Skip to content

CI false-green build fix (§1): derive build-step success from declared-artifact presence+freshness, not exit-code alone — sccache corruption ⇒ exit-0-with-no-artifact is a §5 fail-open IN the floor itself, masks every downstream gate - #5432

Merged
briansrls merged 2 commits into
mainfrom
session/jolly-newt-77
Jun 21, 2026

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jun 21, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Closes the §1/§5 CI false-green build hole: a build that exits 0 with no/stale artifact (sccache false cache-hit ⇒ no relink) was a fail-open inside the CI floor itself — downstream gates then ran a stale/missing binary and passed green, masking every check. Build success was judged by exit code alone (ci_release_build_script; host_prelude ensure_*_built checked -x only before building, never after, and never freshness).

Fixed by construction, not validation (DESIGN §5/§6) and with single authority (§3): a build step is modeled as producing declared artifacts, and success is derived:

built ⟺ exit_success ∧ (∀ a ∈ produces: a exists ∧ no source is newer than a)

What changed

  • dsl/tools/build_step.dag (new): BuildStep{command, produces, source_roots, source_pattern} + one generator (emit_verifications / verifications_script) that emits, after the build, existence (PRIMARY — catches exit-0-with-no-artifact) then source-relative freshness (find <roots> -name '*.rs' -newer <artifact> -print -quit, the make/ninja up-to-date definition — false-positive-free, unlike a ≥ build_start proxy that cries wolf on a legit no-op rebuild). Both are fail-closed exit 1 statements built on the existing extdeps.languages.bash.program substrate.
  • Realizer = bash codegen from the model (not a live host effect). Every floor build site is emitted shell run as a bootstrap: ci.yml bash runs before the interpreter binary exists; host gates serialize one shell.Exec that builds and uses the binary atomically under set -e. There is no live-interpreter seam, so: no new host effect, no transport-type edit, no interpreter edit.
  • All three build sites routed through the one generator: gunbc.ci_spec release bootstrap (declares claim_executor + gunbc) and host_prelude ensure_*_built ×2 (new ensure_bin_built_and_verified helper — kills the forked -x paste).
  • Regenerated .github/workflows/ci.yml (main_wet; CiYamlGate byte-exact drift gate green).

Construction honesty (instance-fixed + class-residue-named)

The three existing build sites are construction-correct: each is authored through the generator, which always appends exists-then-fresh from the declared produces. The class-level guarantee — no build invocation exists outside BuildStep — is not structurally enforced: .dag does not stop someone hand-authoring a new cargo/rustc build as raw shell.Exec.Run bash that bypasses the model. That residue is a named follow-on lens: catch a cargo/rustc build in emitted/inline bash not routed through build_step (ties into the inline-shell reducibility lens family). Named here, not built in this PR — instance fixed, class residue honestly deferred.

Filesystem.Stat{path}->{exists,mtime} (a live readonly file-transport op) is the right realizer for any future interpreter-run build; named-deferred — it has no call site for this hole (all floor builds are bootstrap/emitted-shell).

Test plan

Proven by execution (DESIGN §5 — not spec-without-execution):

  • Wet sabotage on the generated verification script (ci_floor_build_verify_script):
    • real build (bins present + fresh) → exit 0 (green)
    • deleted target/release/claim_executor → exit 1 (existence RED)
    • touched a src/**/*.rs newer than the bin + no-op build → exit 1 (freshness RED)
  • Hermetic floor witness dsl/test/claim/build_artifact_verification_witness_test.dag::build_artifact_verification_holds → GREEN (shape exists→assign→fresh; existence precedes find -newer; tokens; floor covers both bins). Goes RED if either generator arm is dropped.
  • Local floor green: ci_yaml_serializer_keystone_holds, ci_spec_witnesses, dsl_compile_clean_witnesses (real whole-tree gunbc compile through the verified host prelude), layering imports gate (gunbc → tools import clean).

Note: the MODELING-COHERENCE check reports unavailable due to a circular dependency in the operator's ctrl pure-.dag coherence harness (plans.coherence → plans.reducible, std.reducible not found) — infra, not this gunbc dsl/ change (no file here is in that graph).

briansrls and others added 2 commits June 21, 2026 04:23
…artifact presence+freshness, not exit-code alone

A build that exits 0 with no/stale artifact (sccache false cache-hit ⇒ no relink)
is a §5 fail-open IN the CI floor itself: downstream gates then run a stale/missing
binary and pass green, masking every check. Build success was judged by exit code
alone (interpreter `exit_success`; ci_release_build_script; host_prelude ensure-built
checked `-x` only BEFORE building, never after, and never freshness).

Construction fix (§5 correctness-by-construction, §3 single authority), not validation:
model a build step as PRODUCING DECLARED ARTIFACTS and DERIVE success —
  built ⟺ exit_success ∧ (∀ a ∈ produces: a exists ∧ no source newer than a)
- new tools/build_step.dag: BuildStep{command, produces, source_roots, source_pattern}
  + ONE generator emitting exists (PRIMARY — catches exit-0-with-no-artifact) THEN
  source-relative freshness (SECONDARY — the make/ninja up-to-date definition; no
  false-fail on a legit no-op rebuild, unlike a ≥build_start proxy). Both as
  fail-closed `exit 1` ShellStmts via the existing bash.program substrate.
- realizer = bash codegen from the model (every floor build site is emitted shell run
  as a bootstrap — ci.yml bash before the interpreter exists; host gates serialize one
  shell.Exec that builds+uses atomically under set -e). No live-effect seam, so NO new
  host effect, NO transport-type edit, NO interpreter edit. A live Filesystem.Stat is
  the right realizer for a FUTURE interpreter-run build — named-deferred, not built.
- wired all three sites onto the one generator: gunbc.ci_spec (release bootstrap →
  claim_executor + gunbc) and host_prelude ensure_*_built ×2 (single authority, kills
  the forked `-x` paste).
- regenerated .github/workflows/ci.yml (CiYamlGate byte-exact drift).

Proven by execution (§5, not spec-without-execution):
- hermetic floor witness build_artifact_verification_holds: shape (exists→assign→fresh),
  order (existence precedes find -newer), tokens, floor covers both bins. GREEN; RED if
  either generator arm is dropped.
- wet sabotage proof on the generated script: real build → exit 0; deleted artifact →
  exit 1 (existence RED); touched *.rs newer + no-op build → exit 1 (freshness RED).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review June 21, 2026 04:33
@gunbai-bot

gunbai-bot Bot commented Jun 21, 2026

Copy link
Copy Markdown
Contributor Author

Thanks — verified all three findings against the current tree. Two valid (one deferred), one confirmed benign.

Finding 1 (build_step.dag — BuildStep + emit_build_with_verification unused). Valid. Confirmed by grep: zero consumers anywhere (emit_build_with_verification/BuildStep appear only in their own definitions; both real sites call emit_verifications/verifications_script directly). This is speculative scaffold (DESIGN §6 — model just-in-time). Neither site cleanly fits BuildStep{command, …}: the ci.yml site's build command is the hand-authored EAGAIN-retry String (would need a banned RawLine), and the host-prelude site builds conditionally (if ! -x then build), not command-then-verify. So the right move is to delete BuildStep + emit_build_with_verification, keeping the used authority (BuildArtifact / verify_artifact / emit_verifications / verifications_script) and tightening the header claim. Deferred — see note at bottom.

Finding 2 (freshness scans only $ROOT/src/**/*.rs). Valid, minor. One correction: build.rs is covered (it matches *.rs). The genuine residual gap is Cargo.toml/Cargo.lock (non-.rs): a corruption that skips a relink after a manifest-only change, with .rs unchanged, would slip past freshness. As you note, the existence conjunct still catches the primary reported vector (exit-0-with-no-artifact), and in practice a Cargo.lock change forces a cargo relink (fresh mtime). I'll add a dissolve-on: limitation note (and can broaden the pattern to include the manifests) in the same deferred push.

Finding 3 (ensure_discover_source_root_ingest_built now emits assign_root_stmt()). Confirmed benign, no change needed. Both callers (src/v2/workflow/compiler_closure_ingest_transport.dag:87, source_root_ingest_transport.dag:53) run ensure_gunbc_built() immediately before, which already assigns ROOT=$(git rev-parse --show-toplevel || pwd); my added reassign sets the identical value (idempotent). No caller sets a different ROOT in scope — the old discover fn relied on exactly that prior assignment, so this removes a latent ordering dependency rather than changing behavior.

Deferral note: PR #5432 is under a coordinated cross-PR head-freeze (#5431/#5432/#5427) while the operator repoints the ctrl coherence-gate harness (the failing MODELING-COHERENCE check is ctrl infra — a std.reducible import circular dep — not this diff). Pushing now would re-stale this approval and trigger CI during the hold for non-blocking nits. I'll fold the Finding-1 deletion + Finding-2 dissolve-on note into the single push when the freeze lifts.

— sent from jolly-newt-77

@briansrls
briansrls merged commit 3425d68 into main Jun 21, 2026
1 check passed
@briansrls
briansrls deleted the session/jolly-newt-77 branch June 21, 2026 05:37
briansrls added a commit that referenced this pull request Jun 21, 2026
…oster (10 not 9)

The §0-guard impl PR (#5445) grepped current main and found 10 importers of
extdeps.languages.bash.program, not 9 — the 10th (dsl/gunbc/ci_spec.dag) landed via #5432 after
the original pre-merge grep. Rather than bump the frozen count, make the live grep the authority
(the roster shrinks to 0 as the bash-sidecar arc migrates consumers, so any frozen number rots —
the single-authority point). Also note the two *_test importers are intentionally not walled
(guard scans consumer-source roots only).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
…dStep + emit_build_with_verification from dsl/tools/build_step.dag (§6 dead-code now on main; keep emit_verifications/verifications_script/BuildArtifact), widen freshness glob to Cargo.toml/Cargo.lock, reframe residue comment aroun (#5439)

* WIP: §1-A cleanup follow-up (#5432 merged pre-nit): delete the unused BuildSt

* WIP: §1-A cleanup follow-up (#5432 merged pre-nit): delete the unused BuildSt

* fix: bare parens in name_predicate_words + regenerate ci.yml

The bash serializer wraps lit(text: "\\(") as '\(' — two characters passed
to find/bfs as a file path, not a grouping operator, exiting 1 immediately.
Fix: lit(text: "(") → serialized as '(' which find recognizes as grouping.
Regenerate ci.yml to reflect the multi-pattern freshness check.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 21, 2026
…gestion⁻¹ past syntax (#5442)

* WIP: dsl -> v2 scoping

* WIP: ROADMAP planning

* WIP: ROADMAP planning

* WIP: ROADMAP planning

* ROADMAP: scannable dependency-ordered checklist; consolidate caching plan (de-fork zesty-deer-479 owner, absorb quick-ant-298 spine)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* self-host: add bootstrap purity (no stage0 hand-edits / regen-lockstep keystone) + precise v1 cutover

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §0 fail-closed lock-down (blocks expansion) + audit doc; §4 website demo

Audit: cache lossy-digest flake (resolved_graph_cache.rs:146, verified), ~inert analytical
lenses (complexity/cost/etc), regen --verify unwired (#5325). Lock-down checklist gates expansion.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP: flesh §2 idea->idea compiler (medium/language axes); §0 → lock-down LANE (audits→fixes→meta), name model<->realization fork as suspected root

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* lock-down: add CI-coverage-completeness audit (rust gate runs 3 of 60 v1 suites) + axiom/syllogism lens (DESIGN open thread #1 — lock down the reasoning)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* roadmap §0/§7 + lockdown: lead with correctness-by-construction, demote lenses to residue

Folds in the operator principle (relayed via quick-ant-298): a lens is validation
— it concedes the bad thing is writable. Root-cause to make it unwritable (single
authority / realization derived from model); reserve lenses for the genuinely-
unstructurable (complexity/necessity). #5423's spec-only key lens shipped a
false-green as the live proof.

- ROADMAP §0: add the principle; split Fixes into tier-1 construction (dissolve
  model↔realization fork; cache-key derived-from-declared-inputs; self-host purity
  by construction) and tier-2 lens (complexity/cost; cache-redundancy; purity
  oracle; promote-inert). Meta-invariant → construction-justification rule.
- ROADMAP §7: P1 cache-key reframed from 'realizer-key lens' to key derived from
  declared inputs_considered (construction).
- fail-closed-lockdown.md: construction principle in the thesis; §4 checklist
  re-ordered construction-first / lens-residue; meta = construction-justification.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* roadmap §0: add Disposition carrier + 'confront skipped modeling decisions'

Captures the lens/coproduct disposition decision (operator). One typed carrier
(Terminal{reason} | Scaffold{dissolves_to}) for BOTH lens-lifecycle tags AND
coproduct dissolve-markers — today freeform 🟡 comments, unreadable by lens since
comments aren't Nodes.

Decision: middle path (construction-capable carrier + selectively-enforcing lens
that ratchets coverage) now, #1 (substrate can't-define-untagged) as the named
end-state. The lens is itself a Scaffold{dissolves_to: substrate-mandatory-tag} —
self-dissolving when coverage = whole tree. Rejected jumping to #1 on sequencing
(load-bearing §4 substrate change → escalate; flag-day migration; derived
coproducts need disposition derived not authored), not on principle.

Enforceability split: presence = construction (non-optional field, no meta-lens);
redundancy (scaffold + successor both present) = hard gate; Terminal-vs-Scaffold
correctness = retro/judgment (synthesis-feasibility limit).

- docs/plans/disposition-carrier.md (new)
- ROADMAP §0 tier-1 + meta 'confront skipped decisions' standing practice

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* DESIGN §5/§6: promote construction-over-validation; roadmap: scope-partition §0, testgen §1, shelve dashboard

Addresses the review's four flags + sequencing nuance.

- DESIGN.md §5: 'correctness by construction, not validation' is now an axiom
  (a check re-stating a model constraint is a 2nd representation §2/§3; prefer
  realization derived from a single authority; reserve checks for the unstructurable
  residue). §6 'enforce with lenses' reconciled: construction first, lens = residue
  mechanism, AND the executable inert-lens backstop is NOT superseded by the
  authoring-time construction-justification judgment. (flag 4 home + flag 3)
- ROADMAP §0 partitioned: In-scope this window (numeric-tower grounding; cache
  trustworthy + warm==cold oracle shipped NOW as detective; widen rust gate;
  promote inert lenses) vs Fenced-OUT fan-out (Value::Null 131-site split;
  self-host purity gate; cross-tree import activation; Disposition carrier).
  Honest framing: window reduces fail-open surface, does NOT 'lock' the class —
  Null split stays open. (flags 1, 2, sequencing nuance)
- ROADMAP §0 meta: restored executable inert-lens hygiene backstop, construction-
  justification layered on top (not 'supersedes'). (flag 3)
- De-dup: principle no longer restated in ROADMAP/lockdown §0; both point to
  DESIGN §5. cache-key construction homed in §7, §0 references it. (flag 4)
- ROADMAP §1 = testgen as bug-class oracle (+ affected-set completeness half +
  parked anemia lens); dashboard shelved to §8.
- docs/plans/testgen-oracle.md (new), fail-closed-lockdown.md realigned.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* DESIGN §5/§6/§7: wall-vs-ratchet decidability, displaced-pain denominator, open language design

Folds in the operator's product thesis + the two bounds that keep it honest.

- §5: construction makes a class unwritable only when membership is DECIDABLE —
  trichotomy (wall now / wall after grounding / ratchet forever); 'never' is the
  trap (lets an undecidable ratchet masquerade as a wall — optimality by Rice).
- §6: denominate the benefit — the deliverable is a displaced cost (§1 time / a
  paid-for pain), the lens/substrate is the moat not the product; priced in
  elegance the work is unbounded (the economic twin of 'never').
- §7: the recursion's payoff — language design itself opens up. It's locked by
  cost (a check = a compiler fork; a language = an adoption problem); both
  dissolve here (a wall is a row §2, applied over a medium-agnostic substrate §4),
  so (compiler-fork × language) → (row + medium). Sound where ingest is Lossless,
  fail-closed where not (DecodeFidelity §4).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* ROADMAP: fix doc-graph violations from bright-eagle-46 review of #5424

Apply the apex axiom/syllogism lens (single authority / no orphan / no
cycle) to the roadmap itself — manual acyclicity pass:

- orphan: testgen-oracle.md backlinked §1 → repoint §4 (its own lane)
- single authority: §0 cache-key now a pure pointer (= §2 F2/F3/P1);
  §0 numeric-tower marked the authoritative home (§5 de-fork / fork plan
  point here, no second checkbox)
- §0↔§5 cycle: self-host purity reframed as a §5 deliverable §0's
  expansion-gate depends on (edge §5 → §0-gate → products), not §0-owned
- undeclared edge: §7 react/html declares its dependency on §6 media
- backlink sweep: the reorg had broken every numeric backlink across 7
  plan docs; re-point all and anchor each to the stable section TITLE so
  a future renumber can't silently break them again

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §3 + plan: algorithmic-cost reduction by construction (rewrite, not budget)

Reframe §3 from per-fn complexity budgets to the actual intent: rewrite
common suboptimal patterns (O(n²)→O(n), O(2ⁿ)→O(n), O(n)→O(log n)) to the
cheaper equivalent — construction on the cost axis, not a warning.

New plan doc docs/plans/algebraic-rewrite-optimization.md captures the
up-front design: the decidability split (modeled EffectShape makes the
preconditions structural; equivalence stays undecidable so no optimality
oracle), rewrite-rule-as-row + once-proven soundness, the common-case
catalog tiered by precondition, D1 canonical-form-is-truth / D2 two seed
rules / D4 constant-factor deferred, the four-witness DONE bar (incl. the
non-firing control half-done versions skip), and a corpus hit-rate
acceptance gate. complexity.dag is the cost oracle; synthesis.dag stays
the advisory undecidable residue.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §2: Phase-0 measurement instrument done (#5431 peak-RSS) — remaining is the Phase-1 consumer

Per quick-ant-298: the measurement keystone was nearly complete — model
side already floor-enrolled, step timing already emitted; the only gap was
peak-RSS, closed by #5431. P4's Phase-0 dependency is satisfied; remaining
is the Phase-1 measured->plan feedback + width-fold (also unblocks §1-C).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* plan/§3: detection-vs-enforcement containment (E⊆D′⊆D) + explicit seed-rule I/O up front

Grounded in cost.dag U2 + complexity.dag (investigated, not theorized):
- detection is TOTAL by construction (kernel-level cost fold; arbitrary fns
  detectable); boundary is precision (ClassUnknown), not coverage
- enforced rewrites are a strict subset structurally guaranteed by the
  class-drop witness: E ⊆ D′(precise) ⊆ D(all)
- n√n excluded for a MODEL reason (PolynomialDegree is integer-only, n^1.5
  unrepresentable); ternary search excluded (log base is not a class)
- today's small gate roster = subject-production limit (fn-body reflection),
  NOT a detection limit
- new §3a fully specifies the two seed rules up front: input→output→
  precondition→non-firing control→discriminating equivalence input, so the
  worker builds to spec and the project can actually finish

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §0/§1: rust-gate is cadence-decoupling, not run-all (per fierce-hawk #5427)

The 3-filter allowlist was COST selection, not arbitrary gatekeeping — the
v1 SEED compiler costs ~tens of CPU-sec per trivial test, so run-all-per-PR
is CPU-hours (off the table). True shape: per-PR cost-bounded subset +
measured #[ignore="expensive: Ns"] + completeness lens (#5427); nightly
--ignored lane as the destination for expensive + the 58 currently-ignored
tests (owned by §1/quick-ant, after #5431, escalate for load-bearing
CI-gen). Completeness = every test runs on >=1 cadence (fail-closed).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* plan §2a: generalize by structural-redundancy keying (O(n^x)->O(n^(x-1)) free); flag n-log-n as substitution

Per operator: catalog must generalize polynomial-degree reduction without
edge cases. Resolution: rules key on the structural redundancy, never on
degree — degree is not evidence of redundancy (would fire on genuine O(n^x)).
A structurally-keyed nested-membership->set peels one level wherever it
matches; fold-to-fixpoint gives O(n^3)->O(n^2)->O(n). Cost model supports
arbitrary integer degree, so witness (b) holds at every peel.

Flagged OPEN (operator input invited): O(n^x)->O(n log n) is algorithmic
SUBSTITUTION (different algorithms, same I/O) not redundancy elimination —
verges on undecidable equivalence; tractable form is per-idiom rules
(sort-based dedup, repeated-min->heap), not a parameterized rule. Seed Rule 1
now authored structurally + carries a depth-2 generalization witness.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* plan §1b: Unknown is an anemic atom — dissolve over time (reuse Disposition), never a false pass

Per operator: classifying Unknown isn't a fixed up-front split — it's the
standing anemic-leaf dissolution practice (DESIGN §2 decompress->map->reduce)
applied to the cost lens. UnknownCost{diagnostic} already carries its reason;
the anemia is the free-form reason. Each decomposition resolves an Unknown to
construction (now-precise class -> new D′) or a grounded Terminal (genuinely
undecidable, positively recognized -> advisory comment). DFS-first: this IS
the Disposition carrier (resolves to construction-or-justified-Terminal), so
reuse it, don't fork an unknown-reason enum. Supersedes the static
Undecidable|Undetermined split. Two invariants fixed up front: never a false
pass (Unknown=>Violates, already holds); every Unknown on the dissolution
frontier. cost.dag enrichment + un-parking Disposition are operator-gated.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP: §3 reverts to budget-gate validation (stability); rewrite-engine relocated to §5 (post-stability)

Operator decision 2026-06-21: budget-gate validation is fine for the
stability window; the algorithmic-cost REWRITE construction design is
expansion, homed with self-hosting (§5) — IR-rewrite/canonicalization is
most natural once .dag is the self-hosted truth.

- §3 = complexity budget gate (validation): cost-lens symbolic_max fix
  (#5437) + per-fn subject + budget-gates-whole-codebase (gated on fn-body
  reflection) + synthesis advisory. #5437 foundation stays in-window.
- §5 gains an 'adjacent expansion lane' = the rewrite engine, pointing at
  the preserved plan doc; marked post-stability.
- plan doc status -> POST-STABILITY EXPANSION, relocated to §5.

Nothing deleted — the rewrite design is preserved, just fenced out of the
stability window (same as Disposition / Value::Null-split).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* #5442 review fix (warm-lark-306): grep-as-authority for the sidecar roster (10 not 9)

The §0-guard impl PR (#5445) grepped current main and found 10 importers of
extdeps.languages.bash.program, not 9 — the 10th (dsl/gunbc/ci_spec.dag) landed via #5432 after
the original pre-merge grep. Rather than bump the frozen count, make the live grep the authority
(the roster shrinks to 0 as the bash-sidecar arc migrates consumers, so any frozen number rots —
the single-authority point). Also note the two *_test importers are intentionally not walled
(guard scans consumer-source roots only).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP: check off 6 merged items (catch-up sweep)

Flip [ ]→[x] for unambiguously-merged work (PR-ref'd for traceability):
- §0 numeric-tower grounding (#5428 — == straddle guard dead-in-corpus)
- §0 inert-lens hygiene executable backstop (#5433)
- §2 F2/F3 resolved_graph key derived from inputs_considered (#5425)
- §3 cost-lens symbolic_max zero-absorption fix (#5437)
- §4 gate existing generated testgen output (#5434)
- §4 affected-set completeness (#5430)

Partial/compound items left for their lane managers to flip in the PR that completes them.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §1: add compile-clean-gate force-checks-every-fn-body box (2(ii) fail-open)

New floor-coverage item: the compile-clean gate is fail-open — unreached fn bodies escape
typecheck, so undefined symbols in dead code pass green (execution-proven on utf8_decode_bytes).
Construction fix = typecheck total over every declared body. Owned by §1 (quick-ant); measure-first,
operator-gated enforce-flip.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ROADMAP §0: correct the 2(ii) box — registry-leak mechanism, not unreached-bodies

snappy-gull's deeper diagnosis: the fail-open is NOT unreached bodies (bodies ARE visited).
utf8_decode_bytes resolves because it's a global builtin_function_registry entry (04_method.dag,
a marked bridge scaffold) not scoped to the compiled tree. Reframe the box to tree-scoped builtin
availability / registry partition; instance fix = real std fn + remove the registry bridge entry.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* plan doc: enforcement roster is a FROZEN grandfather set, not derived (warm-lark correction)

Deriving the realization-vocab exception roster from a live grep would make the guard vacuous
(leak = non-edge importer AND NOT-in-roster; derived roster ⇒ every importer always in it ⇒
leak_count always 0 ⇒ never fires). Distinguish the informational prose count (rots, re-grep)
from the lens's enforcement roster (frozen, so a new unrostered importer goes RED = the teeth).
Add the 11th importer (extdeps_external_authority_transport, the #5418→#5445 race, fixed by #5453)
and the roster-completeness assertion as the steady-state race-hardening.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ROADMAP planning

* ROADMAP refresh: §1 nightly→Pop-B (opt-level won), §2 resolve-cache GO + P2 de-fork-dependent, §0 census regression + gate-hygiene

Reflects decisions/findings that landed 2026-06-21:
- §1: the "expensive" tests were debug-build amplification, not intrinsic
  seed cost (proud-deer cause-table); opt-level=3 (#5456) restores Pop-A to
  per-PR; nightly lane reduced to Pop-B wet-captures only. Mirror corrected in §0.
- §2: resolve-cache enable = GO (~18% floor-wall, purity-proven, #5429-gated);
  P2 ParseTable dissolution reclassified as a downstream consumer of the dsl→v2
  de-fork (keen-otter: v2-local rewire is cosmetic); #5446 realize kernel green.
- §0: stage0 clone-census ratchet went inert + the seed regressed 1138 over
  budget (rust-side coverage-by-illusion + thesis regression; #5427 surfaced it);
  gate-hygiene rule (floor-enrolled gate must be green-on-main at merge) +
  roster-completeness assertion promoted to should-land (the #5445 floor-skew).
- §1: registry-partition instance fix = #5452 (verified sound).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant