (#5941 roster).

Baseline receipt (pre-fix, this base): realization_schedule_witness_test
(81 lines, 2 imports) killed at 900s still inside typecheck_module,
env_flatten 69.7M and linear (~78k/s) — target/baseline/single_module_pre_fix.log.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Constructor-owner ruling: hand-patched seed (two-step step 2) + diagnostic tests + payoff receipt

Functional hand-patch of generated v1_compiler_infer.rs ONLY (201 insertions,
one generated file — budget was ~200 across <=3): (a) build_module_context
realizes the new flat, collision-walled construction (local arms + direct
imports; owner node on the binding; VariantCollision on two owners for one
name; kernel arms low-priority); (b) variant_owner_node helper; (c)
record_lit_expected_fields owner via the binding node, scan fallback deleted;
(d) infer_record_lit scan-first rung deleted; (e) ExprVar expected-type
owner-picker deleted; (f) unbound constructor literal -> UnresolvedType.
Deferred to regen (semantic gap re-censused with the true seed):
field_in_any_variant_named re-scope, phantom-path flat re-scope, dead-fn
deletions. This hand-patch is replaced wholesale by regen output in the
convergence commit (precedent 3d89b2d/f3cc9f5).

PAYOFF RECEIPT (the C4 stop/go gate): realization_schedule_witness_test.dag
(81 lines, 2 imports) — pre-fix killed at the 900s cap still inside
typecheck_module, env_flatten 69.7M and linear (~78k/s); patched seed:
1.14s TOTAL, env_flatten 0. Receipt logs: target/baseline/.

New constructor_owner_ruling_test.rs (7 tests, green): intra-file collision,
cross-import collision, unbound->UnresolvedType, enum-import/arm-import/
glob-import (brace-less form) construct green, re-export non-collision.

The collision wall found live prey immediately (sweep work, next commits):
dag/std/markup.dag Fragment.TextNode vs MarkupNode.TextNode (converted
cross-owner at :183 — the expected-type pick in vivo); integer.dag
DecimalDigit vs NonZeroDecimalDigit D1..D9; target_model.dag
TargetReferenceLayer{,Wrapped}; plus bare-None uses that resolved via the
transitive scan. Corpus-resolving tests stay red until the sweep lands —
fix-then-sweep ordering, full-suite green re-established pre-regen.

Also: dependency_pool_index whole-tree compile tests (release-binary
corpus walks) join the 2026-07-04 opt-in inversion; they had escaped it by
self-skipping on CI (no release binary) while running unbounded locally.

Gates run: cargo build -p v1-compiler; cargo test -p v1-compiler-tests
constructor_owner_ruling (7/7) + resolve_typed_cache + union_resolve +
source_identity (green); payoff receipt above.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Constructor-owner ruling: re-export chains + witness rewrites + fixture hygiene (C4 follow-through)

Re-export chains (dag authority + seed hand-patch, both sides): a module
re-exports its specific-name imports (get_exported_names), so
'import proxy { B }' where proxy itself imports B is an explicit import
under the ruling. New owner_of_exported_arm / exported_coproduct_item walk
the acyclic import chain to the defining module's coproduct;
build_imported_variants resolves every specific name through them (glob
imports stay own-items-only, matching the export surface which excludes
is_all pass-through). Receipt: all 4 self_gen8 re-export chain tests green.
Hand-patch grows to ~280 lines / still 1 generated file — over the ~200
budget line, accepted because the patched seed is the sweep census tool and
without chains it mis-censuses every re-export site in the tree.

Old-semantics witnesses rewritten to witness the ruling:
- variant_owner_disambiguation_test: expected-type-pick / local-shadow /
  per-site tests -> collision red-controls + a binding-edge emission green
  control (fixtures preserved).
- type_env_scope_chain_test: local-shadows-imported -> collision red-control
  with sole-owner green control.
- pipeline: ambiguous_variant_name_resolves_correctly deleted (redundant
  with constructor_owner_ruling_test collisions);
  duplicate_variant_names_across_enums_dont_collide -> rule-4 witness
  (pattern-position arms resolve via scrutinee with ZERO constructor
  bindings; emitted match still owner-qualified).

Fixture hygiene:
- 6 files moved off std::env::temp_dir() to workspace target/ (12 tests;
  build_module_path_index fails closed outside the workspace — the
  union_resolve_receipts_test precedent, same class as the C1 fix).
- 9 pipeline wire-contract fixtures gain 'VariantNaming' in their
  std.serialization imports (SnakeCase & friends are its arms — the
  rule-(i) migration class, in fixture strings).

Suite: 626 passed / 28 failed / 85 ignored in 167s. All 28 remaining
failures are enumerated corpus-sweep work (integer.dag D1..D9, extdeps
github Pending + openai UrlCitation collisions, dag/std markup TextNode,
samsung.dag Gen3, target_model + src/v2 test-fixture bare-None sites) or
the stale release binary (interp_dry_run) — zero unexplained. They re-green
with the sweep commits, before regen.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Sweep wave 1 (regen-input closure): 3 census findings fixed

Patched-seed census over src/v1 + its dag closure (89 sources, 21s — the
same scope pre-fix was the 48-minute class) found exactly three violations:

1. dag/std/computation.dag: SizeBound.TreeSize collided with the imported
   RankingDimension.TreeSize in the module's own scope. Renamed the bound
   arm to SubtreeSize (the more precise fact — a tree-descent bound
   measures the shrinking subtree per step; rename fully contained in one
   file, SizeBound is imported by name nowhere else). RankingDimension
   keeps TreeSize (~12 sites in v1.complexity/std.induction).
2. src/v1/02_parse.dag constructed InternalError without importing it —
   previously resolved by the deleted whole-env scan (an undeclared-
   dependency fail-open, exactly the census class the ruling predicted).
3. src/v1/04_infer.dag used FieldNotFound without importing it (same
   class, in the compiler's own source).

Generated-seed counterparts of the SubtreeSize rename land at the regen
commit (all TreeSize references in stage0 are in generated files).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Sweep: markup TextNode collision + floor-closure unbound imports

Fragment.TextNode -> FragmentText (dag/std/markup.dag): Fragment and
MarkupNode both declared TextNode in one file, and
markup_node_to_fragment converted one to the other cross-owner via the
deleted expected-type pick. MarkupNode (the larger surface, ~15 consumer
files) keeps TextNode; the 5 Fragment-side consumers follow the rename
(std.markdown, extdeps languages/markdown, serializer witness, regime2
plan prose, medium-structure fixture).

Floor-closure unbound sites from the first CI run of #6235 (exactly the
census class - constructors resolved by the deleted scan without
imports): fleet_posix_accounts gains ConstructionMechanism
(SingleAuthority's owner); samsung + western_digital storage rows gain
PcieGeneration + NvmeFormFactor (Gen3/Gen4/M2_2280 owners).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* CI canary swap + constructor-owner red-control suite

The enrolled CI canary asserted the DELETED semantics (expected-type picks
the variant owner), so it is swapped for
github_merge_state_witness_test.dag :: witness_clean_and_blocked_are_distinct_variants
- small, pure, and exercises imported-variant construction through the new
binding-edge path (operator decision 3, 2026-07-04).

The retired canary fixture becomes the collision RED control: new
diagnostics_witness suite 'constructor_owner' (VariantCollision on the
two-local-owners fixture; UnresolvedType on an unbound constructor literal;
sole-owner green control), wired through the existing transport pair
(tools.diagnostics_witness_transport + test.claim.diagnostics_test).
variant_owner_expected_type_test.dag is deleted from the compiled tree -
its fixture is now illegal by design and lives on inside the red control.

Verified by execution: target/debug/diagnostics_witness constructor_owner
green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Sweep round 1 (10 parallel agents): 51 collisions renamed + 67 unbound sites imported across src/v2 + dag closures

The whole-tree census with the patched seed drove file-disjoint fix
groups; policy per operator decisions: bigger owner keeps the arm name,
smaller side renames along its distinguishing dimension; unbound
constructor literals gain their owner-enum import from the defining
module.

Collision renames (owners in parens keep the shared names):
- cache catalog twins: Catalog-side arms -> CatalogOpaqueStringKey /
  CatalogCasContentDigest / CatalogOpaqueStringEncoding /
  CatalogCasContentEncoding (std.cache_interface keeps); the
  catalog->std converter in extdeps/cache/cache.dag now reads
  per-side by scrutinee/produced type instead of the deleted
  expected-type pick; 5 cache witness suites green by execution.
- integer digits: NonZeroDecimalDigit arms D1..D9 -> NonZeroD1..D9
  (DecimalDigit keeps D0..D9); widen fn patterns renamed, constructed
  DecimalDigit results kept; subset-type modeling flagged as a §3
  follow-up rather than done ad hoc here.
- cpp_abi: singleton width enums' arms -> CppWidth8Fixed..CppWidth64Fixed
  (CppIntegerWidth keeps CppWidth8..64); per-model core-width arms ->
  CppILP32/LP64/LLP64/ILP64CoreIntegerWidthModel; anchor scalar ->
  SignedIntegerScalarAnchor (CppScalar keeps SignedIntegerScalar).
- language width models (rust, ptx, kotlin, java, go, swift): int-width
  enums keep BitsN; float/complex/ordered-ring/etc. sides renamed
  along their dimension (FloatBitsN, ComplexBits64, ...).
- effects + target_model: smaller-side renames per the same policy
  (WrappedReferenceLayerRc/Box on TargetReferenceLayerWrapped).

Unbound-import fixes: 30+ files across src/v2 (manual/execution/lens
test claims, std, compiler stages, program.dag, extdeps languages/
formats, workflow runner test) — each gains exactly the owner-enum
import its constructor literals need. Bare-None sites resolved per
expected type (enum arm import vs the lowercase optional keyword).

VERIFICATION (executable gate): whole-tree census re-run with src/v2
entries — 290 error lines before, 3 after, and all 3 are deliberate
red-fixture plants (parse-error + layering-scan plants, other walls'
fixtures). Zero constructor-ruling findings remain in src/v2 scope.
dag-root verification runs next alongside sweep round 2 (wave-2
findings: srv3 aggregate, same-file pairs, witness-test imports).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Sweep round 2 (4 parallel agents) + env-counter dissolution (unblocks regen)

Round 2 fixes the dag-tree census findings:
- srv3_os_install_diagnostic: 13 collision pairs resolved. The aggregate
  Srv3InstallDiagnostic KEEPS its arm names (larger use counts + owns the
  wire strings); sub-verdict copies renamed with the file's existing
  ...Verdict suffix convention (ReadyToBootVerdict, InstallerHungVerdict,
  OsInstalledVerdict, InconclusiveVerdict, ServePortAbsentVerdict,
  ServePortConflictVerdict, TokenMissingVerdict, IsoMissingVerdict,
  KvmWeakUntrusted) and OsInstallRuntimeDiagnosticVerdict's copies gain the
  Runtime prefix. All wire strings byte-identical.
- Same-file pairs: ReviewSource.Llm -> LlmSource (ReviewProvider keeps);
  ReviewEvent.Pending -> PendingEvent (ReviewState keeps the upstream-cited
  PENDING; not a wire event value upstream, so no cited string breaks;
  pipeline.rs wire-contract needle updated); OpenAI annotation UrlCitation
  -> ChatUrlCitation / ResponsesUrlCitation (both endpoints cited, zero
  uses, no wire-contract rows exist for these enums);
  ConvergeVerdict.Converged -> VerdictConverged (std Reconciliation keeps;
  fleet_show_effective_read's if-branch type mismatch was this collision's
  downstream shadow); workflow/types ArtifactKind.Design -> DesignDoc and
  OutcomeStatus.TerminalFailed -> OutcomeTerminalFailed (IssueLifecycleStage
  keeps both).
- Witness-test + gunbc/extdeps import batches: reviewer_source, hardware
  selection, transport fidelity (S/L/Xs size arms), pep440 (Ordering arms),
  uri path tokens, jedec/bmc/storage grounding rows, ci_render,
  gunbhub_serve, sk_hynix, transports file/rest/shell - each gains its
  owner-enum import from the defining module.

Env-counter dissolution (04_env.dag + 04_infer.dag): the 2026-07-04
pathology instrument's record_* statement calls and stub fns are deleted -
the pathology they measured is dead (900s-capped -> 1.14s), and they were
also the ONLY corpus instances of a statement-then-expression block the
Rust emitter renders without a separator. That emitter deficiency is why
regen has been silently broken since B1/B2 (whose commits hand-edited
generated files): the first regen probe failed parsing emitted
v1_compiler_infer_env.rs at exactly that construct. Getter stubs stay for
phase_profile API compatibility. Emitter statement-separator fix is
ledgered with the emit-stage work (regen probe: Rust emit completes in
~2 min, so C8 is time-feasible).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* regen_stage0: register phase_profile.rs as hand-maintained

The 2026-07-04 heartbeat module was added to stage0/src without a registry
entry, so --emit-fresh assembled a crate whose lib declares mod
phase_profile but carries no file (probe failure after the counter
dissolution unblocked emission). Its header carries its own dissolution
trigger (realization_measurement_loop Phase 0).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Rust emitter: shared_types dominates needs_box_wrapping (kills Box<Rc<T>> double-wrap)

A shared (Rc-rendered) type never needs Box - Rc is already the
cycle-breaking indirection. The old ordering short-circuited
recursive->Box before the shared check, which was benign only while
emit-time recursive_types stayed module-local; after B1's build_type_env
rework propagated imported recursive types, every Rc field of
Node/TypeEnv/PositiveDescentAmount/... double-wrapped, and regen output
stopped matching the committed seed ABI (596 of the 770 build errors on
the first regen attempt). This is one of the deficiencies that
accumulated while RegenVerifyGate was red-by-timeout: B1/B2 co-landed
hand-edited generated files because regen could not reproduce them.

Two-step: dag authority (05_emit_rust.dag) + functional hand-patch of the
generated emitter (v1_compiler_emit_rust.rs), replaced by regen's true
output in the convergence commit. Receipt: re-regen after the reorder
emits ZERO double-boxed fields (the only remaining Box<Rc grep hit is
this fix's own marker string); committed Box<ByteSize>-style non-shared
boxing (std_realization_schedule) preserved exactly.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Fix emitter-fix commit: restore hand-patched needs_box_wrapping (prior commit captured regen output)

The previous commit's v1_compiler_emit_rust.rs accidentally snapshotted
the REGENERATED emitter (regen write had overwritten the hand-patch
before the commit): the regenerated emitter carries the deref-side
boxing asymmetry and does not build. Restored the committed seed's
emitter with the shared_types-dominates reorder applied as intended.
Receipt: cargo build --workspace green on this commit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Resolver design: emitter restoration ledger (§7b) — regen was semantically broken on main

The constructor-ruling PR's regen attempt discovered RegenVerifyGate's
red-by-timeout had been masking semantic regen breakage (B1/B2 co-landed
hand-edited generated files). Three deficiencies fixed in this PR
(statement-separator emission via counter dissolution; needs_box_wrapping
shared-dominates reorder; phase_profile registry); three ledgered with
receipts for the restoration PR (deref-side boxing asymmetry ~800 errs,
alias-brand rendering ~250, misc ~80). Seed stays the functionally-verified
hand-patched realization until restoration lands.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Diagnostics: locate error-typed nodes reaching evaluation

Two instrumentation edits for the fail-open seam where an inference-side
error node reaches the interpreter without a blocking diagnostic:
- v1_interpreter (hand-maintained): ExprError eval errors now carry the
  node's span (file:start-end).
- infer field-access cascade (seed hand-patch, replaced at regen): names
  the accessed field, the error-typed base, and the module.

Receipt: the parse_table_memo failure went from 'error type cascade' to
'error type cascade (field class on error-typed base tok in
v2.compiler.parse) at src/v2/compiler/02_parse.dag:31281-31282' — the
open investigation for the 7 remaining interpreted-parse suite reds.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Fix two pre-existing silent compiler seams (interpreted-parse suite reds) + walls

Both located via span-instrumented errors, a 14-fixture minimal-repro
ladder, and pristine-main worktree A/B (both reproduce identically on
main; both classes were unverifiable there through the pre-fix resolve
timeouts).

1. Interpreter kernel-optional unwrap (hand-maintained v1_interpreter.rs):
   kernel optionals at runtime are raw-value-or-Null, and match_pattern's
   raw-payload unwrap guards (Present+Optional, Holds+Witness) sat BELOW
   the kind-specific arms - Value::Record/List/Str/Int matched their kind
   arm first and returned None from inside it, so
   'match xs |> first { Present { value: t } => ... }' failed
   non-exhaustive on any record element (Variant payloads had an inlined
   fix; everything else fell through). Guards hoisted above the kind arms;
   Variant payloads excluded so the existing Variant-arm logic stays
   authoritative.

2. Kernel-prelude generic shadowing (dag authority 04_resolve.dag +
   seed two-step in v1_compiler_infer_resolve.rs): for multi-import
   modules the ancestry cache merges the kernel as OVERLAY, so a user
   generic coproduct NAMED Optional (v2.std.collection) resolved to the
   paramless kernel Optional at its consumers; is_user_generic_use_site
   went false, Optional<T> signatures were never expanded/stamped,
   lookup_variant_in_type returned Blocked with ZERO diagnostics, and
   pattern bindings went error-typed silently - the 'error type cascade'
   at eval (import-count-dependent because single-import modules skip the
   kernel overlay). Fix is surgical: a use site WITH type arguments whose
   primary lookup lands on a paramless decl retries the DIRECT import
   parents' str_bindings for a parameterized decl (the params filter
   naturally excludes the kernel parent). The wholesale precedence flip
   (kernel-as-base) was tried and reverted - it broke kernel function
   dispatch through an unmapped path; ledgered for the restoration PR.

Receipts: parse_table_grammar_memo_multi_file_ingest_parses PASS (was
'error type cascade at 02_parse.dag:31281'); all 11 repro fixtures PASS;
new permanent walls in kernel_shadow_seams_test.rs (record-payload
unwrap; imported-Optional shadowing). Located-diagnostics kept: ExprError
eval errors now carry spans; the infer cascade names field/base/module.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Post-engine-PR roadmap: deferred ledger + compiler algorithm audit plan

Part A: the twelve items PR #6235 deliberately deferred, weighted -
emitter restoration -> regen convergence (§7b receipts), emit-stage cost
(the next resolver-class pathology, >20min/89 modules measured),
kernel-prelude shadowing root rule (wholesale flip blocked on the
unmapped kernel-fn-dispatch path), Value::Null split, flat-visibility
re-census decision, C9 receipts, determinism roster re-signing, binder
find-first hardening, diagnostics dedup, witness re-enrollment
dissolve-on, coverage-by-illusion census, resolver S2a/S2b/S3.

Part B: the algorithm audit method - every stage factored as units x
work-per-unit (the resolver failed both axes at once), inventory ->
verdict -> measure -> fix by displaced cost -> budget witness per stage.
Survey table lands from the eight-stage parallel inventory in flight.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Brace else-match in resolve_generic_use_decl (v1 grammar requirement)

The parents-retry fold used 'else match' without braces, which the v1
grammar rejects. Claim-path closures never parse src/v1, so only
resolve_expr_types_retraversal_guard_test caught it ("parse failed for
src/v1/04_resolve.dag"). Braced; guard test green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Fix interp_dry_run hermetic fixture: workspace target/, not /tmp

The failure was misdiagnosed as a stale release binary. Real cause: the
hermetic witness fixture was written to std::env::temp_dir(), and
build_module_path_index fail-closes on module paths outside the
workspace — same seam as the 7 test files already migrated; this one
was missed. Fixture now lives under workspace target/ like the rest.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Roadmap: record local full-suite green receipt (656/0/85)

Corrects the A.6 stale-binary diagnosis: the last two suite reds were
the resolve_generic_use_decl else-match brace and the interp_dry_run
/tmp fixture path, both fixed in the prior two commits.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Algorithm audit: 8-stage survey results + ranked fix order

Appends the survey synthesis to the post-engine-PR roadmap: 9
PATHOLOGICAL findings ranked with anchors (dag_collect Rc-accumulator
O(M^2) as the measured >20-min emit suspect; token-stream skip|>first
O(M^2) parse; whole-corpus rewire scan per name; per-entry closure
fixpoint regression vs the in-file worklist BFS; request-major
imported-variant binding; interpreter env chain O(d); v2 translate
facts/serialize quadratics; dead v2 packrat memo; v2 closure-chain
namespace), a SUSPICIOUS tier, six root-cause clusters, and a fix
order priced by displaced cost. Raw per-stage catalogs land as their
own receipt doc. Four top claims spot-verified against the live tree.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* rustfmt: format hand-edited interpreter guards + new test files

CI's cargo fmt --check flagged the hoisted match_pattern guard block in
v1_interpreter.rs, the fixture-dir join chain in
kernel_shadow_seams_test.rs, and the out-of-alphabetical-order mod
declaration in tests/lib.rs (rustfmt reorders modules). cargo fmt --all
applied; fmt --check, clippy -D warnings, and the seam tests verified
green locally. Also enabled the repo pre-push hook path in this clone.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

* Fold hand-edited doc content into dag authorities; main_wet regen green

C9 item: main_wet regen + drift gate. Three findings, all fixed at the
authority layer, not the projection:

- PR #6186 added §11 (folded deltas) to the generated
  bounded-input-cost-envelope-scheduling.md without updating its dag
  authority — a parallel-representation slip the drift gate caught on
  this branch's first hooked push. §11 is now authored in
  dag/gunbc/plans/bounded_input_cost_envelope_scheduling.dag and the
  projection regenerates identically to the signed content.
- regime2-shared-emission-fold.md regenerates with FragmentText (this
  branch's markup collision rename), ROADMAP.md with normalized tail.
- Doc-graph orphans: linked the post-engine deferred-ledger/audit
  roadmap from the CI lane's receipts prose (survey receipt doc is
  reachable through it), and linked docs/plans/host-converge-inventory.md
  (orphaned since #6177 — no inbound link anywhere on main) from the
  converge-lane prose.

Receipts: PASS main_wet, PASS run_generated_artifact_drift_gate_body,
PASS doc_graph_has_no_orphan_docs, PASS doc_graph_has_no_dangling_links.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DcouXUHJmm4NPqwDyvnDKf

---------

Co-authored-by: Claude <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 5, 2026
…tirement path (delete-mass triage) (#6272)

* pipeline.rs self_gen8 cluster: retire 28 of 31 fns (typed dispositions; 3 kept for def-unification lane)

Delete-mass triage of the self_gen8 cluster per the test_migration_debt drain
(#6261 retirement path). Ground truth measured 2026-07-05 via
cargo test -p v1-compiler-tests self_gen8 -- --include-ignored: 22 passed,
9 failed - 8 of the 17 #[ignore]d fns carried stale red-on-main reasons and
pass on main today.

- 22 green fns -> DeleteRedundant: seed-corpus pattern families (homonymous
  type names, variant-specific imports, kernel-ambient types, direct type
  imports) are byte-pinned by RegenVerifyGate (regen_stage0 --verify, #5873)
  plus the emitted-seed rustc/clippy gates; beyond-corpus synthetic shapes
  (parametric-alias RHS, opaque parametric decls, proxy chains, wildcard
  imports) are executed by the v2 self-host fresh-emit lane over dag/std's
  real instances with deficits enumerated in the 1667-error receipt
  (#6253/#6258). An #[ignore]d pin runs in no gate - zero delivered signal.
- 6 red fns -> DeleteLowValue: #[ignore] since #5427, never run in any gate,
  desired-but-absent seed-emitter behavior on synthetic fixtures; deficit
  ownership is the fresh-emit lane.
- 3 red fns KEPT (stays_unemitted alias-to-opaque trio):
  dag/gunbc/plans/dag_v2_defork_audit.dag claims them for the def-unification
  lane (node://adhoc-9d2bb9c3-e7b) - premise flips, not deletes.

Typed receipt: dag/test/retirement/pipeline_self_gen8_retired.dag (two
TestModuleRetirement rows). Receipt-only w.r.t. the delete-guard - the
contributed stem pipeline_self_gen8 matches no v1 test file and pipeline.rs
itself survives, so its eventual file deletion still requires its own
coverage.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Repoint kept trio's #[ignore] reasons to their owning lane (def-unification, node://adhoc-9d2bb9c3-e7b)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant