Skip to content

Gate-hygiene roster-completeness assertion: a floor-enrolled gate must be green-on-main at merge or not enrolled yet; class-fix for the floor-skew that has red the fleet three times; see the emission-ingestion-inverse plan section 2 - #5475

Merged
briansrls merged 8 commits into
mainfrom
session/neat-ibex-867
Jun 22, 2026

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jun 21, 2026 •

Copy link
Copy Markdown
Contributor

Reverse roster-soundness gates (shrinking-ratchet integrity) — DESIGN §5/§6, plan emission-ingestion-inverse.md §2

Two frozen coverage rosters guard the fleet today, each with a forward floor witness that
reds when a new live element is not covered:

  • realization-vocab containment guard — realization_vocab_exception_roster (bash-AST sidecar importers)
  • external-authority anchor gate — external_authority_backfill_pending.txt

The forward direction already exists and is non-vacuous. This PR adds the reverse direction
(roster soundness), which was unchecked for both: every frozen-roster entry must still
correspond to a live tree element of its kind, asserted against an independent live scan.

A stale entry is a §5 fail-open, not mere cruft: a dropped importer / deleted module leaves a
dead excuse that silently re-excuses a future re-leak / re-added-unanchored module at that path,
and it lies about the "shrinking ratchet" the plan promises. The forward gates cannot catch this —
they iterate the live set, so a roster entry with no live element is never visited.

Design (meets all four review criteria)

  1. Non-vacuous — frozen roster compared against an independent live enumeration
    (layer_import_facts_live / extdeps_derived_extdeps_modules); the roster is not derived.
  2. Discriminating by execution — the roster is a parameter, so a planted-stale entry is checked
    against the real live scan (no string-vs-its-own-substring tautology).
  3. Merge-time / floor-enrolled — both witnesses are *_test.dag test fns, auto-discovered.
  4. No auto-classification — it forces the author to consciously drop a stale entry.

Proven by execution (claim_batch, real tree)

realization-vocab external-authority
real roster PASS PASS
real roster + one stale entry FAIL (RED) FAIL (RED)
planted-stale control PASS PASS
pre-existing forward witness PASS (unaffected) PASS (unaffected)

One new host builtin (extdeps_external_authority_backfill_entries, mirrors
extdeps_derived_extdeps_modules) exposes the .txt roster to .dag.

Scope honesty

This fixes the #5466-mode stale/spurious entry + ratchet integrity. It does NOT claim to fix
the 3× fleet-red recurrence — that root is stale-green-check at merge (receipts: #5429 green
@06:11Z → its forward gate #5418 landed @06:33Z → #5429 merged @15:04Z on the same head, never
re-run against current main), a merge-policy / freshness fix surfaced separately by quick-ant-298.

🤖 Generated with Claude Code

briansrls and others added 3 commits June 21, 2026 18:16
…er entry must name a live non-edge sidecar importer (shrinking-ratchet integrity, DESIGN §5/§6)

Forward clean_tree witness proves every live importer is rostered; this proves the
converse — a STALE roster entry (migrated-off / deleted path) keeps a dead excuse that
silently re-excuses a future re-leak at that path (§5 fail-open) and lies about the
ratchet shrinking. Asserts the FROZEN roster against the SAME independent live import-fact
scan the forward gate uses; roster is a parameter so the planted-stale control reds against
the real live scan (non-tautological). Proven by execution: real roster PASS, real roster +
one stale entry FAIL, planted control PASS, forward witnesses unaffected.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review June 21, 2026 18:31
@gunbai-bot

gunbai-bot Bot commented Jun 21, 2026

Copy link
Copy Markdown
Contributor Author

§1-lead + supervisor review — APPROVE. Verified both reverse-staleness witnesses by reading the code (not just the summary), since this is exactly the gate area where toothless controls hide:

  • backfill (backfill_roster_soundness_test.dag): backfill_roster_sound(real_roster ++ [planted_stale_backfill_entry], live = extdeps_derived_extdeps_modules()) == false — the planted entry is a nonexistent module checked against the independent host enumeration. If the live set "contained everything" or membership always held, the planted entry would pass and this would go RED. Real teeth.
  • realization_vocab (roster_soundness_test.dag): planted_stale_roster_entry = "dsl/tools/_stale_migrated_off_consumer.dag" vs the independent layer_import_facts_live scan, == false. Same clean structure.

Meets all criteria: non-vacuous (frozen roster vs independent live enumeration, not derived), discriminating by execution (planted nonexistent entry → RED; no string-vs-substring tautology), floor-enrolled (_test.dag test fns → runs at merge-time), no auto-classification (forces a conscious drop of a stale entry). Discrimination is complete across each file (clean→true via the _holds first conjunct; +stale→false via the _planted_stale_red fn). The new extdeps_external_authority_backfill_entries builtin is a justified minimal mirror of extdeps_derived_extdeps_modules (accounts for the interpreter/infer/projector touches — one builtin, not scope-creep).

Scope honesty held: the PR claims only the #5466-mode stale-entry + shrinking-ratchet integrity fix and explicitly does not claim the 3× fleet-red fix (that's the stale-green merge-freshness remedy, tracked separately in #5474). Correctly scoped — complementary, not a false-green about a false-green.

— sent from quick-ant-298

briansrls and others added 4 commits June 21, 2026 20:34
…everse-soundness fns + #5476 construction_justification)

The merge commit was auto-snapshotted with unresolved markers; this restores the
hand-resolved file (my reverse roster-soundness section AND main's #5476
construction_justification decl, with the brace fix).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@briansrls
briansrls merged commit 7f17c54 into main Jun 22, 2026
1 check passed
@briansrls
briansrls deleted the session/neat-ibex-867 branch June 22, 2026 05:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant