Repository navigation
Flip intent-linearity to live enforcement via the import-graph representation (consumed-input-closure drift wall + ImportGraph LinearityRule) - #5669
Merged
Conversation
… drift wall D1 (wall now): Rust drift oracle (consumed_input_closure_drift_test.rs) asserts each declared ConsumedInputClosure equals its transitive import-graph closure over the live corpus, closing the admitted slice1_status fail-open. Discriminating in both directions (drop-path under-declared / bogus-add over-declared -> red). D2 (modeled lens): Representation gains ImportGraph; ParallelRepresentationRule family carries a populated ConstructionClass verdict (reused, not minted) so a WallNow drift is a hard violation while a WallAfterGrounding/RatchetForever drift is tracked, not failed. Registry-wired via closure_is_clean_for_representation; lens_unit witnesses both drift directions, set-not-order, and the trichotomy dispatch. Tier-2 (live .dag walk) named as the dissolution trigger. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…chor binding name extdeps.ctrl.jobserver (added by #5650) declared its ExternalAuthority as data ctrl_jobserver_authority, but the extdeps_external_authority gate scans for a data item named exactly extdeps_external_authority_anchor (every other extdeps module conforms). The author-provided Https authority URI is correct; only the binding name was off, so the gate read the anchor as missing -> RED. Main CI was severely backlogged (runs queued >1h) so main's tip shipped this red unvalidated. Rename to the recognized convention (value unchanged); no other reference to the old name. Heals the gate on this PR's merge. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Jun 24, 2026
…ure_is_clean_live over module_graph.import_closure_live) [stacked on #5669] (#5703) * WIP: Flip intent-linearity to live enforcement via the import-graph represent * WIP: Flip intent-linearity to live enforcement via the import-graph represent * intent-linearity: ImportGraph representation + consumed-input-closure drift wall D1 (wall now): Rust drift oracle (consumed_input_closure_drift_test.rs) asserts each declared ConsumedInputClosure equals its transitive import-graph closure over the live corpus, closing the admitted slice1_status fail-open. Discriminating in both directions (drop-path under-declared / bogus-add over-declared -> red). D2 (modeled lens): Representation gains ImportGraph; ParallelRepresentationRule family carries a populated ConstructionClass verdict (reused, not minted) so a WallNow drift is a hard violation while a WallAfterGrounding/RatchetForever drift is tracked, not failed. Registry-wired via closure_is_clean_for_representation; lens_unit witnesses both drift directions, set-not-order, and the trichotomy dispatch. Tier-2 (live .dag walk) named as the dissolution trigger. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Fix main-red inherited via merge: jobserver.dag external-authority anchor binding name extdeps.ctrl.jobserver (added by #5650) declared its ExternalAuthority as data ctrl_jobserver_authority, but the extdeps_external_authority gate scans for a data item named exactly extdeps_external_authority_anchor (every other extdeps module conforms). The author-provided Https authority URI is correct; only the binding name was off, so the gate read the anchor as missing -> RED. Main CI was severely backlogged (runs queued >1h) so main's tip shipped this red unvalidated. Rename to the recognized convention (value unchanged); no other reference to the old name. Heals the gate on this PR's merge. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Tier-2: ground the import closure in .dag — module_declaration_facts bui * WIP: Tier-2: ground the import closure in .dag — module_declaration_facts bui * Tier-2 step 3: mark Tier-2 landed in intent_linearity rationale + live witness Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Shape B: dissolve ClosureFact.derived carrier + fact-predicate (witty-crane §3) Remove the stored ClosureFact.derived field and import_closure_is_clean(fact): a stored derived field is the redundant second authority the promotion dissolves, and a writable host-fact carrier is the fail-open. closure_is_clean becomes a pure dispatch kernel over (rule, declared, derived) lists; import_closure_is_clean_live is the SOLE tree-level authority (derives via import_graph_rule.derive). Synthetic lens_unit feeds literal lists to the kernel (class-dispatch seam). Green by execution: live 3/3, synthetic 9/9. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Flip intent-linearity to live enforcement via the import-graph representation
Makes
v2.lens.intent_linearityenforce a real wall over the live corpus for the first time (it was previously only unit-tested over syntheticNodechains), via the import-graph representation: a module's declared inputs should be 1:1 with the inputs it actually consumes — redundancy =declared − minimal, and the wall isdeclared == derived.D1 — the wall, NOW (
src/v1/tests/src/consumed_input_closure_drift_test.rs)dsl/tools/rust_stage0_gates.daghand-declaresdeclared_consumed_input_closuresand admits the fail-open itself (slice1_status: "HAND-LISTED ... declaration drift silently re-opens the .dag→rust fail-open"). That declared list is pure parallel representation of a value the compiler already derives — the transitive import-graph closure.The drift oracle reads the declared closure straight from the
.dag(eval_data_item_value), derives each unit's closure with the existingresolve_imports_transitively_with_source_roots, and asserts the two path sets are equal over the live corpus. This closes the admitted fail-open today..dagimport tripsshould_run_gatesedge-(b) closure-hit → fires the rust gate → the new import surfaces as under-declared drift. The same Edge-(b) coverage keystone — slice 1: declare coproduct_reflection_conformance_test's consumed-.dag closure on the existing NodeArtifactProvenance carrier + fire should_run_gates on a closure-path change (fail-closed: undeclared test = must-run), proven green-by-execution with a discriminating contr #5605 mechanism the declaration feeds guarantees the wall fires when the closure's inputs move.v1-compiler-tests(run-all, Widen the rust gate by construction (§1): invert the hand-picked 3-filter allowlist (29 of 792 green tests) → run-all-unless-#[ignore]d-with-written-reason; add CI-coverage-completeness so a new test is covered by default (fail-closed); measure CI-time impact before committing the full set #5427), and.rs/closure-hit both fire the rust gate.D2 — the lens goes live (modeled) (
src/v2/lens/intent_linearity.dag)Representationgains a 3rd variantImportGraphbesideTermChain/TypeForest.ParallelRepresentationRulefamily whose verdict is a populatedConstructionClass(reused fromconstruction_justification.dag, not minted — a parallel-representation lens that minted its own copy of the §5 trichotomy would be the bug it detects).import_graph_rule=WallNownamingresolve_imports_transitively.closure_is_cleandispatches on the class: WallNow drift = hard violation; WallAfterGrounding / RatchetForever drift = tracked, not failed — so an honestly-marked shrinking scaffold (e.g. an exception roster) is never falsely flagged. This is the §5-bound demonstrated on real corpus rows.closure_is_clean_for_representationfolds the registry — not an inert one-row table). lens_unit witnesses (import_graph_test.dag, 9test fn, all green by execution) cover both drift directions, set-not-list-order, and the trichotomy dispatch.Scope fence (honored)
The
ConsumedInputClosuretype and its values are untouched; migratingshould_run_gates()to derive from the import graph is separate work blocked on the same seam.Tier-2 (named dissolution trigger, escalated separately)
Making the
.dagrow itself live (soimport_closure_is_cleanreadsderivedfrom a real.dagwalk instead of a host-projectedClosureFact) needs the import-graph walk grounded.dag-callable through the host-read seam — load-bearing operator-seeded plumbing (#5241/#5603). Per the model-first checkpoint discipline this is routed to the operator (via witty-crane-380); theWallNow.constructionString names the walk and promotes to a live fn field when the seam grounds. The Rust drift oracle (D1) is the live-corpus discriminating witness in the meantime.🤖 Generated with Claude Code