Repository navigation
warm==cold cache purity detective (§2 P1) - #5429
Conversation
…ize kernel
The §5 caching-via-realization principle made executable: a content-keyed
realization promises output = f(declared key inputs); an input read at realize
time but absent from the content-key makes a WARM hit serve a stale result a
fresh COLD recompute would no longer produce. The cache IS the purity falsifier.
- extdeps/realization/cache_purity.dag — CachePurityVerdict carrier (Pure |
Impure{located violation naming the read-but-unkeyed axis}); the durable
artifact v2 inherits. Discovery witness in dsl/test/claim.
- cache_purity_oracle.rs — v1 proving handler: audit_warm_equals_cold holds the
content-key fixed, perturbs candidate hidden inputs, and raises a located,
typed, LOUD CachePurityViolation on divergence (fail-closed). Probes that move
the key are declared axes (a miss, not a stale hit) and are skipped.
- cache_purity_oracle_test.rs — discriminating witnesses (DESIGN §5
spec-without-execution): REAL kernel warm==cold byte-identical round-trip +
real realization PURE under non-keyed probes (green by execution) PLUS an
injected hidden non-keyed input that goes RED with the loud located error.
ROADMAP §2 P1. Consumes subject_digest_for_closure (no re-fork of #5425's key).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…t-shrinkage receipt Review (claude-opus-4-7, APPROVE) soft concerns: - predicate-dissolution: cache_purity_is_pure was a Bool restating the CachePurityVerdict coproduct. Deleted it; consumers (and the witness) match the verdict directly so the located violation stays in hand on the Impure arm. - §7 hand-Rust receipt: added an explicit SCAFFOLD dissolve-on trigger to the oracle module header (net-new capability bound to the v2 realize-fold fixed point, ROADMAP §2 P5), matching the codebase's named-dissolution convention. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Thanks for the review — both soft concerns addressed in d3bde56:
— sent from stern-otter-43 |
…e dir) Review (claude-opus-4-7) valid non-blocking finding: real_resolved_graph_realization_is_pure_under_nonkeyed_probes took CACHE_ENV_MUTEX but never isolated GUNBC_RESOLVED_GRAPH_CACHE_DIR, so a host with that var set could leak into the test. Replaced the bare mutex lock with CacheEnvGuard::set(temp) — which both isolates the cache dir and serializes the env-var probe — matching tests 1 and 3. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Addressed in af3500a:
— sent from stern-otter-43 |
|
Verified — this review is APPROVE with Findings: none; the cited lines (cache_purity.dag:50-53, cache_purity_oracle.rs:19-23, the test refs) all match the current head af3500a, so it is reviewing the latest code. The dashboard registers it as an approval (request_changes: 0, has_request_changes: false, mergeable: MERGEABLE) — the 'BLOCKING REVIEW' relay header is a misclassification, not a request-changes. Nothing to fix; no commit needed. — sent from stern-otter-43 |
…+ deferred handler binding (dsl->v2 de-fork, not #5429) Per mgr review of #5455: a modeled key with zero production caller is the declared-but-dead fork P2 kills. Mark the production consumer (the imminent v2-local fold-rewire) and the deferred std-kernel handler binding with its named dissolution trigger (the dsl->v2 cross-tree de-fork, explicitly NOT #5429). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…O + P2 de-fork-dependent, §0 census regression + gate-hygiene Reflects decisions/findings that landed 2026-06-21: - §1: the "expensive" tests were debug-build amplification, not intrinsic seed cost (proud-deer cause-table); opt-level=3 (#5456) restores Pop-A to per-PR; nightly lane reduced to Pop-B wet-captures only. Mirror corrected in §0. - §2: resolve-cache enable = GO (~18% floor-wall, purity-proven, #5429-gated); P2 ParseTable dissolution reclassified as a downstream consumer of the dsl→v2 de-fork (keen-otter: v2-local rewire is cosmetic); #5446 realize kernel green. - §0: stage0 clone-census ratchet went inert + the seed regressed 1138 over budget (rust-side coverage-by-illusion + thesis regression; #5427 surfaced it); gate-hygiene rule (floor-enrolled gate must be green-on-main at merge) + roster-completeness assertion promoted to should-land (the #5445 floor-skew). - §1: registry-partition instance fix = #5452 (verified sound). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…gestion⁻¹ past syntax (#5442) * WIP: dsl -> v2 scoping * WIP: ROADMAP planning * WIP: ROADMAP planning * WIP: ROADMAP planning * ROADMAP: scannable dependency-ordered checklist; consolidate caching plan (de-fork zesty-deer-479 owner, absorb quick-ant-298 spine) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * self-host: add bootstrap purity (no stage0 hand-edits / regen-lockstep keystone) + precise v1 cutover Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP §0 fail-closed lock-down (blocks expansion) + audit doc; §4 website demo Audit: cache lossy-digest flake (resolved_graph_cache.rs:146, verified), ~inert analytical lenses (complexity/cost/etc), regen --verify unwired (#5325). Lock-down checklist gates expansion. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP: flesh §2 idea->idea compiler (medium/language axes); §0 → lock-down LANE (audits→fixes→meta), name model<->realization fork as suspected root Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * lock-down: add CI-coverage-completeness audit (rust gate runs 3 of 60 v1 suites) + axiom/syllogism lens (DESIGN open thread #1 — lock down the reasoning) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * roadmap §0/§7 + lockdown: lead with correctness-by-construction, demote lenses to residue Folds in the operator principle (relayed via quick-ant-298): a lens is validation — it concedes the bad thing is writable. Root-cause to make it unwritable (single authority / realization derived from model); reserve lenses for the genuinely- unstructurable (complexity/necessity). #5423's spec-only key lens shipped a false-green as the live proof. - ROADMAP §0: add the principle; split Fixes into tier-1 construction (dissolve model↔realization fork; cache-key derived-from-declared-inputs; self-host purity by construction) and tier-2 lens (complexity/cost; cache-redundancy; purity oracle; promote-inert). Meta-invariant → construction-justification rule. - ROADMAP §7: P1 cache-key reframed from 'realizer-key lens' to key derived from declared inputs_considered (construction). - fail-closed-lockdown.md: construction principle in the thesis; §4 checklist re-ordered construction-first / lens-residue; meta = construction-justification. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * roadmap §0: add Disposition carrier + 'confront skipped modeling decisions' Captures the lens/coproduct disposition decision (operator). One typed carrier (Terminal{reason} | Scaffold{dissolves_to}) for BOTH lens-lifecycle tags AND coproduct dissolve-markers — today freeform 🟡 comments, unreadable by lens since comments aren't Nodes. Decision: middle path (construction-capable carrier + selectively-enforcing lens that ratchets coverage) now, #1 (substrate can't-define-untagged) as the named end-state. The lens is itself a Scaffold{dissolves_to: substrate-mandatory-tag} — self-dissolving when coverage = whole tree. Rejected jumping to #1 on sequencing (load-bearing §4 substrate change → escalate; flag-day migration; derived coproducts need disposition derived not authored), not on principle. Enforceability split: presence = construction (non-optional field, no meta-lens); redundancy (scaffold + successor both present) = hard gate; Terminal-vs-Scaffold correctness = retro/judgment (synthesis-feasibility limit). - docs/plans/disposition-carrier.md (new) - ROADMAP §0 tier-1 + meta 'confront skipped decisions' standing practice Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * DESIGN §5/§6: promote construction-over-validation; roadmap: scope-partition §0, testgen §1, shelve dashboard Addresses the review's four flags + sequencing nuance. - DESIGN.md §5: 'correctness by construction, not validation' is now an axiom (a check re-stating a model constraint is a 2nd representation §2/§3; prefer realization derived from a single authority; reserve checks for the unstructurable residue). §6 'enforce with lenses' reconciled: construction first, lens = residue mechanism, AND the executable inert-lens backstop is NOT superseded by the authoring-time construction-justification judgment. (flag 4 home + flag 3) - ROADMAP §0 partitioned: In-scope this window (numeric-tower grounding; cache trustworthy + warm==cold oracle shipped NOW as detective; widen rust gate; promote inert lenses) vs Fenced-OUT fan-out (Value::Null 131-site split; self-host purity gate; cross-tree import activation; Disposition carrier). Honest framing: window reduces fail-open surface, does NOT 'lock' the class — Null split stays open. (flags 1, 2, sequencing nuance) - ROADMAP §0 meta: restored executable inert-lens hygiene backstop, construction- justification layered on top (not 'supersedes'). (flag 3) - De-dup: principle no longer restated in ROADMAP/lockdown §0; both point to DESIGN §5. cache-key construction homed in §7, §0 references it. (flag 4) - ROADMAP §1 = testgen as bug-class oracle (+ affected-set completeness half + parked anemia lens); dashboard shelved to §8. - docs/plans/testgen-oracle.md (new), fail-closed-lockdown.md realigned. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * DESIGN §5/§6/§7: wall-vs-ratchet decidability, displaced-pain denominator, open language design Folds in the operator's product thesis + the two bounds that keep it honest. - §5: construction makes a class unwritable only when membership is DECIDABLE — trichotomy (wall now / wall after grounding / ratchet forever); 'never' is the trap (lets an undecidable ratchet masquerade as a wall — optimality by Rice). - §6: denominate the benefit — the deliverable is a displaced cost (§1 time / a paid-for pain), the lens/substrate is the moat not the product; priced in elegance the work is unbounded (the economic twin of 'never'). - §7: the recursion's payoff — language design itself opens up. It's locked by cost (a check = a compiler fork; a language = an adoption problem); both dissolve here (a wall is a row §2, applied over a medium-agnostic substrate §4), so (compiler-fork × language) → (row + medium). Sound where ingest is Lossless, fail-closed where not (DecodeFidelity §4). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * ROADMAP: fix doc-graph violations from bright-eagle-46 review of #5424 Apply the apex axiom/syllogism lens (single authority / no orphan / no cycle) to the roadmap itself — manual acyclicity pass: - orphan: testgen-oracle.md backlinked §1 → repoint §4 (its own lane) - single authority: §0 cache-key now a pure pointer (= §2 F2/F3/P1); §0 numeric-tower marked the authoritative home (§5 de-fork / fork plan point here, no second checkbox) - §0↔§5 cycle: self-host purity reframed as a §5 deliverable §0's expansion-gate depends on (edge §5 → §0-gate → products), not §0-owned - undeclared edge: §7 react/html declares its dependency on §6 media - backlink sweep: the reorg had broken every numeric backlink across 7 plan docs; re-point all and anchor each to the stable section TITLE so a future renumber can't silently break them again Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP §3 + plan: algorithmic-cost reduction by construction (rewrite, not budget) Reframe §3 from per-fn complexity budgets to the actual intent: rewrite common suboptimal patterns (O(n²)→O(n), O(2ⁿ)→O(n), O(n)→O(log n)) to the cheaper equivalent — construction on the cost axis, not a warning. New plan doc docs/plans/algebraic-rewrite-optimization.md captures the up-front design: the decidability split (modeled EffectShape makes the preconditions structural; equivalence stays undecidable so no optimality oracle), rewrite-rule-as-row + once-proven soundness, the common-case catalog tiered by precondition, D1 canonical-form-is-truth / D2 two seed rules / D4 constant-factor deferred, the four-witness DONE bar (incl. the non-firing control half-done versions skip), and a corpus hit-rate acceptance gate. complexity.dag is the cost oracle; synthesis.dag stays the advisory undecidable residue. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP §2: Phase-0 measurement instrument done (#5431 peak-RSS) — remaining is the Phase-1 consumer Per quick-ant-298: the measurement keystone was nearly complete — model side already floor-enrolled, step timing already emitted; the only gap was peak-RSS, closed by #5431. P4's Phase-0 dependency is satisfied; remaining is the Phase-1 measured->plan feedback + width-fold (also unblocks §1-C). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * plan/§3: detection-vs-enforcement containment (E⊆D′⊆D) + explicit seed-rule I/O up front Grounded in cost.dag U2 + complexity.dag (investigated, not theorized): - detection is TOTAL by construction (kernel-level cost fold; arbitrary fns detectable); boundary is precision (ClassUnknown), not coverage - enforced rewrites are a strict subset structurally guaranteed by the class-drop witness: E ⊆ D′(precise) ⊆ D(all) - n√n excluded for a MODEL reason (PolynomialDegree is integer-only, n^1.5 unrepresentable); ternary search excluded (log base is not a class) - today's small gate roster = subject-production limit (fn-body reflection), NOT a detection limit - new §3a fully specifies the two seed rules up front: input→output→ precondition→non-firing control→discriminating equivalence input, so the worker builds to spec and the project can actually finish Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP §0/§1: rust-gate is cadence-decoupling, not run-all (per fierce-hawk #5427) The 3-filter allowlist was COST selection, not arbitrary gatekeeping — the v1 SEED compiler costs ~tens of CPU-sec per trivial test, so run-all-per-PR is CPU-hours (off the table). True shape: per-PR cost-bounded subset + measured #[ignore="expensive: Ns"] + completeness lens (#5427); nightly --ignored lane as the destination for expensive + the 58 currently-ignored tests (owned by §1/quick-ant, after #5431, escalate for load-bearing CI-gen). Completeness = every test runs on >=1 cadence (fail-closed). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * plan §2a: generalize by structural-redundancy keying (O(n^x)->O(n^(x-1)) free); flag n-log-n as substitution Per operator: catalog must generalize polynomial-degree reduction without edge cases. Resolution: rules key on the structural redundancy, never on degree — degree is not evidence of redundancy (would fire on genuine O(n^x)). A structurally-keyed nested-membership->set peels one level wherever it matches; fold-to-fixpoint gives O(n^3)->O(n^2)->O(n). Cost model supports arbitrary integer degree, so witness (b) holds at every peel. Flagged OPEN (operator input invited): O(n^x)->O(n log n) is algorithmic SUBSTITUTION (different algorithms, same I/O) not redundancy elimination — verges on undecidable equivalence; tractable form is per-idiom rules (sort-based dedup, repeated-min->heap), not a parameterized rule. Seed Rule 1 now authored structurally + carries a depth-2 generalization witness. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * plan §1b: Unknown is an anemic atom — dissolve over time (reuse Disposition), never a false pass Per operator: classifying Unknown isn't a fixed up-front split — it's the standing anemic-leaf dissolution practice (DESIGN §2 decompress->map->reduce) applied to the cost lens. UnknownCost{diagnostic} already carries its reason; the anemia is the free-form reason. Each decomposition resolves an Unknown to construction (now-precise class -> new D′) or a grounded Terminal (genuinely undecidable, positively recognized -> advisory comment). DFS-first: this IS the Disposition carrier (resolves to construction-or-justified-Terminal), so reuse it, don't fork an unknown-reason enum. Supersedes the static Undecidable|Undetermined split. Two invariants fixed up front: never a false pass (Unknown=>Violates, already holds); every Unknown on the dissolution frontier. cost.dag enrichment + un-parking Disposition are operator-gated. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP: §3 reverts to budget-gate validation (stability); rewrite-engine relocated to §5 (post-stability) Operator decision 2026-06-21: budget-gate validation is fine for the stability window; the algorithmic-cost REWRITE construction design is expansion, homed with self-hosting (§5) — IR-rewrite/canonicalization is most natural once .dag is the self-hosted truth. - §3 = complexity budget gate (validation): cost-lens symbolic_max fix (#5437) + per-fn subject + budget-gates-whole-codebase (gated on fn-body reflection) + synthesis advisory. #5437 foundation stays in-window. - §5 gains an 'adjacent expansion lane' = the rewrite engine, pointing at the preserved plan doc; marked post-stability. - plan doc status -> POST-STABILITY EXPANSION, relocated to §5. Nothing deleted — the rewrite design is preserved, just fenced out of the stability window (same as Disposition / Value::Null-split). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * #5442 review fix (warm-lark-306): grep-as-authority for the sidecar roster (10 not 9) The §0-guard impl PR (#5445) grepped current main and found 10 importers of extdeps.languages.bash.program, not 9 — the 10th (dsl/gunbc/ci_spec.dag) landed via #5432 after the original pre-merge grep. Rather than bump the frozen count, make the live grep the authority (the roster shrinks to 0 as the bash-sidecar arc migrates consumers, so any frozen number rots — the single-authority point). Also note the two *_test importers are intentionally not walled (guard scans consumer-source roots only). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP: check off 6 merged items (catch-up sweep) Flip [ ]→[x] for unambiguously-merged work (PR-ref'd for traceability): - §0 numeric-tower grounding (#5428 — == straddle guard dead-in-corpus) - §0 inert-lens hygiene executable backstop (#5433) - §2 F2/F3 resolved_graph key derived from inputs_considered (#5425) - §3 cost-lens symbolic_max zero-absorption fix (#5437) - §4 gate existing generated testgen output (#5434) - §4 affected-set completeness (#5430) Partial/compound items left for their lane managers to flip in the PR that completes them. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP §1: add compile-clean-gate force-checks-every-fn-body box (2(ii) fail-open) New floor-coverage item: the compile-clean gate is fail-open — unreached fn bodies escape typecheck, so undefined symbols in dead code pass green (execution-proven on utf8_decode_bytes). Construction fix = typecheck total over every declared body. Owned by §1 (quick-ant); measure-first, operator-gated enforce-flip. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ROADMAP §0: correct the 2(ii) box — registry-leak mechanism, not unreached-bodies snappy-gull's deeper diagnosis: the fail-open is NOT unreached bodies (bodies ARE visited). utf8_decode_bytes resolves because it's a global builtin_function_registry entry (04_method.dag, a marked bridge scaffold) not scoped to the compiled tree. Reframe the box to tree-scoped builtin availability / registry partition; instance fix = real std fn + remove the registry bridge entry. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * plan doc: enforcement roster is a FROZEN grandfather set, not derived (warm-lark correction) Deriving the realization-vocab exception roster from a live grep would make the guard vacuous (leak = non-edge importer AND NOT-in-roster; derived roster ⇒ every importer always in it ⇒ leak_count always 0 ⇒ never fires). Distinguish the informational prose count (rots, re-grep) from the lens's enforcement roster (frozen, so a new unrostered importer goes RED = the teeth). Add the 11th importer (extdeps_external_authority_transport, the #5418→#5445 race, fixed by #5453) and the roster-completeness assertion as the steady-state race-hardening. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ROADMAP planning * ROADMAP refresh: §1 nightly→Pop-B (opt-level won), §2 resolve-cache GO + P2 de-fork-dependent, §0 census regression + gate-hygiene Reflects decisions/findings that landed 2026-06-21: - §1: the "expensive" tests were debug-build amplification, not intrinsic seed cost (proud-deer cause-table); opt-level=3 (#5456) restores Pop-A to per-PR; nightly lane reduced to Pop-B wet-captures only. Mirror corrected in §0. - §2: resolve-cache enable = GO (~18% floor-wall, purity-proven, #5429-gated); P2 ParseTable dissolution reclassified as a downstream consumer of the dsl→v2 de-fork (keen-otter: v2-local rewire is cosmetic); #5446 realize kernel green. - §0: stage0 clone-census ratchet went inert + the seed regressed 1138 over budget (rust-side coverage-by-illusion + thesis regression; #5427 surfaced it); gate-hygiene rule (floor-enrolled gate must be green-on-main at merge) + roster-completeness assertion promoted to should-land (the #5445 floor-skew). - §1: registry-partition instance fix = #5452 (verified sound). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…y backfill (fleet-red keystone fix) (#5465) #5429 added the cache_purity module but did not register it in external_authority_backfill_pending.txt (its 4 realization siblings are listed), so #5418's live-clean-tree lens fail-closes — fleet-wide main-red since cdd1421 (#5429); prior commit ac9a7e7 (#5449) was green. Same floor-skew class as #5445/#5453. One-line backfill anchor; diagnosed by bright-stag-194, delegated by sunny-bee-667 (lane owner) for the urgent fleet-unblock. Also unblocks stern-otter's P3 branch. Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…rity.dag (#5464) Co-authored-by: Brian Searls <briansrls@gunb.ai>
… handler-bind deferred (#5455) * WIP: §2 P2 one-door realize(subject) sole cache API; dissolve hand-rolled Par * P2 phase-2 design: ParseTable content-key (realize subject) model DESIGN-FIRST (model-before-implement). parse_table_subject folds the table scope (grammar_digest × token_stream_digest) with the cell coordinate (position × production) into one content hash, reusing v2.std.node combine_hash / byte_limb_hash_peano_digest / atom_identity_hash (no fresh hashing authority). This re-keys the positional {position, production} cell key onto a content-addressed realize subject. MODEL ONLY: derives the subject; does NOT route lookup/insert/the parse fold through it (that cementing is held — escalate first). Binding to the std realize kernel (ArtifactIdentity / realize_route) is blocked on the dsl→v2 cross-tree import. Green-by-execution: parse/parse_table_content_key_test.dag — deterministic + 4 per-component discriminating witnesses (drop any of grammar/token-stream/position/production from the fold and the matching witness goes red; verified by perturbation). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * P2 phase-2: name parse_table_subject consumer (imminent fold-rewire) + deferred handler binding (dsl->v2 de-fork, not #5429) Per mgr review of #5455: a modeled key with zero production caller is the declared-but-dead fork P2 kills. Mark the production consumer (the imminent v2-local fold-rewire) and the deferred std-kernel handler binding with its named dissolution trigger (the dsl->v2 cross-tree de-fork, explicitly NOT #5429). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * P2 phase-2: correct parse_table_subject marker to deferred-consumer (rewire collapses into de-fork handler binding) Per mgr DEFER decision: P2-A v2-local rewire collapses into P2-B. The v1 host is the SOLE parse-memo authority (the .dag entries map is vestigial), so a v2-local host re-key now would trade a collision-free structural tuple for content-hash collision risk (§5) + re-derive the fold in Rust (more §3 host surface) for zero pre-de-fork benefit. The SOLE consumer is the deferred std-kernel handler binding (named trigger = dsl->v2 de-fork); no premature rewire. Honestly-marked deferred-consumer model (defined consumer + named trigger), not a dead fork. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…he 3× fleet-red) Pins the 3× fleet-red to stale-green (PR validated against a pre-gate base, merged without re-validating current main) via the #5429 timeline receipts; ranks the merge-policy fixes (merge-queue >> require-up-to-date under the approval outage); scopes neat-ibex's reverse-staleness lens as complementary, not the 3×-red killer. Decision record for the operator's merge-policy call. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…he 3× fleet-red) (#5474) * WIP: ci is slow investiation * docs/plans: ci-merge-freshness decision record (stale-green root of the 3× fleet-red) Pins the 3× fleet-red to stale-green (PR validated against a pre-gate base, merged without re-validating current main) via the #5429 timeline receipts; ranks the merge-policy fixes (merge-queue >> require-up-to-date under the approval outage); scopes neat-ibex's reverse-staleness lens as complementary, not the 3×-red killer. Decision record for the operator's merge-policy call. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
… coverage keystone) (#5526) * WIP: ci is slow investiation * docs/plans: ci-merge-freshness decision record (stale-green root of the 3× fleet-red) Pins the 3× fleet-red to stale-green (PR validated against a pre-gate base, merged without re-validating current main) via the #5429 timeline receipts; ranks the merge-policy fixes (merge-queue >> require-up-to-date under the approval outage); scopes neat-ibex's reverse-staleness lens as complementary, not the 3×-red killer. Decision record for the operator's merge-policy call. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * docs/plans: scoped edge-(b) brief — rust-test↔consumed-.dag provenance (the §1 coverage keystone) Scoping artifact for the operator greenlight call. One declared fact (rust-test→ consumed-.dag closure on the existing NodeArtifactProvenance carrier) read in two directions: FIRE-when-consumed (coverage wall, fail-closed) and SKIP-when-unaffected (affordability selector) — DESIGN §4 one grammar both directions. Shared testgen-reflection blocker; first vertical slice; honest multi-day estimate. Build HELD for operator nod; decoupled from #5427. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * docs/plans: edge-(b) brief — fold in the coverage-completeness asymmetry (closure ⊇ reads) bright-stag's load-bearing sharpening: coverage (fire-on-change) is fail-OPEN to under-declaration (declaration drift re-opens the .dag→rust hole), while affordability (skip) is fail-safe to over-declaration. So (1) the completeness lens must check closure ⊇ actual-.dag-reads (CORRECTNESS), not mere presence — presence is the §5 faked-cache-key trap; (2) structural closure discovery IS the soundness, not optional polish — a hand-authored closure is the §3/§5 fork that silently re-opens the hole; (3) slice-1 must state whether its closure is structurally derived (proves the wall) or hand-listed (proves only the wiring). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * ROADMAP: anchor the edge-(b) keystone brief from the rust-gate-coverage item (doc reachability) The new docs/plans/edge-b-rust-dag-provenance-brief.md was an orphan doc → the floor witness doc_graph_has_no_orphan_docs (dsl/test/claim/doc_reachability_witness_test.dag) RED on #5526. Fix per the rule (every docs/**/*.md reachable from a ROADMAP/DESIGN root): add a terse pointer on the existing §1 rust-gate-coverage line, its correct semantic home — edge-(b) is the .dag→rust coverage wall that #5427 (the .rs-hole-closer) does not close. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * ROADMAP: trim edge-(b) line 36 to short summary + status (bright-stag refinement) Per the operator short-lines rule (bright-stag enforces): move the mechanism density (rust-test↔consumed-.dag closure, fail-closed both directions) into the brief; keep the ROADMAP line a short scannable summary + pointer + explicit no-overclaim status ('SCOPED / pending operator greenlight'). Build is NOT greenlit; the line now says so. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
…ak (per-job placement divisor) (#5574) * WIP: ci is slow investiation * docs/plans: ci-merge-freshness decision record (stale-green root of the 3× fleet-red) Pins the 3× fleet-red to stale-green (PR validated against a pre-gate base, merged without re-validating current main) via the #5429 timeline receipts; ranks the merge-policy fixes (merge-queue >> require-up-to-date under the approval outage); scopes neat-ibex's reverse-staleness lens as complementary, not the 3×-red killer. Decision record for the operator's merge-policy call. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * docs/plans: scoped edge-(b) brief — rust-test↔consumed-.dag provenance (the §1 coverage keystone) Scoping artifact for the operator greenlight call. One declared fact (rust-test→ consumed-.dag closure on the existing NodeArtifactProvenance carrier) read in two directions: FIRE-when-consumed (coverage wall, fail-closed) and SKIP-when-unaffected (affordability selector) — DESIGN §4 one grammar both directions. Shared testgen-reflection blocker; first vertical slice; honest multi-day estimate. Build HELD for operator nod; decoupled from #5427. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * docs/plans: edge-(b) brief — fold in the coverage-completeness asymmetry (closure ⊇ reads) bright-stag's load-bearing sharpening: coverage (fire-on-change) is fail-OPEN to under-declaration (declaration drift re-opens the .dag→rust hole), while affordability (skip) is fail-safe to over-declaration. So (1) the completeness lens must check closure ⊇ actual-.dag-reads (CORRECTNESS), not mere presence — presence is the §5 faked-cache-key trap; (2) structural closure discovery IS the soundness, not optional polish — a hand-authored closure is the §3/§5 fork that silently re-opens the hole; (3) slice-1 must state whether its closure is structurally derived (proves the wall) or hand-listed (proves only the wiring). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * ROADMAP: anchor the edge-(b) keystone brief from the rust-gate-coverage item (doc reachability) The new docs/plans/edge-b-rust-dag-provenance-brief.md was an orphan doc → the floor witness doc_graph_has_no_orphan_docs (dsl/test/claim/doc_reachability_witness_test.dag) RED on #5526. Fix per the rule (every docs/**/*.md reachable from a ROADMAP/DESIGN root): add a terse pointer on the existing §1 rust-gate-coverage line, its correct semantic home — edge-(b) is the .dag→rust coverage wall that #5427 (the .rs-hole-closer) does not close. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * ROADMAP: trim edge-(b) line 36 to short summary + status (bright-stag refinement) Per the operator short-lines rule (bright-stag enforces): move the mechanism density (rust-test↔consumed-.dag closure, fail-closed both directions) into the brief; keep the ROADMAP line a short scannable summary + pointer + explicit no-overclaim status ('SCOPED / pending operator greenlight'). Build is NOT greenlit; the line now says so. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: ci is slow investiation * fmt: rustfmt the cgroup-peak measurement additions (claim_executor) The hand-written binding_cap_cgroup_dir / cgroup_peak_pids_at_binding_ancestor / sccache_server_cgroup_rel helpers were not rustfmt-clean; this only reflows them. No logic change. Fixes the rust_tests fmt failure on the held draft #5564. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * CI measurement: rust_tests-job leaf cgroup peak + --measure-cgroup-peak (per-job placement divisor) Second half of the whole-tree CI memory measurement (companion to #5564's ci-job emit): a claim_executor --measure-cgroup-peak standalone mode + a rust_tests-job ci.yml step that calls it, so the rust_tests job (the binding ~16-23 GiB per-job constraint, measured live on srv1) emits its own cgroup peak. Corrects #5564's cap-ancestor read for the real fleet. Live srv1 inspection (operator-granted) shows the runner units run MemoryMax=infinity (UNCAPPED), so binding_cap_cgroup_dir returns None and the cap-ancestor read emits "unavailable". The measurement now reads memory.peak at the LEAF runner cgroup (the ephemeral per-job cgroup, always present) and reports capped-vs-uncapped + host MemTotal. One walk, all reads (single authority): the emit line carries memory.peak (usage) + memory.max (budget, =uncapped on the fleet) + host_ram + pids.current/max + the sccache server cgroup classified descendant-vs-sibling (the "accounted exactly once" decision) — consumed by the compile-jobs divisor (#5546) and the placement model (#5559). Stacked on #5564 (reuses its binding_cap_cgroup_dir / sccache scan). ci.yml regenerated via main_wet; drift gate green; fmt + clippy -D warnings + release build clean; --measure-cgroup-peak verified by execution. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Review fix (#5574): path-component prefix for sccache descendant check claude-opus-4-7 flagged that sccache_under_leaf used a bare string prefix, so a sibling like <leaf>-other.service would misclassify as a descendant (under-counts host_fixed_overhead — the fail-OPEN direction). Compare on path components: leaf itself, or a strict <leaf>/ prefix. Comment updated to match. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
warm==cold cache purity detective (ROADMAP §2 P1)
Makes the DESIGN §5 caching-via-realization principle executable: a cache that
changes a verdict is not a cache bug, it is a purity bug the cache exposed. A
content-keyed realization promises
output = f(declared key inputs). If an input isread at realize time but absent from the content-key, a WARM hit (addressed by the
now-stale key) serves a result a fresh COLD recompute would no longer produce:
warm != cold. So the cache IS the purity falsifier — this oracle makes that falsifier run.
What lands
dsl/extdeps/realization/cache_purity.dag—CachePurityVerdict = Pure | Impure { violation }carrier; the violation LOCATES the read-but-unkeyed axis. The durable artifact v2 inherits
(the Rust below is the §7 proving handler). It is the run-side twin of
extdeps.cache.key_completeness(the declare-side lens): both ends of one authority, the content-key.src/v1/stage0/src/cache_purity_oracle.rs— the oracle.audit_warm_equals_coldholdsthe content-key fixed, perturbs candidate hidden inputs, and raises a located, typed, LOUD
CachePurityViolationon divergence (fail-closed, never a warning). A probe that moves thekey is a declared axis (a miss, not a stale hit) and is skipped — no false positive on keyed inputs.
Discriminating witnesses (DESIGN §5 spec-without-execution — green by execution + a RED)
resolved_graph_cache::{lookup,write}path — a cold computethen a warm hit are byte-identical after canonicalization; and the real resolve realization is
PURE under probes the key legitimately ignores (unrelated env var / non-imported sibling file).
key) → the oracle raises the loud located error naming the axis. Without it, the green cases pass
vacuously. Also proven RED-on-revert for the
.dagcarrier (inverting the verdict flips the witness).Coordination
Consumes the public
subject_digest_for_closure(the from-inputs key); does not re-fork #5425'skey derivation. Purely additive (1 new
.dagcarrier, 1 new.dagwitness, 1 new Rust module, 1 newRust test) — no edits to the lines #5425 touches, so no conflict.
P3 (wire it so every cached realization is checked at the kernel/CI seam) follows in a separate PR.
🤖 Generated with Claude Code