Skip to content

warm==cold cache purity detective (§2 P1) - #5429

Merged
briansrls merged 5 commits into
mainfrom
session/stern-otter-43
Jun 21, 2026
Merged

briansrls merged 5 commits into
mainfrom
session/stern-otter-43

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jun 21, 2026 •

Copy link
Copy Markdown
Contributor

warm==cold cache purity detective (ROADMAP §2 P1)

Makes the DESIGN §5 caching-via-realization principle executable: a cache that
changes a verdict is not a cache bug, it is a purity bug the cache exposed. A
content-keyed realization promises output = f(declared key inputs). If an input is
read at realize time but absent from the content-key, a WARM hit (addressed by the
now-stale key) serves a result a fresh COLD recompute would no longer produce:
warm != cold. So the cache IS the purity falsifier — this oracle makes that falsifier run.

What lands

  • dsl/extdeps/realization/cache_purity.dag — CachePurityVerdict = Pure | Impure { violation }
    carrier; the violation LOCATES the read-but-unkeyed axis. The durable artifact v2 inherits
    (the Rust below is the §7 proving handler). It is the run-side twin of
    extdeps.cache.key_completeness (the declare-side lens): both ends of one authority, the content-key.
  • src/v1/stage0/src/cache_purity_oracle.rs — the oracle. audit_warm_equals_cold holds
    the content-key fixed, perturbs candidate hidden inputs, and raises a located, typed, LOUD
    CachePurityViolation on divergence (fail-closed, never a warning). A probe that moves the
    key is a declared axis (a miss, not a stale hit) and is skipped — no false positive on keyed inputs.

Discriminating witnesses (DESIGN §5 spec-without-execution — green by execution + a RED)

  • Real consumer green: the REAL resolved_graph_cache::{lookup,write} path — a cold compute
    then a warm hit are byte-identical after canonicalization; and the real resolve realization is
    PURE under probes the key legitimately ignores (unrelated env var / non-imported sibling file).
  • RED falsifier: an injected hidden non-keyed input (read at realize time, absent from the
    key) → the oracle raises the loud located error naming the axis. Without it, the green cases pass
    vacuously. Also proven RED-on-revert for the .dag carrier (inverting the verdict flips the witness).

Coordination

Consumes the public subject_digest_for_closure (the from-inputs key); does not re-fork #5425's
key derivation. Purely additive (1 new .dag carrier, 1 new .dag witness, 1 new Rust module, 1 new
Rust test) — no edits to the lines #5425 touches, so no conflict.

P3 (wire it so every cached realization is checked at the kernel/CI seam) follows in a separate PR.

🤖 Generated with Claude Code

briansrls and others added 2 commits June 21, 2026 04:18
…ize kernel

The §5 caching-via-realization principle made executable: a content-keyed
realization promises output = f(declared key inputs); an input read at realize
time but absent from the content-key makes a WARM hit serve a stale result a
fresh COLD recompute would no longer produce. The cache IS the purity falsifier.

- extdeps/realization/cache_purity.dag — CachePurityVerdict carrier (Pure |
  Impure{located violation naming the read-but-unkeyed axis}); the durable
  artifact v2 inherits. Discovery witness in dsl/test/claim.
- cache_purity_oracle.rs — v1 proving handler: audit_warm_equals_cold holds the
  content-key fixed, perturbs candidate hidden inputs, and raises a located,
  typed, LOUD CachePurityViolation on divergence (fail-closed). Probes that move
  the key are declared axes (a miss, not a stale hit) and are skipped.
- cache_purity_oracle_test.rs — discriminating witnesses (DESIGN §5
  spec-without-execution): REAL kernel warm==cold byte-identical round-trip +
  real realization PURE under non-keyed probes (green by execution) PLUS an
  injected hidden non-keyed input that goes RED with the loud located error.

ROADMAP §2 P1. Consumes subject_digest_for_closure (no re-fork of #5425's key).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title warm==cold cache purity detective (§2 P1->P3) warm==cold cache purity detective (§2 P1) Jun 21, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review June 21, 2026 04:28
…t-shrinkage receipt

Review (claude-opus-4-7, APPROVE) soft concerns:
- predicate-dissolution: cache_purity_is_pure was a Bool restating the
  CachePurityVerdict coproduct. Deleted it; consumers (and the witness) match the
  verdict directly so the located violation stays in hand on the Impure arm.
- §7 hand-Rust receipt: added an explicit SCAFFOLD dissolve-on trigger to the
  oracle module header (net-new capability bound to the v2 realize-fold fixed
  point, ROADMAP §2 P5), matching the codebase's named-dissolution convention.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 21, 2026

Copy link
Copy Markdown
Contributor Author

Thanks for the review — both soft concerns addressed in d3bde56:

  1. predicate-dissolution (cache_purity_is_pure): valid, deleted. It was a Bool restating the CachePurityVerdict coproduct; consumers (and the .dag witness) now match the verdict directly, so the located violation stays in hand on the Impure arm instead of being flattened to a bare Bool. Left a comment in the carrier marking why no is_pure projection exists.

  2. §7 hand-Rust receipt: added an explicit SCAFFOLD — dissolve-on trigger to the cache_purity_oracle.rs header. The honest receipt here is named dissolution, not a deletion: this is net-new capability (no prior oracle existed, so there is no scaffold path to delete in this diff), bound to a concrete fixed point — when the v2 fold_node evaluator self-hosts the realize fold and content(T) = content_hash(subgraph) lands (ROADMAP §2 P5), the axis set and the audit become one derived .dag fact and the Rust handler is deleted. Until then the .dag carrier is the authority and the Rust is one handler of it, matching the v1_handler.dag convention.

— sent from stern-otter-43

…e dir)

Review (claude-opus-4-7) valid non-blocking finding:
real_resolved_graph_realization_is_pure_under_nonkeyed_probes took
CACHE_ENV_MUTEX but never isolated GUNBC_RESOLVED_GRAPH_CACHE_DIR, so a host
with that var set could leak into the test. Replaced the bare mutex lock with
CacheEnvGuard::set(temp) — which both isolates the cache dir and serializes the
env-var probe — matching tests 1 and 3.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 21, 2026

Copy link
Copy Markdown
Contributor Author

Addressed in af3500a:

  • Hermeticity finding (test 2 not isolating the cache dir): valid, fixed. Replaced the bare CACHE_ENV_MUTEX lock with CacheEnvGuard::set(temp) so the test both isolates GUNBC_RESOLVED_GRAPH_CACHE_DIR to a temp path and serializes the env-var probe — now hermetic like tests 1 and 3. All 4 tests still green, clippy clean.
  • Bool-from-handler flag (verdict fn takes a Bool bridge): agreed it's not a finding — the doc comment names it honestly. It rides the existing DESIGN open thread (the Value::Bool straddle, the remaining-(a) item after the numeric tower); when that grounds, this Bool-from-handler grounds with it. No separate action.
  • §7 hand-Rust receipt and the predicate-dissolution refusal: thanks for confirming both land right.

— sent from stern-otter-43

@gunbai-bot

gunbai-bot Bot commented Jun 21, 2026

Copy link
Copy Markdown
Contributor Author

Verified — this review is APPROVE with Findings: none; the cited lines (cache_purity.dag:50-53, cache_purity_oracle.rs:19-23, the test refs) all match the current head af3500a, so it is reviewing the latest code. The dashboard registers it as an approval (request_changes: 0, has_request_changes: false, mergeable: MERGEABLE) — the 'BLOCKING REVIEW' relay header is a misclassification, not a request-changes. Nothing to fix; no commit needed.

— sent from stern-otter-43

briansrls added a commit that referenced this pull request Jun 21, 2026
…+ deferred handler binding (dsl->v2 de-fork, not #5429)

Per mgr review of #5455: a modeled key with zero production caller is the declared-but-dead
fork P2 kills. Mark the production consumer (the imminent v2-local fold-rewire) and the deferred
std-kernel handler binding with its named dissolution trigger (the dsl->v2 cross-tree de-fork,
explicitly NOT #5429).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
…O + P2 de-fork-dependent, §0 census regression + gate-hygiene

Reflects decisions/findings that landed 2026-06-21:
- §1: the "expensive" tests were debug-build amplification, not intrinsic
  seed cost (proud-deer cause-table); opt-level=3 (#5456) restores Pop-A to
  per-PR; nightly lane reduced to Pop-B wet-captures only. Mirror corrected in §0.
- §2: resolve-cache enable = GO (~18% floor-wall, purity-proven, #5429-gated);
  P2 ParseTable dissolution reclassified as a downstream consumer of the dsl→v2
  de-fork (keen-otter: v2-local rewire is cosmetic); #5446 realize kernel green.
- §0: stage0 clone-census ratchet went inert + the seed regressed 1138 over
  budget (rust-side coverage-by-illusion + thesis regression; #5427 surfaced it);
  gate-hygiene rule (floor-enrolled gate must be green-on-main at merge) +
  roster-completeness assertion promoted to should-land (the #5445 floor-skew).
- §1: registry-partition instance fix = #5452 (verified sound).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
…gestion⁻¹ past syntax (#5442)

* WIP: dsl -> v2 scoping

* WIP: ROADMAP planning

* WIP: ROADMAP planning

* WIP: ROADMAP planning

* ROADMAP: scannable dependency-ordered checklist; consolidate caching plan (de-fork zesty-deer-479 owner, absorb quick-ant-298 spine)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* self-host: add bootstrap purity (no stage0 hand-edits / regen-lockstep keystone) + precise v1 cutover

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §0 fail-closed lock-down (blocks expansion) + audit doc; §4 website demo

Audit: cache lossy-digest flake (resolved_graph_cache.rs:146, verified), ~inert analytical
lenses (complexity/cost/etc), regen --verify unwired (#5325). Lock-down checklist gates expansion.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP: flesh §2 idea->idea compiler (medium/language axes); §0 → lock-down LANE (audits→fixes→meta), name model<->realization fork as suspected root

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* lock-down: add CI-coverage-completeness audit (rust gate runs 3 of 60 v1 suites) + axiom/syllogism lens (DESIGN open thread #1 — lock down the reasoning)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* roadmap §0/§7 + lockdown: lead with correctness-by-construction, demote lenses to residue

Folds in the operator principle (relayed via quick-ant-298): a lens is validation
— it concedes the bad thing is writable. Root-cause to make it unwritable (single
authority / realization derived from model); reserve lenses for the genuinely-
unstructurable (complexity/necessity). #5423's spec-only key lens shipped a
false-green as the live proof.

- ROADMAP §0: add the principle; split Fixes into tier-1 construction (dissolve
  model↔realization fork; cache-key derived-from-declared-inputs; self-host purity
  by construction) and tier-2 lens (complexity/cost; cache-redundancy; purity
  oracle; promote-inert). Meta-invariant → construction-justification rule.
- ROADMAP §7: P1 cache-key reframed from 'realizer-key lens' to key derived from
  declared inputs_considered (construction).
- fail-closed-lockdown.md: construction principle in the thesis; §4 checklist
  re-ordered construction-first / lens-residue; meta = construction-justification.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* roadmap §0: add Disposition carrier + 'confront skipped modeling decisions'

Captures the lens/coproduct disposition decision (operator). One typed carrier
(Terminal{reason} | Scaffold{dissolves_to}) for BOTH lens-lifecycle tags AND
coproduct dissolve-markers — today freeform 🟡 comments, unreadable by lens since
comments aren't Nodes.

Decision: middle path (construction-capable carrier + selectively-enforcing lens
that ratchets coverage) now, #1 (substrate can't-define-untagged) as the named
end-state. The lens is itself a Scaffold{dissolves_to: substrate-mandatory-tag} —
self-dissolving when coverage = whole tree. Rejected jumping to #1 on sequencing
(load-bearing §4 substrate change → escalate; flag-day migration; derived
coproducts need disposition derived not authored), not on principle.

Enforceability split: presence = construction (non-optional field, no meta-lens);
redundancy (scaffold + successor both present) = hard gate; Terminal-vs-Scaffold
correctness = retro/judgment (synthesis-feasibility limit).

- docs/plans/disposition-carrier.md (new)
- ROADMAP §0 tier-1 + meta 'confront skipped decisions' standing practice

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* DESIGN §5/§6: promote construction-over-validation; roadmap: scope-partition §0, testgen §1, shelve dashboard

Addresses the review's four flags + sequencing nuance.

- DESIGN.md §5: 'correctness by construction, not validation' is now an axiom
  (a check re-stating a model constraint is a 2nd representation §2/§3; prefer
  realization derived from a single authority; reserve checks for the unstructurable
  residue). §6 'enforce with lenses' reconciled: construction first, lens = residue
  mechanism, AND the executable inert-lens backstop is NOT superseded by the
  authoring-time construction-justification judgment. (flag 4 home + flag 3)
- ROADMAP §0 partitioned: In-scope this window (numeric-tower grounding; cache
  trustworthy + warm==cold oracle shipped NOW as detective; widen rust gate;
  promote inert lenses) vs Fenced-OUT fan-out (Value::Null 131-site split;
  self-host purity gate; cross-tree import activation; Disposition carrier).
  Honest framing: window reduces fail-open surface, does NOT 'lock' the class —
  Null split stays open. (flags 1, 2, sequencing nuance)
- ROADMAP §0 meta: restored executable inert-lens hygiene backstop, construction-
  justification layered on top (not 'supersedes'). (flag 3)
- De-dup: principle no longer restated in ROADMAP/lockdown §0; both point to
  DESIGN §5. cache-key construction homed in §7, §0 references it. (flag 4)
- ROADMAP §1 = testgen as bug-class oracle (+ affected-set completeness half +
  parked anemia lens); dashboard shelved to §8.
- docs/plans/testgen-oracle.md (new), fail-closed-lockdown.md realigned.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* DESIGN §5/§6/§7: wall-vs-ratchet decidability, displaced-pain denominator, open language design

Folds in the operator's product thesis + the two bounds that keep it honest.

- §5: construction makes a class unwritable only when membership is DECIDABLE —
  trichotomy (wall now / wall after grounding / ratchet forever); 'never' is the
  trap (lets an undecidable ratchet masquerade as a wall — optimality by Rice).
- §6: denominate the benefit — the deliverable is a displaced cost (§1 time / a
  paid-for pain), the lens/substrate is the moat not the product; priced in
  elegance the work is unbounded (the economic twin of 'never').
- §7: the recursion's payoff — language design itself opens up. It's locked by
  cost (a check = a compiler fork; a language = an adoption problem); both
  dissolve here (a wall is a row §2, applied over a medium-agnostic substrate §4),
  so (compiler-fork × language) → (row + medium). Sound where ingest is Lossless,
  fail-closed where not (DecodeFidelity §4).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* ROADMAP: fix doc-graph violations from bright-eagle-46 review of #5424

Apply the apex axiom/syllogism lens (single authority / no orphan / no
cycle) to the roadmap itself — manual acyclicity pass:

- orphan: testgen-oracle.md backlinked §1 → repoint §4 (its own lane)
- single authority: §0 cache-key now a pure pointer (= §2 F2/F3/P1);
  §0 numeric-tower marked the authoritative home (§5 de-fork / fork plan
  point here, no second checkbox)
- §0↔§5 cycle: self-host purity reframed as a §5 deliverable §0's
  expansion-gate depends on (edge §5 → §0-gate → products), not §0-owned
- undeclared edge: §7 react/html declares its dependency on §6 media
- backlink sweep: the reorg had broken every numeric backlink across 7
  plan docs; re-point all and anchor each to the stable section TITLE so
  a future renumber can't silently break them again

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §3 + plan: algorithmic-cost reduction by construction (rewrite, not budget)

Reframe §3 from per-fn complexity budgets to the actual intent: rewrite
common suboptimal patterns (O(n²)→O(n), O(2ⁿ)→O(n), O(n)→O(log n)) to the
cheaper equivalent — construction on the cost axis, not a warning.

New plan doc docs/plans/algebraic-rewrite-optimization.md captures the
up-front design: the decidability split (modeled EffectShape makes the
preconditions structural; equivalence stays undecidable so no optimality
oracle), rewrite-rule-as-row + once-proven soundness, the common-case
catalog tiered by precondition, D1 canonical-form-is-truth / D2 two seed
rules / D4 constant-factor deferred, the four-witness DONE bar (incl. the
non-firing control half-done versions skip), and a corpus hit-rate
acceptance gate. complexity.dag is the cost oracle; synthesis.dag stays
the advisory undecidable residue.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §2: Phase-0 measurement instrument done (#5431 peak-RSS) — remaining is the Phase-1 consumer

Per quick-ant-298: the measurement keystone was nearly complete — model
side already floor-enrolled, step timing already emitted; the only gap was
peak-RSS, closed by #5431. P4's Phase-0 dependency is satisfied; remaining
is the Phase-1 measured->plan feedback + width-fold (also unblocks §1-C).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* plan/§3: detection-vs-enforcement containment (E⊆D′⊆D) + explicit seed-rule I/O up front

Grounded in cost.dag U2 + complexity.dag (investigated, not theorized):
- detection is TOTAL by construction (kernel-level cost fold; arbitrary fns
  detectable); boundary is precision (ClassUnknown), not coverage
- enforced rewrites are a strict subset structurally guaranteed by the
  class-drop witness: E ⊆ D′(precise) ⊆ D(all)
- n√n excluded for a MODEL reason (PolynomialDegree is integer-only, n^1.5
  unrepresentable); ternary search excluded (log base is not a class)
- today's small gate roster = subject-production limit (fn-body reflection),
  NOT a detection limit
- new §3a fully specifies the two seed rules up front: input→output→
  precondition→non-firing control→discriminating equivalence input, so the
  worker builds to spec and the project can actually finish

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §0/§1: rust-gate is cadence-decoupling, not run-all (per fierce-hawk #5427)

The 3-filter allowlist was COST selection, not arbitrary gatekeeping — the
v1 SEED compiler costs ~tens of CPU-sec per trivial test, so run-all-per-PR
is CPU-hours (off the table). True shape: per-PR cost-bounded subset +
measured #[ignore="expensive: Ns"] + completeness lens (#5427); nightly
--ignored lane as the destination for expensive + the 58 currently-ignored
tests (owned by §1/quick-ant, after #5431, escalate for load-bearing
CI-gen). Completeness = every test runs on >=1 cadence (fail-closed).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* plan §2a: generalize by structural-redundancy keying (O(n^x)->O(n^(x-1)) free); flag n-log-n as substitution

Per operator: catalog must generalize polynomial-degree reduction without
edge cases. Resolution: rules key on the structural redundancy, never on
degree — degree is not evidence of redundancy (would fire on genuine O(n^x)).
A structurally-keyed nested-membership->set peels one level wherever it
matches; fold-to-fixpoint gives O(n^3)->O(n^2)->O(n). Cost model supports
arbitrary integer degree, so witness (b) holds at every peel.

Flagged OPEN (operator input invited): O(n^x)->O(n log n) is algorithmic
SUBSTITUTION (different algorithms, same I/O) not redundancy elimination —
verges on undecidable equivalence; tractable form is per-idiom rules
(sort-based dedup, repeated-min->heap), not a parameterized rule. Seed Rule 1
now authored structurally + carries a depth-2 generalization witness.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* plan §1b: Unknown is an anemic atom — dissolve over time (reuse Disposition), never a false pass

Per operator: classifying Unknown isn't a fixed up-front split — it's the
standing anemic-leaf dissolution practice (DESIGN §2 decompress->map->reduce)
applied to the cost lens. UnknownCost{diagnostic} already carries its reason;
the anemia is the free-form reason. Each decomposition resolves an Unknown to
construction (now-precise class -> new D′) or a grounded Terminal (genuinely
undecidable, positively recognized -> advisory comment). DFS-first: this IS
the Disposition carrier (resolves to construction-or-justified-Terminal), so
reuse it, don't fork an unknown-reason enum. Supersedes the static
Undecidable|Undetermined split. Two invariants fixed up front: never a false
pass (Unknown=>Violates, already holds); every Unknown on the dissolution
frontier. cost.dag enrichment + un-parking Disposition are operator-gated.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP: §3 reverts to budget-gate validation (stability); rewrite-engine relocated to §5 (post-stability)

Operator decision 2026-06-21: budget-gate validation is fine for the
stability window; the algorithmic-cost REWRITE construction design is
expansion, homed with self-hosting (§5) — IR-rewrite/canonicalization is
most natural once .dag is the self-hosted truth.

- §3 = complexity budget gate (validation): cost-lens symbolic_max fix
  (#5437) + per-fn subject + budget-gates-whole-codebase (gated on fn-body
  reflection) + synthesis advisory. #5437 foundation stays in-window.
- §5 gains an 'adjacent expansion lane' = the rewrite engine, pointing at
  the preserved plan doc; marked post-stability.
- plan doc status -> POST-STABILITY EXPANSION, relocated to §5.

Nothing deleted — the rewrite design is preserved, just fenced out of the
stability window (same as Disposition / Value::Null-split).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* #5442 review fix (warm-lark-306): grep-as-authority for the sidecar roster (10 not 9)

The §0-guard impl PR (#5445) grepped current main and found 10 importers of
extdeps.languages.bash.program, not 9 — the 10th (dsl/gunbc/ci_spec.dag) landed via #5432 after
the original pre-merge grep. Rather than bump the frozen count, make the live grep the authority
(the roster shrinks to 0 as the bash-sidecar arc migrates consumers, so any frozen number rots —
the single-authority point). Also note the two *_test importers are intentionally not walled
(guard scans consumer-source roots only).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP: check off 6 merged items (catch-up sweep)

Flip [ ]→[x] for unambiguously-merged work (PR-ref'd for traceability):
- §0 numeric-tower grounding (#5428 — == straddle guard dead-in-corpus)
- §0 inert-lens hygiene executable backstop (#5433)
- §2 F2/F3 resolved_graph key derived from inputs_considered (#5425)
- §3 cost-lens symbolic_max zero-absorption fix (#5437)
- §4 gate existing generated testgen output (#5434)
- §4 affected-set completeness (#5430)

Partial/compound items left for their lane managers to flip in the PR that completes them.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §1: add compile-clean-gate force-checks-every-fn-body box (2(ii) fail-open)

New floor-coverage item: the compile-clean gate is fail-open — unreached fn bodies escape
typecheck, so undefined symbols in dead code pass green (execution-proven on utf8_decode_bytes).
Construction fix = typecheck total over every declared body. Owned by §1 (quick-ant); measure-first,
operator-gated enforce-flip.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §0: correct the 2(ii) box — registry-leak mechanism, not unreached-bodies

snappy-gull's deeper diagnosis: the fail-open is NOT unreached bodies (bodies ARE visited).
utf8_decode_bytes resolves because it's a global builtin_function_registry entry (04_method.dag,
a marked bridge scaffold) not scoped to the compiled tree. Reframe the box to tree-scoped builtin
availability / registry partition; instance fix = real std fn + remove the registry bridge entry.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* plan doc: enforcement roster is a FROZEN grandfather set, not derived (warm-lark correction)

Deriving the realization-vocab exception roster from a live grep would make the guard vacuous
(leak = non-edge importer AND NOT-in-roster; derived roster ⇒ every importer always in it ⇒
leak_count always 0 ⇒ never fires). Distinguish the informational prose count (rots, re-grep)
from the lens's enforcement roster (frozen, so a new unrostered importer goes RED = the teeth).
Add the 11th importer (extdeps_external_authority_transport, the #5418→#5445 race, fixed by #5453)
and the roster-completeness assertion as the steady-state race-hardening.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* ROADMAP refresh: §1 nightly→Pop-B (opt-level won), §2 resolve-cache GO + P2 de-fork-dependent, §0 census regression + gate-hygiene

Reflects decisions/findings that landed 2026-06-21:
- §1: the "expensive" tests were debug-build amplification, not intrinsic
  seed cost (proud-deer cause-table); opt-level=3 (#5456) restores Pop-A to
  per-PR; nightly lane reduced to Pop-B wet-captures only. Mirror corrected in §0.
- §2: resolve-cache enable = GO (~18% floor-wall, purity-proven, #5429-gated);
  P2 ParseTable dissolution reclassified as a downstream consumer of the dsl→v2
  de-fork (keen-otter: v2-local rewire is cosmetic); #5446 realize kernel green.
- §0: stage0 clone-census ratchet went inert + the seed regressed 1138 over
  budget (rust-side coverage-by-illusion + thesis regression; #5427 surfaced it);
  gate-hygiene rule (floor-enrolled gate must be green-on-main at merge) +
  roster-completeness assertion promoted to should-land (the #5445 floor-skew).
- §1: registry-partition instance fix = #5452 (verified sound).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@briansrls
briansrls merged commit cdd1421 into main Jun 21, 2026
1 check passed
@briansrls
briansrls deleted the session/stern-otter-43 branch June 21, 2026 15:04
briansrls added a commit that referenced this pull request Jun 21, 2026
…y backfill (fleet-red keystone fix) (#5465)

#5429 added the cache_purity module but did not register it in external_authority_backfill_pending.txt
(its 4 realization siblings are listed), so #5418's live-clean-tree lens fail-closes — fleet-wide main-red
since cdd1421 (#5429); prior commit ac9a7e7 (#5449) was green. Same floor-skew class as #5445/#5453.
One-line backfill anchor; diagnosed by bright-stag-194, delegated by sunny-bee-667 (lane owner) for the
urgent fleet-unblock. Also unblocks stern-otter's P3 branch.

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
…rity.dag (#5464)

Co-authored-by: Brian Searls <briansrls@gunb.ai>
briansrls added a commit that referenced this pull request Jun 21, 2026
… handler-bind deferred (#5455)

* WIP: §2 P2 one-door realize(subject) sole cache API; dissolve hand-rolled Par

* P2 phase-2 design: ParseTable content-key (realize subject) model

DESIGN-FIRST (model-before-implement). parse_table_subject folds the table scope
(grammar_digest × token_stream_digest) with the cell coordinate (position × production)
into one content hash, reusing v2.std.node combine_hash / byte_limb_hash_peano_digest /
atom_identity_hash (no fresh hashing authority). This re-keys the positional
{position, production} cell key onto a content-addressed realize subject.

MODEL ONLY: derives the subject; does NOT route lookup/insert/the parse fold through it
(that cementing is held — escalate first). Binding to the std realize kernel
(ArtifactIdentity / realize_route) is blocked on the dsl→v2 cross-tree import.

Green-by-execution: parse/parse_table_content_key_test.dag — deterministic + 4 per-component
discriminating witnesses (drop any of grammar/token-stream/position/production from the fold
and the matching witness goes red; verified by perturbation).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* P2 phase-2: name parse_table_subject consumer (imminent fold-rewire) + deferred handler binding (dsl->v2 de-fork, not #5429)

Per mgr review of #5455: a modeled key with zero production caller is the declared-but-dead
fork P2 kills. Mark the production consumer (the imminent v2-local fold-rewire) and the deferred
std-kernel handler binding with its named dissolution trigger (the dsl->v2 cross-tree de-fork,
explicitly NOT #5429).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* P2 phase-2: correct parse_table_subject marker to deferred-consumer (rewire collapses into de-fork handler binding)

Per mgr DEFER decision: P2-A v2-local rewire collapses into P2-B. The v1 host is the SOLE
parse-memo authority (the .dag entries map is vestigial), so a v2-local host re-key now would
trade a collision-free structural tuple for content-hash collision risk (§5) + re-derive the
fold in Rust (more §3 host surface) for zero pre-de-fork benefit. The SOLE consumer is the
deferred std-kernel handler binding (named trigger = dsl->v2 de-fork); no premature rewire.
Honestly-marked deferred-consumer model (defined consumer + named trigger), not a dead fork.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
…he 3× fleet-red)

Pins the 3× fleet-red to stale-green (PR validated against a pre-gate base,
merged without re-validating current main) via the #5429 timeline receipts;
ranks the merge-policy fixes (merge-queue >> require-up-to-date under the
approval outage); scopes neat-ibex's reverse-staleness lens as complementary,
not the 3×-red killer. Decision record for the operator's merge-policy call.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
…he 3× fleet-red) (#5474)

* WIP: ci is slow investiation

* docs/plans: ci-merge-freshness decision record (stale-green root of the 3× fleet-red)

Pins the 3× fleet-red to stale-green (PR validated against a pre-gate base,
merged without re-validating current main) via the #5429 timeline receipts;
ranks the merge-policy fixes (merge-queue >> require-up-to-date under the
approval outage); scopes neat-ibex's reverse-staleness lens as complementary,
not the 3×-red killer. Decision record for the operator's merge-policy call.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 22, 2026
… coverage keystone) (#5526)

* WIP: ci is slow investiation

* docs/plans: ci-merge-freshness decision record (stale-green root of the 3× fleet-red)

Pins the 3× fleet-red to stale-green (PR validated against a pre-gate base,
merged without re-validating current main) via the #5429 timeline receipts;
ranks the merge-policy fixes (merge-queue >> require-up-to-date under the
approval outage); scopes neat-ibex's reverse-staleness lens as complementary,
not the 3×-red killer. Decision record for the operator's merge-policy call.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* docs/plans: scoped edge-(b) brief — rust-test↔consumed-.dag provenance (the §1 coverage keystone)

Scoping artifact for the operator greenlight call. One declared fact (rust-test→
consumed-.dag closure on the existing NodeArtifactProvenance carrier) read in two
directions: FIRE-when-consumed (coverage wall, fail-closed) and SKIP-when-unaffected
(affordability selector) — DESIGN §4 one grammar both directions. Shared
testgen-reflection blocker; first vertical slice; honest multi-day estimate. Build
HELD for operator nod; decoupled from #5427.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* docs/plans: edge-(b) brief — fold in the coverage-completeness asymmetry (closure ⊇ reads)

bright-stag's load-bearing sharpening: coverage (fire-on-change) is fail-OPEN to
under-declaration (declaration drift re-opens the .dag→rust hole), while affordability
(skip) is fail-safe to over-declaration. So (1) the completeness lens must check
closure ⊇ actual-.dag-reads (CORRECTNESS), not mere presence — presence is the §5
faked-cache-key trap; (2) structural closure discovery IS the soundness, not optional
polish — a hand-authored closure is the §3/§5 fork that silently re-opens the hole;
(3) slice-1 must state whether its closure is structurally derived (proves the wall) or
hand-listed (proves only the wiring).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* ROADMAP: anchor the edge-(b) keystone brief from the rust-gate-coverage item (doc reachability)

The new docs/plans/edge-b-rust-dag-provenance-brief.md was an orphan doc → the
floor witness doc_graph_has_no_orphan_docs (dsl/test/claim/doc_reachability_witness_test.dag)
RED on #5526. Fix per the rule (every docs/**/*.md reachable from a ROADMAP/DESIGN
root): add a terse pointer on the existing §1 rust-gate-coverage line, its correct
semantic home — edge-(b) is the .dag→rust coverage wall that #5427 (the .rs-hole-closer)
does not close.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* ROADMAP: trim edge-(b) line 36 to short summary + status (bright-stag refinement)

Per the operator short-lines rule (bright-stag enforces): move the mechanism density
(rust-test↔consumed-.dag closure, fail-closed both directions) into the brief; keep the
ROADMAP line a short scannable summary + pointer + explicit no-overclaim status
('SCOPED / pending operator greenlight'). Build is NOT greenlit; the line now says so.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 22, 2026
…ak (per-job placement divisor) (#5574)

* WIP: ci is slow investiation

* docs/plans: ci-merge-freshness decision record (stale-green root of the 3× fleet-red)

Pins the 3× fleet-red to stale-green (PR validated against a pre-gate base,
merged without re-validating current main) via the #5429 timeline receipts;
ranks the merge-policy fixes (merge-queue >> require-up-to-date under the
approval outage); scopes neat-ibex's reverse-staleness lens as complementary,
not the 3×-red killer. Decision record for the operator's merge-policy call.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* docs/plans: scoped edge-(b) brief — rust-test↔consumed-.dag provenance (the §1 coverage keystone)

Scoping artifact for the operator greenlight call. One declared fact (rust-test→
consumed-.dag closure on the existing NodeArtifactProvenance carrier) read in two
directions: FIRE-when-consumed (coverage wall, fail-closed) and SKIP-when-unaffected
(affordability selector) — DESIGN §4 one grammar both directions. Shared
testgen-reflection blocker; first vertical slice; honest multi-day estimate. Build
HELD for operator nod; decoupled from #5427.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* docs/plans: edge-(b) brief — fold in the coverage-completeness asymmetry (closure ⊇ reads)

bright-stag's load-bearing sharpening: coverage (fire-on-change) is fail-OPEN to
under-declaration (declaration drift re-opens the .dag→rust hole), while affordability
(skip) is fail-safe to over-declaration. So (1) the completeness lens must check
closure ⊇ actual-.dag-reads (CORRECTNESS), not mere presence — presence is the §5
faked-cache-key trap; (2) structural closure discovery IS the soundness, not optional
polish — a hand-authored closure is the §3/§5 fork that silently re-opens the hole;
(3) slice-1 must state whether its closure is structurally derived (proves the wall) or
hand-listed (proves only the wiring).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* ROADMAP: anchor the edge-(b) keystone brief from the rust-gate-coverage item (doc reachability)

The new docs/plans/edge-b-rust-dag-provenance-brief.md was an orphan doc → the
floor witness doc_graph_has_no_orphan_docs (dsl/test/claim/doc_reachability_witness_test.dag)
RED on #5526. Fix per the rule (every docs/**/*.md reachable from a ROADMAP/DESIGN
root): add a terse pointer on the existing §1 rust-gate-coverage line, its correct
semantic home — edge-(b) is the .dag→rust coverage wall that #5427 (the .rs-hole-closer)
does not close.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* ROADMAP: trim edge-(b) line 36 to short summary + status (bright-stag refinement)

Per the operator short-lines rule (bright-stag enforces): move the mechanism density
(rust-test↔consumed-.dag closure, fail-closed both directions) into the brief; keep the
ROADMAP line a short scannable summary + pointer + explicit no-overclaim status
('SCOPED / pending operator greenlight'). Build is NOT greenlit; the line now says so.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: ci is slow investiation

* fmt: rustfmt the cgroup-peak measurement additions (claim_executor)

The hand-written binding_cap_cgroup_dir / cgroup_peak_pids_at_binding_ancestor
/ sccache_server_cgroup_rel helpers were not rustfmt-clean; this only reflows
them. No logic change. Fixes the rust_tests fmt failure on the held draft #5564.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* CI measurement: rust_tests-job leaf cgroup peak + --measure-cgroup-peak (per-job placement divisor)

Second half of the whole-tree CI memory measurement (companion to #5564's ci-job
emit): a claim_executor --measure-cgroup-peak standalone mode + a rust_tests-job
ci.yml step that calls it, so the rust_tests job (the binding ~16-23 GiB per-job
constraint, measured live on srv1) emits its own cgroup peak.

Corrects #5564's cap-ancestor read for the real fleet. Live srv1 inspection
(operator-granted) shows the runner units run MemoryMax=infinity (UNCAPPED), so
binding_cap_cgroup_dir returns None and the cap-ancestor read emits "unavailable".
The measurement now reads memory.peak at the LEAF runner cgroup (the ephemeral
per-job cgroup, always present) and reports capped-vs-uncapped + host MemTotal.

One walk, all reads (single authority): the emit line carries memory.peak (usage)
+ memory.max (budget, =uncapped on the fleet) + host_ram + pids.current/max + the
sccache server cgroup classified descendant-vs-sibling (the "accounted exactly
once" decision) — consumed by the compile-jobs divisor (#5546) and the placement
model (#5559).

Stacked on #5564 (reuses its binding_cap_cgroup_dir / sccache scan). ci.yml
regenerated via main_wet; drift gate green; fmt + clippy -D warnings + release
build clean; --measure-cgroup-peak verified by execution.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* Review fix (#5574): path-component prefix for sccache descendant check

claude-opus-4-7 flagged that sccache_under_leaf used a bare string prefix, so a
sibling like <leaf>-other.service would misclassify as a descendant (under-counts
host_fixed_overhead — the fail-OPEN direction). Compare on path components: leaf
itself, or a strict <leaf>/ prefix. Comment updated to match.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant