Repository navigation
v1 resolve cache: always-on via temp_dir default (drop env-var gate) - #5789
Conversation
call_function re-derived each parameter's authored name by re-slicing the source span (authored_name_at) on every call — invariant per fn_node but recomputed per call, so inside folds/loops it repeated per iteration. This was the dominant ExprCall self-time in the CI floor's eval phase. Memoize the derivation in a per-InterpContext cache keyed by fn_node pointer identity — sound because the ctx owns fn_nodes (pointers stable for the cache's lifetime, cache dies with the ctx), the same discipline as the existing data_cache. Behavior is identical (same node-eval counts, same witness results). Measured on ci_yaml_serializer_keystone (505k node-evals): ExprCall self-time 255ms->126ms (-51%), total witness eval 602ms->408ms (-32%). Full floor (975 witnesses) green, eval phase 1428s->981s. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Follow-on to the per-call param-name cache. The same chokepoint (authored_name_at re-slicing a name from its source span, then ctx.sym re-interning it) was hit on every ExprVar read and every call's callee-name resolution: - eval_var: cache the resolved Symbol per ExprVar node (var_sym_cache); eval then skips the slice + re-intern and goes straight to env.lookup(sym). Keyword/variant checks use ctx.sym_eq on the cached symbol; the name String is materialized lazily only on the registry slow path. - eval_call: cache the decoded callee name per call node (call_func_name_cache). - call_function: slice each param name once into ; reuses it instead of re-slicing (addresses review note on redundant per-param slicing). All caches are per-InterpContext fields keyed by node pointer identity — sound for the ctx lifetime, the same discipline as data_cache/param_name_cache. Behavior is identical: same node-eval counts, same witness results. Measured on ci_yaml_serializer_keystone (505,325 node-evals, vs the param-only base): ExprVar self-time 82ms->29ms (-64%), ExprCall 126ms->106ms; cumulative witness eval 602ms->322ms (-47%) across both commits. node-eval count unchanged (correctness). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
GUNBC_RESOLVED_GRAPH_CACHE_DIR still overrides the path; without it the cache defaults to $TMPDIR/gunbc-rg-cache. Eliminates the 447s resolve serial sum in the CI floor corpus run — type inference for each unique closure now runs once and is reused across all witnesses sharing that closure. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Four-node plan for making spawn_width self-calibrating from per-shard measured RSS rather than a static data row: - Node A: measurement plumbing (claim_batch emit, claim_executor collect) - Node B: CostEstimate.space on Runnable in std substrate - Node C: width derivation moves into scheduler, side-channel deleted - Node D: calibration loop retires static data rows Also updates ROADMAP §1 scheduling band (new resource-aware bullet) and §2 P3/P4 (resolve-cache always-on via #5789, P4 space+time arms). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
typescript_import_emit_by_execution_test.dag, typescript.dag, and target_model.dag exist on main but were absent/different on this session branch — restoring to match origin/main so the PR does not delete them on merge. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
Addressing the two findings: TypeScript files (scope creep): The TS files the reviewer saw are no longer in the diff — they were restorations, not additions. The session branch had accidentally dropped them (stale base), and the restoration commit pushed after the prior review brought them back to match main exactly. The current diff shows only the three Rust files + plan/ROADMAP session overhead. temp_dir trust model: Correct observation. Adding a follow-up code comment is the right move rather than a code change now. The content-addressed key is the load-bearing purity guarantee; the world-writable path is a permission-error risk at worst (already fail-soft via Plan doc bundling: Acknowledged — the — sent from calm-carp-204 |
Design converged 2026-06-25 with sharp-stag-782: PerformanceReceipt.cost: CostAccount<Nano> is the single measured authority for Time+Space+Energy. The [calibration]/[measurement] text lines are Lossless transport projections of that receipt, not the authority themselves. wall_duration removed as stored field; becomes a pure projection fn. cache_state_summary stays top-level (it is a measurement-context tag, not a cost axis). nimble-tern-908 authors the shape PR; #5792 (gentle-newt-542) carries the Rust plumbing. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…oadmap Derivation is the authority (CostBasis.Predicted); measurement is the §5 falsifier + physical-constant calibration (CostBasis.Measured). P0/P1 decouple cleanly: P0 = PerformanceReceipt.cost shape (nimble-tern #5798), P1 = InputEnvelope (sharp-stag-782), both parallel. P2 symbolic- cost fold follows P1; P3 min_bytes dissolve after P0; P4 BestEffort width swaps static row for Predicted once P2 ships; P5 falsifier compares. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
On the temp-dir uid-collision finding: confirmed the risk is real on multi-user hosts. In our CI context it is not a factor — runners are ephemeral single-user containers, so no concurrent users can race on the dir. The On the bundled TS/ROADMAP files: those were stale-base restorations from a prior merge divergence (the session branch predated those files landing on main). The merge-main commit pushed just now cleans the diff to the 4 intended files: — sent from calm-carp-204 |
|
Addressed finding #1 (uid collision): cache dir now suffixed with On finding #2 (bundled smoke test fix): not a drive-by. The prior CI run on this PR (28145032701) failed — sent from calm-carp-204 |
…tes) derives width from live cgroup budget (#5825) * v1 interp: memoize per-call parameter-name resolution (ctx-owned cache) call_function re-derived each parameter's authored name by re-slicing the source span (authored_name_at) on every call — invariant per fn_node but recomputed per call, so inside folds/loops it repeated per iteration. This was the dominant ExprCall self-time in the CI floor's eval phase. Memoize the derivation in a per-InterpContext cache keyed by fn_node pointer identity — sound because the ctx owns fn_nodes (pointers stable for the cache's lifetime, cache dies with the ctx), the same discipline as the existing data_cache. Behavior is identical (same node-eval counts, same witness results). Measured on ci_yaml_serializer_keystone (505k node-evals): ExprCall self-time 255ms->126ms (-51%), total witness eval 602ms->408ms (-32%). Full floor (975 witnesses) green, eval phase 1428s->981s. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * v1 interp: extend symbol-reuse memoization to ExprVar and callee names Follow-on to the per-call param-name cache. The same chokepoint (authored_name_at re-slicing a name from its source span, then ctx.sym re-interning it) was hit on every ExprVar read and every call's callee-name resolution: - eval_var: cache the resolved Symbol per ExprVar node (var_sym_cache); eval then skips the slice + re-intern and goes straight to env.lookup(sym). Keyword/variant checks use ctx.sym_eq on the cached symbol; the name String is materialized lazily only on the registry slow path. - eval_call: cache the decoded callee name per call node (call_func_name_cache). - call_function: slice each param name once into ; reuses it instead of re-slicing (addresses review note on redundant per-param slicing). All caches are per-InterpContext fields keyed by node pointer identity — sound for the ctx lifetime, the same discipline as data_cache/param_name_cache. Behavior is identical: same node-eval counts, same witness results. Measured on ci_yaml_serializer_keystone (505,325 node-evals, vs the param-only base): ExprVar self-time 82ms->29ms (-64%), ExprCall 126ms->106ms; cumulative witness eval 602ms->322ms (-47%) across both commits. node-eval count unchanged (correctness). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: CI profiling * v1 resolve cache: always-on via temp_dir default (drop env-var gate) GUNBC_RESOLVED_GRAPH_CACHE_DIR still overrides the path; without it the cache defaults to $TMPDIR/gunbc-rg-cache. Eliminates the 447s resolve serial sum in the CI floor corpus run — type inference for each unique closure now runs once and is reused across all witnesses sharing that closure. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * WIP: CI profiling * Scope resource-aware scheduler (nodes A-D) + ROADMAP update Four-node plan for making spawn_width self-calibrating from per-shard measured RSS rather than a static data row: - Node A: measurement plumbing (claim_batch emit, claim_executor collect) - Node B: CostEstimate.space on Runnable in std substrate - Node C: width derivation moves into scheduler, side-channel deleted - Node D: calibration loop retires static data rows Also updates ROADMAP §1 scheduling band (new resource-aware bullet) and §2 P3/P4 (resolve-cache always-on via #5789, P4 space+time arms). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * Restore foreign files reverted by stale branch base typescript_import_emit_by_execution_test.dag, typescript.dag, and target_model.dag exist on main but were absent/different on this session branch — restoring to match origin/main so the PR does not delete them on merge. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * resource-aware-scheduler plan: lock PerformanceReceipt as cost authority Design converged 2026-06-25 with sharp-stag-782: PerformanceReceipt.cost: CostAccount<Nano> is the single measured authority for Time+Space+Energy. The [calibration]/[measurement] text lines are Lossless transport projections of that receipt, not the authority themselves. wall_duration removed as stored field; becomes a pure projection fn. cache_state_summary stays top-level (it is a measurement-context tag, not a cost axis). nimble-tern-908 authors the shape PR; #5792 (gentle-newt-542) carries the Rust plumbing. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * resource-aware-scheduler plan: add cost-authority re-role and P0-P6 roadmap Derivation is the authority (CostBasis.Predicted); measurement is the §5 falsifier + physical-constant calibration (CostBasis.Measured). P0/P1 decouple cleanly: P0 = PerformanceReceipt.cost shape (nimble-tern #5798), P1 = InputEnvelope (sharp-stag-782), both parallel. P2 symbolic- cost fold follows P1; P3 min_bytes dissolve after P0; P4 BestEffort width swaps static row for Predicted once P2 ships; P5 falsifier compares. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * WIP: CI profiling * WIP: CI profiling * WIP: CI profiling --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…g ROADMAP drift
Two changes that make the runner converge an enforced single-authority artifact
the operator can run, and clear the drift gate that was reding main CI.
1. FleetConvergeArtifact: NotCommitted -> CommitRequired { consumer: HostReconciler }.
The emitted .github/fleet-converge.sh is now committed and drift-gated: edit the
.dag and the committed script must regenerate to match, else CI reds. This is the
"changes actually take effect" reconciler - the gate is the change-detector; the
ssh-apply is the action. Gitignore auto-drops the ignore line (it filters on
!artifact_is_committed). generated_artifact_drift_test updated: HostReconciler arm
added to the consumer match (exhaustiveness), commit-policy/ignore assertions
flipped to committed.
2. ROADMAP.md drift (pre-existing on main, unrelated to the converge work): the
committed ROADMAP carried newer scheduler/cache profiling status (resource-aware
spawn_width nodes A-D, #5789 always-on resolve-cache) that was hand-edited without
modeling into roadmap_authority.dag - the #5745/#5813-class single-authority
violation. Healed by modeling that content INTO the authority (add 1-sched-resource-aware
row, update 1-caching-forked / 2-p3 / 2-p4), so emit == committed with no revert
of the profiling content.
Drift gate now ExitSuccess; all generated-artifact + roadmap + runner-placement
witnesses green by execution.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…wap-off) + drift-gate heal (#5827) * WIP: CI profiling * Runner converge: model MemorySwapMax=0 swap-off safety knob Adds the missing crash-prevention property to the runner converge: - extdeps/os/systemd: systemd_memory_swap_max_property = "MemorySwapMax" - host_converge: per-slot swap-off knob (PerSlotMemoryCap, value 0) on a dedicated 30-fleet-swap.conf drop-in, paired with the existing MemoryMax cap. Swap-off is the property that converts a host livelock (swap-thrash -> reboot, the srv2 vector) into a scoped cgroup OOM-kill: an over-budget CI job dies, the host survives. The knob is INERT until gunbc_ci_runner_slot_enforcement flips from RunnerSlotUnenforced -> RunnerSlotEnforced (the converge emit is fail-closed behind that gate; see ci_runner_placement.dag:313). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: CI profiling * Host allocation: conservation model (declared pools + node_conserves) Replaces the 'whole host -> runners' residual + the chicken-and-egg RunnerSlotUnenforced gate with a declared-partition conservation model: host_total >= runner_pool + session_pool + fixed_overhead + headroom - gunbc_runner_pool_budget = 80 GiB (declared intent, was residual) - gunbc_per_runner_memory_cap = 8 GiB (declared) => declared_runner_count() = 10 - gunbc_session_container_memory = 1 GiB (uniform session demand class, ctrl-aligned) - host_allocation_conserves() = node_conserves over the partition (primitive already in product/budget_tree.dag); over-commit ANY pool -> Unsound with a located reason. - max_concurrent_sessions(pool) = floor(pool / 1 GiB), the ctrl admission bound. Soundness becomes declared-math conservation; 'is the cap live' moves to the converge receipt (no circular lock). Session pool is the uniform 1 GiB/1 core/swap-off/pids-4096 envelope agreed with ctrl (keen-dove-772) for session-dashboard container spawns. 5 witnesses green by execution (host_allocation_conservation_test.dag): count==10, conserves when pools fit, Unsound when runner pool OR sessions over-commit, max sessions derives from pool. This is the CORE; cutting the live runner_deployment_plan over to it (rewrites ~4 gate-witnesses) is the next step. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: CI profiling * Runner placement: cut over to conservation model, rip out the 5-gate fail-closed tangle The runner deployment plan no longer threads enforcement / oomd / jobserver / overhead / headroom through a fail-closed cascade premised on a per-slot cap that is not yet live on the host (the RunnerSlotUnenforced chicken-and-egg: the converge script that applies the cap refused to emit until the cap was applied). Plan soundness is now declared-math conservation: runner_count divides the DECLARED runner_pool_budget by the DECLARED per_runner_memory_cap, and the host is sound iff host_allocation_conserves (node_conserves over runner_pool + session_pool + fixed_overhead + headroom <= host RAM). "Is the cap live on the host" is no longer a plan-soundness question - it is a converge-receipt question (verdict=converged/drifted/absent), which dissolves the circular lock. Result: the live fleet converge now emits a SOUND script for srv1+srv2 - 80 GiB runner slice cap, 8 GiB per-slot MemoryMax, MemorySwapMax=0 (swap-off: converts host livelock into a scoped cgroup OOM-kill), runner_count=10. - ci_runner_placement.dag: delete RunnerSlotEnforcement gate, JobPeakResolution fold, host_runner_count_from_cap, runner_deployment_plan_for; replace with host_fixed_overhead_bytes / conservation_host_deployment / accumulate_conservation_deployment / runner_deployment_plan. Prune now-unused imports. - runner_placement_witness_test.dag: flip the live-plan witnesses from fail-closed to conservation-sound (runner_count==10, per-slot cap==8 GiB, within runner pool); keep the session-reservation / operating-curve / cpu-weight / manifest witnesses; drop the deleted gate-cascade witnesses. - fleet_converge_emit_test.dag: replace witness_live_unsound_fails_closed with witness_live_converge_is_conservation_sound; assert MemorySwapMax=0 swap-off knob in the fixture runner-knobs witness. All affected witnesses green by execution. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: CI profiling * Commit fleet-converge.sh (HostReconciler artifact) + heal pre-existing ROADMAP drift Two changes that make the runner converge an enforced single-authority artifact the operator can run, and clear the drift gate that was reding main CI. 1. FleetConvergeArtifact: NotCommitted -> CommitRequired { consumer: HostReconciler }. The emitted .github/fleet-converge.sh is now committed and drift-gated: edit the .dag and the committed script must regenerate to match, else CI reds. This is the "changes actually take effect" reconciler - the gate is the change-detector; the ssh-apply is the action. Gitignore auto-drops the ignore line (it filters on !artifact_is_committed). generated_artifact_drift_test updated: HostReconciler arm added to the consumer match (exhaustiveness), commit-policy/ignore assertions flipped to committed. 2. ROADMAP.md drift (pre-existing on main, unrelated to the converge work): the committed ROADMAP carried newer scheduler/cache profiling status (resource-aware spawn_width nodes A-D, #5789 always-on resolve-cache) that was hand-edited without modeling into roadmap_authority.dag - the #5745/#5813-class single-authority violation. Healed by modeling that content INTO the authority (add 1-sched-resource-aware row, update 1-caching-forked / 2-p3 / 2-p4), so emit == committed with no revert of the profiling content. Drift gate now ExitSuccess; all generated-artifact + roadmap + runner-placement witnesses green by execution. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: CI profiling --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
…se-drift (#5829) * WIP: CI profiling * Runner converge: model MemorySwapMax=0 swap-off safety knob Adds the missing crash-prevention property to the runner converge: - extdeps/os/systemd: systemd_memory_swap_max_property = "MemorySwapMax" - host_converge: per-slot swap-off knob (PerSlotMemoryCap, value 0) on a dedicated 30-fleet-swap.conf drop-in, paired with the existing MemoryMax cap. Swap-off is the property that converts a host livelock (swap-thrash -> reboot, the srv2 vector) into a scoped cgroup OOM-kill: an over-budget CI job dies, the host survives. The knob is INERT until gunbc_ci_runner_slot_enforcement flips from RunnerSlotUnenforced -> RunnerSlotEnforced (the converge emit is fail-closed behind that gate; see ci_runner_placement.dag:313). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: CI profiling * Host allocation: conservation model (declared pools + node_conserves) Replaces the 'whole host -> runners' residual + the chicken-and-egg RunnerSlotUnenforced gate with a declared-partition conservation model: host_total >= runner_pool + session_pool + fixed_overhead + headroom - gunbc_runner_pool_budget = 80 GiB (declared intent, was residual) - gunbc_per_runner_memory_cap = 8 GiB (declared) => declared_runner_count() = 10 - gunbc_session_container_memory = 1 GiB (uniform session demand class, ctrl-aligned) - host_allocation_conserves() = node_conserves over the partition (primitive already in product/budget_tree.dag); over-commit ANY pool -> Unsound with a located reason. - max_concurrent_sessions(pool) = floor(pool / 1 GiB), the ctrl admission bound. Soundness becomes declared-math conservation; 'is the cap live' moves to the converge receipt (no circular lock). Session pool is the uniform 1 GiB/1 core/swap-off/pids-4096 envelope agreed with ctrl (keen-dove-772) for session-dashboard container spawns. 5 witnesses green by execution (host_allocation_conservation_test.dag): count==10, conserves when pools fit, Unsound when runner pool OR sessions over-commit, max sessions derives from pool. This is the CORE; cutting the live runner_deployment_plan over to it (rewrites ~4 gate-witnesses) is the next step. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: CI profiling * Runner placement: cut over to conservation model, rip out the 5-gate fail-closed tangle The runner deployment plan no longer threads enforcement / oomd / jobserver / overhead / headroom through a fail-closed cascade premised on a per-slot cap that is not yet live on the host (the RunnerSlotUnenforced chicken-and-egg: the converge script that applies the cap refused to emit until the cap was applied). Plan soundness is now declared-math conservation: runner_count divides the DECLARED runner_pool_budget by the DECLARED per_runner_memory_cap, and the host is sound iff host_allocation_conserves (node_conserves over runner_pool + session_pool + fixed_overhead + headroom <= host RAM). "Is the cap live on the host" is no longer a plan-soundness question - it is a converge-receipt question (verdict=converged/drifted/absent), which dissolves the circular lock. Result: the live fleet converge now emits a SOUND script for srv1+srv2 - 80 GiB runner slice cap, 8 GiB per-slot MemoryMax, MemorySwapMax=0 (swap-off: converts host livelock into a scoped cgroup OOM-kill), runner_count=10. - ci_runner_placement.dag: delete RunnerSlotEnforcement gate, JobPeakResolution fold, host_runner_count_from_cap, runner_deployment_plan_for; replace with host_fixed_overhead_bytes / conservation_host_deployment / accumulate_conservation_deployment / runner_deployment_plan. Prune now-unused imports. - runner_placement_witness_test.dag: flip the live-plan witnesses from fail-closed to conservation-sound (runner_count==10, per-slot cap==8 GiB, within runner pool); keep the session-reservation / operating-curve / cpu-weight / manifest witnesses; drop the deleted gate-cascade witnesses. - fleet_converge_emit_test.dag: replace witness_live_unsound_fails_closed with witness_live_converge_is_conservation_sound; assert MemorySwapMax=0 swap-off knob in the fixture runner-knobs witness. All affected witnesses green by execution. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: CI profiling * Commit fleet-converge.sh (HostReconciler artifact) + heal pre-existing ROADMAP drift Two changes that make the runner converge an enforced single-authority artifact the operator can run, and clear the drift gate that was reding main CI. 1. FleetConvergeArtifact: NotCommitted -> CommitRequired { consumer: HostReconciler }. The emitted .github/fleet-converge.sh is now committed and drift-gated: edit the .dag and the committed script must regenerate to match, else CI reds. This is the "changes actually take effect" reconciler - the gate is the change-detector; the ssh-apply is the action. Gitignore auto-drops the ignore line (it filters on !artifact_is_committed). generated_artifact_drift_test updated: HostReconciler arm added to the consumer match (exhaustiveness), commit-policy/ignore assertions flipped to committed. 2. ROADMAP.md drift (pre-existing on main, unrelated to the converge work): the committed ROADMAP carried newer scheduler/cache profiling status (resource-aware spawn_width nodes A-D, #5789 always-on resolve-cache) that was hand-edited without modeling into roadmap_authority.dag - the #5745/#5813-class single-authority violation. Healed by modeling that content INTO the authority (add 1-sched-resource-aware row, update 1-caching-forked / 2-p3 / 2-p4), so emit == committed with no revert of the profiling content. Drift gate now ExitSuccess; all generated-artifact + roadmap + runner-placement witnesses green by execution. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * WIP: CI profiling * WIP: CI profiling * Converge script: fix set-e abort in membership probe + oomd-limit false-drift Two bugs surfaced by the operator's live srv1/srv2 run. BUG A (functional, critical): emit_sessions_membership's `ls -d .../docker-*.scope` returns non-zero when the glob matches nothing, and under `set -euo pipefail` that aborted the whole script at the sessions-membership probe — before host_summary and before the *second host's* entire section ever ran. That's why both runs stopped after srv1's last sessions knob and the srv2 invocation printed host=srv1 receipts. Fix: guard both `ls | wc | tr` pipelines with `|| true` (proven: old line exits 2 under set -e, guarded line continues with count 0). BUG B (receipt lies): systemd stores ManagedOOMMemoryPressureLimit as a fraction of UINT32_MAX, so `60%` reads back as 2576980377 and the receipt compared it to the literal "60%" → false `drifted` (host_failed=1) though the cap is correctly set. Ground the encoding in extdeps.os.oomd (`systemd_managed_oom_pressure_limit_show_scale` = 4294967295, `managed_oom_pressure_limit_show_value`) and set the knob's expected_effective to that show-value; apply stays "60%", desired_display stays "60". Per-slot caps (8 GiB MemoryMax + MemorySwapMax=0) were already persisted correctly — the drop-in is written unconditionally before the (empty) active-instance loop, so the ABSENT verdicts were just "no live runner to set-property", not a write failure. Witness updated: oom-limit expected-effective asserts 2576980377; added a tooth that the membership `ls` carries `|| true`. Drift gate ExitSuccess; all converge / oomd / runner-placement witnesses green by execution. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
…loor) (#5855) * Revert resolve cache to opt-in (#5789 always-on default OOMs the CI floor) #5789 made the cross-process resolved-graph disk cache always-on by defaulting its directory to `temp_dir()/gunbc-rg-cache-{user}`, dropping the `GUNBC_RESOLVED_GRAPH_CACHE_DIR` opt-in gate. That turned the cache on in CI, where it is pure cost: - Both IO paths buffer a whole cache file in memory. A hit `read_to_end`s the entire verbose-JSON file (~11x the packed 18-field-Node graph, so a 272 MiB graph is a ~3 GiB read); a miss `to_vec`s the whole JSON before write. Across concurrent floor shards this OOMs the runner (measured 14.16 GiB self-RSS at width=3 vs the 8 GiB cap). - CI hit-rate is ~0: the cache lives in /tmp (absent from ci.yml's actions/cache paths, empty on each fresh runner) and the subject key folds the compiler-exe hash, so every commit colds the whole cache. So in CI it only ever writes (which also OOMs) and never reads a graph back. This re-confirms the prior cold-CI cache-enable finding (#5447) that #5789 contradicted unreferenced. Restore the #4878 opt-in: `resolved_graph_cache_root_from_env()` returns `None` when the env var is unset, and both callers re-gate on it, so with no env var the cache is fully off (lookup and write both skipped). Both sites are pure perf shortcuts (lookup falls through to recompute, write is best-effort `let _ =`), so this changes only timing, never the resolved graph. ROADMAP regenerated from roadmap_authority.dag. Re-enabling by default is gated on a streaming IO realization (binary + `deserialize_from`/`serialize_into`, no whole-file `Vec<u8>`) — follow-on. Seed-infra (the v1 caching kernel's gating); does not cement Rust into templates and is not the substrate Share work. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fmt: rustfmt the cache import line (fix fmt --check gate) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… law Operator synthesis (2026-07-09): Materialization = the verdict vocabulary; ownership = the verdict computation at the eval frame; realization = provider selection discharging the verdict at each frame's carrier. Share's handler is layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable carrier + readonly => point-at-it, no copy, no destroyed memory), demoting through HAMT structural share / process memo / artifact / CAS, and demotion must be priced, never silent (#6249 clone-fallback is the receipt). Census of every hand-rolled instance found in-tree (16 rows): each named with its frame, ladder cell, action, and dissolution trigger — ownership (consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall), ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green / sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789 (rule-4 requirements), recompute-trace (state-4 finding source). Peers kept distinct: affected-set, Independence/Placement, mutable state. Sequence C1-C5 with C1 = this PR (ladder + live CI gate). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… law Operator synthesis (2026-07-09): Materialization = the verdict vocabulary; ownership = the verdict computation at the eval frame; realization = provider selection discharging the verdict at each frame's carrier. Share's handler is layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable carrier + readonly => point-at-it, no copy, no destroyed memory), demoting through HAMT structural share / process memo / artifact / CAS, and demotion must be priced, never silent (#6249 clone-fallback is the receipt). Census of every hand-rolled instance found in-tree (16 rows): each named with its frame, ladder cell, action, and dissolution trigger — ownership (consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall), ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green / sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789 (rule-4 requirements), recompute-trace (state-4 finding source). Peers kept distinct: affected-set, Independence/Placement, mutable state. Sequence C1-C5 with C1 = this PR (ladder + live CI gate). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… law Operator synthesis (2026-07-09): Materialization = the verdict vocabulary; ownership = the verdict computation at the eval frame; realization = provider selection discharging the verdict at each frame's carrier. Share's handler is layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable carrier + readonly => point-at-it, no copy, no destroyed memory), demoting through HAMT structural share / process memo / artifact / CAS, and demotion must be priced, never silent (#6249 clone-fallback is the receipt). Census of every hand-rolled instance found in-tree (16 rows): each named with its frame, ladder cell, action, and dissolution trigger — ownership (consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall), ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green / sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789 (rule-4 requirements), recompute-trace (state-4 finding source). Peers kept distinct: affected-set, Independence/Placement, mutable state. Sequence C1-C5 with C1 = this PR (ladder + live CI gate). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* WIP: Duplicate Computation
* WIP: Duplicate Computation
* WIP: Duplicate Computation
* WIP: Duplicate Computation
* WIP: Duplicate Computation
* WIP: Duplicate Computation
* WIP: Duplicate Computation
* WIP: Duplicate Computation
* WIP: Duplicate Computation
* WIP: Duplicate Computation
* WIP: Duplicate Computation
* WIP: Duplicate Computation
* WIP: Duplicate Computation
* Analysis spine: spine_receipt composes dependency_view + materialize (increment 1)
The Rc-safe half of run ≜ realize ∘ materialize ∘ dependency_view: compose
the two catamorphisms that need no interpreter thread-safety.
- src/v2/std/spine.dag: level-profile fold over the DependencyView DAG →
critical_path_depth (longest dependency chain / the reduce spine) +
independence_width (max nodes at one level / what parallelizes to hw width).
spine_receipt emits the §9 numbers by COMPUTATION, not assertion, joining
materialize's content-hash Share/dedup counts.
- Discriminating RED (§9): single chain A→B→C → depth 3 / width 1 (serial);
root over N independent leaves → depth 2 / width N.
- Witnesses 9/9 (spine) green by execution; materialize 6/6 unchanged.
The RUNNER (wall-clock parallel execution, §8 steps 3-4) stays increment 2+,
gated on interpreter Rc→Arc (v1 interp is !Send). This increment measures the
achievable width/critical-path floor the runner targets; it does not fabricate
wall-clock N×.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Unbundle recompute-trace interpreter extension from the analysis-spine PR
CI root cause: the recompute-trace extension edited v1_interpreter.rs, which
hosts the atom_identity_hash/hash_combine fnv1a64 intrinsics that
dag_collect_fingerprint_witness executes. That correctly invalidated the
re-verify 'assumed-green node-frontier' SKIP of that witness (cone-touch,
fail-closed) — but the witness is a pre-existing 806s (13min) fnv1a64
whole-corpus walk, so un-skipping it blew the 30-min floor budget. Main stays
green only because its interpreter cone is untouched (witness stays skipped).
The interpreter extension is a separable, env-gated (GUNBC_RECOMPUTE_TRACE=1),
READ-mode diagnostic — not a dependency of the spine/materialize analysis
substrate (pure .dag, content_hash-based). Reverting v1_interpreter.rs to main
restores byte-identical interpreter content → the fingerprint witness returns to
assumed-green SKIP → floor budget restored. The recompute-trace extension lands
as its own follow-up PR where the fingerprint-witness re-run is expected.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* WIP: Duplicate Computation
* Materialization ladder: the state x decision law, as executable witnesses
The operator's 4-rule business logic generalized on one axis: the decision is
a function of WHEN the redundancy is knowable and WHETHER what was knowable
was prepared for. Errors fire only on knowable-but-unprepared; genuine
emergence and declared triviality are typed acceptances, never silence.
std.materialization_ladder (dag/std):
- Frame/FrameKind: SharedStateFrame | IsolatedChildrenFrame |
ReplayedFrame{attempts} | UnboundedSiblingsFrame — the nested-scope axis;
a 'run' at any layer is a frame, never a different kind of thing.
- DemandNature: Pure | IdempotentEffect | WorldRead{envelope_declared} |
FreshEffect — the D3 effect gate; TTL = unmodeled dependency XOR declared
staleness, never an eviction knob.
- CacheProvider: keying (ContentKeyed|ExistenceKeyed) + EvictionPolicy
(ScopeExit|SpacePacked) REQUIRED by construction — rule 3 unwritable-bad.
- LadderVerdict (total): AuthoredDuplication | Discharged | RefusedNoProvider
| RefusedScopeTooNarrow | RefusedExistenceKeyed (the build-if-absent #6352
wall) | RefusedUnmodeledWorldRead | ExemptFreshEffect |
AcceptedBelowCostFloor | AcceptedSingleRecompute.
- Declared-emergent frames obligate UP FRONT: retry frames derive
checkpointing, unbounded-sibling frames (server loops, CI-runs-over-time)
derive persistent caches — prepare-before-demand.
12/12 witnesses green by execution; each test is one cell of the table,
fixtures mirror the live worked example (workflow/jobs/steps, retry, fleet).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* WIP: Duplicate Computation
* Docs crystallization: derived materialization placement into roadmap ④ + the state x decision table
- roadmap_authority ④ (ROADMAP.md regenerated via main_wet, drift-consistent):
the nested-frame law, plurality cells, declared-emergent prepare-up-front,
keying/staleness walls, the caching-completion un-shelve, the ①-vs-§2
cross-run-caching contradiction subsumed into per-node derived verdicts,
and the v1.compiler.ownership §3-convergence row.
- duplicate-work design doc: the state x decision table as the qualifier's
final verdict logic + the ownership consolidation subsection.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Consolidation plan: realization + materialization + ownership are one law
Operator synthesis (2026-07-09): Materialization = the verdict vocabulary;
ownership = the verdict computation at the eval frame; realization = provider
selection discharging the verdict at each frame's carrier. Share's handler is
layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable
carrier + readonly => point-at-it, no copy, no destroyed memory), demoting
through HAMT structural share / process memo / artifact / CAS, and demotion
must be priced, never silent (#6249 clone-fallback is the receipt).
Census of every hand-rolled instance found in-tree (16 rows): each named with
its frame, ladder cell, action, and dissolution trigger — ownership
(consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall),
ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green /
sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB
scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789
(rule-4 requirements), recompute-trace (state-4 finding source). Peers kept
distinct: affected-set, Independence/Placement, mutable state.
Sequence C1-C5 with C1 = this PR (ladder + live CI gate).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* WIP: Duplicate Computation
* Ownership refactored onto materialization: the value tier, tested as providers
First consolidation increment (operator-directed): v1.compiler.ownership's
decision IS provider selection at the value grain, now expressed in the ladder
and proven by mirror witnesses.
- ProviderTier: Reference | Copy | Memo{keying} | Artifact{keying} | Cas{keying}
— keying folded INTO store tiers, so an existence-keyed reference is
unwritable BY SHAPE (§5 construction); frame obligations at isolation LCAs
are dischargeable only by store tiers (a reference cannot cross an isolation
boundary — witnessed).
- Value tier: AccessMode (Read|Consume|Carry|Project), ValueUsage,
value_materialization -> ValueDead | ValueMoved | ValueSharedByReference |
ValueDemotedToCopy (PRICED, requires a declared CopyTier provider — the
#6249 silent clone-fallback made refusable) | ValueRefusedAffine |
ValueRefusedNoCarrierProvider.
- Faithful to v1's THREE distinct plurality readings, kept separate:
take_count = semantic_consumer_count (Consumed only, affine axis);
value_access_plurality = binding_fan_out (Carry excluded, reference axis);
borrow_count = whole_value_borrow_count (Read+Carry not Project, movability).
- Fold-accumulator case mirrored at conservative pre-FoldAccUnwrap semantics:
carries excluded from plurality but blocking the move -> demoted-to-copy.
23/23 witnesses green (14 frame cells + 9 value cells). Corpus-level
equivalence against live v1 ownership folds = the C4 receipt.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* WIP: Duplicate Computation
* WIP: Duplicate Computation/Materialization
* G: exhaustive cache/share census (52 mechanisms, 6 groups) + C0 catalog-grounding of provider rows + forward-wiring walls
The sweep found the tree already models caches: extdeps/cache cache_catalog
(CacheInterfaceCatalogFacts, 9 rows) + extdeps/realization carrier facts +
the warm==cold purity oracle. C0 grounds CacheProvider on that catalog
(provider_from_catalog projection; CacheProvider.id -> CacheInterfaceId)
so the ladder and the catalog never restate each other's half. Three
forward walls (demands-from-DependencyView, hand-cache shape lens,
live-provider-or-red) make new caches born as provider rows only.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* WIP: Duplicate Computation/Materialization
* C0: provider rows derive from the cited cache catalog (extdeps/cache/materialization.dag projection)
Operator ruling 2026-07-09: extdeps stays the ground-truth/interface layer;
every USE of a cache goes through materialization so memo never gets
re-invented. provider_from_catalog is the only door from a catalog row into
the ladder: keying/tier/eviction derived from cited facts (mechanism->class:
InProcess=>ScopeExit; Ttl/Lru/SizeBounded=>SpacePacked; Never/Manual outside
a process => typed ProjectionRefused, counted by the new enrolled witness;
HandAuthored/prefix-fallback keys => ExistenceKeyed until key-completeness
upgrades them). CI sccache row now derived, hand-typed tier facts deleted,
6/6 + 23/23 witnesses green. 10b re-scoped: v1-internal caches = inventory
only (retire with seed); ParseTable/cached_stage promoted to next.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* WIP: Duplicate Computation/Materialization
* WIP: Duplicate Computation/Materialization
* WIP: Duplicate Computation/Materialization
* WIP: Duplicate Computation/Materialization
* Fail-closed hardening: RefusedNatureConflict arm, weakest-claim nature default, UsesStep silence counted, ladder cells enrolled in CI
The complexity-lens false-clean lesson applied to this gate before anyone
relies on it: (1) heterogeneous natures on one identity were first-wins —
now a typed RefusedNatureConflict (24th ladder cell, RED witness); (2) an
unrostered run-step claimed PureComputation — now IdempotentEffect, the
weakest claim (verdict-identical, no purity overclaim; a misdeclared
WorldRead can no longer be legally memoized by default); (3) UsesStep
foreign actions produced silence — now a pinned denominator (==9; a new
foreign action must consciously bump it); (4) the ladder's 24 cells enroll
on the CI surface so the law's own witnesses gate every run. 24/24 + 7/7.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* WIP: Duplicate Computation/Materialization
* M1 ratchet bump: declared resolve count 1 -> 3 (gate's first live catch — enrollment pays counted resolves)
Run 29058798771: enrolling the ladder witness file moved resolves_total
1 -> 3 (each enrolled entry file pays one closure resolve against the
shared index) and the receipt gate redded that exact run — the designed
semantics, receipted in the note. Bump acknowledges the two witness-entry
resolves as declared debt; M2 (one closure resolve per roots set)
ratchets back toward 1.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* Retire the M1/M2 labels from carriers (no-codename rule; collided with DESIGN's floor-memoization M1/M2)
Step renamed to 'Floor resolve receipt gate (declared cold-resolve count)';
notes and the gate echo now say what the things are: the counted
cold-resolve receipt, and the shared-resolve rewire (one closure resolve
per source-roots set). Naming-retirement note left on the carrier.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* WIP: Duplicate Computation/Materialization
* Run-step natures pinned as counted claims, not affordances
Operator ruling 2026-07-10: hardcoded shell scripts get no affordances
— run-steps are supposed to be modeled as typed intents and emitted
(shell-emission-model slice 4 covers ci_workflow RunSteps). Until that
slice lands, every nature in job_run_demands is a claim (rostered
FreshEffect / weakest-default IdempotentEffect), never derived from a
modeled effect row. Count the whole claimed-nature surface (16 by
execution) and pin it in the enrolled witness: a new raw-script step
must consciously bump the pin, and slice-4 migration becomes a
countable ratchet ending at zero, where the pin becomes a wall.
Rejected alternative recorded in the carrier note: a per-step
declared-natures roster (a second parallel ledger over scripts the
shell-emission plan already governs).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* Regen DESIGN.md after main merge (duplicate-work row + #6373 body-lowering row coexist)
Conflict was both sides editing the open-threads list in design_document.dag:
ours added the duplicate-work thread, main's #6373 rewrote body-lowering to
Stages 1-3 LANDED. Resolution keeps both rows in the .dag authority; DESIGN.md
regenerated from it, never hand-edited.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ealization carrier, provider rows via provider_from_catalog (design: docs/plans/duplicate-work-graph-lens-design.md section 10b; the .dag-substrate demonstration lane) (#6422) * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Ground v2 ParseTable + cached_stage on materialization: inhabit the Real * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * Analysis spine: spine_receipt composes dependency_view + materialize (increment 1) The Rc-safe half of run ≜ realize ∘ materialize ∘ dependency_view: compose the two catamorphisms that need no interpreter thread-safety. - src/v2/std/spine.dag: level-profile fold over the DependencyView DAG → critical_path_depth (longest dependency chain / the reduce spine) + independence_width (max nodes at one level / what parallelizes to hw width). spine_receipt emits the §9 numbers by COMPUTATION, not assertion, joining materialize's content-hash Share/dedup counts. - Discriminating RED (§9): single chain A→B→C → depth 3 / width 1 (serial); root over N independent leaves → depth 2 / width N. - Witnesses 9/9 (spine) green by execution; materialize 6/6 unchanged. The RUNNER (wall-clock parallel execution, §8 steps 3-4) stays increment 2+, gated on interpreter Rc→Arc (v1 interp is !Send). This increment measures the achievable width/critical-path floor the runner targets; it does not fabricate wall-clock N×. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Unbundle recompute-trace interpreter extension from the analysis-spine PR CI root cause: the recompute-trace extension edited v1_interpreter.rs, which hosts the atom_identity_hash/hash_combine fnv1a64 intrinsics that dag_collect_fingerprint_witness executes. That correctly invalidated the re-verify 'assumed-green node-frontier' SKIP of that witness (cone-touch, fail-closed) — but the witness is a pre-existing 806s (13min) fnv1a64 whole-corpus walk, so un-skipping it blew the 30-min floor budget. Main stays green only because its interpreter cone is untouched (witness stays skipped). The interpreter extension is a separable, env-gated (GUNBC_RECOMPUTE_TRACE=1), READ-mode diagnostic — not a dependency of the spine/materialize analysis substrate (pure .dag, content_hash-based). Reverting v1_interpreter.rs to main restores byte-identical interpreter content → the fingerprint witness returns to assumed-green SKIP → floor budget restored. The recompute-trace extension lands as its own follow-up PR where the fingerprint-witness re-run is expected. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Materialization ladder: the state x decision law, as executable witnesses The operator's 4-rule business logic generalized on one axis: the decision is a function of WHEN the redundancy is knowable and WHETHER what was knowable was prepared for. Errors fire only on knowable-but-unprepared; genuine emergence and declared triviality are typed acceptances, never silence. std.materialization_ladder (dag/std): - Frame/FrameKind: SharedStateFrame | IsolatedChildrenFrame | ReplayedFrame{attempts} | UnboundedSiblingsFrame — the nested-scope axis; a 'run' at any layer is a frame, never a different kind of thing. - DemandNature: Pure | IdempotentEffect | WorldRead{envelope_declared} | FreshEffect — the D3 effect gate; TTL = unmodeled dependency XOR declared staleness, never an eviction knob. - CacheProvider: keying (ContentKeyed|ExistenceKeyed) + EvictionPolicy (ScopeExit|SpacePacked) REQUIRED by construction — rule 3 unwritable-bad. - LadderVerdict (total): AuthoredDuplication | Discharged | RefusedNoProvider | RefusedScopeTooNarrow | RefusedExistenceKeyed (the build-if-absent #6352 wall) | RefusedUnmodeledWorldRead | ExemptFreshEffect | AcceptedBelowCostFloor | AcceptedSingleRecompute. - Declared-emergent frames obligate UP FRONT: retry frames derive checkpointing, unbounded-sibling frames (server loops, CI-runs-over-time) derive persistent caches — prepare-before-demand. 12/12 witnesses green by execution; each test is one cell of the table, fixtures mirror the live worked example (workflow/jobs/steps, retry, fleet). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Docs crystallization: derived materialization placement into roadmap ④ + the state x decision table - roadmap_authority ④ (ROADMAP.md regenerated via main_wet, drift-consistent): the nested-frame law, plurality cells, declared-emergent prepare-up-front, keying/staleness walls, the caching-completion un-shelve, the ①-vs-§2 cross-run-caching contradiction subsumed into per-node derived verdicts, and the v1.compiler.ownership §3-convergence row. - duplicate-work design doc: the state x decision table as the qualifier's final verdict logic + the ownership consolidation subsection. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Consolidation plan: realization + materialization + ownership are one law Operator synthesis (2026-07-09): Materialization = the verdict vocabulary; ownership = the verdict computation at the eval frame; realization = provider selection discharging the verdict at each frame's carrier. Share's handler is layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable carrier + readonly => point-at-it, no copy, no destroyed memory), demoting through HAMT structural share / process memo / artifact / CAS, and demotion must be priced, never silent (#6249 clone-fallback is the receipt). Census of every hand-rolled instance found in-tree (16 rows): each named with its frame, ladder cell, action, and dissolution trigger — ownership (consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall), ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green / sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789 (rule-4 requirements), recompute-trace (state-4 finding source). Peers kept distinct: affected-set, Independence/Placement, mutable state. Sequence C1-C5 with C1 = this PR (ladder + live CI gate). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Ownership refactored onto materialization: the value tier, tested as providers First consolidation increment (operator-directed): v1.compiler.ownership's decision IS provider selection at the value grain, now expressed in the ladder and proven by mirror witnesses. - ProviderTier: Reference | Copy | Memo{keying} | Artifact{keying} | Cas{keying} — keying folded INTO store tiers, so an existence-keyed reference is unwritable BY SHAPE (§5 construction); frame obligations at isolation LCAs are dischargeable only by store tiers (a reference cannot cross an isolation boundary — witnessed). - Value tier: AccessMode (Read|Consume|Carry|Project), ValueUsage, value_materialization -> ValueDead | ValueMoved | ValueSharedByReference | ValueDemotedToCopy (PRICED, requires a declared CopyTier provider — the #6249 silent clone-fallback made refusable) | ValueRefusedAffine | ValueRefusedNoCarrierProvider. - Faithful to v1's THREE distinct plurality readings, kept separate: take_count = semantic_consumer_count (Consumed only, affine axis); value_access_plurality = binding_fan_out (Carry excluded, reference axis); borrow_count = whole_value_borrow_count (Read+Carry not Project, movability). - Fold-accumulator case mirrored at conservative pre-FoldAccUnwrap semantics: carries excluded from plurality but blocking the move -> demoted-to-copy. 23/23 witnesses green (14 frame cells + 9 value cells). Corpus-level equivalence against live v1 ownership folds = the C4 receipt. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * WIP: Duplicate Computation/Materialization * G: exhaustive cache/share census (52 mechanisms, 6 groups) + C0 catalog-grounding of provider rows + forward-wiring walls The sweep found the tree already models caches: extdeps/cache cache_catalog (CacheInterfaceCatalogFacts, 9 rows) + extdeps/realization carrier facts + the warm==cold purity oracle. C0 grounds CacheProvider on that catalog (provider_from_catalog projection; CacheProvider.id -> CacheInterfaceId) so the ladder and the catalog never restate each other's half. Three forward walls (demands-from-DependencyView, hand-cache shape lens, live-provider-or-red) make new caches born as provider rows only. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * C0: provider rows derive from the cited cache catalog (extdeps/cache/materialization.dag projection) Operator ruling 2026-07-09: extdeps stays the ground-truth/interface layer; every USE of a cache goes through materialization so memo never gets re-invented. provider_from_catalog is the only door from a catalog row into the ladder: keying/tier/eviction derived from cited facts (mechanism->class: InProcess=>ScopeExit; Ttl/Lru/SizeBounded=>SpacePacked; Never/Manual outside a process => typed ProjectionRefused, counted by the new enrolled witness; HandAuthored/prefix-fallback keys => ExistenceKeyed until key-completeness upgrades them). CI sccache row now derived, hand-typed tier facts deleted, 6/6 + 23/23 witnesses green. 10b re-scoped: v1-internal caches = inventory only (retire with seed); ParseTable/cached_stage promoted to next. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Ground v2 ParseTable + cached_stage on materialization: inhabit the Real * Fix compiler materialization witnesses: RealizedStep carrier, plural RED fixture. Use RealizedStep<Nano> (not unit), drop 02_parse import from witnesses in favor of parse_table_carrier_grounded_on_catalog, and model cross-run memo plurality with an isolation-boundary LCA matching the CI ladder pattern. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix CI: move materialization_carriers to compiler layer (no std→extdeps import). Resolves layering_imports_gate and compile-clean failures from v2.std importing extdeps via materialization_carriers. CachedStageRealization lives in v2.compiler.materialization_carriers; staging.dag stays transport-only. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Ground v2 ParseTable + cached_stage on materialization: inhabit the Real * WIP: Ground v2 ParseTable + cached_stage on materialization: inhabit the Real * Fix governed memo door: resolve_probe in cached_stage_governed, parse lookup match braces. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Ground v2 ParseTable + cached_stage on materialization: inhabit the Real * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * Fail-closed hardening: RefusedNatureConflict arm, weakest-claim nature default, UsesStep silence counted, ladder cells enrolled in CI The complexity-lens false-clean lesson applied to this gate before anyone relies on it: (1) heterogeneous natures on one identity were first-wins — now a typed RefusedNatureConflict (24th ladder cell, RED witness); (2) an unrostered run-step claimed PureComputation — now IdempotentEffect, the weakest claim (verdict-identical, no purity overclaim; a misdeclared WorldRead can no longer be legally memoized by default); (3) UsesStep foreign actions produced silence — now a pinned denominator (==9; a new foreign action must consciously bump it); (4) the ladder's 24 cells enroll on the CI surface so the law's own witnesses gate every run. 24/24 + 7/7. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Merge merry-moth-539 (main-integrated); harden governed memo door witnesses. Merge origin/session/merry-moth-539 for post-main semantics alignment. Export parse_table_memo_lookup_refuses_store / parse_table_memo_insert_refused door oracles in 02_parse; witnesses call them directly (reason atom, not full Diagnostic equality). Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Ground v2 ParseTable + cached_stage on materialization: inhabit the Real * Regenerate ci.yml for floor resolve receipt pin at 3. CI run 29059860791 measured resolves_total=3 after enrolling the two new v2 witness entry classes; sync the emitted gate with ci_floor_declared_resolve_count in ci_materialization.dag. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Ground v2 ParseTable + cached_stage on materialization: inhabit the Real * fix: escape ComputationIdentity braces in design_document.dag Rebase conflict left unescaped {bound}/{cause} in a li() string, which broke dag compile and the generated-artifact drift gate. Regenerate ci.yml. Co-authored-by: Cursor <cursoragent@cursor.com> * merge origin/main and resolve conflict markers; fix ParseTableMemo Case-A leak Integrate main (#6431) atop #6375 base. Remove leftover merge conflict markers from ci_materialization, commit_workflow, design_document, ci.yml. Gate seed ParseTableMemo insert/serve on Memoize only (after governed door) so insert-then-lookup door observables are order-independent; enroll parse_table_memo_door_order_independent witness. Co-authored-by: Cursor <cursoragent@cursor.com> * fix: add Terminal disposition contracts for carrier predicate helpers Land v2_compiler_materialization_memo_gate_predicate_contract and v2_compiler_catalog_projection_predicate_contract on materialization_allows_memo_store / projection_is_projected — matching the Terminal predicate discipline already in materialization_ladder.dag. Co-authored-by: Cursor <cursoragent@cursor.com> * fix: correct resolve-receipt note attribution for #6422 enrollments Pin was already 3 before #6422 witness entries; run 29059860791 held at 3 with those entries enrolled because they pooled warm on the shared index (zero additional cold resolves). Remove false per-entry bump claim. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Ground v2 ParseTable + cached_stage on materialization: inhabit the Real * fix: drop duplicate projection_is_projected; use extdeps authority Remove forked CatalogProviderProjection predicate from materialization_carriers.dag; projection_ok cells now call !projection_is_refused from extdeps.cache.materialization (§3 single authority). Remove local Terminal contract that documented the fork. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ci): raise floor step timeout to 45m for #6422 witness cone Receipt run 29065683045 @ a2bcd6f: batches 1-3 ~20m, batch 4 rust_monolith_gate killed at 30m step cap. Bump floor step and ci/ci_regen job backstop (85m→100m) to match rust gate step budget. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: Cursor <cursoragent@cursor.com>
…rier (#6435) * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * Analysis spine: spine_receipt composes dependency_view + materialize (increment 1) The Rc-safe half of run ≜ realize ∘ materialize ∘ dependency_view: compose the two catamorphisms that need no interpreter thread-safety. - src/v2/std/spine.dag: level-profile fold over the DependencyView DAG → critical_path_depth (longest dependency chain / the reduce spine) + independence_width (max nodes at one level / what parallelizes to hw width). spine_receipt emits the §9 numbers by COMPUTATION, not assertion, joining materialize's content-hash Share/dedup counts. - Discriminating RED (§9): single chain A→B→C → depth 3 / width 1 (serial); root over N independent leaves → depth 2 / width N. - Witnesses 9/9 (spine) green by execution; materialize 6/6 unchanged. The RUNNER (wall-clock parallel execution, §8 steps 3-4) stays increment 2+, gated on interpreter Rc→Arc (v1 interp is !Send). This increment measures the achievable width/critical-path floor the runner targets; it does not fabricate wall-clock N×. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Unbundle recompute-trace interpreter extension from the analysis-spine PR CI root cause: the recompute-trace extension edited v1_interpreter.rs, which hosts the atom_identity_hash/hash_combine fnv1a64 intrinsics that dag_collect_fingerprint_witness executes. That correctly invalidated the re-verify 'assumed-green node-frontier' SKIP of that witness (cone-touch, fail-closed) — but the witness is a pre-existing 806s (13min) fnv1a64 whole-corpus walk, so un-skipping it blew the 30-min floor budget. Main stays green only because its interpreter cone is untouched (witness stays skipped). The interpreter extension is a separable, env-gated (GUNBC_RECOMPUTE_TRACE=1), READ-mode diagnostic — not a dependency of the spine/materialize analysis substrate (pure .dag, content_hash-based). Reverting v1_interpreter.rs to main restores byte-identical interpreter content → the fingerprint witness returns to assumed-green SKIP → floor budget restored. The recompute-trace extension lands as its own follow-up PR where the fingerprint-witness re-run is expected. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Materialization ladder: the state x decision law, as executable witnesses The operator's 4-rule business logic generalized on one axis: the decision is a function of WHEN the redundancy is knowable and WHETHER what was knowable was prepared for. Errors fire only on knowable-but-unprepared; genuine emergence and declared triviality are typed acceptances, never silence. std.materialization_ladder (dag/std): - Frame/FrameKind: SharedStateFrame | IsolatedChildrenFrame | ReplayedFrame{attempts} | UnboundedSiblingsFrame — the nested-scope axis; a 'run' at any layer is a frame, never a different kind of thing. - DemandNature: Pure | IdempotentEffect | WorldRead{envelope_declared} | FreshEffect — the D3 effect gate; TTL = unmodeled dependency XOR declared staleness, never an eviction knob. - CacheProvider: keying (ContentKeyed|ExistenceKeyed) + EvictionPolicy (ScopeExit|SpacePacked) REQUIRED by construction — rule 3 unwritable-bad. - LadderVerdict (total): AuthoredDuplication | Discharged | RefusedNoProvider | RefusedScopeTooNarrow | RefusedExistenceKeyed (the build-if-absent #6352 wall) | RefusedUnmodeledWorldRead | ExemptFreshEffect | AcceptedBelowCostFloor | AcceptedSingleRecompute. - Declared-emergent frames obligate UP FRONT: retry frames derive checkpointing, unbounded-sibling frames (server loops, CI-runs-over-time) derive persistent caches — prepare-before-demand. 12/12 witnesses green by execution; each test is one cell of the table, fixtures mirror the live worked example (workflow/jobs/steps, retry, fleet). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Docs crystallization: derived materialization placement into roadmap ④ + the state x decision table - roadmap_authority ④ (ROADMAP.md regenerated via main_wet, drift-consistent): the nested-frame law, plurality cells, declared-emergent prepare-up-front, keying/staleness walls, the caching-completion un-shelve, the ①-vs-§2 cross-run-caching contradiction subsumed into per-node derived verdicts, and the v1.compiler.ownership §3-convergence row. - duplicate-work design doc: the state x decision table as the qualifier's final verdict logic + the ownership consolidation subsection. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Consolidation plan: realization + materialization + ownership are one law Operator synthesis (2026-07-09): Materialization = the verdict vocabulary; ownership = the verdict computation at the eval frame; realization = provider selection discharging the verdict at each frame's carrier. Share's handler is layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable carrier + readonly => point-at-it, no copy, no destroyed memory), demoting through HAMT structural share / process memo / artifact / CAS, and demotion must be priced, never silent (#6249 clone-fallback is the receipt). Census of every hand-rolled instance found in-tree (16 rows): each named with its frame, ladder cell, action, and dissolution trigger — ownership (consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall), ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green / sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789 (rule-4 requirements), recompute-trace (state-4 finding source). Peers kept distinct: affected-set, Independence/Placement, mutable state. Sequence C1-C5 with C1 = this PR (ladder + live CI gate). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Ownership refactored onto materialization: the value tier, tested as providers First consolidation increment (operator-directed): v1.compiler.ownership's decision IS provider selection at the value grain, now expressed in the ladder and proven by mirror witnesses. - ProviderTier: Reference | Copy | Memo{keying} | Artifact{keying} | Cas{keying} — keying folded INTO store tiers, so an existence-keyed reference is unwritable BY SHAPE (§5 construction); frame obligations at isolation LCAs are dischargeable only by store tiers (a reference cannot cross an isolation boundary — witnessed). - Value tier: AccessMode (Read|Consume|Carry|Project), ValueUsage, value_materialization -> ValueDead | ValueMoved | ValueSharedByReference | ValueDemotedToCopy (PRICED, requires a declared CopyTier provider — the #6249 silent clone-fallback made refusable) | ValueRefusedAffine | ValueRefusedNoCarrierProvider. - Faithful to v1's THREE distinct plurality readings, kept separate: take_count = semantic_consumer_count (Consumed only, affine axis); value_access_plurality = binding_fan_out (Carry excluded, reference axis); borrow_count = whole_value_borrow_count (Read+Carry not Project, movability). - Fold-accumulator case mirrored at conservative pre-FoldAccUnwrap semantics: carries excluded from plurality but blocking the move -> demoted-to-copy. 23/23 witnesses green (14 frame cells + 9 value cells). Corpus-level equivalence against live v1 ownership folds = the C4 receipt. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * WIP: Duplicate Computation/Materialization * G: exhaustive cache/share census (52 mechanisms, 6 groups) + C0 catalog-grounding of provider rows + forward-wiring walls The sweep found the tree already models caches: extdeps/cache cache_catalog (CacheInterfaceCatalogFacts, 9 rows) + extdeps/realization carrier facts + the warm==cold purity oracle. C0 grounds CacheProvider on that catalog (provider_from_catalog projection; CacheProvider.id -> CacheInterfaceId) so the ladder and the catalog never restate each other's half. Three forward walls (demands-from-DependencyView, hand-cache shape lens, live-provider-or-red) make new caches born as provider rows only. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * C0: provider rows derive from the cited cache catalog (extdeps/cache/materialization.dag projection) Operator ruling 2026-07-09: extdeps stays the ground-truth/interface layer; every USE of a cache goes through materialization so memo never gets re-invented. provider_from_catalog is the only door from a catalog row into the ladder: keying/tier/eviction derived from cited facts (mechanism->class: InProcess=>ScopeExit; Ttl/Lru/SizeBounded=>SpacePacked; Never/Manual outside a process => typed ProjectionRefused, counted by the new enrolled witness; HandAuthored/prefix-fallback keys => ExistenceKeyed until key-completeness upgrades them). CI sccache row now derived, hand-typed tier facts deleted, 6/6 + 23/23 witnesses green. 10b re-scoped: v1-internal caches = inventory only (retire with seed); ParseTable/cached_stage promoted to next. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * Fail-closed hardening: RefusedNatureConflict arm, weakest-claim nature default, UsesStep silence counted, ladder cells enrolled in CI The complexity-lens false-clean lesson applied to this gate before anyone relies on it: (1) heterogeneous natures on one identity were first-wins — now a typed RefusedNatureConflict (24th ladder cell, RED witness); (2) an unrostered run-step claimed PureComputation — now IdempotentEffect, the weakest claim (verdict-identical, no purity overclaim; a misdeclared WorldRead can no longer be legally memoized by default); (3) UsesStep foreign actions produced silence — now a pinned denominator (==9; a new foreign action must consciously bump it); (4) the ladder's 24 cells enroll on the CI surface so the law's own witnesses gate every run. 24/24 + 7/7. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * M1 ratchet bump: declared resolve count 1 -> 3 (gate's first live catch — enrollment pays counted resolves) Run 29058798771: enrolling the ladder witness file moved resolves_total 1 -> 3 (each enrolled entry file pays one closure resolve against the shared index) and the receipt gate redded that exact run — the designed semantics, receipted in the note. Bump acknowledges the two witness-entry resolves as declared debt; M2 (one closure resolve per roots set) ratchets back toward 1. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Retire the M1/M2 labels from carriers (no-codename rule; collided with DESIGN's floor-memoization M1/M2) Step renamed to 'Floor resolve receipt gate (declared cold-resolve count)'; notes and the gate echo now say what the things are: the counted cold-resolve receipt, and the shared-resolve rewire (one closure resolve per source-roots set). Naming-retirement note left on the carrier. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * Run-step natures pinned as counted claims, not affordances Operator ruling 2026-07-10: hardcoded shell scripts get no affordances — run-steps are supposed to be modeled as typed intents and emitted (shell-emission-model slice 4 covers ci_workflow RunSteps). Until that slice lands, every nature in job_run_demands is a claim (rostered FreshEffect / weakest-default IdempotentEffect), never derived from a modeled effect row. Count the whole claimed-nature surface (16 by execution) and pin it in the enrolled witness: a new raw-script step must consciously bump the pin, and slice-4 migration becomes a countable ratchet ending at zero, where the pin becomes a wall. Rejected alternative recorded in the carrier note: a per-step declared-natures roster (a second parallel ledger over scripts the shell-emission plan already governs). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Regen DESIGN.md after main merge (duplicate-work row + #6373 body-lowering row coexist) Conflict was both sides editing the open-threads list in design_document.dag: ours added the duplicate-work thread, main's #6373 rewrote body-lowering to Stages 1-3 LANDED. Resolution keeps both rows in the .dag authority; DESIGN.md regenerated from it, never hand-edited. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ate (#6441) * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * Analysis spine: spine_receipt composes dependency_view + materialize (increment 1) The Rc-safe half of run ≜ realize ∘ materialize ∘ dependency_view: compose the two catamorphisms that need no interpreter thread-safety. - src/v2/std/spine.dag: level-profile fold over the DependencyView DAG → critical_path_depth (longest dependency chain / the reduce spine) + independence_width (max nodes at one level / what parallelizes to hw width). spine_receipt emits the §9 numbers by COMPUTATION, not assertion, joining materialize's content-hash Share/dedup counts. - Discriminating RED (§9): single chain A→B→C → depth 3 / width 1 (serial); root over N independent leaves → depth 2 / width N. - Witnesses 9/9 (spine) green by execution; materialize 6/6 unchanged. The RUNNER (wall-clock parallel execution, §8 steps 3-4) stays increment 2+, gated on interpreter Rc→Arc (v1 interp is !Send). This increment measures the achievable width/critical-path floor the runner targets; it does not fabricate wall-clock N×. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Unbundle recompute-trace interpreter extension from the analysis-spine PR CI root cause: the recompute-trace extension edited v1_interpreter.rs, which hosts the atom_identity_hash/hash_combine fnv1a64 intrinsics that dag_collect_fingerprint_witness executes. That correctly invalidated the re-verify 'assumed-green node-frontier' SKIP of that witness (cone-touch, fail-closed) — but the witness is a pre-existing 806s (13min) fnv1a64 whole-corpus walk, so un-skipping it blew the 30-min floor budget. Main stays green only because its interpreter cone is untouched (witness stays skipped). The interpreter extension is a separable, env-gated (GUNBC_RECOMPUTE_TRACE=1), READ-mode diagnostic — not a dependency of the spine/materialize analysis substrate (pure .dag, content_hash-based). Reverting v1_interpreter.rs to main restores byte-identical interpreter content → the fingerprint witness returns to assumed-green SKIP → floor budget restored. The recompute-trace extension lands as its own follow-up PR where the fingerprint-witness re-run is expected. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Materialization ladder: the state x decision law, as executable witnesses The operator's 4-rule business logic generalized on one axis: the decision is a function of WHEN the redundancy is knowable and WHETHER what was knowable was prepared for. Errors fire only on knowable-but-unprepared; genuine emergence and declared triviality are typed acceptances, never silence. std.materialization_ladder (dag/std): - Frame/FrameKind: SharedStateFrame | IsolatedChildrenFrame | ReplayedFrame{attempts} | UnboundedSiblingsFrame — the nested-scope axis; a 'run' at any layer is a frame, never a different kind of thing. - DemandNature: Pure | IdempotentEffect | WorldRead{envelope_declared} | FreshEffect — the D3 effect gate; TTL = unmodeled dependency XOR declared staleness, never an eviction knob. - CacheProvider: keying (ContentKeyed|ExistenceKeyed) + EvictionPolicy (ScopeExit|SpacePacked) REQUIRED by construction — rule 3 unwritable-bad. - LadderVerdict (total): AuthoredDuplication | Discharged | RefusedNoProvider | RefusedScopeTooNarrow | RefusedExistenceKeyed (the build-if-absent #6352 wall) | RefusedUnmodeledWorldRead | ExemptFreshEffect | AcceptedBelowCostFloor | AcceptedSingleRecompute. - Declared-emergent frames obligate UP FRONT: retry frames derive checkpointing, unbounded-sibling frames (server loops, CI-runs-over-time) derive persistent caches — prepare-before-demand. 12/12 witnesses green by execution; each test is one cell of the table, fixtures mirror the live worked example (workflow/jobs/steps, retry, fleet). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Docs crystallization: derived materialization placement into roadmap ④ + the state x decision table - roadmap_authority ④ (ROADMAP.md regenerated via main_wet, drift-consistent): the nested-frame law, plurality cells, declared-emergent prepare-up-front, keying/staleness walls, the caching-completion un-shelve, the ①-vs-§2 cross-run-caching contradiction subsumed into per-node derived verdicts, and the v1.compiler.ownership §3-convergence row. - duplicate-work design doc: the state x decision table as the qualifier's final verdict logic + the ownership consolidation subsection. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Consolidation plan: realization + materialization + ownership are one law Operator synthesis (2026-07-09): Materialization = the verdict vocabulary; ownership = the verdict computation at the eval frame; realization = provider selection discharging the verdict at each frame's carrier. Share's handler is layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable carrier + readonly => point-at-it, no copy, no destroyed memory), demoting through HAMT structural share / process memo / artifact / CAS, and demotion must be priced, never silent (#6249 clone-fallback is the receipt). Census of every hand-rolled instance found in-tree (16 rows): each named with its frame, ladder cell, action, and dissolution trigger — ownership (consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall), ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green / sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789 (rule-4 requirements), recompute-trace (state-4 finding source). Peers kept distinct: affected-set, Independence/Placement, mutable state. Sequence C1-C5 with C1 = this PR (ladder + live CI gate). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Ownership refactored onto materialization: the value tier, tested as providers First consolidation increment (operator-directed): v1.compiler.ownership's decision IS provider selection at the value grain, now expressed in the ladder and proven by mirror witnesses. - ProviderTier: Reference | Copy | Memo{keying} | Artifact{keying} | Cas{keying} — keying folded INTO store tiers, so an existence-keyed reference is unwritable BY SHAPE (§5 construction); frame obligations at isolation LCAs are dischargeable only by store tiers (a reference cannot cross an isolation boundary — witnessed). - Value tier: AccessMode (Read|Consume|Carry|Project), ValueUsage, value_materialization -> ValueDead | ValueMoved | ValueSharedByReference | ValueDemotedToCopy (PRICED, requires a declared CopyTier provider — the #6249 silent clone-fallback made refusable) | ValueRefusedAffine | ValueRefusedNoCarrierProvider. - Faithful to v1's THREE distinct plurality readings, kept separate: take_count = semantic_consumer_count (Consumed only, affine axis); value_access_plurality = binding_fan_out (Carry excluded, reference axis); borrow_count = whole_value_borrow_count (Read+Carry not Project, movability). - Fold-accumulator case mirrored at conservative pre-FoldAccUnwrap semantics: carries excluded from plurality but blocking the move -> demoted-to-copy. 23/23 witnesses green (14 frame cells + 9 value cells). Corpus-level equivalence against live v1 ownership folds = the C4 receipt. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * WIP: Duplicate Computation/Materialization * G: exhaustive cache/share census (52 mechanisms, 6 groups) + C0 catalog-grounding of provider rows + forward-wiring walls The sweep found the tree already models caches: extdeps/cache cache_catalog (CacheInterfaceCatalogFacts, 9 rows) + extdeps/realization carrier facts + the warm==cold purity oracle. C0 grounds CacheProvider on that catalog (provider_from_catalog projection; CacheProvider.id -> CacheInterfaceId) so the ladder and the catalog never restate each other's half. Three forward walls (demands-from-DependencyView, hand-cache shape lens, live-provider-or-red) make new caches born as provider rows only. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * C0: provider rows derive from the cited cache catalog (extdeps/cache/materialization.dag projection) Operator ruling 2026-07-09: extdeps stays the ground-truth/interface layer; every USE of a cache goes through materialization so memo never gets re-invented. provider_from_catalog is the only door from a catalog row into the ladder: keying/tier/eviction derived from cited facts (mechanism->class: InProcess=>ScopeExit; Ttl/Lru/SizeBounded=>SpacePacked; Never/Manual outside a process => typed ProjectionRefused, counted by the new enrolled witness; HandAuthored/prefix-fallback keys => ExistenceKeyed until key-completeness upgrades them). CI sccache row now derived, hand-typed tier facts deleted, 6/6 + 23/23 witnesses green. 10b re-scoped: v1-internal caches = inventory only (retire with seed); ParseTable/cached_stage promoted to next. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * Fail-closed hardening: RefusedNatureConflict arm, weakest-claim nature default, UsesStep silence counted, ladder cells enrolled in CI The complexity-lens false-clean lesson applied to this gate before anyone relies on it: (1) heterogeneous natures on one identity were first-wins — now a typed RefusedNatureConflict (24th ladder cell, RED witness); (2) an unrostered run-step claimed PureComputation — now IdempotentEffect, the weakest claim (verdict-identical, no purity overclaim; a misdeclared WorldRead can no longer be legally memoized by default); (3) UsesStep foreign actions produced silence — now a pinned denominator (==9; a new foreign action must consciously bump it); (4) the ladder's 24 cells enroll on the CI surface so the law's own witnesses gate every run. 24/24 + 7/7. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * M1 ratchet bump: declared resolve count 1 -> 3 (gate's first live catch — enrollment pays counted resolves) Run 29058798771: enrolling the ladder witness file moved resolves_total 1 -> 3 (each enrolled entry file pays one closure resolve against the shared index) and the receipt gate redded that exact run — the designed semantics, receipted in the note. Bump acknowledges the two witness-entry resolves as declared debt; M2 (one closure resolve per roots set) ratchets back toward 1. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Retire the M1/M2 labels from carriers (no-codename rule; collided with DESIGN's floor-memoization M1/M2) Step renamed to 'Floor resolve receipt gate (declared cold-resolve count)'; notes and the gate echo now say what the things are: the counted cold-resolve receipt, and the shared-resolve rewire (one closure resolve per source-roots set). Naming-retirement note left on the carrier. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * Run-step natures pinned as counted claims, not affordances Operator ruling 2026-07-10: hardcoded shell scripts get no affordances — run-steps are supposed to be modeled as typed intents and emitted (shell-emission-model slice 4 covers ci_workflow RunSteps). Until that slice lands, every nature in job_run_demands is a claim (rostered FreshEffect / weakest-default IdempotentEffect), never derived from a modeled effect row. Count the whole claimed-nature surface (16 by execution) and pin it in the enrolled witness: a new raw-script step must consciously bump the pin, and slice-4 migration becomes a countable ratchet ending at zero, where the pin becomes a wall. Rejected alternative recorded in the carrier note: a per-step declared-natures roster (a second parallel ledger over scripts the shell-emission plan already governs). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Regen DESIGN.md after main merge (duplicate-work row + #6373 body-lowering row coexist) Conflict was both sides editing the open-threads list in design_document.dag: ours added the duplicate-work thread, main's #6373 rewrote body-lowering to Stages 1-3 LANDED. Resolution keeps both rows in the .dag authority; DESIGN.md regenerated from it, never hand-edited. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * Inferred materialization increment 1: floor demand ledger + receipt-or-red gate Running IS enrolling: the interpreter ledgers every keyed pure call and every InterpContext absorbs its totals into a process accumulator on Drop — by construction, no eval path escapes the receipt. claim_executor writes target/floor-materialization-receipt.txt at walk end; trace defaults ON in the executor, and an explicit =0 zeroes keyed_calls which the gate refuses. Gate arms this push (all verified under dash from the emitted ci.yml): receipt missing/malformed/keyed_calls=0 fail closed. Exact pins for unkeyed_calls and duplicated_keys land from the FIRST CI receipt (the resolve gate's measure-then-pin path) — unkeyed is known nonzero on the floor (count_matching takes a predicate closure; closures are the one disclosed identity-less class, dissolve-on captured-env content identity). Unit witness green: resolve -> eval -> ctx Drop -> absorb -> drain-once. Step addition bumped the claimed-natures pin 16 -> 17 consciously. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Review fix: drop the racy drain-once assertion from the receipt unit test opus-4-7 finding on #6441: under plain cargo test (still the documented runner) tests share a process, the env latch is OnceLock-sticky, and sibling ctx drops could absorb between the two takes — making the drain-empty assertion racy. Absorb-on-Drop stays asserted (monotone under concurrent absorbs: siblings only ADD); drain-once is Option::take by construction, not asserted through the shared global. Comment states the sharing semantics explicitly. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… gated) (#6455) * Inferred materialization increment 1: floor demand ledger + receipt gate (#6441) * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * Analysis spine: spine_receipt composes dependency_view + materialize (increment 1) The Rc-safe half of run ≜ realize ∘ materialize ∘ dependency_view: compose the two catamorphisms that need no interpreter thread-safety. - src/v2/std/spine.dag: level-profile fold over the DependencyView DAG → critical_path_depth (longest dependency chain / the reduce spine) + independence_width (max nodes at one level / what parallelizes to hw width). spine_receipt emits the §9 numbers by COMPUTATION, not assertion, joining materialize's content-hash Share/dedup counts. - Discriminating RED (§9): single chain A→B→C → depth 3 / width 1 (serial); root over N independent leaves → depth 2 / width N. - Witnesses 9/9 (spine) green by execution; materialize 6/6 unchanged. The RUNNER (wall-clock parallel execution, §8 steps 3-4) stays increment 2+, gated on interpreter Rc→Arc (v1 interp is !Send). This increment measures the achievable width/critical-path floor the runner targets; it does not fabricate wall-clock N×. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Unbundle recompute-trace interpreter extension from the analysis-spine PR CI root cause: the recompute-trace extension edited v1_interpreter.rs, which hosts the atom_identity_hash/hash_combine fnv1a64 intrinsics that dag_collect_fingerprint_witness executes. That correctly invalidated the re-verify 'assumed-green node-frontier' SKIP of that witness (cone-touch, fail-closed) — but the witness is a pre-existing 806s (13min) fnv1a64 whole-corpus walk, so un-skipping it blew the 30-min floor budget. Main stays green only because its interpreter cone is untouched (witness stays skipped). The interpreter extension is a separable, env-gated (GUNBC_RECOMPUTE_TRACE=1), READ-mode diagnostic — not a dependency of the spine/materialize analysis substrate (pure .dag, content_hash-based). Reverting v1_interpreter.rs to main restores byte-identical interpreter content → the fingerprint witness returns to assumed-green SKIP → floor budget restored. The recompute-trace extension lands as its own follow-up PR where the fingerprint-witness re-run is expected. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Materialization ladder: the state x decision law, as executable witnesses The operator's 4-rule business logic generalized on one axis: the decision is a function of WHEN the redundancy is knowable and WHETHER what was knowable was prepared for. Errors fire only on knowable-but-unprepared; genuine emergence and declared triviality are typed acceptances, never silence. std.materialization_ladder (dag/std): - Frame/FrameKind: SharedStateFrame | IsolatedChildrenFrame | ReplayedFrame{attempts} | UnboundedSiblingsFrame — the nested-scope axis; a 'run' at any layer is a frame, never a different kind of thing. - DemandNature: Pure | IdempotentEffect | WorldRead{envelope_declared} | FreshEffect — the D3 effect gate; TTL = unmodeled dependency XOR declared staleness, never an eviction knob. - CacheProvider: keying (ContentKeyed|ExistenceKeyed) + EvictionPolicy (ScopeExit|SpacePacked) REQUIRED by construction — rule 3 unwritable-bad. - LadderVerdict (total): AuthoredDuplication | Discharged | RefusedNoProvider | RefusedScopeTooNarrow | RefusedExistenceKeyed (the build-if-absent #6352 wall) | RefusedUnmodeledWorldRead | ExemptFreshEffect | AcceptedBelowCostFloor | AcceptedSingleRecompute. - Declared-emergent frames obligate UP FRONT: retry frames derive checkpointing, unbounded-sibling frames (server loops, CI-runs-over-time) derive persistent caches — prepare-before-demand. 12/12 witnesses green by execution; each test is one cell of the table, fixtures mirror the live worked example (workflow/jobs/steps, retry, fleet). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Docs crystallization: derived materialization placement into roadmap ④ + the state x decision table - roadmap_authority ④ (ROADMAP.md regenerated via main_wet, drift-consistent): the nested-frame law, plurality cells, declared-emergent prepare-up-front, keying/staleness walls, the caching-completion un-shelve, the ①-vs-§2 cross-run-caching contradiction subsumed into per-node derived verdicts, and the v1.compiler.ownership §3-convergence row. - duplicate-work design doc: the state x decision table as the qualifier's final verdict logic + the ownership consolidation subsection. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Consolidation plan: realization + materialization + ownership are one law Operator synthesis (2026-07-09): Materialization = the verdict vocabulary; ownership = the verdict computation at the eval frame; realization = provider selection discharging the verdict at each frame's carrier. Share's handler is layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable carrier + readonly => point-at-it, no copy, no destroyed memory), demoting through HAMT structural share / process memo / artifact / CAS, and demotion must be priced, never silent (#6249 clone-fallback is the receipt). Census of every hand-rolled instance found in-tree (16 rows): each named with its frame, ladder cell, action, and dissolution trigger — ownership (consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall), ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green / sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789 (rule-4 requirements), recompute-trace (state-4 finding source). Peers kept distinct: affected-set, Independence/Placement, mutable state. Sequence C1-C5 with C1 = this PR (ladder + live CI gate). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Ownership refactored onto materialization: the value tier, tested as providers First consolidation increment (operator-directed): v1.compiler.ownership's decision IS provider selection at the value grain, now expressed in the ladder and proven by mirror witnesses. - ProviderTier: Reference | Copy | Memo{keying} | Artifact{keying} | Cas{keying} — keying folded INTO store tiers, so an existence-keyed reference is unwritable BY SHAPE (§5 construction); frame obligations at isolation LCAs are dischargeable only by store tiers (a reference cannot cross an isolation boundary — witnessed). - Value tier: AccessMode (Read|Consume|Carry|Project), ValueUsage, value_materialization -> ValueDead | ValueMoved | ValueSharedByReference | ValueDemotedToCopy (PRICED, requires a declared CopyTier provider — the #6249 silent clone-fallback made refusable) | ValueRefusedAffine | ValueRefusedNoCarrierProvider. - Faithful to v1's THREE distinct plurality readings, kept separate: take_count = semantic_consumer_count (Consumed only, affine axis); value_access_plurality = binding_fan_out (Carry excluded, reference axis); borrow_count = whole_value_borrow_count (Read+Carry not Project, movability). - Fold-accumulator case mirrored at conservative pre-FoldAccUnwrap semantics: carries excluded from plurality but blocking the move -> demoted-to-copy. 23/23 witnesses green (14 frame cells + 9 value cells). Corpus-level equivalence against live v1 ownership folds = the C4 receipt. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * WIP: Duplicate Computation/Materialization * G: exhaustive cache/share census (52 mechanisms, 6 groups) + C0 catalog-grounding of provider rows + forward-wiring walls The sweep found the tree already models caches: extdeps/cache cache_catalog (CacheInterfaceCatalogFacts, 9 rows) + extdeps/realization carrier facts + the warm==cold purity oracle. C0 grounds CacheProvider on that catalog (provider_from_catalog projection; CacheProvider.id -> CacheInterfaceId) so the ladder and the catalog never restate each other's half. Three forward walls (demands-from-DependencyView, hand-cache shape lens, live-provider-or-red) make new caches born as provider rows only. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * C0: provider rows derive from the cited cache catalog (extdeps/cache/materialization.dag projection) Operator ruling 2026-07-09: extdeps stays the ground-truth/interface layer; every USE of a cache goes through materialization so memo never gets re-invented. provider_from_catalog is the only door from a catalog row into the ladder: keying/tier/eviction derived from cited facts (mechanism->class: InProcess=>ScopeExit; Ttl/Lru/SizeBounded=>SpacePacked; Never/Manual outside a process => typed ProjectionRefused, counted by the new enrolled witness; HandAuthored/prefix-fallback keys => ExistenceKeyed until key-completeness upgrades them). CI sccache row now derived, hand-typed tier facts deleted, 6/6 + 23/23 witnesses green. 10b re-scoped: v1-internal caches = inventory only (retire with seed); ParseTable/cached_stage promoted to next. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * Fail-closed hardening: RefusedNatureConflict arm, weakest-claim nature default, UsesStep silence counted, ladder cells enrolled in CI The complexity-lens false-clean lesson applied to this gate before anyone relies on it: (1) heterogeneous natures on one identity were first-wins — now a typed RefusedNatureConflict (24th ladder cell, RED witness); (2) an unrostered run-step claimed PureComputation — now IdempotentEffect, the weakest claim (verdict-identical, no purity overclaim; a misdeclared WorldRead can no longer be legally memoized by default); (3) UsesStep foreign actions produced silence — now a pinned denominator (==9; a new foreign action must consciously bump it); (4) the ladder's 24 cells enroll on the CI surface so the law's own witnesses gate every run. 24/24 + 7/7. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * M1 ratchet bump: declared resolve count 1 -> 3 (gate's first live catch — enrollment pays counted resolves) Run 29058798771: enrolling the ladder witness file moved resolves_total 1 -> 3 (each enrolled entry file pays one closure resolve against the shared index) and the receipt gate redded that exact run — the designed semantics, receipted in the note. Bump acknowledges the two witness-entry resolves as declared debt; M2 (one closure resolve per roots set) ratchets back toward 1. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Retire the M1/M2 labels from carriers (no-codename rule; collided with DESIGN's floor-memoization M1/M2) Step renamed to 'Floor resolve receipt gate (declared cold-resolve count)'; notes and the gate echo now say what the things are: the counted cold-resolve receipt, and the shared-resolve rewire (one closure resolve per source-roots set). Naming-retirement note left on the carrier. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * Run-step natures pinned as counted claims, not affordances Operator ruling 2026-07-10: hardcoded shell scripts get no affordances — run-steps are supposed to be modeled as typed intents and emitted (shell-emission-model slice 4 covers ci_workflow RunSteps). Until that slice lands, every nature in job_run_demands is a claim (rostered FreshEffect / weakest-default IdempotentEffect), never derived from a modeled effect row. Count the whole claimed-nature surface (16 by execution) and pin it in the enrolled witness: a new raw-script step must consciously bump the pin, and slice-4 migration becomes a countable ratchet ending at zero, where the pin becomes a wall. Rejected alternative recorded in the carrier note: a per-step declared-natures roster (a second parallel ledger over scripts the shell-emission plan already governs). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Regen DESIGN.md after main merge (duplicate-work row + #6373 body-lowering row coexist) Conflict was both sides editing the open-threads list in design_document.dag: ours added the duplicate-work thread, main's #6373 rewrote body-lowering to Stages 1-3 LANDED. Resolution keeps both rows in the .dag authority; DESIGN.md regenerated from it, never hand-edited. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * Inferred materialization increment 1: floor demand ledger + receipt-or-red gate Running IS enrolling: the interpreter ledgers every keyed pure call and every InterpContext absorbs its totals into a process accumulator on Drop — by construction, no eval path escapes the receipt. claim_executor writes target/floor-materialization-receipt.txt at walk end; trace defaults ON in the executor, and an explicit =0 zeroes keyed_calls which the gate refuses. Gate arms this push (all verified under dash from the emitted ci.yml): receipt missing/malformed/keyed_calls=0 fail closed. Exact pins for unkeyed_calls and duplicated_keys land from the FIRST CI receipt (the resolve gate's measure-then-pin path) — unkeyed is known nonzero on the floor (count_matching takes a predicate closure; closures are the one disclosed identity-less class, dissolve-on captured-env content identity). Unit witness green: resolve -> eval -> ctx Drop -> absorb -> drain-once. Step addition bumped the claimed-natures pin 16 -> 17 consciously. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Review fix: drop the racy drain-once assertion from the receipt unit test opus-4-7 finding on #6441: under plain cargo test (still the documented runner) tests share a process, the env latch is OnceLock-sticky, and sibling ctx drops could absorb between the two takes — making the drain-empty assertion racy. Absorb-on-Drop stays asserted (monotone under concurrent absorbs: siblings only ADD); drain-once is Option::take by construction, not asserted through the shared global. Comment states the sharing semantics explicitly. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Turn on affected-set CI: re-land witness enrollment flip (discovery shrunk by affected set) + falsifier host-OOM receipt (#6438) * WIP: Re-land affected-set CI enrollment flip once shard resolve footprint is * WIP: Re-land affected-set CI enrollment flip once shard resolve footprint is * Fix CI OOM: pin discovery corpus spawn_width_cap to 1. Run 28999086030 OOM-killed at width=2 on the 24GiB live slot during the discovery-flip corpus batch. Gate workloads still fit at width=2; only the tree-wide discovery batch serializes via spawn_width_cap=1, with a receipt witness and dissolve-on note. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix type error in corpus discovery spawn width cap helper. Both if-branches must return Nat (hardware_thread_count_value), not a bare Int literal. Co-authored-by: Cursor <cursoragent@cursor.com> * Merge affected-set enrollment flip (takeover of PR #6403 from session/gentle-stag-677-flip) Conflict resolutions onto post-#6422/#6431/#6432/#6435 main: - ci_witness_optin_inversion: main's typed Scaffold Disposition -> Terminal (dissolve fired at the flip; roster stays as explicit-entry home, exclusivity dissolved) - floor step timeout: 45 (main) vs 60 (flip) -> 60 with provenance note - ci_spec notes: kept flip notes, stale fixed-8 phrasing dated - falsifier width note: + RESIDUE paragraph (5x exit-137 on srv2-class slots = converge lane, not plan width) Verified before commit: discovery batches charge corpus_resolve_nanos (own key), resolve_nanos=0 -> resolves_total declared 3 is NOT moved by the flip. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: affected set processing * WIP: affected set processing * WIP: affected set processing * WIP: affected set processing * Correct the false flip receipt + kill-surviving calibration receipts (space-lens loop) CORRECTED RECEIPT: run 29000557166's floor never completed - the executor was host-OOM-killed mid-discovery-corpus at ~8min; the log's ExitSuccess belongs to the merge-admission stamp tool stamping CI_FLOOR_EXIT=137. No flipped corpus has completed in CI (0/1 ci + 0/5 falsifier). Both carrier notes corrected. Calibration (coordinated with merry-owl-649's space-lens lane): - roster_import_closure_nodes_pre_resolve: shared closure-count authority (pure import walk, closure grain not entry grain), emitted BEFORE the heavy resolve so killed runs still yield the (nodes, peak) lower-bound pair - width-1 definition-drift oracle: pre-resolve walk must equal post-resolve resolved union on completed runs; refuses on divergence. Proven by execution: pre == post == 190/213 nodes across Off/Applied modes - kill-surviving cgroup memory.peak pre/post steps (post is always()) in the ci job and falsifier.yml; scope semantics labeled on the emission lines (reset=ok floor-scoped; span compares post>pre; never silently conflated) - job backstop timeouts extended by the two aux steps in both jobs Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: affected set processing * Calibration pairs carry censored-vs-exact labels (methodology: killed runs are censored observations) Floor steps get id=floor; the always() post-peak step emits floor_outcome so each (closure_nodes, peak) pair is explicitly labeled: success = exact point, anything else = censored lower bound (true demand strictly greater than read). Prevents the fit from treating cap-kill reads as point estimates, which would drag the slope down and make the predictor underestimate - the dangerous direction (merry-owl methodology catch, 2026-07-10). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: affected set processing * Review fixes: explicit witness import + complete step-budget ledger - ci_floor_plan_witness_test.dag: import witness_ci_corpus_discovery_serializes_at_width_one explicitly (cursor catch on #6438). The call resolved pre-fix via the seed resolver's flat namespace, so the witness ran green by execution; the explicit import restores the file's per-symbol import convention. - ci_workflow.dag: the resolve-receipt gate step had NO step cap — a hang there could only die by job-cancel (the #6323 starvation-kill class). It now carries the aux cap (script is a sub-second receipt read) and the ci job backstop counts four aux terms (peak pre/post, resolve-receipt gate, merge-admission gate): every step budgeted, backstop = step-sum + prelude (claude review catch on #6438, sharpened). - falsifier_workflow_witness_test.dag: falsifier_backstop_is_step_sum_plus_prelude asserted the pre-calibration formula — latent red proven by execution (FAIL receipt), fixed to the live two-aux sum, re-run PASS. - ci.yml regenerated byte-stable from the carrier (backstops 125->130, gate step timeout 5m). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Rebind calibration provenance comments to real artifacts (cursor review catch) The two cli_run.rs comments cited docs/plans/space-lens-minimal-project.md, which does not exist on main — the predictor design is in flight on PR #6442 (merry-owl-649's lane) and was never landed under that path. Rebound: the shared closure-definition authority is stated as this function itself, with the in-flight design cited by PR number and the landed parent-lane authorities cited by real paths (compute-envelope-model.md fleet envelope; input-envelope-roadmap.md admission). No behavior change; cargo check clean. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: affected set processing * Remove stray empty file (shell-redirect artifact the auto-committer flushed) An internal-messaging command's backtick content was command-substituted by bash; a '-> fail-closed' fragment became a stdout redirect and created an empty file at the repo root, which the auto-committer then committed as 38f0a46. No tree content beyond the empty file; removing it restores the branch to e99c757's content. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: affected set processing * Scaffold-mark the cgroup peak calibration shell (cursor review catch) The three concat-built calibration runners (ci_cgroup_peak_locate_shell, ci_floor_peak_pre_script, ci_floor_peak_post_script) landed without the on-carrier scaffold markers repo convention requires for hand-shell. Each now carries a Disposition = Scaffold { dissolves_to: RealizationDispatch } row binding the decl (the ci_materialization pattern), and both scripts embed the shared dissolve-on note as a shell comment (the ci_spec pattern): dissolution = bash-emit (#5828 / gap-B emit(intent, Bash)) realizing the observation as an emitted ShellProgram intent or a typed host Observe effect. ci.yml + falsifier.yml regenerated; falsifier_workflow_witness_holds and the flip witnesses re-run PASS. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Merge origin/main into session/loyal-wren-398 (resolve #6441 step-list conflict) Conflict resolution, all consciously declared: - ci_job steps: union — the calibration peak pre/post steps wrap the floor step (this branch) and #6441's materialization receipt gate slots between the resolve-receipt gate and the merge-admission gate (main). - The incoming materialization receipt gate step landed with timeout none — the same uncapped-step starvation-kill class this branch's review fix eliminated — so it now carries the aux cap, and the ci backstop counts FIVE aux terms (peak pre, peak post, resolve-receipt gate, materialization receipt gate, merge-admission gate); the budget disposition note records the merge provenance. - ci_run_step_natures_are_claims_counted_not_silent: RunStep count pin bumped 17 -> 19, acknowledging the two peak calibration steps #6441's count predates (conscious-count discipline; proven red at 17 then green at 19 by execution). - ci.yml regenerated from the merged carriers (backstops 130 -> 135). Verified on the merged tree: release bins rebuilt on merged Rust; falsifier workflow witness, flip witnesses, floor-plan/optin/width witnesses, and all 8 ci_materialization witnesses PASS; generated-artifact regen ExitSuccess. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * ShellProgram -> DAG: transport intent collapse + live importer ratchet (phase 0 of the sidecar dissolution) (#6449) * WIP: ShellProgram -> DAG * WIP: ShellProgram -> DAG * WIP: ShellProgram -> DAG * WIP: ShellProgram -> DAG * WIP: ShellProgram -> DAG * bash fold: native Concat/CmdSubst/WithRedir coverage + measured cost wall on the whole-tree emit path Fold-family productions extended so the fold no longer refuses word Concat/CmdSubst or stmt WithRedir (all four Redir variants): new concat_parts/word-compound/with_redir production families, lex tokens, kind-tag emit transforms, and recursive bundle arms. Byte-identity vs serialize_bash proven by execution: five depth-2 oracle tests plus the depth-4 assign_root_stmt manual probe (ROOT=$('git' 'rev-parse' '--show-toplevel' 2>/dev/null || 'pwd') byte-exact). The delegated fail-closed RED control repoints from WithRedir (now native) to Heredoc (still delegated) so the boundary guard stays discriminating. Measured cost wall, declared on-carrier (bash_program_emit_cost_wall_note): whole-tree backward row-selection is ~alternatives^depth (1s flat stmt, 64s for the single depth-4 stmt, DNF >8min for the full witness_bin program) because formal_production_unique_lhs_exact_match deep-validates every candidate per level and the descent re-validates each level again. Real-program oracles therefore stay MANUAL probes, not test fns (a discovery-run test would hang the local floor); the probe note on the test carrier names the dissolution triggers. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * WIP: Wave 1A - namespace-only name resolution: make the syntactic containment * B1: NameResolutionPolicy row + position-tracked resolve (NamespaceOnlyY gated). Add v2.std.resolution_policy (ImportScoped default | NamespaceOnlyY). Thread ResolveContext { position, expected, policy } through resolve walk; namespace-only skips import module bindings and uses symbol_index at position. Policy pilot witness: green under NamespaceOnlyY at type position, RED under ImportScoped at module position. Import-scoped global default unchanged — zero corpus churn. Co-authored-by: Cursor <cursoragent@cursor.com> * Wave 1A - namespace-only name resolution: make the syntactic containment tree the single naming authority (qualified name = nesting position, reference = lexical lookup up ancestors, . = projection one level down). Path: confirm loyal-heron SymbolIndex scaling receipt FIRST, then SymbolIndex = conta (#6451) * WIP: Wave 1A - namespace-only name resolution: make the syntactic containment * v2.std.symbol_index: materialize containment tree as single naming authority Add SymbolIndex fill from nesting (qualified path → Node), qualified-name path algebra bridges, and discriminating witnesses. Retarget #6436 variant- visibility scaffold to dissolve into symbol_index_lexical_lookup; harvest_unique stays interim until module-scoped index scan lands. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Wave 1A - namespace-only name resolution: make the syntactic containment * Fix rust fmt on qualified-name bridge host functions (CI rust_tests gate). Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Wave 1A - namespace-only name resolution: make the syntactic containment * Remove symbol_index_has_path; tests match symbol_index_lookup directly Dissolve Optional→Bool predicate in new std/ surface per review. Lexical lookup root termination already uses qualified_name_is_empty (not dotted string projection). Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Wave 1A - namespace-only name resolution: make the syntactic containment * Address review: is_empty authority, host scaffold binds, layer split - Remove qualified_name_is_empty; lexical lookup uses is_empty(xs: position) - Host dispositions bind to from/to_dotted_string bridges; add P5 receipt tests - Move extdeps-coupled fill to v2.compiler.symbol_index_fill (layer DAG fix) Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Wave 1A - namespace-only name resolution: make the syntactic containment * WIP: Wave 1A - namespace-only name resolution: make the syntactic containment * Wire resolver through SymbolIndex; dissolve harvest_unique_disj interim. Build SymbolIndex at admission and thread it through Namespace. resolve_atom falls back to symbol_index_lexical_lookup for unbound atoms after import-scoped lookup_chain. Fill-time unique-variant aliases (suffix-scan equivalent) replace #6436 harvest_unique_disj. Equivalence witnesses prove SymbolIndex-alone covers variant visibility (green + without-alias RED control); end-to-end wire green. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Wave 1A - namespace-only name resolution: make the syntactic containment * Drop unused ResolveContext.expected until expected-type lane lands. Removes the dead field and uncalled resolve_ctx_with_expected helper flagged in #6454 review 36717 — B1 uses position-only disambiguation; expected-type filtering returns when that slice is scoped. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com> Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
…eipt-write refusal + counter invariant (#6456) * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * Analysis spine: spine_receipt composes dependency_view + materialize (increment 1) The Rc-safe half of run ≜ realize ∘ materialize ∘ dependency_view: compose the two catamorphisms that need no interpreter thread-safety. - src/v2/std/spine.dag: level-profile fold over the DependencyView DAG → critical_path_depth (longest dependency chain / the reduce spine) + independence_width (max nodes at one level / what parallelizes to hw width). spine_receipt emits the §9 numbers by COMPUTATION, not assertion, joining materialize's content-hash Share/dedup counts. - Discriminating RED (§9): single chain A→B→C → depth 3 / width 1 (serial); root over N independent leaves → depth 2 / width N. - Witnesses 9/9 (spine) green by execution; materialize 6/6 unchanged. The RUNNER (wall-clock parallel execution, §8 steps 3-4) stays increment 2+, gated on interpreter Rc→Arc (v1 interp is !Send). This increment measures the achievable width/critical-path floor the runner targets; it does not fabricate wall-clock N×. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Unbundle recompute-trace interpreter extension from the analysis-spine PR CI root cause: the recompute-trace extension edited v1_interpreter.rs, which hosts the atom_identity_hash/hash_combine fnv1a64 intrinsics that dag_collect_fingerprint_witness executes. That correctly invalidated the re-verify 'assumed-green node-frontier' SKIP of that witness (cone-touch, fail-closed) — but the witness is a pre-existing 806s (13min) fnv1a64 whole-corpus walk, so un-skipping it blew the 30-min floor budget. Main stays green only because its interpreter cone is untouched (witness stays skipped). The interpreter extension is a separable, env-gated (GUNBC_RECOMPUTE_TRACE=1), READ-mode diagnostic — not a dependency of the spine/materialize analysis substrate (pure .dag, content_hash-based). Reverting v1_interpreter.rs to main restores byte-identical interpreter content → the fingerprint witness returns to assumed-green SKIP → floor budget restored. The recompute-trace extension lands as its own follow-up PR where the fingerprint-witness re-run is expected. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Materialization ladder: the state x decision law, as executable witnesses The operator's 4-rule business logic generalized on one axis: the decision is a function of WHEN the redundancy is knowable and WHETHER what was knowable was prepared for. Errors fire only on knowable-but-unprepared; genuine emergence and declared triviality are typed acceptances, never silence. std.materialization_ladder (dag/std): - Frame/FrameKind: SharedStateFrame | IsolatedChildrenFrame | ReplayedFrame{attempts} | UnboundedSiblingsFrame — the nested-scope axis; a 'run' at any layer is a frame, never a different kind of thing. - DemandNature: Pure | IdempotentEffect | WorldRead{envelope_declared} | FreshEffect — the D3 effect gate; TTL = unmodeled dependency XOR declared staleness, never an eviction knob. - CacheProvider: keying (ContentKeyed|ExistenceKeyed) + EvictionPolicy (ScopeExit|SpacePacked) REQUIRED by construction — rule 3 unwritable-bad. - LadderVerdict (total): AuthoredDuplication | Discharged | RefusedNoProvider | RefusedScopeTooNarrow | RefusedExistenceKeyed (the build-if-absent #6352 wall) | RefusedUnmodeledWorldRead | ExemptFreshEffect | AcceptedBelowCostFloor | AcceptedSingleRecompute. - Declared-emergent frames obligate UP FRONT: retry frames derive checkpointing, unbounded-sibling frames (server loops, CI-runs-over-time) derive persistent caches — prepare-before-demand. 12/12 witnesses green by execution; each test is one cell of the table, fixtures mirror the live worked example (workflow/jobs/steps, retry, fleet). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Docs crystallization: derived materialization placement into roadmap ④ + the state x decision table - roadmap_authority ④ (ROADMAP.md regenerated via main_wet, drift-consistent): the nested-frame law, plurality cells, declared-emergent prepare-up-front, keying/staleness walls, the caching-completion un-shelve, the ①-vs-§2 cross-run-caching contradiction subsumed into per-node derived verdicts, and the v1.compiler.ownership §3-convergence row. - duplicate-work design doc: the state x decision table as the qualifier's final verdict logic + the ownership consolidation subsection. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Consolidation plan: realization + materialization + ownership are one law Operator synthesis (2026-07-09): Materialization = the verdict vocabulary; ownership = the verdict computation at the eval frame; realization = provider selection discharging the verdict at each frame's carrier. Share's handler is layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable carrier + readonly => point-at-it, no copy, no destroyed memory), demoting through HAMT structural share / process memo / artifact / CAS, and demotion must be priced, never silent (#6249 clone-fallback is the receipt). Census of every hand-rolled instance found in-tree (16 rows): each named with its frame, ladder cell, action, and dissolution trigger — ownership (consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall), ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green / sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789 (rule-4 requirements), recompute-trace (state-4 finding source). Peers kept distinct: affected-set, Independence/Placement, mutable state. Sequence C1-C5 with C1 = this PR (ladder + live CI gate). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Ownership refactored onto materialization: the value tier, tested as providers First consolidation increment (operator-directed): v1.compiler.ownership's decision IS provider selection at the value grain, now expressed in the ladder and proven by mirror witnesses. - ProviderTier: Reference | Copy | Memo{keying} | Artifact{keying} | Cas{keying} — keying folded INTO store tiers, so an existence-keyed reference is unwritable BY SHAPE (§5 construction); frame obligations at isolation LCAs are dischargeable only by store tiers (a reference cannot cross an isolation boundary — witnessed). - Value tier: AccessMode (Read|Consume|Carry|Project), ValueUsage, value_materialization -> ValueDead | ValueMoved | ValueSharedByReference | ValueDemotedToCopy (PRICED, requires a declared CopyTier provider — the #6249 silent clone-fallback made refusable) | ValueRefusedAffine | ValueRefusedNoCarrierProvider. - Faithful to v1's THREE distinct plurality readings, kept separate: take_count = semantic_consumer_count (Consumed only, affine axis); value_access_plurality = binding_fan_out (Carry excluded, reference axis); borrow_count = whole_value_borrow_count (Read+Carry not Project, movability). - Fold-accumulator case mirrored at conservative pre-FoldAccUnwrap semantics: carries excluded from plurality but blocking the move -> demoted-to-copy. 23/23 witnesses green (14 frame cells + 9 value cells). Corpus-level equivalence against live v1 ownership folds = the C4 receipt. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * WIP: Duplicate Computation/Materialization * G: exhaustive cache/share census (52 mechanisms, 6 groups) + C0 catalog-grounding of provider rows + forward-wiring walls The sweep found the tree already models caches: extdeps/cache cache_catalog (CacheInterfaceCatalogFacts, 9 rows) + extdeps/realization carrier facts + the warm==cold purity oracle. C0 grounds CacheProvider on that catalog (provider_from_catalog projection; CacheProvider.id -> CacheInterfaceId) so the ladder and the catalog never restate each other's half. Three forward walls (demands-from-DependencyView, hand-cache shape lens, live-provider-or-red) make new caches born as provider rows only. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * C0: provider rows derive from the cited cache catalog (extdeps/cache/materialization.dag projection) Operator ruling 2026-07-09: extdeps stays the ground-truth/interface layer; every USE of a cache goes through materialization so memo never gets re-invented. provider_from_catalog is the only door from a catalog row into the ladder: keying/tier/eviction derived from cited facts (mechanism->class: InProcess=>ScopeExit; Ttl/Lru/SizeBounded=>SpacePacked; Never/Manual outside a process => typed ProjectionRefused, counted by the new enrolled witness; HandAuthored/prefix-fallback keys => ExistenceKeyed until key-completeness upgrades them). CI sccache row now derived, hand-typed tier facts deleted, 6/6 + 23/23 witnesses green. 10b re-scoped: v1-internal caches = inventory only (retire with seed); ParseTable/cached_stage promoted to next. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * Fail-closed hardening: RefusedNatureConflict arm, weakest-claim nature default, UsesStep silence counted, ladder cells enrolled in CI The complexity-lens false-clean lesson applied to this gate before anyone relies on it: (1) heterogeneous natures on one identity were first-wins — now a typed RefusedNatureConflict (24th ladder cell, RED witness); (2) an unrostered run-step claimed PureComputation — now IdempotentEffect, the weakest claim (verdict-identical, no purity overclaim; a misdeclared WorldRead can no longer be legally memoized by default); (3) UsesStep foreign actions produced silence — now a pinned denominator (==9; a new foreign action must consciously bump it); (4) the ladder's 24 cells enroll on the CI surface so the law's own witnesses gate every run. 24/24 + 7/7. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * M1 ratchet bump: declared resolve count 1 -> 3 (gate's first live catch — enrollment pays counted resolves) Run 29058798771: enrolling the ladder witness file moved resolves_total 1 -> 3 (each enrolled entry file pays one closure resolve against the shared index) and the receipt gate redded that exact run — the designed semantics, receipted in the note. Bump acknowledges the two witness-entry resolves as declared debt; M2 (one closure resolve per roots set) ratchets back toward 1. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Retire the M1/M2 labels from carriers (no-codename rule; collided with DESIGN's floor-memoization M1/M2) Step renamed to 'Floor resolve receipt gate (declared cold-resolve count)'; notes and the gate echo now say what the things are: the counted cold-resolve receipt, and the shared-resolve rewire (one closure resolve per source-roots set). Naming-retirement note left on the carrier. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * Run-step natures pinned as counted claims, not affordances Operator ruling 2026-07-10: hardcoded shell scripts get no affordances — run-steps are supposed to be modeled as typed intents and emitted (shell-emission-model slice 4 covers ci_workflow RunSteps). Until that slice lands, every nature in job_run_demands is a claim (rostered FreshEffect / weakest-default IdempotentEffect), never derived from a modeled effect row. Count the whole claimed-nature surface (16 by execution) and pin it in the enrolled witness: a new raw-script step must consciously bump the pin, and slice-4 migration becomes a countable ratchet ending at zero, where the pin becomes a wall. Rejected alternative recorded in the carrier note: a per-step declared-natures roster (a second parallel ledger over scripts the shell-emission plan already governs). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Regen DESIGN.md after main merge (duplicate-work row + #6373 body-lowering row coexist) Conflict was both sides editing the open-threads list in design_document.dag: ours added the duplicate-work thread, main's #6373 rewrote body-lowering to Stages 1-3 LANDED. Resolution keeps both rows in the .dag authority; DESIGN.md regenerated from it, never hand-edited. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * Inferred materialization increment 1: floor demand ledger + receipt-or-red gate Running IS enrolling: the interpreter ledgers every keyed pure call and every InterpContext absorbs its totals into a process accumulator on Drop — by construction, no eval path escapes the receipt. claim_executor writes target/floor-materialization-receipt.txt at walk end; trace defaults ON in the executor, and an explicit =0 zeroes keyed_calls which the gate refuses. Gate arms this push (all verified under dash from the emitted ci.yml): receipt missing/malformed/keyed_calls=0 fail closed. Exact pins for unkeyed_calls and duplicated_keys land from the FIRST CI receipt (the resolve gate's measure-then-pin path) — unkeyed is known nonzero on the floor (count_matching takes a predicate closure; closures are the one disclosed identity-less class, dissolve-on captured-env content identity). Unit witness green: resolve -> eval -> ctx Drop -> absorb -> drain-once. Step addition bumped the claimed-natures pin 16 -> 17 consciously. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Review fix: drop the racy drain-once assertion from the receipt unit test opus-4-7 finding on #6441: under plain cargo test (still the documented runner) tests share a process, the env latch is OnceLock-sticky, and sibling ctx drops could absorb between the two takes — making the drain-empty assertion racy. Absorb-on-Drop stays asserted (monotone under concurrent absorbs: siblings only ADD); drain-once is Option::take by construction, not asserted through the shared global. Comment states the sharing semantics explicitly. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ncident, argued serially with receipts) (#6469) * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * WIP: Duplicate Computation * Analysis spine: spine_receipt composes dependency_view + materialize (increment 1) The Rc-safe half of run ≜ realize ∘ materialize ∘ dependency_view: compose the two catamorphisms that need no interpreter thread-safety. - src/v2/std/spine.dag: level-profile fold over the DependencyView DAG → critical_path_depth (longest dependency chain / the reduce spine) + independence_width (max nodes at one level / what parallelizes to hw width). spine_receipt emits the §9 numbers by COMPUTATION, not assertion, joining materialize's content-hash Share/dedup counts. - Discriminating RED (§9): single chain A→B→C → depth 3 / width 1 (serial); root over N independent leaves → depth 2 / width N. - Witnesses 9/9 (spine) green by execution; materialize 6/6 unchanged. The RUNNER (wall-clock parallel execution, §8 steps 3-4) stays increment 2+, gated on interpreter Rc→Arc (v1 interp is !Send). This increment measures the achievable width/critical-path floor the runner targets; it does not fabricate wall-clock N×. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Unbundle recompute-trace interpreter extension from the analysis-spine PR CI root cause: the recompute-trace extension edited v1_interpreter.rs, which hosts the atom_identity_hash/hash_combine fnv1a64 intrinsics that dag_collect_fingerprint_witness executes. That correctly invalidated the re-verify 'assumed-green node-frontier' SKIP of that witness (cone-touch, fail-closed) — but the witness is a pre-existing 806s (13min) fnv1a64 whole-corpus walk, so un-skipping it blew the 30-min floor budget. Main stays green only because its interpreter cone is untouched (witness stays skipped). The interpreter extension is a separable, env-gated (GUNBC_RECOMPUTE_TRACE=1), READ-mode diagnostic — not a dependency of the spine/materialize analysis substrate (pure .dag, content_hash-based). Reverting v1_interpreter.rs to main restores byte-identical interpreter content → the fingerprint witness returns to assumed-green SKIP → floor budget restored. The recompute-trace extension lands as its own follow-up PR where the fingerprint-witness re-run is expected. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Materialization ladder: the state x decision law, as executable witnesses The operator's 4-rule business logic generalized on one axis: the decision is a function of WHEN the redundancy is knowable and WHETHER what was knowable was prepared for. Errors fire only on knowable-but-unprepared; genuine emergence and declared triviality are typed acceptances, never silence. std.materialization_ladder (dag/std): - Frame/FrameKind: SharedStateFrame | IsolatedChildrenFrame | ReplayedFrame{attempts} | UnboundedSiblingsFrame — the nested-scope axis; a 'run' at any layer is a frame, never a different kind of thing. - DemandNature: Pure | IdempotentEffect | WorldRead{envelope_declared} | FreshEffect — the D3 effect gate; TTL = unmodeled dependency XOR declared staleness, never an eviction knob. - CacheProvider: keying (ContentKeyed|ExistenceKeyed) + EvictionPolicy (ScopeExit|SpacePacked) REQUIRED by construction — rule 3 unwritable-bad. - LadderVerdict (total): AuthoredDuplication | Discharged | RefusedNoProvider | RefusedScopeTooNarrow | RefusedExistenceKeyed (the build-if-absent #6352 wall) | RefusedUnmodeledWorldRead | ExemptFreshEffect | AcceptedBelowCostFloor | AcceptedSingleRecompute. - Declared-emergent frames obligate UP FRONT: retry frames derive checkpointing, unbounded-sibling frames (server loops, CI-runs-over-time) derive persistent caches — prepare-before-demand. 12/12 witnesses green by execution; each test is one cell of the table, fixtures mirror the live worked example (workflow/jobs/steps, retry, fleet). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Docs crystallization: derived materialization placement into roadmap ④ + the state x decision table - roadmap_authority ④ (ROADMAP.md regenerated via main_wet, drift-consistent): the nested-frame law, plurality cells, declared-emergent prepare-up-front, keying/staleness walls, the caching-completion un-shelve, the ①-vs-§2 cross-run-caching contradiction subsumed into per-node derived verdicts, and the v1.compiler.ownership §3-convergence row. - duplicate-work design doc: the state x decision table as the qualifier's final verdict logic + the ownership consolidation subsection. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Consolidation plan: realization + materialization + ownership are one law Operator synthesis (2026-07-09): Materialization = the verdict vocabulary; ownership = the verdict computation at the eval frame; realization = provider selection discharging the verdict at each frame's carrier. Share's handler is layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable carrier + readonly => point-at-it, no copy, no destroyed memory), demoting through HAMT structural share / process memo / artifact / CAS, and demotion must be priced, never silent (#6249 clone-fallback is the receipt). Census of every hand-rolled instance found in-tree (16 rows): each named with its frame, ladder cell, action, and dissolution trigger — ownership (consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall), ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green / sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789 (rule-4 requirements), recompute-trace (state-4 finding source). Peers kept distinct: affected-set, Independence/Placement, mutable state. Sequence C1-C5 with C1 = this PR (ladder + live CI gate). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * Ownership refactored onto materialization: the value tier, tested as providers First consolidation increment (operator-directed): v1.compiler.ownership's decision IS provider selection at the value grain, now expressed in the ladder and proven by mirror witnesses. - ProviderTier: Reference | Copy | Memo{keying} | Artifact{keying} | Cas{keying} — keying folded INTO store tiers, so an existence-keyed reference is unwritable BY SHAPE (§5 construction); frame obligations at isolation LCAs are dischargeable only by store tiers (a reference cannot cross an isolation boundary — witnessed). - Value tier: AccessMode (Read|Consume|Carry|Project), ValueUsage, value_materialization -> ValueDead | ValueMoved | ValueSharedByReference | ValueDemotedToCopy (PRICED, requires a declared CopyTier provider — the #6249 silent clone-fallback made refusable) | ValueRefusedAffine | ValueRefusedNoCarrierProvider. - Faithful to v1's THREE distinct plurality readings, kept separate: take_count = semantic_consumer_count (Consumed only, affine axis); value_access_plurality = binding_fan_out (Carry excluded, reference axis); borrow_count = whole_value_borrow_count (Read+Carry not Project, movability). - Fold-accumulator case mirrored at conservative pre-FoldAccUnwrap semantics: carries excluded from plurality but blocking the move -> demoted-to-copy. 23/23 witnesses green (14 frame cells + 9 value cells). Corpus-level equivalence against live v1 ownership folds = the C4 receipt. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Duplicate Computation * WIP: Duplicate Computation/Materialization * G: exhaustive cache/share census (52 mechanisms, 6 groups) + C0 catalog-grounding of provider rows + forward-wiring walls The sweep found the tree already models caches: extdeps/cache cache_catalog (CacheInterfaceCatalogFacts, 9 rows) + extdeps/realization carrier facts + the warm==cold purity oracle. C0 grounds CacheProvider on that catalog (provider_from_catalog projection; CacheProvider.id -> CacheInterfaceId) so the ladder and the catalog never restate each other's half. Three forward walls (demands-from-DependencyView, hand-cache shape lens, live-provider-or-red) make new caches born as provider rows only. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * C0: provider rows derive from the cited cache catalog (extdeps/cache/materialization.dag projection) Operator ruling 2026-07-09: extdeps stays the ground-truth/interface layer; every USE of a cache goes through materialization so memo never gets re-invented. provider_from_catalog is the only door from a catalog row into the ladder: keying/tier/eviction derived from cited facts (mechanism->class: InProcess=>ScopeExit; Ttl/Lru/SizeBounded=>SpacePacked; Never/Manual outside a process => typed ProjectionRefused, counted by the new enrolled witness; HandAuthored/prefix-fallback keys => ExistenceKeyed until key-completeness upgrades them). CI sccache row now derived, hand-typed tier facts deleted, 6/6 + 23/23 witnesses green. 10b re-scoped: v1-internal caches = inventory only (retire with seed); ParseTable/cached_stage promoted to next. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * Fail-closed hardening: RefusedNatureConflict arm, weakest-claim nature default, UsesStep silence counted, ladder cells enrolled in CI The complexity-lens false-clean lesson applied to this gate before anyone relies on it: (1) heterogeneous natures on one identity were first-wins — now a typed RefusedNatureConflict (24th ladder cell, RED witness); (2) an unrostered run-step claimed PureComputation — now IdempotentEffect, the weakest claim (verdict-identical, no purity overclaim; a misdeclared WorldRead can no longer be legally memoized by default); (3) UsesStep foreign actions produced silence — now a pinned denominator (==9; a new foreign action must consciously bump it); (4) the ladder's 24 cells enroll on the CI surface so the law's own witnesses gate every run. 24/24 + 7/7. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * M1 ratchet bump: declared resolve count 1 -> 3 (gate's first live catch — enrollment pays counted resolves) Run 29058798771: enrolling the ladder witness file moved resolves_total 1 -> 3 (each enrolled entry file pays one closure resolve against the shared index) and the receipt gate redded that exact run — the designed semantics, receipted in the note. Bump acknowledges the two witness-entry resolves as declared debt; M2 (one closure resolve per roots set) ratchets back toward 1. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Retire the M1/M2 labels from carriers (no-codename rule; collided with DESIGN's floor-memoization M1/M2) Step renamed to 'Floor resolve receipt gate (declared cold-resolve count)'; notes and the gate echo now say what the things are: the counted cold-resolve receipt, and the shared-resolve rewire (one closure resolve per source-roots set). Naming-retirement note left on the carrier. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * Run-step natures pinned as counted claims, not affordances Operator ruling 2026-07-10: hardcoded shell scripts get no affordances — run-steps are supposed to be modeled as typed intents and emitted (shell-emission-model slice 4 covers ci_workflow RunSteps). Until that slice lands, every nature in job_run_demands is a claim (rostered FreshEffect / weakest-default IdempotentEffect), never derived from a modeled effect row. Count the whole claimed-nature surface (16 by execution) and pin it in the enrolled witness: a new raw-script step must consciously bump the pin, and slice-4 migration becomes a countable ratchet ending at zero, where the pin becomes a wall. Rejected alternative recorded in the carrier note: a per-step declared-natures roster (a second parallel ledger over scripts the shell-emission plan already governs). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Regen DESIGN.md after main merge (duplicate-work row + #6373 body-lowering row coexist) Conflict was both sides editing the open-threads list in design_document.dag: ours added the duplicate-work thread, main's #6373 rewrote body-lowering to Stages 1-3 LANDED. Resolution keeps both rows in the .dag authority; DESIGN.md regenerated from it, never hand-edited. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * Inferred materialization increment 1: floor demand ledger + receipt-or-red gate Running IS enrolling: the interpreter ledgers every keyed pure call and every InterpContext absorbs its totals into a process accumulator on Drop — by construction, no eval path escapes the receipt. claim_executor writes target/floor-materialization-receipt.txt at walk end; trace defaults ON in the executor, and an explicit =0 zeroes keyed_calls which the gate refuses. Gate arms this push (all verified under dash from the emitted ci.yml): receipt missing/malformed/keyed_calls=0 fail closed. Exact pins for unkeyed_calls and duplicated_keys land from the FIRST CI receipt (the resolve gate's measure-then-pin path) — unkeyed is known nonzero on the floor (count_matching takes a predicate closure; closures are the one disclosed identity-less class, dissolve-on captured-env content identity). Unit witness green: resolve -> eval -> ctx Drop -> absorb -> drain-once. Step addition bumped the claimed-natures pin 16 -> 17 consciously. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Review fix: drop the racy drain-once assertion from the receipt unit test opus-4-7 finding on #6441: under plain cargo test (still the documented runner) tests share a process, the env latch is OnceLock-sticky, and sibling ctx drops could absorb between the two takes — making the drain-empty assertion racy. Absorb-on-Drop stays asserted (monotone under concurrent absorbs: siblings only ADD); drain-once is Option::take by construction, not asserted through the shared global. Comment states the sharing semantics explicitly. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization * WIP: Duplicate Computation/Materialization --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
What
GUNBC_RESOLVED_GRAPH_CACHE_DIRwas introduced in #4878 but never wired into CI, so the resolved-graph cache was silently off everywhere. This drops the env-var gate: the cache now defaults to$TMPDIR/gunbc-rg-cache, withGUNBC_RESOLVED_GRAPH_CACHE_DIRstill accepted as an override for explicit placement.Why
Without the cache,
resolve_entry_with_parse_cachere-runs the full v1 type inference pipeline for every unique*_test.dagentry in the discovery corpus — even though 95%+ of each closure (std/, extdeps/) is shared across entries. Profiling on the post-#5757 baseline showed 447,734ms serial resolve total across 1011 witnesses (~443ms/entry). With the cache on, each unique closure resolves once and is reused.Correctness
Cache key = content-hash(closure sources) + content-hash(compiler binary). Invalidates correctly on any source or compiler change. Existing falsifiers from #4878 cover cold-oracle equivalence, poisoned-hit rejection, WriteOnce concurrency, and key-mismatch miss.
Impact
Eliminates most of the 447s resolve serial sum in the CI floor corpus run. Secondary effect: per-shard peak RSS drops (no large type-checked AST graphs held per shard), which will unlock a higher corpus evaluation width via the memory-aware spawn-width formula on next re-measurement.