Skip to content

Flip intent-linearity to live enforcement via the import-graph representation (consumed-input-closure drift wall + ImportGraph LinearityRule) - #5669

Merged
briansrls merged 9 commits into
mainfrom
session/swift-bat-896
Jun 24, 2026
Merged

briansrls merged 9 commits into
mainfrom
session/swift-bat-896

Conversation

@briansrls

@briansrls briansrls commented Jun 23, 2026 •

Copy link
Copy Markdown
Contributor

Flip intent-linearity to live enforcement via the import-graph representation

Makes v2.lens.intent_linearity enforce a real wall over the live corpus for the first time (it was previously only unit-tested over synthetic Node chains), via the import-graph representation: a module's declared inputs should be 1:1 with the inputs it actually consumes — redundancy = declared − minimal, and the wall is declared == derived.

D1 — the wall, NOW (src/v1/tests/src/consumed_input_closure_drift_test.rs)

dsl/tools/rust_stage0_gates.dag hand-declares declared_consumed_input_closures and admits the fail-open itself (slice1_status: "HAND-LISTED ... declaration drift silently re-opens the .dag→rust fail-open"). That declared list is pure parallel representation of a value the compiler already derives — the transitive import-graph closure.

The drift oracle reads the declared closure straight from the .dag (eval_data_item_value), derives each unit's closure with the existing resolve_imports_transitively_with_source_roots, and asserts the two path sets are equal over the live corpus. This closes the admitted fail-open today.

D2 — the lens goes live (modeled) (src/v2/lens/intent_linearity.dag)

  • Representation gains a 3rd variant ImportGraph beside TermChain/TypeForest.
  • New ParallelRepresentationRule family whose verdict is a populated ConstructionClass (reused from construction_justification.dag, not minted — a parallel-representation lens that minted its own copy of the §5 trichotomy would be the bug it detects). import_graph_rule = WallNow naming resolve_imports_transitively.
  • closure_is_clean dispatches on the class: WallNow drift = hard violation; WallAfterGrounding / RatchetForever drift = tracked, not failed — so an honestly-marked shrinking scaffold (e.g. an exception roster) is never falsely flagged. This is the §5-bound demonstrated on real corpus rows.
  • Registry-wired (closure_is_clean_for_representation folds the registry — not an inert one-row table). lens_unit witnesses (import_graph_test.dag, 9 test fn, all green by execution) cover both drift directions, set-not-list-order, and the trichotomy dispatch.

Scope fence (honored)

The ConsumedInputClosure type and its values are untouched; migrating should_run_gates() to derive from the import graph is separate work blocked on the same seam.

Tier-2 (named dissolution trigger, escalated separately)

Making the .dag row itself live (so import_closure_is_clean reads derived from a real .dag walk instead of a host-projected ClosureFact) needs the import-graph walk grounded .dag-callable through the host-read seam — load-bearing operator-seeded plumbing (#5241/#5603). Per the model-first checkpoint discipline this is routed to the operator (via witty-crane-380); the WallNow.construction String names the walk and promotes to a live fn field when the seam grounds. The Rust drift oracle (D1) is the live-corpus discriminating witness in the meantime.

🤖 Generated with Claude Code

Brian Searls and others added 3 commits June 23, 2026 19:56
… drift wall

D1 (wall now): Rust drift oracle (consumed_input_closure_drift_test.rs) asserts
each declared ConsumedInputClosure equals its transitive import-graph closure
over the live corpus, closing the admitted slice1_status fail-open. Discriminating
in both directions (drop-path under-declared / bogus-add over-declared -> red).

D2 (modeled lens): Representation gains ImportGraph; ParallelRepresentationRule
family carries a populated ConstructionClass verdict (reused, not minted) so a
WallNow drift is a hard violation while a WallAfterGrounding/RatchetForever drift
is tracked, not failed. Registry-wired via closure_is_clean_for_representation;
lens_unit witnesses both drift directions, set-not-order, and the trichotomy
dispatch. Tier-2 (live .dag walk) named as the dissolution trigger.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review June 23, 2026 20:18
Brian Searls and others added 2 commits June 23, 2026 20:49
…chor binding name

extdeps.ctrl.jobserver (added by #5650) declared its ExternalAuthority as
data ctrl_jobserver_authority, but the extdeps_external_authority gate scans for
a data item named exactly extdeps_external_authority_anchor (every other extdeps
module conforms). The author-provided Https authority URI is correct; only the
binding name was off, so the gate read the anchor as missing -> RED. Main CI was
severely backlogged (runs queued >1h) so main's tip shipped this red unvalidated.
Rename to the recognized convention (value unchanged); no other reference to the
old name. Heals the gate on this PR's merge.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@briansrls
briansrls merged commit ec34d05 into main Jun 24, 2026
2 checks passed
@briansrls
briansrls deleted the session/swift-bat-896 branch June 24, 2026 13:19
briansrls added a commit that referenced this pull request Jun 24, 2026
…ure_is_clean_live over module_graph.import_closure_live) [stacked on #5669] (#5703)

* WIP: Flip intent-linearity to live enforcement via the import-graph represent

* WIP: Flip intent-linearity to live enforcement via the import-graph represent

* intent-linearity: ImportGraph representation + consumed-input-closure drift wall

D1 (wall now): Rust drift oracle (consumed_input_closure_drift_test.rs) asserts
each declared ConsumedInputClosure equals its transitive import-graph closure
over the live corpus, closing the admitted slice1_status fail-open. Discriminating
in both directions (drop-path under-declared / bogus-add over-declared -> red).

D2 (modeled lens): Representation gains ImportGraph; ParallelRepresentationRule
family carries a populated ConstructionClass verdict (reused, not minted) so a
WallNow drift is a hard violation while a WallAfterGrounding/RatchetForever drift
is tracked, not failed. Registry-wired via closure_is_clean_for_representation;
lens_unit witnesses both drift directions, set-not-order, and the trichotomy
dispatch. Tier-2 (live .dag walk) named as the dissolution trigger.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Fix main-red inherited via merge: jobserver.dag external-authority anchor binding name

extdeps.ctrl.jobserver (added by #5650) declared its ExternalAuthority as
data ctrl_jobserver_authority, but the extdeps_external_authority gate scans for
a data item named exactly extdeps_external_authority_anchor (every other extdeps
module conforms). The author-provided Https authority URI is correct; only the
binding name was off, so the gate read the anchor as missing -> RED. Main CI was
severely backlogged (runs queued >1h) so main's tip shipped this red unvalidated.
Rename to the recognized convention (value unchanged); no other reference to the
old name. Heals the gate on this PR's merge.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Tier-2: ground the import closure in .dag — module_declaration_facts bui

* WIP: Tier-2: ground the import closure in .dag — module_declaration_facts bui

* Tier-2 step 3: mark Tier-2 landed in intent_linearity rationale + live witness

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Shape B: dissolve ClosureFact.derived carrier + fact-predicate (witty-crane §3)

Remove the stored ClosureFact.derived field and import_closure_is_clean(fact):
a stored derived field is the redundant second authority the promotion
dissolves, and a writable host-fact carrier is the fail-open. closure_is_clean
becomes a pure dispatch kernel over (rule, declared, derived) lists;
import_closure_is_clean_live is the SOLE tree-level authority (derives via
import_graph_rule.derive). Synthetic lens_unit feeds literal lists to the kernel
(class-dispatch seam). Green by execution: live 3/3, synthetic 9/9.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant