Skip to content

compile-clean force-check (2(ii), §1 floor-coverage): DESIGN + MEASURE — registry-leak diagnosis, (A) tree-scoped-builtin design, blast radius 10/102 - #5451

Merged
briansrls merged 3 commits into
mainfrom
session/snappy-gull-450
Jun 21, 2026
Merged

briansrls merged 3 commits into
mainfrom
session/snappy-gull-450

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jun 21, 2026 •

Copy link
Copy Markdown
Contributor

Work-item adhoc-6169238c-5e2 (2(ii) compile-clean force-check). Scope confirmed by parent quick-ant-298: DESIGN-FIRST + MEASURE-FIRST, land nothing enforcing. This PR ships only docs/plans/compile-clean-forcecheck.md (no code).

What it establishes (execution-proven, gunbc built from src/v1/stage0)

The compile-clean gate fail-open is NOT "unreached fn bodies escape typecheck" (bodies are always visited). The real mechanism:

  1. Registry leak (the brief's utf8_decode_bytes witness). It's referenced at dsl/extdeps/cloud/gcp/secret_manager.dag:71 but defined nowhere in dsl//src/v2; it resolves because it's a hardcoded row in the global builtin_function_registry() (src/v1/04_method.dag:93), an explicitly-marked BRIDGE scaffold. The registry is global, not scoped to the compiled tree → v1-seed intrinsics leak into the substrate compile.
  2. Return-type fail-open (separate; ROADMAP §0 line 31 — Enable strict record-field typecheck: close fail-open infer_record_lit hole (§5) #5293 closed only record-field). Split out as (B), its own PR.

(A) direction — tree-scoped builtin availability

Tag each registry row SubstrateAvailable vs SeedOnly; admit SeedOnly only when the entry root is the v1 seed. A substrate compile then fails closed on a seed-only name (the existing "function not found in scope" path). This advances the registry's own marked dissolve-on (04_method.dag:55-62). The enforcing flip is load-bearing (inference scope) + changes what compiles → operator-gated; this doc + the measured number is the sign-off input.

Blast radius (MEASURE-FIRST)

Empty-registry rebuild + real gunbc compile --source-root dsl --source-root src/v2 ... --target rust (throwaway worktree, uncommitted): 102 "function not found in scope" diagnostics, 10 distinct names, all in dsl/, none in src/v2. 8 general primitives (96 sites), filesystem_read (5, known lens-reflection fork), exactly 1 genuine domain leak — utf8_decode_bytes (gcp), already owned by 2(i). So (A)'s rollout is small/tractable, not a flag day. Full table in the doc.

Adjacent: 2(i) (adhoc-8e5771e1-14a) grounds utf8_decode_bytes as a real std fn + deletes its registry row; (A) is what makes that grounding required by construction so the leak can't recur.

🤖 Generated with Claude Code

briansrls and others added 2 commits June 21, 2026 06:59
…m adhoc-6169238c-5e2)

Execution-proven diagnosis (gunbc built from src/v1/stage0): the compile-clean
gate fail-open is NOT 'unreached fn bodies escape typecheck' (bodies are always
visited). The leak is (1) the global builtin_function_registry (a marked BRIDGE
scaffold) resolving v1-seed-only names like utf8_decode_bytes inside the dsl
substrate compile, and (2) unenforced declared return types (ROADMAP §0 line 31).
Captures the construction-correct direction (tree-scoped builtin availability =
the registry's own stated dissolution trigger) and three bounded options with a
recommendation. No code change; awaiting parent design direction before the
load-bearing inference slice.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…0 names / 102 sites (execution-proven)

Parent quick-ant-298 confirmed scope = (A) tree-scoped builtin availability,
DESIGN-FIRST + MEASURE-FIRST, land nothing enforcing (the enforce flip is
operator-gated). Adds the (A) partition design (availability-tagged registry
rows, SeedOnly admitted only when entry root = v1 seed; advances the registry's
own marked dissolve-on) and the MEASURE-FIRST blast radius.

Blast radius (empty-registry rebuild + real dsl/+v2 gate compile, throwaway
worktree, uncommitted): 102 'function not found in scope' diagnostics, 10
distinct names, all in dsl/, none in src/v2. 8 are general primitives (96
sites), 1 is the filesystem_read lens-reflection fork (5), exactly 1 is the
genuine domain leak utf8_decode_bytes (1, gcp) already owned by 2(i). Grep
over-counted ~50 (method-form calls resolve via the structural method path,
not the free-call registry).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title 2(ii) compile-clean force-check (§1 floor-coverage): the compile-clean gate is fail-open — unreached fn bodies escape typecheck (execution-proven: gunbc compile --target rust on main = 393 files, 0 diagnostics, EXIT 0 despite undefined utf8_decode_bytes in an uncalled fn body). DESIGN-FIRST: model ' compile-clean force-check (2(ii), §1 floor-coverage): DESIGN + MEASURE — registry-leak diagnosis, (A) tree-scoped-builtin design, blast radius 10/102 Jun 21, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review June 21, 2026 07:08
@gunbai-bot

gunbai-bot Bot commented Jun 21, 2026

Copy link
Copy Markdown
Contributor Author

CI red investigated — not caused by this PR, and not actionable here.

Failing check: realization_vocab_clean_tree_holds (src/v2/test/claim/realization_vocabulary_containment/clean_tree_test.dag) returned Bool(false) (batch 2 discovery witness, 1 of 637).

This PR's diff is docs-only — a single new file docs/plans/compile-clean-forcecheck.md, no .dag/code/roster changes (git diff --stat origin/main...HEAD = 1 file). A docs-only diff cannot change the evaluation of a .dag witness, so this is an inherited red from main: the #5445 realization_vocabulary_containment hand-frozen roster rotting until warm-lark's roster fix lands (dissolve-on warm-badger-46). Confirmed with the owning lane (quick-ant-298), which explicitly scoped this out: "that's not #5451's content, don't chase it."

No fix pushed (a docs-only PR has nothing to fix here, and a no-op push would only stale the standing approval). Holding frozen at merge-ready pending the inherited red clearing on main + a 2nd review.

— sent from snappy-gull-450

@gunbai-bot

gunbai-bot Bot commented Jun 21, 2026

Copy link
Copy Markdown
Contributor Author

CI red investigated — inherited from main, not this PR.

Failing witnesses: corpus_live_anchored_modules_clean_holds / corpus_live_clean_tree_holds / extdeps_external_authority_gate_passes (the extdeps external-authority anchor lens, batch 2).

This is a different red from the earlier #5445 one — it appeared after the auto-merge of origin/main (58b2135) pulled in #5452 (std.encoding: declare utf8_decode_bytes ... wire import in secret_manager.dag), which adds dsl/std/encoding.dag and rewires the extdeps module secret_manager.dag that the anchor lens reads live.

Evidence it's inherited: this PR's diff vs main is docs-only — a single file docs/plans/compile-clean-forcecheck.md; the live dsl/extdeps/** tree is byte-identical to main, so this filesystem-read witness returns the same Bool as main. And main is in fact red on it — the #5452 merge commit's own CI run (1bba051f7) concluded failure, as did #5462's.

No fix pushed: a docs-only PR cannot change an extdeps-tree witness, and the fix belongs to #5452's owner (re-green main's anchor lens). Holding frozen; #5451 goes mergeable once main is green again.

— sent from snappy-gull-450

@gunbai-bot

gunbai-bot Bot commented Jun 21, 2026

Copy link
Copy Markdown
Contributor Author

Correction to my prior comment's attribution (the conclusion is unchanged — still an inherited main red, this docs-only PR can't cause or fix it):

The anchor-lens red is #5429 (warm==cold cache purity adds dsl/extdeps/realization/cache_purity.dag, which doesn't conform to the extdeps anchor gate), not #5452. Bisect (per the owning lane): main was green at 14:44, #5429 merged 15:04 = first failure, #5452 merged 15:17 into already-red main (it only modifies secret_manager.dag with +1 import — can't un-anchor an already-anchored module). So the fix is owned by zesty-crane-172 (conform cache_purity.dag to the anchor gate), not #5452's author. #5451 stays frozen; mergeable once that lands and main re-greens.

— sent from snappy-gull-450

@briansrls
briansrls merged commit a1a68bb into main Jun 21, 2026
1 check failed
@briansrls
briansrls deleted the session/snappy-gull-450 branch June 21, 2026 16:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant