Skip to content

v1 resolve cache: always-on via temp_dir default (drop env-var gate) - #5789

Merged
briansrls merged 16 commits into
mainfrom
session/calm-carp-204
Jun 25, 2026
Merged

briansrls merged 16 commits into
mainfrom
session/calm-carp-204

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

What

GUNBC_RESOLVED_GRAPH_CACHE_DIR was introduced in #4878 but never wired into CI, so the resolved-graph cache was silently off everywhere. This drops the env-var gate: the cache now defaults to $TMPDIR/gunbc-rg-cache, with GUNBC_RESOLVED_GRAPH_CACHE_DIR still accepted as an override for explicit placement.

Why

Without the cache, resolve_entry_with_parse_cache re-runs the full v1 type inference pipeline for every unique *_test.dag entry in the discovery corpus — even though 95%+ of each closure (std/, extdeps/) is shared across entries. Profiling on the post-#5757 baseline showed 447,734ms serial resolve total across 1011 witnesses (~443ms/entry). With the cache on, each unique closure resolves once and is reused.

Correctness

Cache key = content-hash(closure sources) + content-hash(compiler binary). Invalidates correctly on any source or compiler change. Existing falsifiers from #4878 cover cold-oracle equivalence, poisoned-hit rejection, WriteOnce concurrency, and key-mismatch miss.

Impact

Eliminates most of the 447s resolve serial sum in the CI floor corpus run. Secondary effect: per-shard peak RSS drops (no large type-checked AST graphs held per shard), which will unlock a higher corpus evaluation width via the memory-aware spawn-width formula on next re-measurement.

Brian Searls and others added 8 commits June 24, 2026 19:10
call_function re-derived each parameter's authored name by re-slicing the
source span (authored_name_at) on every call — invariant per fn_node but
recomputed per call, so inside folds/loops it repeated per iteration. This
was the dominant ExprCall self-time in the CI floor's eval phase.

Memoize the derivation in a per-InterpContext cache keyed by fn_node pointer
identity — sound because the ctx owns fn_nodes (pointers stable for the
cache's lifetime, cache dies with the ctx), the same discipline as the
existing data_cache. Behavior is identical (same node-eval counts, same
witness results).

Measured on ci_yaml_serializer_keystone (505k node-evals): ExprCall self-time
255ms->126ms (-51%), total witness eval 602ms->408ms (-32%). Full floor
(975 witnesses) green, eval phase 1428s->981s.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Follow-on to the per-call param-name cache. The same chokepoint (authored_name_at
re-slicing a name from its source span, then ctx.sym re-interning it) was hit on
every ExprVar read and every call's callee-name resolution:

- eval_var: cache the resolved Symbol per ExprVar node (var_sym_cache); eval then
  skips the slice + re-intern and goes straight to env.lookup(sym). Keyword/variant
  checks use ctx.sym_eq on the cached symbol; the name String is materialized lazily
  only on the registry slow path.
- eval_call: cache the decoded callee name per call node (call_func_name_cache).
- call_function: slice each param name once into ;  reuses it instead
  of re-slicing (addresses review note on redundant per-param slicing).

All caches are per-InterpContext fields keyed by node pointer identity — sound for
the ctx lifetime, the same discipline as data_cache/param_name_cache. Behavior is
identical: same node-eval counts, same witness results.

Measured on ci_yaml_serializer_keystone (505,325 node-evals, vs the param-only base):
ExprVar self-time 82ms->29ms (-64%), ExprCall 126ms->106ms; cumulative witness eval
602ms->322ms (-47%) across both commits. node-eval count unchanged (correctness).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
GUNBC_RESOLVED_GRAPH_CACHE_DIR still overrides the path; without it the
cache defaults to $TMPDIR/gunbc-rg-cache. Eliminates the 447s resolve
serial sum in the CI floor corpus run — type inference for each unique
closure now runs once and is reused across all witnesses sharing that
closure.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Brian Searls and others added 3 commits June 25, 2026 02:11
Four-node plan for making spawn_width self-calibrating from
per-shard measured RSS rather than a static data row:
- Node A: measurement plumbing (claim_batch emit, claim_executor collect)
- Node B: CostEstimate.space on Runnable in std substrate
- Node C: width derivation moves into scheduler, side-channel deleted
- Node D: calibration loop retires static data rows

Also updates ROADMAP §1 scheduling band (new resource-aware bullet)
and §2 P3/P4 (resolve-cache always-on via #5789, P4 space+time arms).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
typescript_import_emit_by_execution_test.dag, typescript.dag, and
target_model.dag exist on main but were absent/different on this
session branch — restoring to match origin/main so the PR does not
delete them on merge.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor Author

Addressing the two findings:

TypeScript files (scope creep): The TS files the reviewer saw are no longer in the diff — they were restorations, not additions. The session branch had accidentally dropped them (stale base), and the restoration commit pushed after the prior review brought them back to match main exactly. The current diff shows only the three Rust files + plan/ROADMAP session overhead.

temp_dir trust model: Correct observation. Adding a follow-up code comment is the right move rather than a code change now. The content-addressed key is the load-bearing purity guarantee; the world-writable path is a permission-error risk at worst (already fail-soft via let _ =). Will add a one-liner in the next pass.

Plan doc bundling: Acknowledged — the resource-aware-scheduler.md and ROADMAP edits are session-branch overhead that will squash-merge with the cache change. Noted for future PRs.

— sent from calm-carp-204

Brian Searls and others added 3 commits June 25, 2026 03:17
Design converged 2026-06-25 with sharp-stag-782: PerformanceReceipt.cost:
CostAccount<Nano> is the single measured authority for Time+Space+Energy.
The [calibration]/[measurement] text lines are Lossless transport projections
of that receipt, not the authority themselves. wall_duration removed as stored
field; becomes a pure projection fn. cache_state_summary stays top-level (it
is a measurement-context tag, not a cost axis). nimble-tern-908 authors the
shape PR; #5792 (gentle-newt-542) carries the Rust plumbing.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…oadmap

Derivation is the authority (CostBasis.Predicted); measurement is the
§5 falsifier + physical-constant calibration (CostBasis.Measured).
P0/P1 decouple cleanly: P0 = PerformanceReceipt.cost shape (nimble-tern
#5798), P1 = InputEnvelope (sharp-stag-782), both parallel. P2 symbolic-
cost fold follows P1; P3 min_bytes dissolve after P0; P4 BestEffort width
swaps static row for Predicted once P2 ships; P5 falsifier compares.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor Author

On the temp-dir uid-collision finding: confirmed the risk is real on multi-user hosts. In our CI context it is not a factor — runners are ephemeral single-user containers, so no concurrent users can race on the dir. The GUNBC_RESOLVED_GRAPH_CACHE_DIR env var override is the escape hatch for any shared-host setup. I'll track XDG-based namespacing ($XDG_CACHE_HOME/gunbc/rg-cache → $HOME/.cache/gunbc/rg-cache → temp fallback) as a follow-up once this lands.

On the bundled TS/ROADMAP files: those were stale-base restorations from a prior merge divergence (the session branch predated those files landing on main). The merge-main commit pushed just now cleans the diff to the 4 intended files: resolved_graph_cache.rs, cli_run.rs, ROADMAP.md, and the plan doc.

— sent from calm-carp-204

@gunbai-bot

gunbai-bot Bot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor Author

Addressed finding #1 (uid collision): cache dir now suffixed with USER/USERNAME env var → gunbc-rg-cache-${user} per user, so shared-host /tmp installs don't collide on EACCES.

On finding #2 (bundled smoke test fix): not a drive-by. The prior CI run on this PR (28145032701) failed rust_tests at html_markup_smoke_runs_green because PR #5787 updated html_markup_smoke.dag to import extdeps.languages.html but didn't update the Rust test runner's source root list. The breakage was latent on main because main's CI gate short-circuits when no Rust files changed (fast path, doesn't run the full nextest suite). Our branch's Rust file changes triggered the full gate and exposed it. The fix had to ship on this branch or CI would stay red.

— sent from calm-carp-204

@briansrls
briansrls merged commit 6a9b0c3 into main Jun 25, 2026
1 of 2 checks passed
@briansrls
briansrls deleted the session/calm-carp-204 branch June 25, 2026 04:41
briansrls pushed a commit that referenced this pull request Jun 25, 2026
…tes) derives width from live cgroup budget (#5825)

* v1 interp: memoize per-call parameter-name resolution (ctx-owned cache)

call_function re-derived each parameter's authored name by re-slicing the
source span (authored_name_at) on every call — invariant per fn_node but
recomputed per call, so inside folds/loops it repeated per iteration. This
was the dominant ExprCall self-time in the CI floor's eval phase.

Memoize the derivation in a per-InterpContext cache keyed by fn_node pointer
identity — sound because the ctx owns fn_nodes (pointers stable for the
cache's lifetime, cache dies with the ctx), the same discipline as the
existing data_cache. Behavior is identical (same node-eval counts, same
witness results).

Measured on ci_yaml_serializer_keystone (505k node-evals): ExprCall self-time
255ms->126ms (-51%), total witness eval 602ms->408ms (-32%). Full floor
(975 witnesses) green, eval phase 1428s->981s.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* v1 interp: extend symbol-reuse memoization to ExprVar and callee names

Follow-on to the per-call param-name cache. The same chokepoint (authored_name_at
re-slicing a name from its source span, then ctx.sym re-interning it) was hit on
every ExprVar read and every call's callee-name resolution:

- eval_var: cache the resolved Symbol per ExprVar node (var_sym_cache); eval then
  skips the slice + re-intern and goes straight to env.lookup(sym). Keyword/variant
  checks use ctx.sym_eq on the cached symbol; the name String is materialized lazily
  only on the registry slow path.
- eval_call: cache the decoded callee name per call node (call_func_name_cache).
- call_function: slice each param name once into ;  reuses it instead
  of re-slicing (addresses review note on redundant per-param slicing).

All caches are per-InterpContext fields keyed by node pointer identity — sound for
the ctx lifetime, the same discipline as data_cache/param_name_cache. Behavior is
identical: same node-eval counts, same witness results.

Measured on ci_yaml_serializer_keystone (505,325 node-evals, vs the param-only base):
ExprVar self-time 82ms->29ms (-64%), ExprCall 126ms->106ms; cumulative witness eval
602ms->322ms (-47%) across both commits. node-eval count unchanged (correctness).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: CI profiling

* v1 resolve cache: always-on via temp_dir default (drop env-var gate)

GUNBC_RESOLVED_GRAPH_CACHE_DIR still overrides the path; without it the
cache defaults to $TMPDIR/gunbc-rg-cache. Eliminates the 447s resolve
serial sum in the CI floor corpus run — type inference for each unique
closure now runs once and is reused across all witnesses sharing that
closure.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* WIP: CI profiling

* Scope resource-aware scheduler (nodes A-D) + ROADMAP update

Four-node plan for making spawn_width self-calibrating from
per-shard measured RSS rather than a static data row:
- Node A: measurement plumbing (claim_batch emit, claim_executor collect)
- Node B: CostEstimate.space on Runnable in std substrate
- Node C: width derivation moves into scheduler, side-channel deleted
- Node D: calibration loop retires static data rows

Also updates ROADMAP §1 scheduling band (new resource-aware bullet)
and §2 P3/P4 (resolve-cache always-on via #5789, P4 space+time arms).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* Restore foreign files reverted by stale branch base

typescript_import_emit_by_execution_test.dag, typescript.dag, and
target_model.dag exist on main but were absent/different on this
session branch — restoring to match origin/main so the PR does not
delete them on merge.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* resource-aware-scheduler plan: lock PerformanceReceipt as cost authority

Design converged 2026-06-25 with sharp-stag-782: PerformanceReceipt.cost:
CostAccount<Nano> is the single measured authority for Time+Space+Energy.
The [calibration]/[measurement] text lines are Lossless transport projections
of that receipt, not the authority themselves. wall_duration removed as stored
field; becomes a pure projection fn. cache_state_summary stays top-level (it
is a measurement-context tag, not a cost axis). nimble-tern-908 authors the
shape PR; #5792 (gentle-newt-542) carries the Rust plumbing.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* resource-aware-scheduler plan: add cost-authority re-role and P0-P6 roadmap

Derivation is the authority (CostBasis.Predicted); measurement is the
§5 falsifier + physical-constant calibration (CostBasis.Measured).
P0/P1 decouple cleanly: P0 = PerformanceReceipt.cost shape (nimble-tern
#5798), P1 = InputEnvelope (sharp-stag-782), both parallel. P2 symbolic-
cost fold follows P1; P3 min_bytes dissolve after P0; P4 BestEffort width
swaps static row for Predicted once P2 ships; P5 falsifier compares.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* WIP: CI profiling

* WIP: CI profiling

* WIP: CI profiling

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jun 25, 2026
…g ROADMAP drift

Two changes that make the runner converge an enforced single-authority artifact
the operator can run, and clear the drift gate that was reding main CI.

1. FleetConvergeArtifact: NotCommitted -> CommitRequired { consumer: HostReconciler }.
   The emitted .github/fleet-converge.sh is now committed and drift-gated: edit the
   .dag and the committed script must regenerate to match, else CI reds. This is the
   "changes actually take effect" reconciler - the gate is the change-detector; the
   ssh-apply is the action. Gitignore auto-drops the ignore line (it filters on
   !artifact_is_committed). generated_artifact_drift_test updated: HostReconciler arm
   added to the consumer match (exhaustiveness), commit-policy/ignore assertions
   flipped to committed.

2. ROADMAP.md drift (pre-existing on main, unrelated to the converge work): the
   committed ROADMAP carried newer scheduler/cache profiling status (resource-aware
   spawn_width nodes A-D, #5789 always-on resolve-cache) that was hand-edited without
   modeling into roadmap_authority.dag - the #5745/#5813-class single-authority
   violation. Healed by modeling that content INTO the authority (add 1-sched-resource-aware
   row, update 1-caching-forked / 2-p3 / 2-p4), so emit == committed with no revert
   of the profiling content.

Drift gate now ExitSuccess; all generated-artifact + roadmap + runner-placement
witnesses green by execution.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 25, 2026
…wap-off) + drift-gate heal (#5827)

* WIP: CI profiling

* Runner converge: model MemorySwapMax=0 swap-off safety knob

Adds the missing crash-prevention property to the runner converge:
- extdeps/os/systemd: systemd_memory_swap_max_property = "MemorySwapMax"
- host_converge: per-slot swap-off knob (PerSlotMemoryCap, value 0) on a
  dedicated 30-fleet-swap.conf drop-in, paired with the existing MemoryMax cap.

Swap-off is the property that converts a host livelock (swap-thrash -> reboot,
the srv2 vector) into a scoped cgroup OOM-kill: an over-budget CI job dies, the
host survives. The knob is INERT until gunbc_ci_runner_slot_enforcement flips
from RunnerSlotUnenforced -> RunnerSlotEnforced (the converge emit is fail-closed
behind that gate; see ci_runner_placement.dag:313).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: CI profiling

* Host allocation: conservation model (declared pools + node_conserves)

Replaces the 'whole host -> runners' residual + the chicken-and-egg
RunnerSlotUnenforced gate with a declared-partition conservation model:

  host_total  >=  runner_pool + session_pool + fixed_overhead + headroom

- gunbc_runner_pool_budget = 80 GiB (declared intent, was residual)
- gunbc_per_runner_memory_cap = 8 GiB (declared)  => declared_runner_count() = 10
- gunbc_session_container_memory = 1 GiB (uniform session demand class, ctrl-aligned)
- host_allocation_conserves() = node_conserves over the partition (primitive already
  in product/budget_tree.dag); over-commit ANY pool -> Unsound with a located reason.
- max_concurrent_sessions(pool) = floor(pool / 1 GiB), the ctrl admission bound.

Soundness becomes declared-math conservation; 'is the cap live' moves to the converge
receipt (no circular lock). Session pool is the uniform 1 GiB/1 core/swap-off/pids-4096
envelope agreed with ctrl (keen-dove-772) for session-dashboard container spawns.

5 witnesses green by execution (host_allocation_conservation_test.dag): count==10,
conserves when pools fit, Unsound when runner pool OR sessions over-commit, max
sessions derives from pool.

This is the CORE; cutting the live runner_deployment_plan over to it (rewrites ~4
gate-witnesses) is the next step.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: CI profiling

* Runner placement: cut over to conservation model, rip out the 5-gate fail-closed tangle

The runner deployment plan no longer threads enforcement / oomd / jobserver /
overhead / headroom through a fail-closed cascade premised on a per-slot cap
that is not yet live on the host (the RunnerSlotUnenforced chicken-and-egg: the
converge script that applies the cap refused to emit until the cap was applied).

Plan soundness is now declared-math conservation: runner_count divides the
DECLARED runner_pool_budget by the DECLARED per_runner_memory_cap, and the host
is sound iff host_allocation_conserves (node_conserves over runner_pool +
session_pool + fixed_overhead + headroom <= host RAM). "Is the cap live on the
host" is no longer a plan-soundness question - it is a converge-receipt question
(verdict=converged/drifted/absent), which dissolves the circular lock.

Result: the live fleet converge now emits a SOUND script for srv1+srv2 -
80 GiB runner slice cap, 8 GiB per-slot MemoryMax, MemorySwapMax=0 (swap-off:
converts host livelock into a scoped cgroup OOM-kill), runner_count=10.

- ci_runner_placement.dag: delete RunnerSlotEnforcement gate, JobPeakResolution
  fold, host_runner_count_from_cap, runner_deployment_plan_for; replace with
  host_fixed_overhead_bytes / conservation_host_deployment /
  accumulate_conservation_deployment / runner_deployment_plan. Prune now-unused
  imports.
- runner_placement_witness_test.dag: flip the live-plan witnesses from
  fail-closed to conservation-sound (runner_count==10, per-slot cap==8 GiB,
  within runner pool); keep the session-reservation / operating-curve /
  cpu-weight / manifest witnesses; drop the deleted gate-cascade witnesses.
- fleet_converge_emit_test.dag: replace witness_live_unsound_fails_closed with
  witness_live_converge_is_conservation_sound; assert MemorySwapMax=0 swap-off
  knob in the fixture runner-knobs witness.

All affected witnesses green by execution.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: CI profiling

* Commit fleet-converge.sh (HostReconciler artifact) + heal pre-existing ROADMAP drift

Two changes that make the runner converge an enforced single-authority artifact
the operator can run, and clear the drift gate that was reding main CI.

1. FleetConvergeArtifact: NotCommitted -> CommitRequired { consumer: HostReconciler }.
   The emitted .github/fleet-converge.sh is now committed and drift-gated: edit the
   .dag and the committed script must regenerate to match, else CI reds. This is the
   "changes actually take effect" reconciler - the gate is the change-detector; the
   ssh-apply is the action. Gitignore auto-drops the ignore line (it filters on
   !artifact_is_committed). generated_artifact_drift_test updated: HostReconciler arm
   added to the consumer match (exhaustiveness), commit-policy/ignore assertions
   flipped to committed.

2. ROADMAP.md drift (pre-existing on main, unrelated to the converge work): the
   committed ROADMAP carried newer scheduler/cache profiling status (resource-aware
   spawn_width nodes A-D, #5789 always-on resolve-cache) that was hand-edited without
   modeling into roadmap_authority.dag - the #5745/#5813-class single-authority
   violation. Healed by modeling that content INTO the authority (add 1-sched-resource-aware
   row, update 1-caching-forked / 2-p3 / 2-p4), so emit == committed with no revert
   of the profiling content.

Drift gate now ExitSuccess; all generated-artifact + roadmap + runner-placement
witnesses green by execution.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: CI profiling

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 26, 2026
…se-drift (#5829)

* WIP: CI profiling

* Runner converge: model MemorySwapMax=0 swap-off safety knob

Adds the missing crash-prevention property to the runner converge:
- extdeps/os/systemd: systemd_memory_swap_max_property = "MemorySwapMax"
- host_converge: per-slot swap-off knob (PerSlotMemoryCap, value 0) on a
  dedicated 30-fleet-swap.conf drop-in, paired with the existing MemoryMax cap.

Swap-off is the property that converts a host livelock (swap-thrash -> reboot,
the srv2 vector) into a scoped cgroup OOM-kill: an over-budget CI job dies, the
host survives. The knob is INERT until gunbc_ci_runner_slot_enforcement flips
from RunnerSlotUnenforced -> RunnerSlotEnforced (the converge emit is fail-closed
behind that gate; see ci_runner_placement.dag:313).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: CI profiling

* Host allocation: conservation model (declared pools + node_conserves)

Replaces the 'whole host -> runners' residual + the chicken-and-egg
RunnerSlotUnenforced gate with a declared-partition conservation model:

  host_total  >=  runner_pool + session_pool + fixed_overhead + headroom

- gunbc_runner_pool_budget = 80 GiB (declared intent, was residual)
- gunbc_per_runner_memory_cap = 8 GiB (declared)  => declared_runner_count() = 10
- gunbc_session_container_memory = 1 GiB (uniform session demand class, ctrl-aligned)
- host_allocation_conserves() = node_conserves over the partition (primitive already
  in product/budget_tree.dag); over-commit ANY pool -> Unsound with a located reason.
- max_concurrent_sessions(pool) = floor(pool / 1 GiB), the ctrl admission bound.

Soundness becomes declared-math conservation; 'is the cap live' moves to the converge
receipt (no circular lock). Session pool is the uniform 1 GiB/1 core/swap-off/pids-4096
envelope agreed with ctrl (keen-dove-772) for session-dashboard container spawns.

5 witnesses green by execution (host_allocation_conservation_test.dag): count==10,
conserves when pools fit, Unsound when runner pool OR sessions over-commit, max
sessions derives from pool.

This is the CORE; cutting the live runner_deployment_plan over to it (rewrites ~4
gate-witnesses) is the next step.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: CI profiling

* Runner placement: cut over to conservation model, rip out the 5-gate fail-closed tangle

The runner deployment plan no longer threads enforcement / oomd / jobserver /
overhead / headroom through a fail-closed cascade premised on a per-slot cap
that is not yet live on the host (the RunnerSlotUnenforced chicken-and-egg: the
converge script that applies the cap refused to emit until the cap was applied).

Plan soundness is now declared-math conservation: runner_count divides the
DECLARED runner_pool_budget by the DECLARED per_runner_memory_cap, and the host
is sound iff host_allocation_conserves (node_conserves over runner_pool +
session_pool + fixed_overhead + headroom <= host RAM). "Is the cap live on the
host" is no longer a plan-soundness question - it is a converge-receipt question
(verdict=converged/drifted/absent), which dissolves the circular lock.

Result: the live fleet converge now emits a SOUND script for srv1+srv2 -
80 GiB runner slice cap, 8 GiB per-slot MemoryMax, MemorySwapMax=0 (swap-off:
converts host livelock into a scoped cgroup OOM-kill), runner_count=10.

- ci_runner_placement.dag: delete RunnerSlotEnforcement gate, JobPeakResolution
  fold, host_runner_count_from_cap, runner_deployment_plan_for; replace with
  host_fixed_overhead_bytes / conservation_host_deployment /
  accumulate_conservation_deployment / runner_deployment_plan. Prune now-unused
  imports.
- runner_placement_witness_test.dag: flip the live-plan witnesses from
  fail-closed to conservation-sound (runner_count==10, per-slot cap==8 GiB,
  within runner pool); keep the session-reservation / operating-curve /
  cpu-weight / manifest witnesses; drop the deleted gate-cascade witnesses.
- fleet_converge_emit_test.dag: replace witness_live_unsound_fails_closed with
  witness_live_converge_is_conservation_sound; assert MemorySwapMax=0 swap-off
  knob in the fixture runner-knobs witness.

All affected witnesses green by execution.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: CI profiling

* Commit fleet-converge.sh (HostReconciler artifact) + heal pre-existing ROADMAP drift

Two changes that make the runner converge an enforced single-authority artifact
the operator can run, and clear the drift gate that was reding main CI.

1. FleetConvergeArtifact: NotCommitted -> CommitRequired { consumer: HostReconciler }.
   The emitted .github/fleet-converge.sh is now committed and drift-gated: edit the
   .dag and the committed script must regenerate to match, else CI reds. This is the
   "changes actually take effect" reconciler - the gate is the change-detector; the
   ssh-apply is the action. Gitignore auto-drops the ignore line (it filters on
   !artifact_is_committed). generated_artifact_drift_test updated: HostReconciler arm
   added to the consumer match (exhaustiveness), commit-policy/ignore assertions
   flipped to committed.

2. ROADMAP.md drift (pre-existing on main, unrelated to the converge work): the
   committed ROADMAP carried newer scheduler/cache profiling status (resource-aware
   spawn_width nodes A-D, #5789 always-on resolve-cache) that was hand-edited without
   modeling into roadmap_authority.dag - the #5745/#5813-class single-authority
   violation. Healed by modeling that content INTO the authority (add 1-sched-resource-aware
   row, update 1-caching-forked / 2-p3 / 2-p4), so emit == committed with no revert
   of the profiling content.

Drift gate now ExitSuccess; all generated-artifact + roadmap + runner-placement
witnesses green by execution.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: CI profiling

* WIP: CI profiling

* Converge script: fix set-e abort in membership probe + oomd-limit false-drift

Two bugs surfaced by the operator's live srv1/srv2 run.

BUG A (functional, critical): emit_sessions_membership's `ls -d .../docker-*.scope`
returns non-zero when the glob matches nothing, and under `set -euo pipefail` that
aborted the whole script at the sessions-membership probe — before host_summary and
before the *second host's* entire section ever ran. That's why both runs stopped
after srv1's last sessions knob and the srv2 invocation printed host=srv1 receipts.
Fix: guard both `ls | wc | tr` pipelines with `|| true` (proven: old line exits 2
under set -e, guarded line continues with count 0).

BUG B (receipt lies): systemd stores ManagedOOMMemoryPressureLimit as a fraction of
UINT32_MAX, so `60%` reads back as 2576980377 and the receipt compared it to the
literal "60%" → false `drifted` (host_failed=1) though the cap is correctly set.
Ground the encoding in extdeps.os.oomd (`systemd_managed_oom_pressure_limit_show_scale`
= 4294967295, `managed_oom_pressure_limit_show_value`) and set the knob's
expected_effective to that show-value; apply stays "60%", desired_display stays "60".

Per-slot caps (8 GiB MemoryMax + MemorySwapMax=0) were already persisted correctly —
the drop-in is written unconditionally before the (empty) active-instance loop, so the
ABSENT verdicts were just "no live runner to set-property", not a write failure.

Witness updated: oom-limit expected-effective asserts 2576980377; added a tooth that
the membership `ls` carries `|| true`. Drift gate ExitSuccess; all converge / oomd /
runner-placement witnesses green by execution.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 27, 2026
…loor) (#5855)

* Revert resolve cache to opt-in (#5789 always-on default OOMs the CI floor)

#5789 made the cross-process resolved-graph disk cache always-on by
defaulting its directory to `temp_dir()/gunbc-rg-cache-{user}`, dropping
the `GUNBC_RESOLVED_GRAPH_CACHE_DIR` opt-in gate. That turned the cache
on in CI, where it is pure cost:

  - Both IO paths buffer a whole cache file in memory. A hit `read_to_end`s
    the entire verbose-JSON file (~11x the packed 18-field-Node graph, so a
    272 MiB graph is a ~3 GiB read); a miss `to_vec`s the whole JSON before
    write. Across concurrent floor shards this OOMs the runner (measured
    14.16 GiB self-RSS at width=3 vs the 8 GiB cap).
  - CI hit-rate is ~0: the cache lives in /tmp (absent from ci.yml's
    actions/cache paths, empty on each fresh runner) and the subject key
    folds the compiler-exe hash, so every commit colds the whole cache.
    So in CI it only ever writes (which also OOMs) and never reads a graph
    back. This re-confirms the prior cold-CI cache-enable finding (#5447)
    that #5789 contradicted unreferenced.

Restore the #4878 opt-in: `resolved_graph_cache_root_from_env()` returns
`None` when the env var is unset, and both callers re-gate on it, so with
no env var the cache is fully off (lookup and write both skipped). Both
sites are pure perf shortcuts (lookup falls through to recompute, write is
best-effort `let _ =`), so this changes only timing, never the resolved
graph. ROADMAP regenerated from roadmap_authority.dag.

Re-enabling by default is gated on a streaming IO realization (binary +
`deserialize_from`/`serialize_into`, no whole-file `Vec<u8>`) — follow-on.

Seed-infra (the v1 caching kernel's gating); does not cement Rust into
templates and is not the substrate Share work.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fmt: rustfmt the cache import line (fix fmt --check gate)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot mentioned this pull request Jul 1, 2026
6 tasks
briansrls added a commit that referenced this pull request Jul 9, 2026
… law

Operator synthesis (2026-07-09): Materialization = the verdict vocabulary;
ownership = the verdict computation at the eval frame; realization = provider
selection discharging the verdict at each frame's carrier. Share's handler is
layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable
carrier + readonly => point-at-it, no copy, no destroyed memory), demoting
through HAMT structural share / process memo / artifact / CAS, and demotion
must be priced, never silent (#6249 clone-fallback is the receipt).

Census of every hand-rolled instance found in-tree (16 rows): each named with
its frame, ladder cell, action, and dissolution trigger — ownership
(consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall),
ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green /
sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB
scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789
(rule-4 requirements), recompute-trace (state-4 finding source). Peers kept
distinct: affected-set, Independence/Placement, mutable state.

Sequence C1-C5 with C1 = this PR (ladder + live CI gate).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 10, 2026
… law

Operator synthesis (2026-07-09): Materialization = the verdict vocabulary;
ownership = the verdict computation at the eval frame; realization = provider
selection discharging the verdict at each frame's carrier. Share's handler is
layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable
carrier + readonly => point-at-it, no copy, no destroyed memory), demoting
through HAMT structural share / process memo / artifact / CAS, and demotion
must be priced, never silent (#6249 clone-fallback is the receipt).

Census of every hand-rolled instance found in-tree (16 rows): each named with
its frame, ladder cell, action, and dissolution trigger — ownership
(consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall),
ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green /
sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB
scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789
(rule-4 requirements), recompute-trace (state-4 finding source). Peers kept
distinct: affected-set, Independence/Placement, mutable state.

Sequence C1-C5 with C1 = this PR (ladder + live CI gate).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 10, 2026
… law

Operator synthesis (2026-07-09): Materialization = the verdict vocabulary;
ownership = the verdict computation at the eval frame; realization = provider
selection discharging the verdict at each frame's carrier. Share's handler is
layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable
carrier + readonly => point-at-it, no copy, no destroyed memory), demoting
through HAMT structural share / process memo / artifact / CAS, and demotion
must be priced, never silent (#6249 clone-fallback is the receipt).

Census of every hand-rolled instance found in-tree (16 rows): each named with
its frame, ladder cell, action, and dissolution trigger — ownership
(consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall),
ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green /
sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB
scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789
(rule-4 requirements), recompute-trace (state-4 finding source). Peers kept
distinct: affected-set, Independence/Placement, mutable state.

Sequence C1-C5 with C1 = this PR (ladder + live CI gate).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 10, 2026
* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* Analysis spine: spine_receipt composes dependency_view + materialize (increment 1)

The Rc-safe half of run ≜ realize ∘ materialize ∘ dependency_view: compose
the two catamorphisms that need no interpreter thread-safety.

- src/v2/std/spine.dag: level-profile fold over the DependencyView DAG →
  critical_path_depth (longest dependency chain / the reduce spine) +
  independence_width (max nodes at one level / what parallelizes to hw width).
  spine_receipt emits the §9 numbers by COMPUTATION, not assertion, joining
  materialize's content-hash Share/dedup counts.
- Discriminating RED (§9): single chain A→B→C → depth 3 / width 1 (serial);
  root over N independent leaves → depth 2 / width N.
- Witnesses 9/9 (spine) green by execution; materialize 6/6 unchanged.

The RUNNER (wall-clock parallel execution, §8 steps 3-4) stays increment 2+,
gated on interpreter Rc→Arc (v1 interp is !Send). This increment measures the
achievable width/critical-path floor the runner targets; it does not fabricate
wall-clock N×.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Unbundle recompute-trace interpreter extension from the analysis-spine PR

CI root cause: the recompute-trace extension edited v1_interpreter.rs, which
hosts the atom_identity_hash/hash_combine fnv1a64 intrinsics that
dag_collect_fingerprint_witness executes. That correctly invalidated the
re-verify 'assumed-green node-frontier' SKIP of that witness (cone-touch,
fail-closed) — but the witness is a pre-existing 806s (13min) fnv1a64
whole-corpus walk, so un-skipping it blew the 30-min floor budget. Main stays
green only because its interpreter cone is untouched (witness stays skipped).

The interpreter extension is a separable, env-gated (GUNBC_RECOMPUTE_TRACE=1),
READ-mode diagnostic — not a dependency of the spine/materialize analysis
substrate (pure .dag, content_hash-based). Reverting v1_interpreter.rs to main
restores byte-identical interpreter content → the fingerprint witness returns to
assumed-green SKIP → floor budget restored. The recompute-trace extension lands
as its own follow-up PR where the fingerprint-witness re-run is expected.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Materialization ladder: the state x decision law, as executable witnesses

The operator's 4-rule business logic generalized on one axis: the decision is
a function of WHEN the redundancy is knowable and WHETHER what was knowable
was prepared for. Errors fire only on knowable-but-unprepared; genuine
emergence and declared triviality are typed acceptances, never silence.

std.materialization_ladder (dag/std):
- Frame/FrameKind: SharedStateFrame | IsolatedChildrenFrame |
  ReplayedFrame{attempts} | UnboundedSiblingsFrame — the nested-scope axis;
  a 'run' at any layer is a frame, never a different kind of thing.
- DemandNature: Pure | IdempotentEffect | WorldRead{envelope_declared} |
  FreshEffect — the D3 effect gate; TTL = unmodeled dependency XOR declared
  staleness, never an eviction knob.
- CacheProvider: keying (ContentKeyed|ExistenceKeyed) + EvictionPolicy
  (ScopeExit|SpacePacked) REQUIRED by construction — rule 3 unwritable-bad.
- LadderVerdict (total): AuthoredDuplication | Discharged | RefusedNoProvider
  | RefusedScopeTooNarrow | RefusedExistenceKeyed (the build-if-absent #6352
  wall) | RefusedUnmodeledWorldRead | ExemptFreshEffect |
  AcceptedBelowCostFloor | AcceptedSingleRecompute.
- Declared-emergent frames obligate UP FRONT: retry frames derive
  checkpointing, unbounded-sibling frames (server loops, CI-runs-over-time)
  derive persistent caches — prepare-before-demand.

12/12 witnesses green by execution; each test is one cell of the table,
fixtures mirror the live worked example (workflow/jobs/steps, retry, fleet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Docs crystallization: derived materialization placement into roadmap ④ + the state x decision table

- roadmap_authority ④ (ROADMAP.md regenerated via main_wet, drift-consistent):
  the nested-frame law, plurality cells, declared-emergent prepare-up-front,
  keying/staleness walls, the caching-completion un-shelve, the ①-vs-§2
  cross-run-caching contradiction subsumed into per-node derived verdicts,
  and the v1.compiler.ownership §3-convergence row.
- duplicate-work design doc: the state x decision table as the qualifier's
  final verdict logic + the ownership consolidation subsection.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Consolidation plan: realization + materialization + ownership are one law

Operator synthesis (2026-07-09): Materialization = the verdict vocabulary;
ownership = the verdict computation at the eval frame; realization = provider
selection discharging the verdict at each frame's carrier. Share's handler is
layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable
carrier + readonly => point-at-it, no copy, no destroyed memory), demoting
through HAMT structural share / process memo / artifact / CAS, and demotion
must be priced, never silent (#6249 clone-fallback is the receipt).

Census of every hand-rolled instance found in-tree (16 rows): each named with
its frame, ladder cell, action, and dissolution trigger — ownership
(consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall),
ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green /
sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB
scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789
(rule-4 requirements), recompute-trace (state-4 finding source). Peers kept
distinct: affected-set, Independence/Placement, mutable state.

Sequence C1-C5 with C1 = this PR (ladder + live CI gate).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Ownership refactored onto materialization: the value tier, tested as providers

First consolidation increment (operator-directed): v1.compiler.ownership's
decision IS provider selection at the value grain, now expressed in the ladder
and proven by mirror witnesses.

- ProviderTier: Reference | Copy | Memo{keying} | Artifact{keying} | Cas{keying}
  — keying folded INTO store tiers, so an existence-keyed reference is
  unwritable BY SHAPE (§5 construction); frame obligations at isolation LCAs
  are dischargeable only by store tiers (a reference cannot cross an isolation
  boundary — witnessed).
- Value tier: AccessMode (Read|Consume|Carry|Project), ValueUsage,
  value_materialization -> ValueDead | ValueMoved | ValueSharedByReference |
  ValueDemotedToCopy (PRICED, requires a declared CopyTier provider — the
  #6249 silent clone-fallback made refusable) | ValueRefusedAffine |
  ValueRefusedNoCarrierProvider.
- Faithful to v1's THREE distinct plurality readings, kept separate:
  take_count = semantic_consumer_count (Consumed only, affine axis);
  value_access_plurality = binding_fan_out (Carry excluded, reference axis);
  borrow_count = whole_value_borrow_count (Read+Carry not Project, movability).
- Fold-accumulator case mirrored at conservative pre-FoldAccUnwrap semantics:
  carries excluded from plurality but blocking the move -> demoted-to-copy.

23/23 witnesses green (14 frame cells + 9 value cells). Corpus-level
equivalence against live v1 ownership folds = the C4 receipt.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* WIP: Duplicate Computation/Materialization

* G: exhaustive cache/share census (52 mechanisms, 6 groups) + C0 catalog-grounding of provider rows + forward-wiring walls

The sweep found the tree already models caches: extdeps/cache cache_catalog
(CacheInterfaceCatalogFacts, 9 rows) + extdeps/realization carrier facts +
the warm==cold purity oracle. C0 grounds CacheProvider on that catalog
(provider_from_catalog projection; CacheProvider.id -> CacheInterfaceId)
so the ladder and the catalog never restate each other's half. Three
forward walls (demands-from-DependencyView, hand-cache shape lens,
live-provider-or-red) make new caches born as provider rows only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* C0: provider rows derive from the cited cache catalog (extdeps/cache/materialization.dag projection)

Operator ruling 2026-07-09: extdeps stays the ground-truth/interface layer;
every USE of a cache goes through materialization so memo never gets
re-invented. provider_from_catalog is the only door from a catalog row into
the ladder: keying/tier/eviction derived from cited facts (mechanism->class:
InProcess=>ScopeExit; Ttl/Lru/SizeBounded=>SpacePacked; Never/Manual outside
a process => typed ProjectionRefused, counted by the new enrolled witness;
HandAuthored/prefix-fallback keys => ExistenceKeyed until key-completeness
upgrades them). CI sccache row now derived, hand-typed tier facts deleted,
6/6 + 23/23 witnesses green. 10b re-scoped: v1-internal caches = inventory
only (retire with seed); ParseTable/cached_stage promoted to next.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* Fail-closed hardening: RefusedNatureConflict arm, weakest-claim nature default, UsesStep silence counted, ladder cells enrolled in CI

The complexity-lens false-clean lesson applied to this gate before anyone
relies on it: (1) heterogeneous natures on one identity were first-wins —
now a typed RefusedNatureConflict (24th ladder cell, RED witness); (2) an
unrostered run-step claimed PureComputation — now IdempotentEffect, the
weakest claim (verdict-identical, no purity overclaim; a misdeclared
WorldRead can no longer be legally memoized by default); (3) UsesStep
foreign actions produced silence — now a pinned denominator (==9; a new
foreign action must consciously bump it); (4) the ladder's 24 cells enroll
on the CI surface so the law's own witnesses gate every run. 24/24 + 7/7.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* M1 ratchet bump: declared resolve count 1 -> 3 (gate's first live catch — enrollment pays counted resolves)

Run 29058798771: enrolling the ladder witness file moved resolves_total
1 -> 3 (each enrolled entry file pays one closure resolve against the
shared index) and the receipt gate redded that exact run — the designed
semantics, receipted in the note. Bump acknowledges the two witness-entry
resolves as declared debt; M2 (one closure resolve per roots set)
ratchets back toward 1.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Retire the M1/M2 labels from carriers (no-codename rule; collided with DESIGN's floor-memoization M1/M2)

Step renamed to 'Floor resolve receipt gate (declared cold-resolve count)';
notes and the gate echo now say what the things are: the counted
cold-resolve receipt, and the shared-resolve rewire (one closure resolve
per source-roots set). Naming-retirement note left on the carrier.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* Run-step natures pinned as counted claims, not affordances

Operator ruling 2026-07-10: hardcoded shell scripts get no affordances
— run-steps are supposed to be modeled as typed intents and emitted
(shell-emission-model slice 4 covers ci_workflow RunSteps). Until that
slice lands, every nature in job_run_demands is a claim (rostered
FreshEffect / weakest-default IdempotentEffect), never derived from a
modeled effect row. Count the whole claimed-nature surface (16 by
execution) and pin it in the enrolled witness: a new raw-script step
must consciously bump the pin, and slice-4 migration becomes a
countable ratchet ending at zero, where the pin becomes a wall.
Rejected alternative recorded in the carrier note: a per-step
declared-natures roster (a second parallel ledger over scripts the
shell-emission plan already governs).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Regen DESIGN.md after main merge (duplicate-work row + #6373 body-lowering row coexist)

Conflict was both sides editing the open-threads list in design_document.dag:
ours added the duplicate-work thread, main's #6373 rewrote body-lowering to
Stages 1-3 LANDED. Resolution keeps both rows in the .dag authority; DESIGN.md
regenerated from it, never hand-edited.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 10, 2026
…ealization carrier, provider rows via provider_from_catalog (design: docs/plans/duplicate-work-graph-lens-design.md section 10b; the .dag-substrate demonstration lane) (#6422)

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Ground v2 ParseTable + cached_stage on materialization: inhabit the Real

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* Analysis spine: spine_receipt composes dependency_view + materialize (increment 1)

The Rc-safe half of run ≜ realize ∘ materialize ∘ dependency_view: compose
the two catamorphisms that need no interpreter thread-safety.

- src/v2/std/spine.dag: level-profile fold over the DependencyView DAG →
  critical_path_depth (longest dependency chain / the reduce spine) +
  independence_width (max nodes at one level / what parallelizes to hw width).
  spine_receipt emits the §9 numbers by COMPUTATION, not assertion, joining
  materialize's content-hash Share/dedup counts.
- Discriminating RED (§9): single chain A→B→C → depth 3 / width 1 (serial);
  root over N independent leaves → depth 2 / width N.
- Witnesses 9/9 (spine) green by execution; materialize 6/6 unchanged.

The RUNNER (wall-clock parallel execution, §8 steps 3-4) stays increment 2+,
gated on interpreter Rc→Arc (v1 interp is !Send). This increment measures the
achievable width/critical-path floor the runner targets; it does not fabricate
wall-clock N×.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Unbundle recompute-trace interpreter extension from the analysis-spine PR

CI root cause: the recompute-trace extension edited v1_interpreter.rs, which
hosts the atom_identity_hash/hash_combine fnv1a64 intrinsics that
dag_collect_fingerprint_witness executes. That correctly invalidated the
re-verify 'assumed-green node-frontier' SKIP of that witness (cone-touch,
fail-closed) — but the witness is a pre-existing 806s (13min) fnv1a64
whole-corpus walk, so un-skipping it blew the 30-min floor budget. Main stays
green only because its interpreter cone is untouched (witness stays skipped).

The interpreter extension is a separable, env-gated (GUNBC_RECOMPUTE_TRACE=1),
READ-mode diagnostic — not a dependency of the spine/materialize analysis
substrate (pure .dag, content_hash-based). Reverting v1_interpreter.rs to main
restores byte-identical interpreter content → the fingerprint witness returns to
assumed-green SKIP → floor budget restored. The recompute-trace extension lands
as its own follow-up PR where the fingerprint-witness re-run is expected.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Materialization ladder: the state x decision law, as executable witnesses

The operator's 4-rule business logic generalized on one axis: the decision is
a function of WHEN the redundancy is knowable and WHETHER what was knowable
was prepared for. Errors fire only on knowable-but-unprepared; genuine
emergence and declared triviality are typed acceptances, never silence.

std.materialization_ladder (dag/std):
- Frame/FrameKind: SharedStateFrame | IsolatedChildrenFrame |
  ReplayedFrame{attempts} | UnboundedSiblingsFrame — the nested-scope axis;
  a 'run' at any layer is a frame, never a different kind of thing.
- DemandNature: Pure | IdempotentEffect | WorldRead{envelope_declared} |
  FreshEffect — the D3 effect gate; TTL = unmodeled dependency XOR declared
  staleness, never an eviction knob.
- CacheProvider: keying (ContentKeyed|ExistenceKeyed) + EvictionPolicy
  (ScopeExit|SpacePacked) REQUIRED by construction — rule 3 unwritable-bad.
- LadderVerdict (total): AuthoredDuplication | Discharged | RefusedNoProvider
  | RefusedScopeTooNarrow | RefusedExistenceKeyed (the build-if-absent #6352
  wall) | RefusedUnmodeledWorldRead | ExemptFreshEffect |
  AcceptedBelowCostFloor | AcceptedSingleRecompute.
- Declared-emergent frames obligate UP FRONT: retry frames derive
  checkpointing, unbounded-sibling frames (server loops, CI-runs-over-time)
  derive persistent caches — prepare-before-demand.

12/12 witnesses green by execution; each test is one cell of the table,
fixtures mirror the live worked example (workflow/jobs/steps, retry, fleet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Docs crystallization: derived materialization placement into roadmap ④ + the state x decision table

- roadmap_authority ④ (ROADMAP.md regenerated via main_wet, drift-consistent):
  the nested-frame law, plurality cells, declared-emergent prepare-up-front,
  keying/staleness walls, the caching-completion un-shelve, the ①-vs-§2
  cross-run-caching contradiction subsumed into per-node derived verdicts,
  and the v1.compiler.ownership §3-convergence row.
- duplicate-work design doc: the state x decision table as the qualifier's
  final verdict logic + the ownership consolidation subsection.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Consolidation plan: realization + materialization + ownership are one law

Operator synthesis (2026-07-09): Materialization = the verdict vocabulary;
ownership = the verdict computation at the eval frame; realization = provider
selection discharging the verdict at each frame's carrier. Share's handler is
layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable
carrier + readonly => point-at-it, no copy, no destroyed memory), demoting
through HAMT structural share / process memo / artifact / CAS, and demotion
must be priced, never silent (#6249 clone-fallback is the receipt).

Census of every hand-rolled instance found in-tree (16 rows): each named with
its frame, ladder cell, action, and dissolution trigger — ownership
(consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall),
ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green /
sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB
scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789
(rule-4 requirements), recompute-trace (state-4 finding source). Peers kept
distinct: affected-set, Independence/Placement, mutable state.

Sequence C1-C5 with C1 = this PR (ladder + live CI gate).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Ownership refactored onto materialization: the value tier, tested as providers

First consolidation increment (operator-directed): v1.compiler.ownership's
decision IS provider selection at the value grain, now expressed in the ladder
and proven by mirror witnesses.

- ProviderTier: Reference | Copy | Memo{keying} | Artifact{keying} | Cas{keying}
  — keying folded INTO store tiers, so an existence-keyed reference is
  unwritable BY SHAPE (§5 construction); frame obligations at isolation LCAs
  are dischargeable only by store tiers (a reference cannot cross an isolation
  boundary — witnessed).
- Value tier: AccessMode (Read|Consume|Carry|Project), ValueUsage,
  value_materialization -> ValueDead | ValueMoved | ValueSharedByReference |
  ValueDemotedToCopy (PRICED, requires a declared CopyTier provider — the
  #6249 silent clone-fallback made refusable) | ValueRefusedAffine |
  ValueRefusedNoCarrierProvider.
- Faithful to v1's THREE distinct plurality readings, kept separate:
  take_count = semantic_consumer_count (Consumed only, affine axis);
  value_access_plurality = binding_fan_out (Carry excluded, reference axis);
  borrow_count = whole_value_borrow_count (Read+Carry not Project, movability).
- Fold-accumulator case mirrored at conservative pre-FoldAccUnwrap semantics:
  carries excluded from plurality but blocking the move -> demoted-to-copy.

23/23 witnesses green (14 frame cells + 9 value cells). Corpus-level
equivalence against live v1 ownership folds = the C4 receipt.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* WIP: Duplicate Computation/Materialization

* G: exhaustive cache/share census (52 mechanisms, 6 groups) + C0 catalog-grounding of provider rows + forward-wiring walls

The sweep found the tree already models caches: extdeps/cache cache_catalog
(CacheInterfaceCatalogFacts, 9 rows) + extdeps/realization carrier facts +
the warm==cold purity oracle. C0 grounds CacheProvider on that catalog
(provider_from_catalog projection; CacheProvider.id -> CacheInterfaceId)
so the ladder and the catalog never restate each other's half. Three
forward walls (demands-from-DependencyView, hand-cache shape lens,
live-provider-or-red) make new caches born as provider rows only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* C0: provider rows derive from the cited cache catalog (extdeps/cache/materialization.dag projection)

Operator ruling 2026-07-09: extdeps stays the ground-truth/interface layer;
every USE of a cache goes through materialization so memo never gets
re-invented. provider_from_catalog is the only door from a catalog row into
the ladder: keying/tier/eviction derived from cited facts (mechanism->class:
InProcess=>ScopeExit; Ttl/Lru/SizeBounded=>SpacePacked; Never/Manual outside
a process => typed ProjectionRefused, counted by the new enrolled witness;
HandAuthored/prefix-fallback keys => ExistenceKeyed until key-completeness
upgrades them). CI sccache row now derived, hand-typed tier facts deleted,
6/6 + 23/23 witnesses green. 10b re-scoped: v1-internal caches = inventory
only (retire with seed); ParseTable/cached_stage promoted to next.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Ground v2 ParseTable + cached_stage on materialization: inhabit the Real

* Fix compiler materialization witnesses: RealizedStep carrier, plural RED fixture.

Use RealizedStep<Nano> (not unit), drop 02_parse import from witnesses in favor
of parse_table_carrier_grounded_on_catalog, and model cross-run memo plurality
with an isolation-boundary LCA matching the CI ladder pattern.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix CI: move materialization_carriers to compiler layer (no std→extdeps import).

Resolves layering_imports_gate and compile-clean failures from v2.std
importing extdeps via materialization_carriers. CachedStageRealization lives
in v2.compiler.materialization_carriers; staging.dag stays transport-only.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Ground v2 ParseTable + cached_stage on materialization: inhabit the Real

* WIP: Ground v2 ParseTable + cached_stage on materialization: inhabit the Real

* Fix governed memo door: resolve_probe in cached_stage_governed, parse lookup match braces.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Ground v2 ParseTable + cached_stage on materialization: inhabit the Real

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* Fail-closed hardening: RefusedNatureConflict arm, weakest-claim nature default, UsesStep silence counted, ladder cells enrolled in CI

The complexity-lens false-clean lesson applied to this gate before anyone
relies on it: (1) heterogeneous natures on one identity were first-wins —
now a typed RefusedNatureConflict (24th ladder cell, RED witness); (2) an
unrostered run-step claimed PureComputation — now IdempotentEffect, the
weakest claim (verdict-identical, no purity overclaim; a misdeclared
WorldRead can no longer be legally memoized by default); (3) UsesStep
foreign actions produced silence — now a pinned denominator (==9; a new
foreign action must consciously bump it); (4) the ladder's 24 cells enroll
on the CI surface so the law's own witnesses gate every run. 24/24 + 7/7.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Merge merry-moth-539 (main-integrated); harden governed memo door witnesses.

Merge origin/session/merry-moth-539 for post-main semantics alignment.
Export parse_table_memo_lookup_refuses_store / parse_table_memo_insert_refused
door oracles in 02_parse; witnesses call them directly (reason atom, not full
Diagnostic equality).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Ground v2 ParseTable + cached_stage on materialization: inhabit the Real

* Regenerate ci.yml for floor resolve receipt pin at 3.

CI run 29059860791 measured resolves_total=3 after enrolling the two
new v2 witness entry classes; sync the emitted gate with
ci_floor_declared_resolve_count in ci_materialization.dag.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Ground v2 ParseTable + cached_stage on materialization: inhabit the Real

* fix: escape ComputationIdentity braces in design_document.dag

Rebase conflict left unescaped {bound}/{cause} in a li() string, which
broke dag compile and the generated-artifact drift gate. Regenerate ci.yml.

Co-authored-by: Cursor <cursoragent@cursor.com>

* merge origin/main and resolve conflict markers; fix ParseTableMemo Case-A leak

Integrate main (#6431) atop #6375 base. Remove leftover merge conflict
markers from ci_materialization, commit_workflow, design_document, ci.yml.
Gate seed ParseTableMemo insert/serve on Memoize only (after governed door)
so insert-then-lookup door observables are order-independent; enroll
parse_table_memo_door_order_independent witness.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix: add Terminal disposition contracts for carrier predicate helpers

Land v2_compiler_materialization_memo_gate_predicate_contract and
v2_compiler_catalog_projection_predicate_contract on
materialization_allows_memo_store / projection_is_projected — matching
the Terminal predicate discipline already in materialization_ladder.dag.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix: correct resolve-receipt note attribution for #6422 enrollments

Pin was already 3 before #6422 witness entries; run 29059860791 held
at 3 with those entries enrolled because they pooled warm on the shared
index (zero additional cold resolves). Remove false per-entry bump claim.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Ground v2 ParseTable + cached_stage on materialization: inhabit the Real

* fix: drop duplicate projection_is_projected; use extdeps authority

Remove forked CatalogProviderProjection predicate from
materialization_carriers.dag; projection_ok cells now call
!projection_is_refused from extdeps.cache.materialization (§3 single
authority). Remove local Terminal contract that documented the fork.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ci): raise floor step timeout to 45m for #6422 witness cone

Receipt run 29065683045 @ a2bcd6f: batches 1-3 ~20m, batch 4
rust_monolith_gate killed at 30m step cap. Bump floor step and ci/ci_regen
job backstop (85m→100m) to match rust gate step budget.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jul 10, 2026
…rier (#6435)

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* Analysis spine: spine_receipt composes dependency_view + materialize (increment 1)

The Rc-safe half of run ≜ realize ∘ materialize ∘ dependency_view: compose
the two catamorphisms that need no interpreter thread-safety.

- src/v2/std/spine.dag: level-profile fold over the DependencyView DAG →
  critical_path_depth (longest dependency chain / the reduce spine) +
  independence_width (max nodes at one level / what parallelizes to hw width).
  spine_receipt emits the §9 numbers by COMPUTATION, not assertion, joining
  materialize's content-hash Share/dedup counts.
- Discriminating RED (§9): single chain A→B→C → depth 3 / width 1 (serial);
  root over N independent leaves → depth 2 / width N.
- Witnesses 9/9 (spine) green by execution; materialize 6/6 unchanged.

The RUNNER (wall-clock parallel execution, §8 steps 3-4) stays increment 2+,
gated on interpreter Rc→Arc (v1 interp is !Send). This increment measures the
achievable width/critical-path floor the runner targets; it does not fabricate
wall-clock N×.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Unbundle recompute-trace interpreter extension from the analysis-spine PR

CI root cause: the recompute-trace extension edited v1_interpreter.rs, which
hosts the atom_identity_hash/hash_combine fnv1a64 intrinsics that
dag_collect_fingerprint_witness executes. That correctly invalidated the
re-verify 'assumed-green node-frontier' SKIP of that witness (cone-touch,
fail-closed) — but the witness is a pre-existing 806s (13min) fnv1a64
whole-corpus walk, so un-skipping it blew the 30-min floor budget. Main stays
green only because its interpreter cone is untouched (witness stays skipped).

The interpreter extension is a separable, env-gated (GUNBC_RECOMPUTE_TRACE=1),
READ-mode diagnostic — not a dependency of the spine/materialize analysis
substrate (pure .dag, content_hash-based). Reverting v1_interpreter.rs to main
restores byte-identical interpreter content → the fingerprint witness returns to
assumed-green SKIP → floor budget restored. The recompute-trace extension lands
as its own follow-up PR where the fingerprint-witness re-run is expected.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Materialization ladder: the state x decision law, as executable witnesses

The operator's 4-rule business logic generalized on one axis: the decision is
a function of WHEN the redundancy is knowable and WHETHER what was knowable
was prepared for. Errors fire only on knowable-but-unprepared; genuine
emergence and declared triviality are typed acceptances, never silence.

std.materialization_ladder (dag/std):
- Frame/FrameKind: SharedStateFrame | IsolatedChildrenFrame |
  ReplayedFrame{attempts} | UnboundedSiblingsFrame — the nested-scope axis;
  a 'run' at any layer is a frame, never a different kind of thing.
- DemandNature: Pure | IdempotentEffect | WorldRead{envelope_declared} |
  FreshEffect — the D3 effect gate; TTL = unmodeled dependency XOR declared
  staleness, never an eviction knob.
- CacheProvider: keying (ContentKeyed|ExistenceKeyed) + EvictionPolicy
  (ScopeExit|SpacePacked) REQUIRED by construction — rule 3 unwritable-bad.
- LadderVerdict (total): AuthoredDuplication | Discharged | RefusedNoProvider
  | RefusedScopeTooNarrow | RefusedExistenceKeyed (the build-if-absent #6352
  wall) | RefusedUnmodeledWorldRead | ExemptFreshEffect |
  AcceptedBelowCostFloor | AcceptedSingleRecompute.
- Declared-emergent frames obligate UP FRONT: retry frames derive
  checkpointing, unbounded-sibling frames (server loops, CI-runs-over-time)
  derive persistent caches — prepare-before-demand.

12/12 witnesses green by execution; each test is one cell of the table,
fixtures mirror the live worked example (workflow/jobs/steps, retry, fleet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Docs crystallization: derived materialization placement into roadmap ④ + the state x decision table

- roadmap_authority ④ (ROADMAP.md regenerated via main_wet, drift-consistent):
  the nested-frame law, plurality cells, declared-emergent prepare-up-front,
  keying/staleness walls, the caching-completion un-shelve, the ①-vs-§2
  cross-run-caching contradiction subsumed into per-node derived verdicts,
  and the v1.compiler.ownership §3-convergence row.
- duplicate-work design doc: the state x decision table as the qualifier's
  final verdict logic + the ownership consolidation subsection.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Consolidation plan: realization + materialization + ownership are one law

Operator synthesis (2026-07-09): Materialization = the verdict vocabulary;
ownership = the verdict computation at the eval frame; realization = provider
selection discharging the verdict at each frame's carrier. Share's handler is
layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable
carrier + readonly => point-at-it, no copy, no destroyed memory), demoting
through HAMT structural share / process memo / artifact / CAS, and demotion
must be priced, never silent (#6249 clone-fallback is the receipt).

Census of every hand-rolled instance found in-tree (16 rows): each named with
its frame, ladder cell, action, and dissolution trigger — ownership
(consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall),
ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green /
sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB
scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789
(rule-4 requirements), recompute-trace (state-4 finding source). Peers kept
distinct: affected-set, Independence/Placement, mutable state.

Sequence C1-C5 with C1 = this PR (ladder + live CI gate).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Ownership refactored onto materialization: the value tier, tested as providers

First consolidation increment (operator-directed): v1.compiler.ownership's
decision IS provider selection at the value grain, now expressed in the ladder
and proven by mirror witnesses.

- ProviderTier: Reference | Copy | Memo{keying} | Artifact{keying} | Cas{keying}
  — keying folded INTO store tiers, so an existence-keyed reference is
  unwritable BY SHAPE (§5 construction); frame obligations at isolation LCAs
  are dischargeable only by store tiers (a reference cannot cross an isolation
  boundary — witnessed).
- Value tier: AccessMode (Read|Consume|Carry|Project), ValueUsage,
  value_materialization -> ValueDead | ValueMoved | ValueSharedByReference |
  ValueDemotedToCopy (PRICED, requires a declared CopyTier provider — the
  #6249 silent clone-fallback made refusable) | ValueRefusedAffine |
  ValueRefusedNoCarrierProvider.
- Faithful to v1's THREE distinct plurality readings, kept separate:
  take_count = semantic_consumer_count (Consumed only, affine axis);
  value_access_plurality = binding_fan_out (Carry excluded, reference axis);
  borrow_count = whole_value_borrow_count (Read+Carry not Project, movability).
- Fold-accumulator case mirrored at conservative pre-FoldAccUnwrap semantics:
  carries excluded from plurality but blocking the move -> demoted-to-copy.

23/23 witnesses green (14 frame cells + 9 value cells). Corpus-level
equivalence against live v1 ownership folds = the C4 receipt.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* WIP: Duplicate Computation/Materialization

* G: exhaustive cache/share census (52 mechanisms, 6 groups) + C0 catalog-grounding of provider rows + forward-wiring walls

The sweep found the tree already models caches: extdeps/cache cache_catalog
(CacheInterfaceCatalogFacts, 9 rows) + extdeps/realization carrier facts +
the warm==cold purity oracle. C0 grounds CacheProvider on that catalog
(provider_from_catalog projection; CacheProvider.id -> CacheInterfaceId)
so the ladder and the catalog never restate each other's half. Three
forward walls (demands-from-DependencyView, hand-cache shape lens,
live-provider-or-red) make new caches born as provider rows only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* C0: provider rows derive from the cited cache catalog (extdeps/cache/materialization.dag projection)

Operator ruling 2026-07-09: extdeps stays the ground-truth/interface layer;
every USE of a cache goes through materialization so memo never gets
re-invented. provider_from_catalog is the only door from a catalog row into
the ladder: keying/tier/eviction derived from cited facts (mechanism->class:
InProcess=>ScopeExit; Ttl/Lru/SizeBounded=>SpacePacked; Never/Manual outside
a process => typed ProjectionRefused, counted by the new enrolled witness;
HandAuthored/prefix-fallback keys => ExistenceKeyed until key-completeness
upgrades them). CI sccache row now derived, hand-typed tier facts deleted,
6/6 + 23/23 witnesses green. 10b re-scoped: v1-internal caches = inventory
only (retire with seed); ParseTable/cached_stage promoted to next.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* Fail-closed hardening: RefusedNatureConflict arm, weakest-claim nature default, UsesStep silence counted, ladder cells enrolled in CI

The complexity-lens false-clean lesson applied to this gate before anyone
relies on it: (1) heterogeneous natures on one identity were first-wins —
now a typed RefusedNatureConflict (24th ladder cell, RED witness); (2) an
unrostered run-step claimed PureComputation — now IdempotentEffect, the
weakest claim (verdict-identical, no purity overclaim; a misdeclared
WorldRead can no longer be legally memoized by default); (3) UsesStep
foreign actions produced silence — now a pinned denominator (==9; a new
foreign action must consciously bump it); (4) the ladder's 24 cells enroll
on the CI surface so the law's own witnesses gate every run. 24/24 + 7/7.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* M1 ratchet bump: declared resolve count 1 -> 3 (gate's first live catch — enrollment pays counted resolves)

Run 29058798771: enrolling the ladder witness file moved resolves_total
1 -> 3 (each enrolled entry file pays one closure resolve against the
shared index) and the receipt gate redded that exact run — the designed
semantics, receipted in the note. Bump acknowledges the two witness-entry
resolves as declared debt; M2 (one closure resolve per roots set)
ratchets back toward 1.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Retire the M1/M2 labels from carriers (no-codename rule; collided with DESIGN's floor-memoization M1/M2)

Step renamed to 'Floor resolve receipt gate (declared cold-resolve count)';
notes and the gate echo now say what the things are: the counted
cold-resolve receipt, and the shared-resolve rewire (one closure resolve
per source-roots set). Naming-retirement note left on the carrier.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* Run-step natures pinned as counted claims, not affordances

Operator ruling 2026-07-10: hardcoded shell scripts get no affordances
— run-steps are supposed to be modeled as typed intents and emitted
(shell-emission-model slice 4 covers ci_workflow RunSteps). Until that
slice lands, every nature in job_run_demands is a claim (rostered
FreshEffect / weakest-default IdempotentEffect), never derived from a
modeled effect row. Count the whole claimed-nature surface (16 by
execution) and pin it in the enrolled witness: a new raw-script step
must consciously bump the pin, and slice-4 migration becomes a
countable ratchet ending at zero, where the pin becomes a wall.
Rejected alternative recorded in the carrier note: a per-step
declared-natures roster (a second parallel ledger over scripts the
shell-emission plan already governs).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Regen DESIGN.md after main merge (duplicate-work row + #6373 body-lowering row coexist)

Conflict was both sides editing the open-threads list in design_document.dag:
ours added the duplicate-work thread, main's #6373 rewrote body-lowering to
Stages 1-3 LANDED. Resolution keeps both rows in the .dag authority; DESIGN.md
regenerated from it, never hand-edited.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 10, 2026
…ate (#6441)

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* Analysis spine: spine_receipt composes dependency_view + materialize (increment 1)

The Rc-safe half of run ≜ realize ∘ materialize ∘ dependency_view: compose
the two catamorphisms that need no interpreter thread-safety.

- src/v2/std/spine.dag: level-profile fold over the DependencyView DAG →
  critical_path_depth (longest dependency chain / the reduce spine) +
  independence_width (max nodes at one level / what parallelizes to hw width).
  spine_receipt emits the §9 numbers by COMPUTATION, not assertion, joining
  materialize's content-hash Share/dedup counts.
- Discriminating RED (§9): single chain A→B→C → depth 3 / width 1 (serial);
  root over N independent leaves → depth 2 / width N.
- Witnesses 9/9 (spine) green by execution; materialize 6/6 unchanged.

The RUNNER (wall-clock parallel execution, §8 steps 3-4) stays increment 2+,
gated on interpreter Rc→Arc (v1 interp is !Send). This increment measures the
achievable width/critical-path floor the runner targets; it does not fabricate
wall-clock N×.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Unbundle recompute-trace interpreter extension from the analysis-spine PR

CI root cause: the recompute-trace extension edited v1_interpreter.rs, which
hosts the atom_identity_hash/hash_combine fnv1a64 intrinsics that
dag_collect_fingerprint_witness executes. That correctly invalidated the
re-verify 'assumed-green node-frontier' SKIP of that witness (cone-touch,
fail-closed) — but the witness is a pre-existing 806s (13min) fnv1a64
whole-corpus walk, so un-skipping it blew the 30-min floor budget. Main stays
green only because its interpreter cone is untouched (witness stays skipped).

The interpreter extension is a separable, env-gated (GUNBC_RECOMPUTE_TRACE=1),
READ-mode diagnostic — not a dependency of the spine/materialize analysis
substrate (pure .dag, content_hash-based). Reverting v1_interpreter.rs to main
restores byte-identical interpreter content → the fingerprint witness returns to
assumed-green SKIP → floor budget restored. The recompute-trace extension lands
as its own follow-up PR where the fingerprint-witness re-run is expected.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Materialization ladder: the state x decision law, as executable witnesses

The operator's 4-rule business logic generalized on one axis: the decision is
a function of WHEN the redundancy is knowable and WHETHER what was knowable
was prepared for. Errors fire only on knowable-but-unprepared; genuine
emergence and declared triviality are typed acceptances, never silence.

std.materialization_ladder (dag/std):
- Frame/FrameKind: SharedStateFrame | IsolatedChildrenFrame |
  ReplayedFrame{attempts} | UnboundedSiblingsFrame — the nested-scope axis;
  a 'run' at any layer is a frame, never a different kind of thing.
- DemandNature: Pure | IdempotentEffect | WorldRead{envelope_declared} |
  FreshEffect — the D3 effect gate; TTL = unmodeled dependency XOR declared
  staleness, never an eviction knob.
- CacheProvider: keying (ContentKeyed|ExistenceKeyed) + EvictionPolicy
  (ScopeExit|SpacePacked) REQUIRED by construction — rule 3 unwritable-bad.
- LadderVerdict (total): AuthoredDuplication | Discharged | RefusedNoProvider
  | RefusedScopeTooNarrow | RefusedExistenceKeyed (the build-if-absent #6352
  wall) | RefusedUnmodeledWorldRead | ExemptFreshEffect |
  AcceptedBelowCostFloor | AcceptedSingleRecompute.
- Declared-emergent frames obligate UP FRONT: retry frames derive
  checkpointing, unbounded-sibling frames (server loops, CI-runs-over-time)
  derive persistent caches — prepare-before-demand.

12/12 witnesses green by execution; each test is one cell of the table,
fixtures mirror the live worked example (workflow/jobs/steps, retry, fleet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Docs crystallization: derived materialization placement into roadmap ④ + the state x decision table

- roadmap_authority ④ (ROADMAP.md regenerated via main_wet, drift-consistent):
  the nested-frame law, plurality cells, declared-emergent prepare-up-front,
  keying/staleness walls, the caching-completion un-shelve, the ①-vs-§2
  cross-run-caching contradiction subsumed into per-node derived verdicts,
  and the v1.compiler.ownership §3-convergence row.
- duplicate-work design doc: the state x decision table as the qualifier's
  final verdict logic + the ownership consolidation subsection.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Consolidation plan: realization + materialization + ownership are one law

Operator synthesis (2026-07-09): Materialization = the verdict vocabulary;
ownership = the verdict computation at the eval frame; realization = provider
selection discharging the verdict at each frame's carrier. Share's handler is
layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable
carrier + readonly => point-at-it, no copy, no destroyed memory), demoting
through HAMT structural share / process memo / artifact / CAS, and demotion
must be priced, never silent (#6249 clone-fallback is the receipt).

Census of every hand-rolled instance found in-tree (16 rows): each named with
its frame, ladder cell, action, and dissolution trigger — ownership
(consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall),
ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green /
sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB
scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789
(rule-4 requirements), recompute-trace (state-4 finding source). Peers kept
distinct: affected-set, Independence/Placement, mutable state.

Sequence C1-C5 with C1 = this PR (ladder + live CI gate).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Ownership refactored onto materialization: the value tier, tested as providers

First consolidation increment (operator-directed): v1.compiler.ownership's
decision IS provider selection at the value grain, now expressed in the ladder
and proven by mirror witnesses.

- ProviderTier: Reference | Copy | Memo{keying} | Artifact{keying} | Cas{keying}
  — keying folded INTO store tiers, so an existence-keyed reference is
  unwritable BY SHAPE (§5 construction); frame obligations at isolation LCAs
  are dischargeable only by store tiers (a reference cannot cross an isolation
  boundary — witnessed).
- Value tier: AccessMode (Read|Consume|Carry|Project), ValueUsage,
  value_materialization -> ValueDead | ValueMoved | ValueSharedByReference |
  ValueDemotedToCopy (PRICED, requires a declared CopyTier provider — the
  #6249 silent clone-fallback made refusable) | ValueRefusedAffine |
  ValueRefusedNoCarrierProvider.
- Faithful to v1's THREE distinct plurality readings, kept separate:
  take_count = semantic_consumer_count (Consumed only, affine axis);
  value_access_plurality = binding_fan_out (Carry excluded, reference axis);
  borrow_count = whole_value_borrow_count (Read+Carry not Project, movability).
- Fold-accumulator case mirrored at conservative pre-FoldAccUnwrap semantics:
  carries excluded from plurality but blocking the move -> demoted-to-copy.

23/23 witnesses green (14 frame cells + 9 value cells). Corpus-level
equivalence against live v1 ownership folds = the C4 receipt.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* WIP: Duplicate Computation/Materialization

* G: exhaustive cache/share census (52 mechanisms, 6 groups) + C0 catalog-grounding of provider rows + forward-wiring walls

The sweep found the tree already models caches: extdeps/cache cache_catalog
(CacheInterfaceCatalogFacts, 9 rows) + extdeps/realization carrier facts +
the warm==cold purity oracle. C0 grounds CacheProvider on that catalog
(provider_from_catalog projection; CacheProvider.id -> CacheInterfaceId)
so the ladder and the catalog never restate each other's half. Three
forward walls (demands-from-DependencyView, hand-cache shape lens,
live-provider-or-red) make new caches born as provider rows only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* C0: provider rows derive from the cited cache catalog (extdeps/cache/materialization.dag projection)

Operator ruling 2026-07-09: extdeps stays the ground-truth/interface layer;
every USE of a cache goes through materialization so memo never gets
re-invented. provider_from_catalog is the only door from a catalog row into
the ladder: keying/tier/eviction derived from cited facts (mechanism->class:
InProcess=>ScopeExit; Ttl/Lru/SizeBounded=>SpacePacked; Never/Manual outside
a process => typed ProjectionRefused, counted by the new enrolled witness;
HandAuthored/prefix-fallback keys => ExistenceKeyed until key-completeness
upgrades them). CI sccache row now derived, hand-typed tier facts deleted,
6/6 + 23/23 witnesses green. 10b re-scoped: v1-internal caches = inventory
only (retire with seed); ParseTable/cached_stage promoted to next.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* Fail-closed hardening: RefusedNatureConflict arm, weakest-claim nature default, UsesStep silence counted, ladder cells enrolled in CI

The complexity-lens false-clean lesson applied to this gate before anyone
relies on it: (1) heterogeneous natures on one identity were first-wins —
now a typed RefusedNatureConflict (24th ladder cell, RED witness); (2) an
unrostered run-step claimed PureComputation — now IdempotentEffect, the
weakest claim (verdict-identical, no purity overclaim; a misdeclared
WorldRead can no longer be legally memoized by default); (3) UsesStep
foreign actions produced silence — now a pinned denominator (==9; a new
foreign action must consciously bump it); (4) the ladder's 24 cells enroll
on the CI surface so the law's own witnesses gate every run. 24/24 + 7/7.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* M1 ratchet bump: declared resolve count 1 -> 3 (gate's first live catch — enrollment pays counted resolves)

Run 29058798771: enrolling the ladder witness file moved resolves_total
1 -> 3 (each enrolled entry file pays one closure resolve against the
shared index) and the receipt gate redded that exact run — the designed
semantics, receipted in the note. Bump acknowledges the two witness-entry
resolves as declared debt; M2 (one closure resolve per roots set)
ratchets back toward 1.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Retire the M1/M2 labels from carriers (no-codename rule; collided with DESIGN's floor-memoization M1/M2)

Step renamed to 'Floor resolve receipt gate (declared cold-resolve count)';
notes and the gate echo now say what the things are: the counted
cold-resolve receipt, and the shared-resolve rewire (one closure resolve
per source-roots set). Naming-retirement note left on the carrier.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* Run-step natures pinned as counted claims, not affordances

Operator ruling 2026-07-10: hardcoded shell scripts get no affordances
— run-steps are supposed to be modeled as typed intents and emitted
(shell-emission-model slice 4 covers ci_workflow RunSteps). Until that
slice lands, every nature in job_run_demands is a claim (rostered
FreshEffect / weakest-default IdempotentEffect), never derived from a
modeled effect row. Count the whole claimed-nature surface (16 by
execution) and pin it in the enrolled witness: a new raw-script step
must consciously bump the pin, and slice-4 migration becomes a
countable ratchet ending at zero, where the pin becomes a wall.
Rejected alternative recorded in the carrier note: a per-step
declared-natures roster (a second parallel ledger over scripts the
shell-emission plan already governs).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Regen DESIGN.md after main merge (duplicate-work row + #6373 body-lowering row coexist)

Conflict was both sides editing the open-threads list in design_document.dag:
ours added the duplicate-work thread, main's #6373 rewrote body-lowering to
Stages 1-3 LANDED. Resolution keeps both rows in the .dag authority; DESIGN.md
regenerated from it, never hand-edited.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* Inferred materialization increment 1: floor demand ledger + receipt-or-red gate

Running IS enrolling: the interpreter ledgers every keyed pure call and every
InterpContext absorbs its totals into a process accumulator on Drop — by
construction, no eval path escapes the receipt. claim_executor writes
target/floor-materialization-receipt.txt at walk end; trace defaults ON in
the executor, and an explicit =0 zeroes keyed_calls which the gate refuses.

Gate arms this push (all verified under dash from the emitted ci.yml):
receipt missing/malformed/keyed_calls=0 fail closed. Exact pins for
unkeyed_calls and duplicated_keys land from the FIRST CI receipt (the
resolve gate's measure-then-pin path) — unkeyed is known nonzero on the
floor (count_matching takes a predicate closure; closures are the one
disclosed identity-less class, dissolve-on captured-env content identity).

Unit witness green: resolve -> eval -> ctx Drop -> absorb -> drain-once.
Step addition bumped the claimed-natures pin 16 -> 17 consciously.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Review fix: drop the racy drain-once assertion from the receipt unit test

opus-4-7 finding on #6441: under plain cargo test (still the documented
runner) tests share a process, the env latch is OnceLock-sticky, and
sibling ctx drops could absorb between the two takes — making the
drain-empty assertion racy. Absorb-on-Drop stays asserted (monotone under
concurrent absorbs: siblings only ADD); drain-once is Option::take by
construction, not asserted through the shared global. Comment states the
sharing semantics explicitly.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 10, 2026
… gated) (#6455)

* Inferred materialization increment 1: floor demand ledger + receipt gate (#6441)

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* Analysis spine: spine_receipt composes dependency_view + materialize (increment 1)

The Rc-safe half of run ≜ realize ∘ materialize ∘ dependency_view: compose
the two catamorphisms that need no interpreter thread-safety.

- src/v2/std/spine.dag: level-profile fold over the DependencyView DAG →
  critical_path_depth (longest dependency chain / the reduce spine) +
  independence_width (max nodes at one level / what parallelizes to hw width).
  spine_receipt emits the §9 numbers by COMPUTATION, not assertion, joining
  materialize's content-hash Share/dedup counts.
- Discriminating RED (§9): single chain A→B→C → depth 3 / width 1 (serial);
  root over N independent leaves → depth 2 / width N.
- Witnesses 9/9 (spine) green by execution; materialize 6/6 unchanged.

The RUNNER (wall-clock parallel execution, §8 steps 3-4) stays increment 2+,
gated on interpreter Rc→Arc (v1 interp is !Send). This increment measures the
achievable width/critical-path floor the runner targets; it does not fabricate
wall-clock N×.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Unbundle recompute-trace interpreter extension from the analysis-spine PR

CI root cause: the recompute-trace extension edited v1_interpreter.rs, which
hosts the atom_identity_hash/hash_combine fnv1a64 intrinsics that
dag_collect_fingerprint_witness executes. That correctly invalidated the
re-verify 'assumed-green node-frontier' SKIP of that witness (cone-touch,
fail-closed) — but the witness is a pre-existing 806s (13min) fnv1a64
whole-corpus walk, so un-skipping it blew the 30-min floor budget. Main stays
green only because its interpreter cone is untouched (witness stays skipped).

The interpreter extension is a separable, env-gated (GUNBC_RECOMPUTE_TRACE=1),
READ-mode diagnostic — not a dependency of the spine/materialize analysis
substrate (pure .dag, content_hash-based). Reverting v1_interpreter.rs to main
restores byte-identical interpreter content → the fingerprint witness returns to
assumed-green SKIP → floor budget restored. The recompute-trace extension lands
as its own follow-up PR where the fingerprint-witness re-run is expected.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Materialization ladder: the state x decision law, as executable witnesses

The operator's 4-rule business logic generalized on one axis: the decision is
a function of WHEN the redundancy is knowable and WHETHER what was knowable
was prepared for. Errors fire only on knowable-but-unprepared; genuine
emergence and declared triviality are typed acceptances, never silence.

std.materialization_ladder (dag/std):
- Frame/FrameKind: SharedStateFrame | IsolatedChildrenFrame |
  ReplayedFrame{attempts} | UnboundedSiblingsFrame — the nested-scope axis;
  a 'run' at any layer is a frame, never a different kind of thing.
- DemandNature: Pure | IdempotentEffect | WorldRead{envelope_declared} |
  FreshEffect — the D3 effect gate; TTL = unmodeled dependency XOR declared
  staleness, never an eviction knob.
- CacheProvider: keying (ContentKeyed|ExistenceKeyed) + EvictionPolicy
  (ScopeExit|SpacePacked) REQUIRED by construction — rule 3 unwritable-bad.
- LadderVerdict (total): AuthoredDuplication | Discharged | RefusedNoProvider
  | RefusedScopeTooNarrow | RefusedExistenceKeyed (the build-if-absent #6352
  wall) | RefusedUnmodeledWorldRead | ExemptFreshEffect |
  AcceptedBelowCostFloor | AcceptedSingleRecompute.
- Declared-emergent frames obligate UP FRONT: retry frames derive
  checkpointing, unbounded-sibling frames (server loops, CI-runs-over-time)
  derive persistent caches — prepare-before-demand.

12/12 witnesses green by execution; each test is one cell of the table,
fixtures mirror the live worked example (workflow/jobs/steps, retry, fleet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Docs crystallization: derived materialization placement into roadmap ④ + the state x decision table

- roadmap_authority ④ (ROADMAP.md regenerated via main_wet, drift-consistent):
  the nested-frame law, plurality cells, declared-emergent prepare-up-front,
  keying/staleness walls, the caching-completion un-shelve, the ①-vs-§2
  cross-run-caching contradiction subsumed into per-node derived verdicts,
  and the v1.compiler.ownership §3-convergence row.
- duplicate-work design doc: the state x decision table as the qualifier's
  final verdict logic + the ownership consolidation subsection.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Consolidation plan: realization + materialization + ownership are one law

Operator synthesis (2026-07-09): Materialization = the verdict vocabulary;
ownership = the verdict computation at the eval frame; realization = provider
selection discharging the verdict at each frame's carrier. Share's handler is
layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable
carrier + readonly => point-at-it, no copy, no destroyed memory), demoting
through HAMT structural share / process memo / artifact / CAS, and demotion
must be priced, never silent (#6249 clone-fallback is the receipt).

Census of every hand-rolled instance found in-tree (16 rows): each named with
its frame, ladder cell, action, and dissolution trigger — ownership
(consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall),
ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green /
sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB
scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789
(rule-4 requirements), recompute-trace (state-4 finding source). Peers kept
distinct: affected-set, Independence/Placement, mutable state.

Sequence C1-C5 with C1 = this PR (ladder + live CI gate).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Ownership refactored onto materialization: the value tier, tested as providers

First consolidation increment (operator-directed): v1.compiler.ownership's
decision IS provider selection at the value grain, now expressed in the ladder
and proven by mirror witnesses.

- ProviderTier: Reference | Copy | Memo{keying} | Artifact{keying} | Cas{keying}
  — keying folded INTO store tiers, so an existence-keyed reference is
  unwritable BY SHAPE (§5 construction); frame obligations at isolation LCAs
  are dischargeable only by store tiers (a reference cannot cross an isolation
  boundary — witnessed).
- Value tier: AccessMode (Read|Consume|Carry|Project), ValueUsage,
  value_materialization -> ValueDead | ValueMoved | ValueSharedByReference |
  ValueDemotedToCopy (PRICED, requires a declared CopyTier provider — the
  #6249 silent clone-fallback made refusable) | ValueRefusedAffine |
  ValueRefusedNoCarrierProvider.
- Faithful to v1's THREE distinct plurality readings, kept separate:
  take_count = semantic_consumer_count (Consumed only, affine axis);
  value_access_plurality = binding_fan_out (Carry excluded, reference axis);
  borrow_count = whole_value_borrow_count (Read+Carry not Project, movability).
- Fold-accumulator case mirrored at conservative pre-FoldAccUnwrap semantics:
  carries excluded from plurality but blocking the move -> demoted-to-copy.

23/23 witnesses green (14 frame cells + 9 value cells). Corpus-level
equivalence against live v1 ownership folds = the C4 receipt.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* WIP: Duplicate Computation/Materialization

* G: exhaustive cache/share census (52 mechanisms, 6 groups) + C0 catalog-grounding of provider rows + forward-wiring walls

The sweep found the tree already models caches: extdeps/cache cache_catalog
(CacheInterfaceCatalogFacts, 9 rows) + extdeps/realization carrier facts +
the warm==cold purity oracle. C0 grounds CacheProvider on that catalog
(provider_from_catalog projection; CacheProvider.id -> CacheInterfaceId)
so the ladder and the catalog never restate each other's half. Three
forward walls (demands-from-DependencyView, hand-cache shape lens,
live-provider-or-red) make new caches born as provider rows only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* C0: provider rows derive from the cited cache catalog (extdeps/cache/materialization.dag projection)

Operator ruling 2026-07-09: extdeps stays the ground-truth/interface layer;
every USE of a cache goes through materialization so memo never gets
re-invented. provider_from_catalog is the only door from a catalog row into
the ladder: keying/tier/eviction derived from cited facts (mechanism->class:
InProcess=>ScopeExit; Ttl/Lru/SizeBounded=>SpacePacked; Never/Manual outside
a process => typed ProjectionRefused, counted by the new enrolled witness;
HandAuthored/prefix-fallback keys => ExistenceKeyed until key-completeness
upgrades them). CI sccache row now derived, hand-typed tier facts deleted,
6/6 + 23/23 witnesses green. 10b re-scoped: v1-internal caches = inventory
only (retire with seed); ParseTable/cached_stage promoted to next.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* Fail-closed hardening: RefusedNatureConflict arm, weakest-claim nature default, UsesStep silence counted, ladder cells enrolled in CI

The complexity-lens false-clean lesson applied to this gate before anyone
relies on it: (1) heterogeneous natures on one identity were first-wins —
now a typed RefusedNatureConflict (24th ladder cell, RED witness); (2) an
unrostered run-step claimed PureComputation — now IdempotentEffect, the
weakest claim (verdict-identical, no purity overclaim; a misdeclared
WorldRead can no longer be legally memoized by default); (3) UsesStep
foreign actions produced silence — now a pinned denominator (==9; a new
foreign action must consciously bump it); (4) the ladder's 24 cells enroll
on the CI surface so the law's own witnesses gate every run. 24/24 + 7/7.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* M1 ratchet bump: declared resolve count 1 -> 3 (gate's first live catch — enrollment pays counted resolves)

Run 29058798771: enrolling the ladder witness file moved resolves_total
1 -> 3 (each enrolled entry file pays one closure resolve against the
shared index) and the receipt gate redded that exact run — the designed
semantics, receipted in the note. Bump acknowledges the two witness-entry
resolves as declared debt; M2 (one closure resolve per roots set)
ratchets back toward 1.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Retire the M1/M2 labels from carriers (no-codename rule; collided with DESIGN's floor-memoization M1/M2)

Step renamed to 'Floor resolve receipt gate (declared cold-resolve count)';
notes and the gate echo now say what the things are: the counted
cold-resolve receipt, and the shared-resolve rewire (one closure resolve
per source-roots set). Naming-retirement note left on the carrier.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* Run-step natures pinned as counted claims, not affordances

Operator ruling 2026-07-10: hardcoded shell scripts get no affordances
— run-steps are supposed to be modeled as typed intents and emitted
(shell-emission-model slice 4 covers ci_workflow RunSteps). Until that
slice lands, every nature in job_run_demands is a claim (rostered
FreshEffect / weakest-default IdempotentEffect), never derived from a
modeled effect row. Count the whole claimed-nature surface (16 by
execution) and pin it in the enrolled witness: a new raw-script step
must consciously bump the pin, and slice-4 migration becomes a
countable ratchet ending at zero, where the pin becomes a wall.
Rejected alternative recorded in the carrier note: a per-step
declared-natures roster (a second parallel ledger over scripts the
shell-emission plan already governs).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Regen DESIGN.md after main merge (duplicate-work row + #6373 body-lowering row coexist)

Conflict was both sides editing the open-threads list in design_document.dag:
ours added the duplicate-work thread, main's #6373 rewrote body-lowering to
Stages 1-3 LANDED. Resolution keeps both rows in the .dag authority; DESIGN.md
regenerated from it, never hand-edited.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* Inferred materialization increment 1: floor demand ledger + receipt-or-red gate

Running IS enrolling: the interpreter ledgers every keyed pure call and every
InterpContext absorbs its totals into a process accumulator on Drop — by
construction, no eval path escapes the receipt. claim_executor writes
target/floor-materialization-receipt.txt at walk end; trace defaults ON in
the executor, and an explicit =0 zeroes keyed_calls which the gate refuses.

Gate arms this push (all verified under dash from the emitted ci.yml):
receipt missing/malformed/keyed_calls=0 fail closed. Exact pins for
unkeyed_calls and duplicated_keys land from the FIRST CI receipt (the
resolve gate's measure-then-pin path) — unkeyed is known nonzero on the
floor (count_matching takes a predicate closure; closures are the one
disclosed identity-less class, dissolve-on captured-env content identity).

Unit witness green: resolve -> eval -> ctx Drop -> absorb -> drain-once.
Step addition bumped the claimed-natures pin 16 -> 17 consciously.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Review fix: drop the racy drain-once assertion from the receipt unit test

opus-4-7 finding on #6441: under plain cargo test (still the documented
runner) tests share a process, the env latch is OnceLock-sticky, and
sibling ctx drops could absorb between the two takes — making the
drain-empty assertion racy. Absorb-on-Drop stays asserted (monotone under
concurrent absorbs: siblings only ADD); drain-once is Option::take by
construction, not asserted through the shared global. Comment states the
sharing semantics explicitly.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Turn on affected-set CI: re-land witness enrollment flip (discovery shrunk by affected set) + falsifier host-OOM receipt (#6438)

* WIP: Re-land affected-set CI enrollment flip once shard resolve footprint is

* WIP: Re-land affected-set CI enrollment flip once shard resolve footprint is

* Fix CI OOM: pin discovery corpus spawn_width_cap to 1.

Run 28999086030 OOM-killed at width=2 on the 24GiB live slot during the
discovery-flip corpus batch. Gate workloads still fit at width=2; only the
tree-wide discovery batch serializes via spawn_width_cap=1, with a receipt
witness and dissolve-on note.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix type error in corpus discovery spawn width cap helper.

Both if-branches must return Nat (hardware_thread_count_value), not a
bare Int literal.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Merge affected-set enrollment flip (takeover of PR #6403 from session/gentle-stag-677-flip)

Conflict resolutions onto post-#6422/#6431/#6432/#6435 main:
- ci_witness_optin_inversion: main's typed Scaffold Disposition -> Terminal (dissolve fired at the flip; roster stays as explicit-entry home, exclusivity dissolved)
- floor step timeout: 45 (main) vs 60 (flip) -> 60 with provenance note
- ci_spec notes: kept flip notes, stale fixed-8 phrasing dated
- falsifier width note: + RESIDUE paragraph (5x exit-137 on srv2-class slots = converge lane, not plan width)

Verified before commit: discovery batches charge corpus_resolve_nanos (own key), resolve_nanos=0 -> resolves_total declared 3 is NOT moved by the flip.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: affected set processing

* WIP: affected set processing

* WIP: affected set processing

* WIP: affected set processing

* Correct the false flip receipt + kill-surviving calibration receipts (space-lens loop)

CORRECTED RECEIPT: run 29000557166's floor never completed - the executor was
host-OOM-killed mid-discovery-corpus at ~8min; the log's ExitSuccess belongs to
the merge-admission stamp tool stamping CI_FLOOR_EXIT=137. No flipped corpus
has completed in CI (0/1 ci + 0/5 falsifier). Both carrier notes corrected.

Calibration (coordinated with merry-owl-649's space-lens lane):
- roster_import_closure_nodes_pre_resolve: shared closure-count authority
  (pure import walk, closure grain not entry grain), emitted BEFORE the heavy
  resolve so killed runs still yield the (nodes, peak) lower-bound pair
- width-1 definition-drift oracle: pre-resolve walk must equal post-resolve
  resolved union on completed runs; refuses on divergence. Proven by execution:
  pre == post == 190/213 nodes across Off/Applied modes
- kill-surviving cgroup memory.peak pre/post steps (post is always()) in the
  ci job and falsifier.yml; scope semantics labeled on the emission lines
  (reset=ok floor-scoped; span compares post>pre; never silently conflated)
- job backstop timeouts extended by the two aux steps in both jobs

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: affected set processing

* Calibration pairs carry censored-vs-exact labels (methodology: killed runs are censored observations)

Floor steps get id=floor; the always() post-peak step emits floor_outcome so
each (closure_nodes, peak) pair is explicitly labeled: success = exact point,
anything else = censored lower bound (true demand strictly greater than read).
Prevents the fit from treating cap-kill reads as point estimates, which would
drag the slope down and make the predictor underestimate - the dangerous
direction (merry-owl methodology catch, 2026-07-10).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: affected set processing

* Review fixes: explicit witness import + complete step-budget ledger

- ci_floor_plan_witness_test.dag: import witness_ci_corpus_discovery_serializes_at_width_one
  explicitly (cursor catch on #6438). The call resolved pre-fix via the seed resolver's flat
  namespace, so the witness ran green by execution; the explicit import restores the file's
  per-symbol import convention.
- ci_workflow.dag: the resolve-receipt gate step had NO step cap — a hang there could only die
  by job-cancel (the #6323 starvation-kill class). It now carries the aux cap (script is a
  sub-second receipt read) and the ci job backstop counts four aux terms (peak pre/post,
  resolve-receipt gate, merge-admission gate): every step budgeted, backstop = step-sum + prelude
  (claude review catch on #6438, sharpened).
- falsifier_workflow_witness_test.dag: falsifier_backstop_is_step_sum_plus_prelude asserted the
  pre-calibration formula — latent red proven by execution (FAIL receipt), fixed to the live
  two-aux sum, re-run PASS.
- ci.yml regenerated byte-stable from the carrier (backstops 125->130, gate step timeout 5m).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Rebind calibration provenance comments to real artifacts (cursor review catch)

The two cli_run.rs comments cited docs/plans/space-lens-minimal-project.md, which does
not exist on main — the predictor design is in flight on PR #6442 (merry-owl-649's lane)
and was never landed under that path. Rebound: the shared closure-definition authority is
stated as this function itself, with the in-flight design cited by PR number and the
landed parent-lane authorities cited by real paths (compute-envelope-model.md fleet
envelope; input-envelope-roadmap.md admission). No behavior change; cargo check clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: affected set processing

* Remove stray empty file (shell-redirect artifact the auto-committer flushed)

An internal-messaging command's backtick content was command-substituted by bash; a
'-> fail-closed' fragment became a stdout redirect and created an empty file at the
repo root, which the auto-committer then committed as 38f0a46. No tree content
beyond the empty file; removing it restores the branch to e99c757's content.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: affected set processing

* Scaffold-mark the cgroup peak calibration shell (cursor review catch)

The three concat-built calibration runners (ci_cgroup_peak_locate_shell,
ci_floor_peak_pre_script, ci_floor_peak_post_script) landed without the on-carrier
scaffold markers repo convention requires for hand-shell. Each now carries a
Disposition = Scaffold { dissolves_to: RealizationDispatch } row binding the decl
(the ci_materialization pattern), and both scripts embed the shared dissolve-on
note as a shell comment (the ci_spec pattern): dissolution = bash-emit (#5828 /
gap-B emit(intent, Bash)) realizing the observation as an emitted ShellProgram
intent or a typed host Observe effect. ci.yml + falsifier.yml regenerated;
falsifier_workflow_witness_holds and the flip witnesses re-run PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Merge origin/main into session/loyal-wren-398 (resolve #6441 step-list conflict)

Conflict resolution, all consciously declared:
- ci_job steps: union — the calibration peak pre/post steps wrap the floor step (this
  branch) and #6441's materialization receipt gate slots between the resolve-receipt
  gate and the merge-admission gate (main).
- The incoming materialization receipt gate step landed with timeout none — the same
  uncapped-step starvation-kill class this branch's review fix eliminated — so it now
  carries the aux cap, and the ci backstop counts FIVE aux terms (peak pre, peak post,
  resolve-receipt gate, materialization receipt gate, merge-admission gate); the budget
  disposition note records the merge provenance.
- ci_run_step_natures_are_claims_counted_not_silent: RunStep count pin bumped 17 -> 19,
  acknowledging the two peak calibration steps #6441's count predates (conscious-count
  discipline; proven red at 17 then green at 19 by execution).
- ci.yml regenerated from the merged carriers (backstops 130 -> 135).

Verified on the merged tree: release bins rebuilt on merged Rust; falsifier workflow
witness, flip witnesses, floor-plan/optin/width witnesses, and all 8 ci_materialization
witnesses PASS; generated-artifact regen ExitSuccess.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* ShellProgram -> DAG: transport intent collapse + live importer ratchet (phase 0 of the sidecar dissolution) (#6449)

* WIP: ShellProgram -> DAG

* WIP: ShellProgram -> DAG

* WIP: ShellProgram -> DAG

* WIP: ShellProgram -> DAG

* WIP: ShellProgram -> DAG

* bash fold: native Concat/CmdSubst/WithRedir coverage + measured cost wall on the whole-tree emit path

Fold-family productions extended so the fold no longer refuses word
Concat/CmdSubst or stmt WithRedir (all four Redir variants): new
concat_parts/word-compound/with_redir production families, lex tokens,
kind-tag emit transforms, and recursive bundle arms. Byte-identity vs
serialize_bash proven by execution: five depth-2 oracle tests plus the
depth-4 assign_root_stmt manual probe (ROOT=$('git' 'rev-parse'
'--show-toplevel' 2>/dev/null || 'pwd') byte-exact). The delegated
fail-closed RED control repoints from WithRedir (now native) to Heredoc
(still delegated) so the boundary guard stays discriminating.

Measured cost wall, declared on-carrier (bash_program_emit_cost_wall_note):
whole-tree backward row-selection is ~alternatives^depth (1s flat stmt,
64s for the single depth-4 stmt, DNF >8min for the full witness_bin
program) because formal_production_unique_lhs_exact_match deep-validates
every candidate per level and the descent re-validates each level again.
Real-program oracles therefore stay MANUAL probes, not test fns (a
discovery-run test would hang the local floor); the probe note on the
test carrier names the dissolution triggers.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* WIP: Wave 1A - namespace-only name resolution: make the syntactic containment

* B1: NameResolutionPolicy row + position-tracked resolve (NamespaceOnlyY gated).

Add v2.std.resolution_policy (ImportScoped default | NamespaceOnlyY). Thread
ResolveContext { position, expected, policy } through resolve walk; namespace-only
skips import module bindings and uses symbol_index at position. Policy pilot
witness: green under NamespaceOnlyY at type position, RED under ImportScoped at
module position. Import-scoped global default unchanged — zero corpus churn.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Wave 1A - namespace-only name resolution: make the syntactic containment tree the single naming authority (qualified name = nesting position, reference = lexical lookup up ancestors, . = projection one level down). Path: confirm loyal-heron SymbolIndex scaling receipt FIRST, then SymbolIndex = conta (#6451)

* WIP: Wave 1A - namespace-only name resolution: make the syntactic containment

* v2.std.symbol_index: materialize containment tree as single naming authority

Add SymbolIndex fill from nesting (qualified path → Node), qualified-name
path algebra bridges, and discriminating witnesses. Retarget #6436 variant-
visibility scaffold to dissolve into symbol_index_lexical_lookup; harvest_unique
stays interim until module-scoped index scan lands.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Wave 1A - namespace-only name resolution: make the syntactic containment

* Fix rust fmt on qualified-name bridge host functions (CI rust_tests gate).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Wave 1A - namespace-only name resolution: make the syntactic containment

* Remove symbol_index_has_path; tests match symbol_index_lookup directly

Dissolve Optional→Bool predicate in new std/ surface per review. Lexical
lookup root termination already uses qualified_name_is_empty (not dotted
string projection).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Wave 1A - namespace-only name resolution: make the syntactic containment

* Address review: is_empty authority, host scaffold binds, layer split

- Remove qualified_name_is_empty; lexical lookup uses is_empty(xs: position)
- Host dispositions bind to from/to_dotted_string bridges; add P5 receipt tests
- Move extdeps-coupled fill to v2.compiler.symbol_index_fill (layer DAG fix)

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Wave 1A - namespace-only name resolution: make the syntactic containment

* WIP: Wave 1A - namespace-only name resolution: make the syntactic containment

* Wire resolver through SymbolIndex; dissolve harvest_unique_disj interim.

Build SymbolIndex at admission and thread it through Namespace. resolve_atom
falls back to symbol_index_lexical_lookup for unbound atoms after import-scoped
lookup_chain. Fill-time unique-variant aliases (suffix-scan equivalent) replace
#6436 harvest_unique_disj. Equivalence witnesses prove SymbolIndex-alone covers
variant visibility (green + without-alias RED control); end-to-end wire green.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Wave 1A - namespace-only name resolution: make the syntactic containment

* Drop unused ResolveContext.expected until expected-type lane lands.

Removes the dead field and uncalled resolve_ctx_with_expected helper
flagged in #6454 review 36717 — B1 uses position-only disambiguation;
expected-type filtering returns when that slice is scoped.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
briansrls added a commit that referenced this pull request Jul 11, 2026
…eipt-write refusal + counter invariant (#6456)

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* Analysis spine: spine_receipt composes dependency_view + materialize (increment 1)

The Rc-safe half of run ≜ realize ∘ materialize ∘ dependency_view: compose
the two catamorphisms that need no interpreter thread-safety.

- src/v2/std/spine.dag: level-profile fold over the DependencyView DAG →
  critical_path_depth (longest dependency chain / the reduce spine) +
  independence_width (max nodes at one level / what parallelizes to hw width).
  spine_receipt emits the §9 numbers by COMPUTATION, not assertion, joining
  materialize's content-hash Share/dedup counts.
- Discriminating RED (§9): single chain A→B→C → depth 3 / width 1 (serial);
  root over N independent leaves → depth 2 / width N.
- Witnesses 9/9 (spine) green by execution; materialize 6/6 unchanged.

The RUNNER (wall-clock parallel execution, §8 steps 3-4) stays increment 2+,
gated on interpreter Rc→Arc (v1 interp is !Send). This increment measures the
achievable width/critical-path floor the runner targets; it does not fabricate
wall-clock N×.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Unbundle recompute-trace interpreter extension from the analysis-spine PR

CI root cause: the recompute-trace extension edited v1_interpreter.rs, which
hosts the atom_identity_hash/hash_combine fnv1a64 intrinsics that
dag_collect_fingerprint_witness executes. That correctly invalidated the
re-verify 'assumed-green node-frontier' SKIP of that witness (cone-touch,
fail-closed) — but the witness is a pre-existing 806s (13min) fnv1a64
whole-corpus walk, so un-skipping it blew the 30-min floor budget. Main stays
green only because its interpreter cone is untouched (witness stays skipped).

The interpreter extension is a separable, env-gated (GUNBC_RECOMPUTE_TRACE=1),
READ-mode diagnostic — not a dependency of the spine/materialize analysis
substrate (pure .dag, content_hash-based). Reverting v1_interpreter.rs to main
restores byte-identical interpreter content → the fingerprint witness returns to
assumed-green SKIP → floor budget restored. The recompute-trace extension lands
as its own follow-up PR where the fingerprint-witness re-run is expected.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Materialization ladder: the state x decision law, as executable witnesses

The operator's 4-rule business logic generalized on one axis: the decision is
a function of WHEN the redundancy is knowable and WHETHER what was knowable
was prepared for. Errors fire only on knowable-but-unprepared; genuine
emergence and declared triviality are typed acceptances, never silence.

std.materialization_ladder (dag/std):
- Frame/FrameKind: SharedStateFrame | IsolatedChildrenFrame |
  ReplayedFrame{attempts} | UnboundedSiblingsFrame — the nested-scope axis;
  a 'run' at any layer is a frame, never a different kind of thing.
- DemandNature: Pure | IdempotentEffect | WorldRead{envelope_declared} |
  FreshEffect — the D3 effect gate; TTL = unmodeled dependency XOR declared
  staleness, never an eviction knob.
- CacheProvider: keying (ContentKeyed|ExistenceKeyed) + EvictionPolicy
  (ScopeExit|SpacePacked) REQUIRED by construction — rule 3 unwritable-bad.
- LadderVerdict (total): AuthoredDuplication | Discharged | RefusedNoProvider
  | RefusedScopeTooNarrow | RefusedExistenceKeyed (the build-if-absent #6352
  wall) | RefusedUnmodeledWorldRead | ExemptFreshEffect |
  AcceptedBelowCostFloor | AcceptedSingleRecompute.
- Declared-emergent frames obligate UP FRONT: retry frames derive
  checkpointing, unbounded-sibling frames (server loops, CI-runs-over-time)
  derive persistent caches — prepare-before-demand.

12/12 witnesses green by execution; each test is one cell of the table,
fixtures mirror the live worked example (workflow/jobs/steps, retry, fleet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Docs crystallization: derived materialization placement into roadmap ④ + the state x decision table

- roadmap_authority ④ (ROADMAP.md regenerated via main_wet, drift-consistent):
  the nested-frame law, plurality cells, declared-emergent prepare-up-front,
  keying/staleness walls, the caching-completion un-shelve, the ①-vs-§2
  cross-run-caching contradiction subsumed into per-node derived verdicts,
  and the v1.compiler.ownership §3-convergence row.
- duplicate-work design doc: the state x decision table as the qualifier's
  final verdict logic + the ownership consolidation subsection.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Consolidation plan: realization + materialization + ownership are one law

Operator synthesis (2026-07-09): Materialization = the verdict vocabulary;
ownership = the verdict computation at the eval frame; realization = provider
selection discharging the verdict at each frame's carrier. Share's handler is
layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable
carrier + readonly => point-at-it, no copy, no destroyed memory), demoting
through HAMT structural share / process memo / artifact / CAS, and demotion
must be priced, never silent (#6249 clone-fallback is the receipt).

Census of every hand-rolled instance found in-tree (16 rows): each named with
its frame, ladder cell, action, and dissolution trigger — ownership
(consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall),
ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green /
sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB
scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789
(rule-4 requirements), recompute-trace (state-4 finding source). Peers kept
distinct: affected-set, Independence/Placement, mutable state.

Sequence C1-C5 with C1 = this PR (ladder + live CI gate).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Ownership refactored onto materialization: the value tier, tested as providers

First consolidation increment (operator-directed): v1.compiler.ownership's
decision IS provider selection at the value grain, now expressed in the ladder
and proven by mirror witnesses.

- ProviderTier: Reference | Copy | Memo{keying} | Artifact{keying} | Cas{keying}
  — keying folded INTO store tiers, so an existence-keyed reference is
  unwritable BY SHAPE (§5 construction); frame obligations at isolation LCAs
  are dischargeable only by store tiers (a reference cannot cross an isolation
  boundary — witnessed).
- Value tier: AccessMode (Read|Consume|Carry|Project), ValueUsage,
  value_materialization -> ValueDead | ValueMoved | ValueSharedByReference |
  ValueDemotedToCopy (PRICED, requires a declared CopyTier provider — the
  #6249 silent clone-fallback made refusable) | ValueRefusedAffine |
  ValueRefusedNoCarrierProvider.
- Faithful to v1's THREE distinct plurality readings, kept separate:
  take_count = semantic_consumer_count (Consumed only, affine axis);
  value_access_plurality = binding_fan_out (Carry excluded, reference axis);
  borrow_count = whole_value_borrow_count (Read+Carry not Project, movability).
- Fold-accumulator case mirrored at conservative pre-FoldAccUnwrap semantics:
  carries excluded from plurality but blocking the move -> demoted-to-copy.

23/23 witnesses green (14 frame cells + 9 value cells). Corpus-level
equivalence against live v1 ownership folds = the C4 receipt.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* WIP: Duplicate Computation/Materialization

* G: exhaustive cache/share census (52 mechanisms, 6 groups) + C0 catalog-grounding of provider rows + forward-wiring walls

The sweep found the tree already models caches: extdeps/cache cache_catalog
(CacheInterfaceCatalogFacts, 9 rows) + extdeps/realization carrier facts +
the warm==cold purity oracle. C0 grounds CacheProvider on that catalog
(provider_from_catalog projection; CacheProvider.id -> CacheInterfaceId)
so the ladder and the catalog never restate each other's half. Three
forward walls (demands-from-DependencyView, hand-cache shape lens,
live-provider-or-red) make new caches born as provider rows only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* C0: provider rows derive from the cited cache catalog (extdeps/cache/materialization.dag projection)

Operator ruling 2026-07-09: extdeps stays the ground-truth/interface layer;
every USE of a cache goes through materialization so memo never gets
re-invented. provider_from_catalog is the only door from a catalog row into
the ladder: keying/tier/eviction derived from cited facts (mechanism->class:
InProcess=>ScopeExit; Ttl/Lru/SizeBounded=>SpacePacked; Never/Manual outside
a process => typed ProjectionRefused, counted by the new enrolled witness;
HandAuthored/prefix-fallback keys => ExistenceKeyed until key-completeness
upgrades them). CI sccache row now derived, hand-typed tier facts deleted,
6/6 + 23/23 witnesses green. 10b re-scoped: v1-internal caches = inventory
only (retire with seed); ParseTable/cached_stage promoted to next.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* Fail-closed hardening: RefusedNatureConflict arm, weakest-claim nature default, UsesStep silence counted, ladder cells enrolled in CI

The complexity-lens false-clean lesson applied to this gate before anyone
relies on it: (1) heterogeneous natures on one identity were first-wins —
now a typed RefusedNatureConflict (24th ladder cell, RED witness); (2) an
unrostered run-step claimed PureComputation — now IdempotentEffect, the
weakest claim (verdict-identical, no purity overclaim; a misdeclared
WorldRead can no longer be legally memoized by default); (3) UsesStep
foreign actions produced silence — now a pinned denominator (==9; a new
foreign action must consciously bump it); (4) the ladder's 24 cells enroll
on the CI surface so the law's own witnesses gate every run. 24/24 + 7/7.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* M1 ratchet bump: declared resolve count 1 -> 3 (gate's first live catch — enrollment pays counted resolves)

Run 29058798771: enrolling the ladder witness file moved resolves_total
1 -> 3 (each enrolled entry file pays one closure resolve against the
shared index) and the receipt gate redded that exact run — the designed
semantics, receipted in the note. Bump acknowledges the two witness-entry
resolves as declared debt; M2 (one closure resolve per roots set)
ratchets back toward 1.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Retire the M1/M2 labels from carriers (no-codename rule; collided with DESIGN's floor-memoization M1/M2)

Step renamed to 'Floor resolve receipt gate (declared cold-resolve count)';
notes and the gate echo now say what the things are: the counted
cold-resolve receipt, and the shared-resolve rewire (one closure resolve
per source-roots set). Naming-retirement note left on the carrier.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* Run-step natures pinned as counted claims, not affordances

Operator ruling 2026-07-10: hardcoded shell scripts get no affordances
— run-steps are supposed to be modeled as typed intents and emitted
(shell-emission-model slice 4 covers ci_workflow RunSteps). Until that
slice lands, every nature in job_run_demands is a claim (rostered
FreshEffect / weakest-default IdempotentEffect), never derived from a
modeled effect row. Count the whole claimed-nature surface (16 by
execution) and pin it in the enrolled witness: a new raw-script step
must consciously bump the pin, and slice-4 migration becomes a
countable ratchet ending at zero, where the pin becomes a wall.
Rejected alternative recorded in the carrier note: a per-step
declared-natures roster (a second parallel ledger over scripts the
shell-emission plan already governs).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Regen DESIGN.md after main merge (duplicate-work row + #6373 body-lowering row coexist)

Conflict was both sides editing the open-threads list in design_document.dag:
ours added the duplicate-work thread, main's #6373 rewrote body-lowering to
Stages 1-3 LANDED. Resolution keeps both rows in the .dag authority; DESIGN.md
regenerated from it, never hand-edited.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* Inferred materialization increment 1: floor demand ledger + receipt-or-red gate

Running IS enrolling: the interpreter ledgers every keyed pure call and every
InterpContext absorbs its totals into a process accumulator on Drop — by
construction, no eval path escapes the receipt. claim_executor writes
target/floor-materialization-receipt.txt at walk end; trace defaults ON in
the executor, and an explicit =0 zeroes keyed_calls which the gate refuses.

Gate arms this push (all verified under dash from the emitted ci.yml):
receipt missing/malformed/keyed_calls=0 fail closed. Exact pins for
unkeyed_calls and duplicated_keys land from the FIRST CI receipt (the
resolve gate's measure-then-pin path) — unkeyed is known nonzero on the
floor (count_matching takes a predicate closure; closures are the one
disclosed identity-less class, dissolve-on captured-env content identity).

Unit witness green: resolve -> eval -> ctx Drop -> absorb -> drain-once.
Step addition bumped the claimed-natures pin 16 -> 17 consciously.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Review fix: drop the racy drain-once assertion from the receipt unit test

opus-4-7 finding on #6441: under plain cargo test (still the documented
runner) tests share a process, the env latch is OnceLock-sticky, and
sibling ctx drops could absorb between the two takes — making the
drain-empty assertion racy. Absorb-on-Drop stays asserted (monotone under
concurrent absorbs: siblings only ADD); drain-once is Option::take by
construction, not asserted through the shared global. Comment states the
sharing semantics explicitly.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 11, 2026
…ncident, argued serially with receipts) (#6469)

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* Analysis spine: spine_receipt composes dependency_view + materialize (increment 1)

The Rc-safe half of run ≜ realize ∘ materialize ∘ dependency_view: compose
the two catamorphisms that need no interpreter thread-safety.

- src/v2/std/spine.dag: level-profile fold over the DependencyView DAG →
  critical_path_depth (longest dependency chain / the reduce spine) +
  independence_width (max nodes at one level / what parallelizes to hw width).
  spine_receipt emits the §9 numbers by COMPUTATION, not assertion, joining
  materialize's content-hash Share/dedup counts.
- Discriminating RED (§9): single chain A→B→C → depth 3 / width 1 (serial);
  root over N independent leaves → depth 2 / width N.
- Witnesses 9/9 (spine) green by execution; materialize 6/6 unchanged.

The RUNNER (wall-clock parallel execution, §8 steps 3-4) stays increment 2+,
gated on interpreter Rc→Arc (v1 interp is !Send). This increment measures the
achievable width/critical-path floor the runner targets; it does not fabricate
wall-clock N×.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Unbundle recompute-trace interpreter extension from the analysis-spine PR

CI root cause: the recompute-trace extension edited v1_interpreter.rs, which
hosts the atom_identity_hash/hash_combine fnv1a64 intrinsics that
dag_collect_fingerprint_witness executes. That correctly invalidated the
re-verify 'assumed-green node-frontier' SKIP of that witness (cone-touch,
fail-closed) — but the witness is a pre-existing 806s (13min) fnv1a64
whole-corpus walk, so un-skipping it blew the 30-min floor budget. Main stays
green only because its interpreter cone is untouched (witness stays skipped).

The interpreter extension is a separable, env-gated (GUNBC_RECOMPUTE_TRACE=1),
READ-mode diagnostic — not a dependency of the spine/materialize analysis
substrate (pure .dag, content_hash-based). Reverting v1_interpreter.rs to main
restores byte-identical interpreter content → the fingerprint witness returns to
assumed-green SKIP → floor budget restored. The recompute-trace extension lands
as its own follow-up PR where the fingerprint-witness re-run is expected.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Materialization ladder: the state x decision law, as executable witnesses

The operator's 4-rule business logic generalized on one axis: the decision is
a function of WHEN the redundancy is knowable and WHETHER what was knowable
was prepared for. Errors fire only on knowable-but-unprepared; genuine
emergence and declared triviality are typed acceptances, never silence.

std.materialization_ladder (dag/std):
- Frame/FrameKind: SharedStateFrame | IsolatedChildrenFrame |
  ReplayedFrame{attempts} | UnboundedSiblingsFrame — the nested-scope axis;
  a 'run' at any layer is a frame, never a different kind of thing.
- DemandNature: Pure | IdempotentEffect | WorldRead{envelope_declared} |
  FreshEffect — the D3 effect gate; TTL = unmodeled dependency XOR declared
  staleness, never an eviction knob.
- CacheProvider: keying (ContentKeyed|ExistenceKeyed) + EvictionPolicy
  (ScopeExit|SpacePacked) REQUIRED by construction — rule 3 unwritable-bad.
- LadderVerdict (total): AuthoredDuplication | Discharged | RefusedNoProvider
  | RefusedScopeTooNarrow | RefusedExistenceKeyed (the build-if-absent #6352
  wall) | RefusedUnmodeledWorldRead | ExemptFreshEffect |
  AcceptedBelowCostFloor | AcceptedSingleRecompute.
- Declared-emergent frames obligate UP FRONT: retry frames derive
  checkpointing, unbounded-sibling frames (server loops, CI-runs-over-time)
  derive persistent caches — prepare-before-demand.

12/12 witnesses green by execution; each test is one cell of the table,
fixtures mirror the live worked example (workflow/jobs/steps, retry, fleet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Docs crystallization: derived materialization placement into roadmap ④ + the state x decision table

- roadmap_authority ④ (ROADMAP.md regenerated via main_wet, drift-consistent):
  the nested-frame law, plurality cells, declared-emergent prepare-up-front,
  keying/staleness walls, the caching-completion un-shelve, the ①-vs-§2
  cross-run-caching contradiction subsumed into per-node derived verdicts,
  and the v1.compiler.ownership §3-convergence row.
- duplicate-work design doc: the state x decision table as the qualifier's
  final verdict logic + the ownership consolidation subsection.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Consolidation plan: realization + materialization + ownership are one law

Operator synthesis (2026-07-09): Materialization = the verdict vocabulary;
ownership = the verdict computation at the eval frame; realization = provider
selection discharging the verdict at each frame's carrier. Share's handler is
layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable
carrier + readonly => point-at-it, no copy, no destroyed memory), demoting
through HAMT structural share / process memo / artifact / CAS, and demotion
must be priced, never silent (#6249 clone-fallback is the receipt).

Census of every hand-rolled instance found in-tree (16 rows): each named with
its frame, ladder cell, action, and dissolution trigger — ownership
(consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall),
ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green /
sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB
scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789
(rule-4 requirements), recompute-trace (state-4 finding source). Peers kept
distinct: affected-set, Independence/Placement, mutable state.

Sequence C1-C5 with C1 = this PR (ladder + live CI gate).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Ownership refactored onto materialization: the value tier, tested as providers

First consolidation increment (operator-directed): v1.compiler.ownership's
decision IS provider selection at the value grain, now expressed in the ladder
and proven by mirror witnesses.

- ProviderTier: Reference | Copy | Memo{keying} | Artifact{keying} | Cas{keying}
  — keying folded INTO store tiers, so an existence-keyed reference is
  unwritable BY SHAPE (§5 construction); frame obligations at isolation LCAs
  are dischargeable only by store tiers (a reference cannot cross an isolation
  boundary — witnessed).
- Value tier: AccessMode (Read|Consume|Carry|Project), ValueUsage,
  value_materialization -> ValueDead | ValueMoved | ValueSharedByReference |
  ValueDemotedToCopy (PRICED, requires a declared CopyTier provider — the
  #6249 silent clone-fallback made refusable) | ValueRefusedAffine |
  ValueRefusedNoCarrierProvider.
- Faithful to v1's THREE distinct plurality readings, kept separate:
  take_count = semantic_consumer_count (Consumed only, affine axis);
  value_access_plurality = binding_fan_out (Carry excluded, reference axis);
  borrow_count = whole_value_borrow_count (Read+Carry not Project, movability).
- Fold-accumulator case mirrored at conservative pre-FoldAccUnwrap semantics:
  carries excluded from plurality but blocking the move -> demoted-to-copy.

23/23 witnesses green (14 frame cells + 9 value cells). Corpus-level
equivalence against live v1 ownership folds = the C4 receipt.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* WIP: Duplicate Computation/Materialization

* G: exhaustive cache/share census (52 mechanisms, 6 groups) + C0 catalog-grounding of provider rows + forward-wiring walls

The sweep found the tree already models caches: extdeps/cache cache_catalog
(CacheInterfaceCatalogFacts, 9 rows) + extdeps/realization carrier facts +
the warm==cold purity oracle. C0 grounds CacheProvider on that catalog
(provider_from_catalog projection; CacheProvider.id -> CacheInterfaceId)
so the ladder and the catalog never restate each other's half. Three
forward walls (demands-from-DependencyView, hand-cache shape lens,
live-provider-or-red) make new caches born as provider rows only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* C0: provider rows derive from the cited cache catalog (extdeps/cache/materialization.dag projection)

Operator ruling 2026-07-09: extdeps stays the ground-truth/interface layer;
every USE of a cache goes through materialization so memo never gets
re-invented. provider_from_catalog is the only door from a catalog row into
the ladder: keying/tier/eviction derived from cited facts (mechanism->class:
InProcess=>ScopeExit; Ttl/Lru/SizeBounded=>SpacePacked; Never/Manual outside
a process => typed ProjectionRefused, counted by the new enrolled witness;
HandAuthored/prefix-fallback keys => ExistenceKeyed until key-completeness
upgrades them). CI sccache row now derived, hand-typed tier facts deleted,
6/6 + 23/23 witnesses green. 10b re-scoped: v1-internal caches = inventory
only (retire with seed); ParseTable/cached_stage promoted to next.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* Fail-closed hardening: RefusedNatureConflict arm, weakest-claim nature default, UsesStep silence counted, ladder cells enrolled in CI

The complexity-lens false-clean lesson applied to this gate before anyone
relies on it: (1) heterogeneous natures on one identity were first-wins —
now a typed RefusedNatureConflict (24th ladder cell, RED witness); (2) an
unrostered run-step claimed PureComputation — now IdempotentEffect, the
weakest claim (verdict-identical, no purity overclaim; a misdeclared
WorldRead can no longer be legally memoized by default); (3) UsesStep
foreign actions produced silence — now a pinned denominator (==9; a new
foreign action must consciously bump it); (4) the ladder's 24 cells enroll
on the CI surface so the law's own witnesses gate every run. 24/24 + 7/7.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* M1 ratchet bump: declared resolve count 1 -> 3 (gate's first live catch — enrollment pays counted resolves)

Run 29058798771: enrolling the ladder witness file moved resolves_total
1 -> 3 (each enrolled entry file pays one closure resolve against the
shared index) and the receipt gate redded that exact run — the designed
semantics, receipted in the note. Bump acknowledges the two witness-entry
resolves as declared debt; M2 (one closure resolve per roots set)
ratchets back toward 1.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Retire the M1/M2 labels from carriers (no-codename rule; collided with DESIGN's floor-memoization M1/M2)

Step renamed to 'Floor resolve receipt gate (declared cold-resolve count)';
notes and the gate echo now say what the things are: the counted
cold-resolve receipt, and the shared-resolve rewire (one closure resolve
per source-roots set). Naming-retirement note left on the carrier.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* Run-step natures pinned as counted claims, not affordances

Operator ruling 2026-07-10: hardcoded shell scripts get no affordances
— run-steps are supposed to be modeled as typed intents and emitted
(shell-emission-model slice 4 covers ci_workflow RunSteps). Until that
slice lands, every nature in job_run_demands is a claim (rostered
FreshEffect / weakest-default IdempotentEffect), never derived from a
modeled effect row. Count the whole claimed-nature surface (16 by
execution) and pin it in the enrolled witness: a new raw-script step
must consciously bump the pin, and slice-4 migration becomes a
countable ratchet ending at zero, where the pin becomes a wall.
Rejected alternative recorded in the carrier note: a per-step
declared-natures roster (a second parallel ledger over scripts the
shell-emission plan already governs).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Regen DESIGN.md after main merge (duplicate-work row + #6373 body-lowering row coexist)

Conflict was both sides editing the open-threads list in design_document.dag:
ours added the duplicate-work thread, main's #6373 rewrote body-lowering to
Stages 1-3 LANDED. Resolution keeps both rows in the .dag authority; DESIGN.md
regenerated from it, never hand-edited.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* Inferred materialization increment 1: floor demand ledger + receipt-or-red gate

Running IS enrolling: the interpreter ledgers every keyed pure call and every
InterpContext absorbs its totals into a process accumulator on Drop — by
construction, no eval path escapes the receipt. claim_executor writes
target/floor-materialization-receipt.txt at walk end; trace defaults ON in
the executor, and an explicit =0 zeroes keyed_calls which the gate refuses.

Gate arms this push (all verified under dash from the emitted ci.yml):
receipt missing/malformed/keyed_calls=0 fail closed. Exact pins for
unkeyed_calls and duplicated_keys land from the FIRST CI receipt (the
resolve gate's measure-then-pin path) — unkeyed is known nonzero on the
floor (count_matching takes a predicate closure; closures are the one
disclosed identity-less class, dissolve-on captured-env content identity).

Unit witness green: resolve -> eval -> ctx Drop -> absorb -> drain-once.
Step addition bumped the claimed-natures pin 16 -> 17 consciously.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Review fix: drop the racy drain-once assertion from the receipt unit test

opus-4-7 finding on #6441: under plain cargo test (still the documented
runner) tests share a process, the env latch is OnceLock-sticky, and
sibling ctx drops could absorb between the two takes — making the
drain-empty assertion racy. Absorb-on-Drop stays asserted (monotone under
concurrent absorbs: siblings only ADD); drain-once is Option::take by
construction, not asserted through the shared global. Comment states the
sharing semantics explicitly.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant