Skip to content

Two-generation regen cutover + dissolve parked regen_verify_gate plan into executable RegenVerifyGate (cargo-green self-host fixed point, ONE PR) - #5873

Merged
briansrls merged 35 commits into
mainfrom
session/eager-heron-723
Jun 28, 2026
Merged

briansrls merged 35 commits into
mainfrom
session/eager-heron-723

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session eager-heron-723.
Pushing to session/eager-heron-723 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

Brian Searls and others added 5 commits June 27, 2026 17:22
…erifyGate

Adds RegenVerifyGate to the CI floor (ci_spec type Gate + gunbc_ci_floor_gates),
wires all exhaustive Gate matches (ci_floor_plan gate_node/gate_runnable/
gate_is_heavy_resolve/gate_spawns_host_compiler, ci_gates.run_spec_gate,
floor_effect_gate_witness). New dsl/tools/regen_verify_{gate,transport}.dag run
regen_stage0 --verify (the §7 self-host fixed-point wall) via a new
ensure_regen_stage0_built host-prelude helper. Deletes the parked plan, its
empty plan_registry_batch_a, the generated required-facts md, and repoints the
roadmap carrier.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…ed point

Applies #5865's casing fix (05_emit_rust.dag) and runs the 2-pass cutover regen:
pass-1 advances the self-host blob + emitter (gen-1 drops v1_rt starts_with/
ends_with/trim, the one-generation-ahead seed-cement), rebuild, pass-2 re-emits
them fresh (PascalCase). regen_stage0 --verify now exits 0 (a 3rd pass is
byte-identical = THE fixed point). Registers extdeps_uri_path.rs in
GENERATED_STAGE0_FILES (the legit unregistered-emit gap). Regenerates ROADMAP.md.
Drift checks: cargo-header reproduced via emit_cargo_toml, wire_value_serialize.rs
unchanged (hand-maintained, copy-preserved), v1_rt.rs emitted-fresh.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review June 27, 2026 17:52
briansrls and others added 7 commits June 27, 2026 15:15
…5819)

Operator ruled Path B for the #5864 parser seed-cement: v1_compiler_parse.rs
moves to HAND_MAINTAINED_STAGE0_FILES (copy-preserved, so #5864's O(N) cursor
optimization survives the regen instead of being reverted to the O(N^2) baseline
that 02_parse.dag still models). Named dissolution trigger marked on the carrier.
Re-regenerated the two-generation cutover against fresh main (incl #5865 casing,
#5818 Uri grounding, #5819 ci.yml thin-shim). regen_stage0 --verify exit 0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 27, 2026

Copy link
Copy Markdown
Contributor

Re: gate_spawns_host_compiler(RegenVerifyGate) => false — confirmed correct, the second interpretation in your note is the right one.

The predicate means "the gate body directly invokes the host language compiler on emitted DSL output," not "triggers a host cargo build during scheduling." Precedent: DslCompileCleanGate is also false (ci_floor_plan.dag:143) even though its transport calls ensure_gunbc_built() — same build-the-tool-if-absent prereq pattern as ensure_regen_stage0_built(). EmitHostGate is the lone true because its body runs host rustc/cargo on emitted code (the emit-host smoke). RegenVerifyGate runs regen_stage0 --verify, which does an in-process .dag self-compile + byte-compare of the committed seed; the regen_stage0 binary is already built by the floor's release step (cargo build -p v1-compiler --release --bins), so ensure_regen_stage0_built() is a no-op at gate time, not a host-compile of DSL output.

Also note the value is scheduling-inert here regardless: it's consumed only in gate_serializes_against_corpus = heavy_resolve || spawns_host_compiler (ci_floor_plan.dag:151), and RegenVerifyGate is heavy_resolve=true, so it already serializes against the corpus in batch-2. — sent from eager-heron-723

…oint

The full-workspace build (the broadened oracle CI rust_tests uses) exposed two
more pre-existing main non-fixed-points that the cutover surfaces:

1. stage0_core E0432/E0433: the faithful regen emits use crate::extdeps_uri /
   extdeps_external_authority in the extdeps_languages_* modules and
   use crate::std_realization_schedule/std_decl_ref in std_effects/std_emit_model,
   but stage0_crates.dag's CoreCrate modules list omitted them. Added the full
   transitive closure (9 modules: extdeps_external_authority, extdeps_uri,
   std_decl_ref, std_lens_verdict, std_magnitude, std_measure, std_nat,
   std_pareto, std_realization_schedule) so stage0_core is closed under crate:: deps.

2. effects.rs (hand-test) imported parse_path_template/PathTemplateParseResult from
   std_http_path, but #5818 moved them to extdeps_uri_path in the authority (main
   never regenerated, so its stale seed + test still pointed at std_http_path).
   Repointed the imports to the fixed-point location.

regen_stage0 --verify exit 0; cargo build --workspace --all-targets -D warnings 0/0;
parse.rs still byte-identical to origin/main (#5864 preserved).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 27, 2026

Copy link
Copy Markdown
Contributor

Thanks — same note as the earlier thread (issuecomment-4821358842). Keeping it false, deliberately, for consistency rather than dismissal:

The decisive precedent is DslCompileCleanGate — it's false (ci_floor_plan.dag:143) and its transport calls ensure_gunbc_built(), the byte-for-byte same build-the-tool-if-absent pattern as ensure_regen_stage0_built(). So the project's established reading of gate_spawns_host_compiler is "the gate body invokes the host language compiler on emitted DSL output" (true only for EmitHostGate, the emit-host smoke), not "the transport may cargo-build its own tool as a prereq." regen_stage0 --verify does an in-process .dag self-compile + byte-compare; the regen_stage0 binary is already built by the floor's release step, so ensure_regen_stage0_built() is a no-op at gate time.

Under that semantics false is correct and consistent. Under the literal "transport can ever shell cargo" reading, DslCompileCleanGate would be mis-set too — i.e. it's a predicate-rename/reclassification spanning multiple gates, not an asymmetric one-gate flip. That's a fine separate cleanup, but flipping only this gate would introduce the inconsistency, and it's scheduling-inert here (sole consumer ORs with heavy_resolve=true). Leaving it false to match precedent; happy to see a follow-up that reclassifies the predicate across all gates if reading-B is preferred. — sent from eager-heron-723

@gunbai-bot

gunbai-bot Bot commented Jun 28, 2026

Copy link
Copy Markdown
Contributor

Thanks — this is a valid §5 catch, and you've identified a real seed-cement (the same class as the hand-maintained main.rs/v1_compiler_parse.rs carve-outs), not a deliberate scope change.

Root cause: compiler_tests.rs is a GENERATED stage0 file emitted from the .dag authority src/v1/compiler_tests_rust.dag. Both witnesses are present in main's committed compiler_tests.rs seed but absent from that .dag authority (confirmed by git: compiler_tests_rust.dag count = 0 for both on origin/main). They were never grounded in the authority, so main's stale seed was masking them; this PR is the first faithful self-compile, which correctly drops anything the authority doesn't emit. That is exactly what RegenVerifyGate exists to surface.

Resolution (in progress, not a silent drop): both witnesses will be restored by grounding them into compiler_tests_rust.dag so the regen emits them — the §5 'make the regen produce it' fix, not a hand-maintain cement. Notably contracts_sidecar_wired_into_emit_scope is the discriminating witness for the contracts-sidecar emit-scope wiring, which is precisely a separately-identified emitter alias-resolution-scope defect currently under operator review; once grounded it will go red on that defect until its fix lands, so it is being bundled with that fix. The grounding lands before this PR's final single re-regen (the behavioral bar is by-execution at that regen, since a .dag test-emission change can't take effect in the seed-built suite without it). I'll update the PR carrier with the dissolution note when grounded.

— sent from eager-heron-723

@gunbai-bot

gunbai-bot Bot commented Jun 28, 2026

Copy link
Copy Markdown
Contributor

Update: sole_constructor_fieldless_newtype_witness is now grounded in the .dag authority (src/v1/compiler_tests_rust.dag, new ct_sole_constructor_fieldless_witness_test wired into compiler_tests_source), so the regen emits it rather than dropping it — the §5-correct restore, not a hand-maintain. Verified by execution: interpreting the authority fn directly (reads the edited source, no regen needed) emits the witness as valid Rust byte-for-byte; its behavioral pass rides this PR's single re-regen. contracts_sidecar_wired_into_emit_scope is being grounded in the same way, bundled with the operator-gated emitter alias-resolution-scope fix it discriminates (it lands red-until-that-fix-green; nothing red ships since the cutover doesn't merge until then).

Meta-point worth surfacing: this is precisely the class that RegenVerifyGate — the gate this PR adds — exists to catch. An ungrounded hand-edit to a GENERATED file makes committed-seed ≠ regen-fixed-point, which the gate flags RED at the introducing PR. So your catch here is exactly the gate doing its job one PR early; once both witnesses are grounded and the re-regen is green I'll re-request review to clear this.

— sent from eager-heron-723

@gunbai-bot

gunbai-bot Bot commented Jun 28, 2026

Copy link
Copy Markdown
Contributor

Good question, and your hypothesis is exactly right — false is correct, and the resource-scheduling concern is already covered by a different flag.

In ci_floor_plan.dag, scheduling serialization is: gate_serializes_against_corpus(g) = gate_is_heavy_resolve(g) || gate_spawns_host_compiler(g) (line 152). RegenVerifyGate sets gate_is_heavy_resolve => true (line 129), so it already serializes against the corpus as emit-heavy work — the --verify self-compile is resource-scheduled regardless of the host-compiler flag.

gate_spawns_host_compiler is the narrower 'brings up the in-process host compiler' axis — only EmitHostGate is true. RegenVerifyGate shells out to the regen_stage0 child process through its ShellProgram/serialize_bash transport (it does not bring up the in-process host), so false is the semantically correct value — exactly the 'in-process host bring-up vs. child process' distinction you flagged. So no change needed; the emit-heavy weight is carried by gate_is_heavy_resolve => true.

— sent from eager-heron-723

Brian Searls and others added 7 commits June 28, 2026 01:51
… to main (re-regen reconciles), Path-B HAND_MAINTAINED re-applied for main.rs/parse.rs

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…S5, reg-3, both grounded witnesses, extdeps_uri_path reg) on main seed; regen HELD pending #5878 empty_node_list ruling

The faithful regen is blocked: #5878's empty_node_list thread_local singleton is an
ungrounded seed-cement (hand-edited into v1_std_core.rs seed, not in any .dag); a regen
drops the definition while 2 HAND_MAINTAINED files (parse.rs/dag_collect_support.rs)
still call it. Escalated to manager (empty_node_list grounding option + #5878-documented
emitter non-determinism vs RegenVerifyGate bit-identity premise). Seed kept = origin/main
(compilable) until the ruling.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jun 28, 2026

Copy link
Copy Markdown
Contributor

Both findings fixed on head b39cc7db23 (commit regenerates ROADMAP.md from its authority).

F1 (roadmap done-state out of sync) — FIXED. dsl/gunbc/roadmap_authority.dag 5-regen-verify set done: true (the gate is wired into the executable CI floor and green on the merged tree), and ROADMAP.md regenerated from the authority via main_wet — line 223 now [x]. No hand-edit to the generated file; generated_artifact_drift_gate is clean (verified by execution, RC=0).

F2 (scope overstatement) — FIXED. Tightened the wording to match --verify's actual scope: "enforces no hand-edits to generated stage0 files (GENERATED_STAGE0_FILES); HAND_MAINTAINED_STAGE0_FILES are copied through, excluded by design." This matches regen_stage0.rs (only GENERATED files are byte-compared) and the gate's accurate failure text.

Note: this head also folds in origin/main (#5891 variant-owner grounding touched the same 04_infer.dag/v1_compiler_infer.rs region) + a 2-generation re-regen so the committed seed matches a fresh emit from the merged authority — the prior CI red was benign merge-drift (the gate correctly caught a stale seed vs main), now resolved (merged-tree CI run 28328259121 was fully green; full test suite incl. both #5891's variant_owner tests and the wire/variant tests passed, confirming the merged inference is coherent).

— sent from eager-heron-723

@briansrls
briansrls merged commit 09014de into main Jun 28, 2026
2 checks passed
@briansrls
briansrls deleted the session/eager-heron-723 branch June 28, 2026 17:23
gunbai-bot Bot pushed a commit that referenced this pull request Jun 28, 2026
Drop dissolved regen_verify_gate plan/registry (executable gate landed
#5873); move seed_debt_bundle_item_2 into batch_b; keep both
regen_verify_transport and token_stream_cursor_grounding_transport on
the realization-vocab roster; regenerate plan docs.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls pushed a commit that referenced this pull request Jun 28, 2026
* Restore emit-path variant-owner determinism lost in #5873 regen (#5879 grounding)

Port #5879's variant-owner disambiguation back into .dag authority and hand-sync
the v1 Rust seed: imported_variants (source-module local items), alpha-sorted
variant_fold bindings, sorted export-set map_keys, and field-type-hint struct
disambiguation. Regen in #5873 overwrote these fixes; this re-lands them on
current main (#5899) without disturbing expected_type_override_enum (#5891).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix #5899 func_sigs merge regression in variant-owner restore

Re-land imported_variants + sorted variant_fold on top of #5899's
func_sigs/all_declared_sigs path (not the reverted imported_sigs fork).
Restores compile-clean hand-sync; variant_owner_disambiguation 3/3 green.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Ground emit-path variant-owner determinism in .dag authority with pure regen.

Fix imported_variants map type so regen emits valid Rust (Map<String,String>
for unambiguous owners only), then regen stage0 to match .dag fixed point.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jun 28, 2026
…-up) (#5898)

* WIP: Model the floor batch order as a real dependency graph (operator-approve

* Fix cargo fmt on std_realization_schedule after RunnableSpaceCost landing.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Model the floor batch order as a real dependency graph (operator-approve

* Land RunnableResourceProfile floor scheduling and structural witnesses.

Replace RunnableSpaceCost with profile-based resource edges (corpus exclusion + heavy-resolve chain), update floor witnesses to match, and regen std_realization_schedule with ByteSize boxing fixes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix regen_verify by storing memory peaks as Int, not ByteSize.

RunnableMemorySubstantial.peak_byte_count is now Int so v1 emit avoids boxing the ByteSize Rc alias; regen_stage0 --verify and regen_verify_gate_passes green again.

Co-authored-by: Cursor <cursoragent@cursor.com>

* ci: re-trigger checks after stale dashboard report on c0feb29.

c0feb29 failed both jobs with fleet sccache compile errors (run 28331563039); HEAD c3c7996 already green on run 28334631196. Empty commit refreshes required-check status.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Honest compile-gate profile; anchor exclusions in R1/R2/W3.

DslCompileCleanGate profile is heavy+substantial (honest resource fact); compile_root and corpus_node are excluded from R1/R2 derivation via floor_resource_anchor_node, and W3 batch counting skips compile anchor + discovery corpus.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Restore ByteSize unit modeling via RunnableMemoryPeak record.

Replace peak_byte_count: Int workaround with RunnableMemoryPeak { predicted_peak: ByteSize } nested in RunnableMemorySubstantial, fixing the v1 emit boxing issue at the struct boundary instead of forking a bare scalar. regen_stage0 --verify green.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Delete tautological witness_floor_heavy_chain_matches_gate_count.

zip_map edge count is definitionally len(heavy)-1; discriminating R2 coverage stays on witness_plan_serializes_heavy_resolves perturbation pair. Drop unused floor_heavy_gate_count.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jun 30, 2026
…ode -> #5873 emitted-bytes) in self_host.dag + wire validate + §5 source-perturb teeth (#5999)

* WIP: Self-host fixpoint bytes-rework: replace digest basis (content_hash node

* WIP: Self-host fixpoint bytes-rework: replace digest basis (content_hash node

* Fix CI: keep emitted-bytes digest in compiler layer (atom_identity_hash not exportable to std.text).

Move source_text_code_unit_digest into self_host.dag using the primitive
atom_identity_hash (same pattern as 02_parse.dag) and revert the std.text
import that broke resolve: name 'atom_identity_hash' not found in v2.std.node.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Self-host fixpoint bytes-rework: replace digest basis (content_hash node

* WIP: Self-host fixpoint bytes-rework: replace digest basis (content_hash node

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jul 1, 2026
Address cursor REQUEST_CHANGES: regen-verify is wired via RegenVerifyGate
(#5873, not closed #5325); forced-precondition step 1 marks Track A cargo-green
done in lockstep with Track A bullet 2. Regen committed .md from .dag authority.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jul 1, 2026
…#6099)

* integration: slice-2 (length->count) + marker derives

* integration: + bright-badger Measure (04_infer+05_emit) + eager-boar MachineWidth (05_emit)

* emit(import-completeness): authored imports for emitter-rendered symbols (empty_intern_table, InductiveField, is_bare_leaf_item, SemVerConstraint) — clears E0425 from peeled/turbofish types not in source import set

* integration: bring #5325 regen_stage0.rs languages_consumer_census mod-injection patch (clears E0433 x6 in bootstrap)

* emit(List seed carrier): render List nominal as host Vec in seed branch (option d, container analogue of String/Nat) — guarded, List-only, at the 2 preserve-nominal sites; clears E0425/E0432 for newly-enrolled std files (realization_schedule Schedule, std_types list_length). v2-target faithful FreeMonoid untouched.

* emit(Int generic-arg seed carrier): apply rust_seed_host_numeric_alias at the bare-nominal alias-RHS branch so Int/Nat as a generic ARG (Measure<...,Int>) lowers to i64 in the seed, consistent with the type Int = i64 alias def — clears the std_measure Int E0425

* Merge origin/main into emitter/seed-green-integration (resolve emitter conflicts)

Resolved 4 conflicts in src/v1/05_emit_rust.dag and 1 in width_nat_type_arg_test.rs:
- render_rust_applied_type: keep branch's rust_seed_host_container_base (List->host Vec)
- rust_phantom_marker_inner: take main's join() simplification (equivalent, supersedes Optional-peel)
- emit_rust_expr_record_lit: take main's peeled_type_name refactor (branch lines were superseded duplicates)
- phantom-field comment: take main's wording (matches the refactor)
- machine_width test: keep active (un-ignore) — this branch carries the #5325 emitter fix the ignore waited on

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Re-ignore machine_width emit test: committed seed not yet regenerated

The test runs compile_sources against the in-process lib (committed stage0
seed), whose emit_rust.rs does not yet carry this branch's .dag peel fix
(branch updated 05_emit_rust.dag only, not the committed seed mirror). So it
must stay #[ignore]d until the seed regen lands (Track A step 3 / 2-stage
bootstrap). Reverts an over-eager un-ignore from the main merge.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* Add lexer-layer host builtins to v2 interpreter (chars/chars_to_string/metering)

So `gunbc run` can interpret the live .dag compile/emit fold (compile_sources)
WITHOUT regenerating the seed mirror — making a .dag emitter fix verifiable BY
INTERPRETATION (DESIGN §5 green-by-execution, §7 self-host).

Additive only (fills previously-erroring builtin cases; cannot regress existing
behavior). Proven by execution: the interpreter now resolves the source closure
and runs the full lexer (tokenize) over a probe source, advancing into
parse/resolve. Remaining gaps are deeper interpreter semantics (e.g.
raw_map_lookup on a plain Record), not missing builtins.

- chars(s) -> List<Int>: code points (matches languages.dag emit template +
  lexer source_chars: List<Int>), method dispatch.
- chars_to_string(List<Int>, start, end) -> String: code-point slice -> token
  text, free-fn dispatch.
- record_source_chars_index_lookup(): no-op unit metering stub.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* Interpreter spike: additive record-form-map + list_push method dispatch

Bounded spike (parent-approved) toward running the emit fold by interpretation.
Both additive / non-regressing (fill previously-erroring cases):

- raw_map_lookup: a Record without a callable `lookup` field is now treated as a
  record-form map (key looked up as a field name; miss -> Null -> Violates via the
  existing Witness bridge). Unblocks `data x: Map<K,V> = { ... }` literals, which
  the interpreter builds as Records. (Deeper root: literals are never built as
  type-directed Maps; this handles it at the consumption site.)
- list_push: dedicated method-dispatch arm (was free-fn only). Pushes the arg as
  a single element, unlike concat/append/push which merge a list-valued arg.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* Route-A class 1/6: correct splice dissolution pointer to adhoc-1bdd0259-2e3

The HAND-APPLIED-REGEN-MIRROR-SYNC mark previously pointed at snappy-swift-91 /
#5325 (done-but-re-drifted, unreachable). The live dissolution lane is
bright-stag's adhoc-1bdd0259-2e3: re-repair the 18-error regen-fixpoint hole +
add a regen-equals-committed CI drift-gate so a main-merge can never silently
re-drift the fixpoint. Comment-only; the panic! splice (code) is unchanged.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* Route-A: rustfmt the fixture-lever mirror splice (CI fmt gate)

The compile_error! -> panic! mirror splice shortened the string literal, so
rustfmt joins it onto one line (the original was split for the longer
compile_error! form). Hand-edit fmt-drift; cargo fmt --all applied. No code
change -- the splice is identical, only formatting. Restores rust_monolith_gate
fmt --all --check green on #5481.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* WIP class-3 computation layer: corpus_repr single authority (inert, .dag-only)

Foundational half of the class-3 corpus-representation-coherence fix (the
realization-layer handler-selection root behind the 26 List + 15 generic-syntax
census errors). Adds the named selector RustCorpusRepr = HostNative |
FaithfulFreeMonoid (04_emit_info.dag, auto-committed) and computes it ONCE as
the single authority in build_emit_graph_info (rust_corpus_repr over the whole
module corpus), threading it as the corpus_repr field through all 7 EmitGraphInfo
construction sites (each COPIES the field, never recomputes — quick-seal's
field=authority/param=read invariant).

INERT checkpoint: the type-renderer leaf gates still read the old per-module
rust_corpus_includes_v1_compiler/rust_emit_faithful_text_carrier, so emitted
output is byte-unchanged. Typechecks clean via the existing binary (0
diagnostics, 410 files emitted). The gate-switch + ~15-fn corpus_repr threading
+ leaf-fn param swap + dead-gate deletion + exact mirror transcription land in
the next pass, then the full-loop census oracle.

Realization-layer coherence fix, not a model change (List<e>=FreeMonoid<e> at
std/types.dag:227 untouched). Carrier B-home, idiom-threaded (per quick-seal).
adhoc-1bdd0259-2e3 dissolution lane. #5481.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* Revert "WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra"

This reverts commit aeb61f6.

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* Revert "WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra"

This reverts commit 6cf05a7.

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* Section 5 self-host: thread corpus-global RustCorpusRepr selector through emitter (class-3 representation-coherence)

Realization-layer-not-model-change: replaces the per-module host-vs-faithful
gate (rust_emit_faithful_text_carrier(source_indices)) with a single corpus-global
RustCorpusRepr (computed once in rust_corpus_repr, stored on EmitGraphInfo.corpus_repr),
threaded as the corpus_repr selector to every renderer/emitter/seam site. Deletes the
old per-module gate fns (§5 single-authority: divergence was writable). §6-transitional:
collapses to HostNative when src/v1 is deleted.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* Restore known-good stage0 seed (revert premature regen); keep .dag class-3 logic

The auto-committed regen'd seed pulled in pre-existing .dag<->seed drift (the
extdeps.cargo_version import wiring + faithful-emitted orphan modules) that breaks
the v1-compiler build — that drift is the regen-lockstep capstone's domain, not
class-3. The class-3 representation-coherence work stays fully in the .dag source;
the seed regen lands via the regen-lockstep lane once a class-3 gunbc emits the
bundled extdeps modules host-mode. Seed .rs reverted to the committed fixpoint so
CI's rust gate is green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* Restore known-good stage0 seed (auto-committed local regen reverted again)

Local class-3 verification re-ran the regen in the working tree, which the harness
auto-committed and re-broke the seed build. Seed reverted to the committed fixpoint;
class-3 logic remains entirely in the .dag source. Seed regen is the regen-lockstep
lane's deliverable.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* class-3 review fix: correct §6 dissolution-direction comment (src/v1 deleted → FaithfulFreeMonoid, not HostNative)

quick-seal by-execution review: 05_emit_rust.dag:221 stated the dissolution
collapse backwards. src/v1 deleted → no seed → has_seed=false → FaithfulFreeMonoid
(the pure-v2 faithful target), matching 04_infer.dag:6395 and the §6 ruling.
Comment-only; the code (04_infer.dag else-branch) was already correct.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* PATH A — land class-3-embodying cargo-green seed via overlay-3-committed

HAND-SYNCED MIRROR, not a regen fixpoint. Splice the three class-3 emitter
files (v1_compiler_emit_rust.rs, v1_compiler_infer.rs, v1_compiler_infer_emit_info.rs)
from a faithful regen of the class-3 .dag onto the committed seed; every other
module stays byte-identical to committed. Two local drifts hand-resolved:
- cargo header inlined in emit_rust so it does not import the deliberately-unwired
  extdeps_cargo_version orphan (byte-identical to committed emit);
- wire policy passed by value (Rc clone) at wire_value_serialize.rs to match the
  class-3 by-value policy_* signatures.

The std-tower orphans (std_measure / std_algebra / std_realization_schedule /
std_machine_constraints / std_integer / extdeps_version_semver / extdeps_cargo_version)
stay UNWIRED exactly as on main. A faithful full regen would wire them and surface
the deferred ~150-gap emitter-completeness lane (regen-fixpoint emitter-self-host);
that lane is NOT closed here and `regen_stage0 --verify` is expected to differ.
Carrier mark recorded in regen_stage0.rs + the 3 spliced file headers (self-contained;
breadcrumb node://adhoc-80af9ff8-40f).

Validated in scratch: cargo build -p v1-compiler --release --features
text_lookup_work_counter --bins = 0 errors / 0 warnings (all 5 bins); cargo fmt
--all --check clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* PATH A carrier-mark: append quick-seal's representation-invariance caveat

Comment-only. Append quick-seal's verbatim invariance line to all four carrier
marks (regen_stage0.rs registry + the 3 spliced file headers): the class-3
host-vs-faithful selection is representation-invariant on the v1-bundled host seed
at this tip (CONTROL B gate-isolated revert builds green; CONTROL A errors are the
wire policy confound, not representation), so the selection's behavioral
discriminating-proof is OWED by the deferred faithful target where the selection
actually fires. Keeps the HAND-SYNCED-MIRROR / not-regen-fixpoint / deferred-~150-lane
mark intact. Still cargo-green (0 errors/0 warnings, all 5 bins; fmt --all --check clean).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(seed-green): restore main serialize/record_emit after stale merge regressions

The branch had accidentally reverted #6045 record serialization and related
witnesses during prior main merges. Restore the main-line authorities so the
emitter/seed-green-integration branch tracks current main for Route-A closure.

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(route-a): add emit-fresh cargo-green execution witness

Reconcile emitter/seed-green-integration with main and land an ignored-by-default
test that assembles the faithful --emit-fresh crate and proves debug+release
cargo build succeed (0 rustc errors). Closes the Route-A last-mile receipt loop
alongside the existing regen --verify CI gate.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ci): align zero-budget spawn width with execution-corpus cap witness

gunbc_ci_floor_spawn_width_for_budget(0) returned the blind conservative
fallback (4) while witness_floor_spawn_width_zero_budget_falls_back expected
min(4, execution_corpus_spawn_width()) = 3. Apply the same int_min at the
authority site and update the envelope witness to match.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(self-host): mark Route-A cargo-green landed (#5777/#5873)

Re-verified cool-ant-875: regen_stage0 --emit-fresh → cargo build
debug+release is 0 errors. Sync v2_self_hosting plan bullets that still
claimed the last mile was open; note emitter/seed-green-integration absorbed.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(docs): regen v2-self-hosting.md from plan authority

v2_self_hosting.dag is enrolled in PlanArtifact (generated_artifact
registry); committed docs/plans/v2-self-hosting.md must match
artifact_generate. Regen via main_wet after cargo-green bullet sync.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(docs): finish v2-self-hosting plan sync for #5873 wiring

Address cursor REQUEST_CHANGES: regen-verify is wired via RegenVerifyGate
(#5873, not closed #5325); forced-precondition step 1 marks Track A cargo-green
done in lockstep with Track A bullet 2. Regen committed .md from .dag authority.

Co-authored-by: Cursor <cursoragent@cursor.com>

* feat(plans): land TypeScript gap census as generated Plan (Lane C step A)

Discriminating audit-first record: 9 VEP source-string GREEN families,
2 FAIL-CLOSED, 8 FAIL-OPEN (#13–#20) with named witness/authority sites.
Clarifies bar (b) vs bar (c) — tsc/emit_host oracle red even for add (#19).
Enrolled in plan_registry; regen docs/plans/typescript-gap-census.md via main_wet.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Section 5 self-host execution manager: Lane A drive the emitted rust cra

* fix(docs): name .dag authority in typescript gap census plan

Address cursor REQUEST_CHANGES (#34390): status line no longer says "This
file is the authority" in generated .md — names typescript_gap_census.dag
explicitly (DESIGN §3/§6). Regen committed projection via main_wet.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(docs): bind typescript-gap-census into doc graph

CI failed doc_graph_has_no_orphan_docs — new PlanArtifact md had no
reachability root. Add bind: provenance on typescript_gap_census.dag
(mirror commit_workflow / accelerator_demo_plan pattern).

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jul 5, 2026
…tirement path (delete-mass triage) (#6272)

* pipeline.rs self_gen8 cluster: retire 28 of 31 fns (typed dispositions; 3 kept for def-unification lane)

Delete-mass triage of the self_gen8 cluster per the test_migration_debt drain
(#6261 retirement path). Ground truth measured 2026-07-05 via
cargo test -p v1-compiler-tests self_gen8 -- --include-ignored: 22 passed,
9 failed - 8 of the 17 #[ignore]d fns carried stale red-on-main reasons and
pass on main today.

- 22 green fns -> DeleteRedundant: seed-corpus pattern families (homonymous
  type names, variant-specific imports, kernel-ambient types, direct type
  imports) are byte-pinned by RegenVerifyGate (regen_stage0 --verify, #5873)
  plus the emitted-seed rustc/clippy gates; beyond-corpus synthetic shapes
  (parametric-alias RHS, opaque parametric decls, proxy chains, wildcard
  imports) are executed by the v2 self-host fresh-emit lane over dag/std's
  real instances with deficits enumerated in the 1667-error receipt
  (#6253/#6258). An #[ignore]d pin runs in no gate - zero delivered signal.
- 6 red fns -> DeleteLowValue: #[ignore] since #5427, never run in any gate,
  desired-but-absent seed-emitter behavior on synthetic fixtures; deficit
  ownership is the fresh-emit lane.
- 3 red fns KEPT (stays_unemitted alias-to-opaque trio):
  dag/gunbc/plans/dag_v2_defork_audit.dag claims them for the def-unification
  lane (node://adhoc-9d2bb9c3-e7b) - premise flips, not deletes.

Typed receipt: dag/test/retirement/pipeline_self_gen8_retired.dag (two
TestModuleRetirement rows). Receipt-only w.r.t. the delete-guard - the
contributed stem pipeline_self_gen8 matches no v1 test file and pipeline.rs
itself survives, so its eventual file deletion still requires its own
coverage.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Repoint kept trio's #[ignore] reasons to their owning lane (def-unification, node://adhoc-9d2bb9c3-e7b)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 6, 2026
…_wrappers BTreeSet alias; stale guard comment

Addresses PR #6307 review findings (cursor/composer-2.5 + claude-opus-4-7):
- v1_interpreter.rs: Value::Set was std BTreeSet (forked from runtime im_rc::OrdSet)
  and deep-cloned on every set_insert/set_union. Migrated to im_rc::OrdSet, closing
  the live model<->realization fork and the O(n) clone (now O(1) structural + O(log n)
  COW). Makes runtime_rust.dag's 'one realization with Value::Map/List/Set' true.
- 05_emit_rust.dag emit_non_empty_wrappers: std::collections::BTreeSet -> bare BTreeSet
  alias (matches the seed + prelude OrdSet alias; forward-compatible; kills the
  bidirectional regen hazard).
- v1_rt.rs: fixed the stale rc_map_insert sibling comment that still claimed lists/sets
  'remain O(n)-copy carriers and keep the guard'.

Seed-emitter import drift (emit_prelude/emit_main_mod_uses/rt_header/extdeps JSON still
emit std) is the coherent-whole emitter-fix-needs-2-gens cutover: pre-existing on main
(maps PR), tracked against RegenVerifyGate #5873, coordinated with regen lane
(loyal-dove-903). Not fixable as isolated import swaps (emitted runtime bodies need
focus/push_back/VecCompat + the trait emission itself).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 6, 2026
… guard + move licenses (atomic) (#6307)

* WIP: gunb compilation test

* Clone-fallback guard: shared-Rc updates refuse by default (fail|count|allow)

Operator ruling 2026-07-05: the silent clone arm in the rc_* update family
is a degradation that must stop the pipeline, not widen. Every shared-Rc
update (rc_map_insert/merge, rc_list_push/concat, rc_set_insert/union) and
take_owned_counted's clone arm now routes through rc_shared_update_guard:

- GUNBC_CLONE_FALLBACK=fail (default): typed, located panic naming the
  generated caller (#[track_caller]) — the work-queue key for licensing.
- =count: per-site ledger, first-hit line + ranked exit report (Drop on the
  thread_local), so degradation frequency is observable per §5.
- =allow: interim escape hatch.

tier-1 compile enumerates 205 degraded sites; top: rc_map_merge at
infer_env.rs:413 (14,360 clones), dag_collect.rs:234/239 (5,049 each) —
the profiled O(n^2) cold-compile root cause.

Template (runtime_rust.dag) and seed (v1_rt.rs) edited in sync, same
pattern as #6249.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: gunb compilation test

* Fail-closed hardening: ban escape hatches, close guard bypasses, encode the factory model in DESIGN.md §5

Operator rulings 2026-07-05:
- GUNBC_CLONE_FALLBACK=allow removed. Modes are fail (default, refuses) and
  count (stopped-line audit: full ledger, still not a green run). No mode
  silences a refusal.
- DESIGN.md §5: no-escape-hatches corollary + the factory model as a merge
  REQUIREMENT — a diff landing a non-fail-closed failure arm (silent widen,
  fabricated default, uncounted degradation, escape hatch) is a hard reject
  in review.
- 6 inline pre-#6249 `Rc::try_unwrap(..).unwrap_or_else(clone)` fold sites
  in the generated seed (compile/infer_cycle/resolve x2/ownership/emit_rust)
  hand-synced to take_owned_counted — the guard's known bypasses closed;
  regen supersedes the hand-sync.
- take_owned_counted count arm ledgered into the same exit report as rc_*
  (one stopped-line audit surface).
- Interpreter: Bool True|False vs Value::Bool cross-representation `==`
  straddle now refuses (CrossRepresentationEquality), mirroring the numeric
  arm; DESIGN §5 named it the remaining decidable straddle. Its by-execution
  receipt joins the cross_representation receipts behind the stopped line.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: gunb compilation test

* WIP: gunb compilation test

* WIP: gunb compilation test

* Persistent maps: Map realization = im_rc HAMT (one authority with interpreter Value::Map)

Root fix for the clone-fallback class on maps (operator go-ahead 2026-07-05).
The compiled runtime realized Map as Rc<std HashMap> — O(n) copy on any
shared update — while the interpreter already realized Value::Map as
im_rc::HashMap (a §3 model↔realization fork). One swap of which HashMap the
generated code imports (extdeps/languages/rust/types.dag import row +
runtime_rust.dag header + seed hand-sync; type spellings and call sites
unchanged): Rc::make_mut's clone arm is now O(1) structural sharing and each
insert copies an O(log n) node path — shared update becomes the designed
path, so rc_map_insert/rc_map_merge leave the clone-fallback guard (lists
and sets keep it until they migrate too).

By-execution receipts (frozen-unit cold-compile benchmark):
- tier-1: 2.26s -> 0.66s; ledger 205 degraded sites -> 18 (all map sites gone)
- tier-10: 239s -> 41.7s (5.7x); 1.74M map clone-fallbacks -> 0
- remaining ledger is exactly rc_list_push/rc_list_concat/rc_set_insert —
  the named follow-up (List/Set -> persistent carriers need emitter type
  template work, not just the import row)

im-rc serde feature enabled for the artifact-serialization derives; hand
seams (cli_run, interpreter, bins, test mods) repointed per direction —
host-internal std maps stay std. fmt + clippy -D warnings green across all
targets. Run-to-run artifact nondeterminism predates this change (open
v2.std.determinism thread), verified by pre-change A/B.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Persistent carriers: lists+sets -> im_rc Vector/OrdSet; delete clone-fallback guard + per-site move licenses

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix import order in v2 manual ownership_movable mirror (imports precede items)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* Fix sweep-corrupted emit golden; inhabitant import_path rows prelude-provided (generation-agnostic)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Merge origin/main into session/sharp-wolf-473

Resolves #6269 test-migration collision: accept main's deletion of
src/v1/ownership_movable_test.dag (v2 manual mirror carries the license-removal
edit); reconcile dag_collect_fingerprint_witness.rs bin with im_rc carriers
(hashes -> Rc<im_rc::Vector>, Node children/params via .into()).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Review fixes: interpreter Value::Set -> im_rc::OrdSet; emit_non_empty_wrappers BTreeSet alias; stale guard comment

Addresses PR #6307 review findings (cursor/composer-2.5 + claude-opus-4-7):
- v1_interpreter.rs: Value::Set was std BTreeSet (forked from runtime im_rc::OrdSet)
  and deep-cloned on every set_insert/set_union. Migrated to im_rc::OrdSet, closing
  the live model<->realization fork and the O(n) clone (now O(1) structural + O(log n)
  COW). Makes runtime_rust.dag's 'one realization with Value::Map/List/Set' true.
- 05_emit_rust.dag emit_non_empty_wrappers: std::collections::BTreeSet -> bare BTreeSet
  alias (matches the seed + prelude OrdSet alias; forward-compatible; kills the
  bidirectional regen hazard).
- v1_rt.rs: fixed the stale rc_map_insert sibling comment that still claimed lists/sets
  'remain O(n)-copy carriers and keep the guard'.

Seed-emitter import drift (emit_prelude/emit_main_mod_uses/rt_header/extdeps JSON still
emit std) is the coherent-whole emitter-fix-needs-2-gens cutover: pre-existing on main
(maps PR), tracked against RegenVerifyGate #5873, coordinated with regen lane
(loyal-dove-903). Not fixable as isolated import swaps (emitted runtime bodies need
focus/push_back/VecCompat + the trait emission itself).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 6, 2026
…ontainer-dimension seeds (92->30 verify staleness) (#6322)

* WIP: gunb compilation test

* Clone-fallback guard: shared-Rc updates refuse by default (fail|count|allow)

Operator ruling 2026-07-05: the silent clone arm in the rc_* update family
is a degradation that must stop the pipeline, not widen. Every shared-Rc
update (rc_map_insert/merge, rc_list_push/concat, rc_set_insert/union) and
take_owned_counted's clone arm now routes through rc_shared_update_guard:

- GUNBC_CLONE_FALLBACK=fail (default): typed, located panic naming the
  generated caller (#[track_caller]) — the work-queue key for licensing.
- =count: per-site ledger, first-hit line + ranked exit report (Drop on the
  thread_local), so degradation frequency is observable per §5.
- =allow: interim escape hatch.

tier-1 compile enumerates 205 degraded sites; top: rc_map_merge at
infer_env.rs:413 (14,360 clones), dag_collect.rs:234/239 (5,049 each) —
the profiled O(n^2) cold-compile root cause.

Template (runtime_rust.dag) and seed (v1_rt.rs) edited in sync, same
pattern as #6249.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: gunb compilation test

* Fail-closed hardening: ban escape hatches, close guard bypasses, encode the factory model in DESIGN.md §5

Operator rulings 2026-07-05:
- GUNBC_CLONE_FALLBACK=allow removed. Modes are fail (default, refuses) and
  count (stopped-line audit: full ledger, still not a green run). No mode
  silences a refusal.
- DESIGN.md §5: no-escape-hatches corollary + the factory model as a merge
  REQUIREMENT — a diff landing a non-fail-closed failure arm (silent widen,
  fabricated default, uncounted degradation, escape hatch) is a hard reject
  in review.
- 6 inline pre-#6249 `Rc::try_unwrap(..).unwrap_or_else(clone)` fold sites
  in the generated seed (compile/infer_cycle/resolve x2/ownership/emit_rust)
  hand-synced to take_owned_counted — the guard's known bypasses closed;
  regen supersedes the hand-sync.
- take_owned_counted count arm ledgered into the same exit report as rc_*
  (one stopped-line audit surface).
- Interpreter: Bool True|False vs Value::Bool cross-representation `==`
  straddle now refuses (CrossRepresentationEquality), mirroring the numeric
  arm; DESIGN §5 named it the remaining decidable straddle. Its by-execution
  receipt joins the cross_representation receipts behind the stopped line.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: gunb compilation test

* WIP: gunb compilation test

* WIP: gunb compilation test

* Persistent maps: Map realization = im_rc HAMT (one authority with interpreter Value::Map)

Root fix for the clone-fallback class on maps (operator go-ahead 2026-07-05).
The compiled runtime realized Map as Rc<std HashMap> — O(n) copy on any
shared update — while the interpreter already realized Value::Map as
im_rc::HashMap (a §3 model↔realization fork). One swap of which HashMap the
generated code imports (extdeps/languages/rust/types.dag import row +
runtime_rust.dag header + seed hand-sync; type spellings and call sites
unchanged): Rc::make_mut's clone arm is now O(1) structural sharing and each
insert copies an O(log n) node path — shared update becomes the designed
path, so rc_map_insert/rc_map_merge leave the clone-fallback guard (lists
and sets keep it until they migrate too).

By-execution receipts (frozen-unit cold-compile benchmark):
- tier-1: 2.26s -> 0.66s; ledger 205 degraded sites -> 18 (all map sites gone)
- tier-10: 239s -> 41.7s (5.7x); 1.74M map clone-fallbacks -> 0
- remaining ledger is exactly rc_list_push/rc_list_concat/rc_set_insert —
  the named follow-up (List/Set -> persistent carriers need emitter type
  template work, not just the import row)

im-rc serde feature enabled for the artifact-serialization derives; hand
seams (cli_run, interpreter, bins, test mods) repointed per direction —
host-internal std maps stay std. fmt + clippy -D warnings green across all
targets. Run-to-run artifact nondeterminism predates this change (open
v2.std.determinism thread), verified by pre-change A/B.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Persistent carriers: lists+sets -> im_rc Vector/OrdSet; delete clone-fallback guard + per-site move licenses

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix import order in v2 manual ownership_movable mirror (imports precede items)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* Fix sweep-corrupted emit golden; inhabitant import_path rows prelude-provided (generation-agnostic)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Merge origin/main into session/sharp-wolf-473

Resolves #6269 test-migration collision: accept main's deletion of
src/v1/ownership_movable_test.dag (v2 manual mirror carries the license-removal
edit); reconcile dag_collect_fingerprint_witness.rs bin with im_rc carriers
(hashes -> Rc<im_rc::Vector>, Node children/params via .into()).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Review fixes: interpreter Value::Set -> im_rc::OrdSet; emit_non_empty_wrappers BTreeSet alias; stale guard comment

Addresses PR #6307 review findings (cursor/composer-2.5 + claude-opus-4-7):
- v1_interpreter.rs: Value::Set was std BTreeSet (forked from runtime im_rc::OrdSet)
  and deep-cloned on every set_insert/set_union. Migrated to im_rc::OrdSet, closing
  the live model<->realization fork and the O(n) clone (now O(1) structural + O(log n)
  COW). Makes runtime_rust.dag's 'one realization with Value::Map/List/Set' true.
- 05_emit_rust.dag emit_non_empty_wrappers: std::collections::BTreeSet -> bare BTreeSet
  alias (matches the seed + prelude OrdSet alias; forward-compatible; kills the
  bidirectional regen hazard).
- v1_rt.rs: fixed the stale rc_map_insert sibling comment that still claimed lists/sets
  'remain O(n)-copy carriers and keep the guard'.

Seed-emitter import drift (emit_prelude/emit_main_mod_uses/rt_header/extdeps JSON still
emit std) is the coherent-whole emitter-fix-needs-2-gens cutover: pre-existing on main
(maps PR), tracked against RegenVerifyGate #5873, coordinated with regen lane
(loyal-dove-903). Not fixable as isolated import swaps (emitted runtime bodies need
focus/push_back/VecCompat + the trait emission itself).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 7, 2026
…: one-level visibility by construction (floor resolve 286.7s -> 2.4s) (#6331)

* WIP: gunb compilation test

* Clone-fallback guard: shared-Rc updates refuse by default (fail|count|allow)

Operator ruling 2026-07-05: the silent clone arm in the rc_* update family
is a degradation that must stop the pipeline, not widen. Every shared-Rc
update (rc_map_insert/merge, rc_list_push/concat, rc_set_insert/union) and
take_owned_counted's clone arm now routes through rc_shared_update_guard:

- GUNBC_CLONE_FALLBACK=fail (default): typed, located panic naming the
  generated caller (#[track_caller]) — the work-queue key for licensing.
- =count: per-site ledger, first-hit line + ranked exit report (Drop on the
  thread_local), so degradation frequency is observable per §5.
- =allow: interim escape hatch.

tier-1 compile enumerates 205 degraded sites; top: rc_map_merge at
infer_env.rs:413 (14,360 clones), dag_collect.rs:234/239 (5,049 each) —
the profiled O(n^2) cold-compile root cause.

Template (runtime_rust.dag) and seed (v1_rt.rs) edited in sync, same
pattern as #6249.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: gunb compilation test

* Fail-closed hardening: ban escape hatches, close guard bypasses, encode the factory model in DESIGN.md §5

Operator rulings 2026-07-05:
- GUNBC_CLONE_FALLBACK=allow removed. Modes are fail (default, refuses) and
  count (stopped-line audit: full ledger, still not a green run). No mode
  silences a refusal.
- DESIGN.md §5: no-escape-hatches corollary + the factory model as a merge
  REQUIREMENT — a diff landing a non-fail-closed failure arm (silent widen,
  fabricated default, uncounted degradation, escape hatch) is a hard reject
  in review.
- 6 inline pre-#6249 `Rc::try_unwrap(..).unwrap_or_else(clone)` fold sites
  in the generated seed (compile/infer_cycle/resolve x2/ownership/emit_rust)
  hand-synced to take_owned_counted — the guard's known bypasses closed;
  regen supersedes the hand-sync.
- take_owned_counted count arm ledgered into the same exit report as rc_*
  (one stopped-line audit surface).
- Interpreter: Bool True|False vs Value::Bool cross-representation `==`
  straddle now refuses (CrossRepresentationEquality), mirroring the numeric
  arm; DESIGN §5 named it the remaining decidable straddle. Its by-execution
  receipt joins the cross_representation receipts behind the stopped line.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: gunb compilation test

* WIP: gunb compilation test

* WIP: gunb compilation test

* Persistent maps: Map realization = im_rc HAMT (one authority with interpreter Value::Map)

Root fix for the clone-fallback class on maps (operator go-ahead 2026-07-05).
The compiled runtime realized Map as Rc<std HashMap> — O(n) copy on any
shared update — while the interpreter already realized Value::Map as
im_rc::HashMap (a §3 model↔realization fork). One swap of which HashMap the
generated code imports (extdeps/languages/rust/types.dag import row +
runtime_rust.dag header + seed hand-sync; type spellings and call sites
unchanged): Rc::make_mut's clone arm is now O(1) structural sharing and each
insert copies an O(log n) node path — shared update becomes the designed
path, so rc_map_insert/rc_map_merge leave the clone-fallback guard (lists
and sets keep it until they migrate too).

By-execution receipts (frozen-unit cold-compile benchmark):
- tier-1: 2.26s -> 0.66s; ledger 205 degraded sites -> 18 (all map sites gone)
- tier-10: 239s -> 41.7s (5.7x); 1.74M map clone-fallbacks -> 0
- remaining ledger is exactly rc_list_push/rc_list_concat/rc_set_insert —
  the named follow-up (List/Set -> persistent carriers need emitter type
  template work, not just the import row)

im-rc serde feature enabled for the artifact-serialization derives; hand
seams (cli_run, interpreter, bins, test mods) repointed per direction —
host-internal std maps stay std. fmt + clippy -D warnings green across all
targets. Run-to-run artifact nondeterminism predates this change (open
v2.std.determinism thread), verified by pre-change A/B.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Persistent carriers: lists+sets -> im_rc Vector/OrdSet; delete clone-fallback guard + per-site move licenses

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix import order in v2 manual ownership_movable mirror (imports precede items)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* Fix sweep-corrupted emit golden; inhabitant import_path rows prelude-provided (generation-agnostic)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Merge origin/main into session/sharp-wolf-473

Resolves #6269 test-migration collision: accept main's deletion of
src/v1/ownership_movable_test.dag (v2 manual mirror carries the license-removal
edit); reconcile dag_collect_fingerprint_witness.rs bin with im_rc carriers
(hashes -> Rc<im_rc::Vector>, Node children/params via .into()).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Review fixes: interpreter Value::Set -> im_rc::OrdSet; emit_non_empty_wrappers BTreeSet alias; stale guard comment

Addresses PR #6307 review findings (cursor/composer-2.5 + claude-opus-4-7):
- v1_interpreter.rs: Value::Set was std BTreeSet (forked from runtime im_rc::OrdSet)
  and deep-cloned on every set_insert/set_union. Migrated to im_rc::OrdSet, closing
  the live model<->realization fork and the O(n) clone (now O(1) structural + O(log n)
  COW). Makes runtime_rust.dag's 'one realization with Value::Map/List/Set' true.
- 05_emit_rust.dag emit_non_empty_wrappers: std::collections::BTreeSet -> bare BTreeSet
  alias (matches the seed + prelude OrdSet alias; forward-compatible; kills the
  bidirectional regen hazard).
- v1_rt.rs: fixed the stale rc_map_insert sibling comment that still claimed lists/sets
  'remain O(n)-copy carriers and keep the guard'.

Seed-emitter import drift (emit_prelude/emit_main_mod_uses/rt_header/extdeps JSON still
emit std) is the coherent-whole emitter-fix-needs-2-gens cutover: pre-existing on main
(maps PR), tracked against RegenVerifyGate #5873, coordinated with regen lane
(loyal-dove-903). Not fixable as isolated import swaps (emitted runtime bodies need
focus/push_back/VecCompat + the trait emission itself).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Revert speculative import addition in network_identity_subsumption (refusal is a pre-existing alias-expansion deficit, A/B-verified on the pre-diff binary)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* Back-port #6329's operator-signed DESIGN.md edits into design_document.dag; corpus import hygiene; artifact regens

The compile-clean and artifact-drift gates, unmasked by #6331's floor speedup,
found accumulated debt: 43 unlisted-import diagnostics (12 files, mechanical
import-list additions), the network_identity param typed to the alias it
actually receives (DhcpClientHostNameOption12), and DESIGN.md drifted from its
generating authority because #6329 hand-edited the artifact without
back-porting (receipt: main_wet now regenerates DESIGN.md byte-identical to
the committed operator-signed version). falsifier.yml/.gitignore regens are
main_wet output. The complexity_r1 citation-string repoints are reverted out
of this PR: touching those files enrolls a fixture whose lens hits a
pre-existing fold_list lambda-param typing deficit (no field 'label' on 'T');
moved to follow-up with that deficit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* complexity_r1 lens: type the children fold on the demand path (builtin fold idiom); keep truthful post-deletion citations

The diff-scoped discovery frontier (enrolled via the v2.std.diagnostic import
fix) demand-resolves this lens; fold_list<T,A> over n.children left T
un-instantiated on that path (no field 'label' on 'T') while batch reconcile
typed it fine — a batch/demand inference divergence. The children fold now
uses the builtin fold idiom fact_density.dag already uses (resolves on both
paths, receipt: complexity_r1_green_merge_envs_base_holds witness green by
execution); the registry fold_list over a concrete FreeMonoid in the same
module types fine and stays.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* Revert "WIP: emit -> realization"

This reverts commit 3ad16c9.

* WIP: emit -> realization

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 7, 2026
* WIP: gunb compilation test

* Clone-fallback guard: shared-Rc updates refuse by default (fail|count|allow)

Operator ruling 2026-07-05: the silent clone arm in the rc_* update family
is a degradation that must stop the pipeline, not widen. Every shared-Rc
update (rc_map_insert/merge, rc_list_push/concat, rc_set_insert/union) and
take_owned_counted's clone arm now routes through rc_shared_update_guard:

- GUNBC_CLONE_FALLBACK=fail (default): typed, located panic naming the
  generated caller (#[track_caller]) — the work-queue key for licensing.
- =count: per-site ledger, first-hit line + ranked exit report (Drop on the
  thread_local), so degradation frequency is observable per §5.
- =allow: interim escape hatch.

tier-1 compile enumerates 205 degraded sites; top: rc_map_merge at
infer_env.rs:413 (14,360 clones), dag_collect.rs:234/239 (5,049 each) —
the profiled O(n^2) cold-compile root cause.

Template (runtime_rust.dag) and seed (v1_rt.rs) edited in sync, same
pattern as #6249.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: gunb compilation test

* Fail-closed hardening: ban escape hatches, close guard bypasses, encode the factory model in DESIGN.md §5

Operator rulings 2026-07-05:
- GUNBC_CLONE_FALLBACK=allow removed. Modes are fail (default, refuses) and
  count (stopped-line audit: full ledger, still not a green run). No mode
  silences a refusal.
- DESIGN.md §5: no-escape-hatches corollary + the factory model as a merge
  REQUIREMENT — a diff landing a non-fail-closed failure arm (silent widen,
  fabricated default, uncounted degradation, escape hatch) is a hard reject
  in review.
- 6 inline pre-#6249 `Rc::try_unwrap(..).unwrap_or_else(clone)` fold sites
  in the generated seed (compile/infer_cycle/resolve x2/ownership/emit_rust)
  hand-synced to take_owned_counted — the guard's known bypasses closed;
  regen supersedes the hand-sync.
- take_owned_counted count arm ledgered into the same exit report as rc_*
  (one stopped-line audit surface).
- Interpreter: Bool True|False vs Value::Bool cross-representation `==`
  straddle now refuses (CrossRepresentationEquality), mirroring the numeric
  arm; DESIGN §5 named it the remaining decidable straddle. Its by-execution
  receipt joins the cross_representation receipts behind the stopped line.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: gunb compilation test

* WIP: gunb compilation test

* WIP: gunb compilation test

* Persistent maps: Map realization = im_rc HAMT (one authority with interpreter Value::Map)

Root fix for the clone-fallback class on maps (operator go-ahead 2026-07-05).
The compiled runtime realized Map as Rc<std HashMap> — O(n) copy on any
shared update — while the interpreter already realized Value::Map as
im_rc::HashMap (a §3 model↔realization fork). One swap of which HashMap the
generated code imports (extdeps/languages/rust/types.dag import row +
runtime_rust.dag header + seed hand-sync; type spellings and call sites
unchanged): Rc::make_mut's clone arm is now O(1) structural sharing and each
insert copies an O(log n) node path — shared update becomes the designed
path, so rc_map_insert/rc_map_merge leave the clone-fallback guard (lists
and sets keep it until they migrate too).

By-execution receipts (frozen-unit cold-compile benchmark):
- tier-1: 2.26s -> 0.66s; ledger 205 degraded sites -> 18 (all map sites gone)
- tier-10: 239s -> 41.7s (5.7x); 1.74M map clone-fallbacks -> 0
- remaining ledger is exactly rc_list_push/rc_list_concat/rc_set_insert —
  the named follow-up (List/Set -> persistent carriers need emitter type
  template work, not just the import row)

im-rc serde feature enabled for the artifact-serialization derives; hand
seams (cli_run, interpreter, bins, test mods) repointed per direction —
host-internal std maps stay std. fmt + clippy -D warnings green across all
targets. Run-to-run artifact nondeterminism predates this change (open
v2.std.determinism thread), verified by pre-change A/B.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Persistent carriers: lists+sets -> im_rc Vector/OrdSet; delete clone-fallback guard + per-site move licenses

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix import order in v2 manual ownership_movable mirror (imports precede items)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* Fix sweep-corrupted emit golden; inhabitant import_path rows prelude-provided (generation-agnostic)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Merge origin/main into session/sharp-wolf-473

Resolves #6269 test-migration collision: accept main's deletion of
src/v1/ownership_movable_test.dag (v2 manual mirror carries the license-removal
edit); reconcile dag_collect_fingerprint_witness.rs bin with im_rc carriers
(hashes -> Rc<im_rc::Vector>, Node children/params via .into()).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Review fixes: interpreter Value::Set -> im_rc::OrdSet; emit_non_empty_wrappers BTreeSet alias; stale guard comment

Addresses PR #6307 review findings (cursor/composer-2.5 + claude-opus-4-7):
- v1_interpreter.rs: Value::Set was std BTreeSet (forked from runtime im_rc::OrdSet)
  and deep-cloned on every set_insert/set_union. Migrated to im_rc::OrdSet, closing
  the live model<->realization fork and the O(n) clone (now O(1) structural + O(log n)
  COW). Makes runtime_rust.dag's 'one realization with Value::Map/List/Set' true.
- 05_emit_rust.dag emit_non_empty_wrappers: std::collections::BTreeSet -> bare BTreeSet
  alias (matches the seed + prelude OrdSet alias; forward-compatible; kills the
  bidirectional regen hazard).
- v1_rt.rs: fixed the stale rc_map_insert sibling comment that still claimed lists/sets
  'remain O(n)-copy carriers and keep the guard'.

Seed-emitter import drift (emit_prelude/emit_main_mod_uses/rt_header/extdeps JSON still
emit std) is the coherent-whole emitter-fix-needs-2-gens cutover: pre-existing on main
(maps PR), tracked against RegenVerifyGate #5873, coordinated with regen lane
(loyal-dove-903). Not fixable as isolated import swaps (emitted runtime bodies need
focus/push_back/VecCompat + the trait emission itself).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Revert speculative import addition in network_identity_subsumption (refusal is a pre-existing alias-expansion deficit, A/B-verified on the pre-diff binary)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* Back-port #6329's operator-signed DESIGN.md edits into design_document.dag; corpus import hygiene; artifact regens

The compile-clean and artifact-drift gates, unmasked by #6331's floor speedup,
found accumulated debt: 43 unlisted-import diagnostics (12 files, mechanical
import-list additions), the network_identity param typed to the alias it
actually receives (DhcpClientHostNameOption12), and DESIGN.md drifted from its
generating authority because #6329 hand-edited the artifact without
back-porting (receipt: main_wet now regenerates DESIGN.md byte-identical to
the committed operator-signed version). falsifier.yml/.gitignore regens are
main_wet output. The complexity_r1 citation-string repoints are reverted out
of this PR: touching those files enrolls a fixture whose lens hits a
pre-existing fold_list lambda-param typing deficit (no field 'label' on 'T');
moved to follow-up with that deficit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* complexity_r1 lens: type the children fold on the demand path (builtin fold idiom); keep truthful post-deletion citations

The diff-scoped discovery frontier (enrolled via the v2.std.diagnostic import
fix) demand-resolves this lens; fold_list<T,A> over n.children left T
un-instantiated on that path (no field 'label' on 'T') while batch reconcile
typed it fine — a batch/demand inference divergence. The children fold now
uses the builtin fold idiom fact_density.dag already uses (resolves on both
paths, receipt: complexity_r1_green_merge_envs_base_holds witness green by
execution); the registry fold_list over a concrete FreeMonoid in the same
module types fine and stays.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* Revert "WIP: emit -> realization"

This reverts commit 3ad16c9.

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* intern_str build-green: list-get resolves Optional via free_monoid_collection get template

Root cause of the list-get-by-index inference deficit: free_monoid_collection_templates
(the List method table in dag/std/algebra.dag) declared first/last returning
OptionalOf<ReceiverElement> but had NO get row — so `list |> get(index)` never resolved
structurally and its result type defaulted to the receiver (FreeMonoid), leaving the match
Bind arm un-Some-wrapped. Map-get works because PartialFunction declares get: fn(K) -> V?.

- dag/std/algebra.dag: add get: [ReceiverSelf, Int] -> OptionalOf<ReceiverElement> row,
  mirroring the existing first/last rows (completes the model, mints nothing). [already committed]
- src/v1/stage0/src/std_algebra.rs: splice the get template into the seed so the running
  binary's inference resolves list-get as Optional.
- src/v1/00_core.dag: intern_str now matches explicit Present/Absent (was catch-all
  `other => other` which binds the whole Option); emits Some(s)/None, builds green.

Fresh-crate cargo check: 26 -> 2 errors; the 2 remaining are the single std_integer Nat
where-refinement alias-resolution root (Nat<Magnitude>). intern_str builds.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 7, 2026
… gate) + sorted_map_keys builtin (#6357)

* WIP: gunb compilation test

* Clone-fallback guard: shared-Rc updates refuse by default (fail|count|allow)

Operator ruling 2026-07-05: the silent clone arm in the rc_* update family
is a degradation that must stop the pipeline, not widen. Every shared-Rc
update (rc_map_insert/merge, rc_list_push/concat, rc_set_insert/union) and
take_owned_counted's clone arm now routes through rc_shared_update_guard:

- GUNBC_CLONE_FALLBACK=fail (default): typed, located panic naming the
  generated caller (#[track_caller]) — the work-queue key for licensing.
- =count: per-site ledger, first-hit line + ranked exit report (Drop on the
  thread_local), so degradation frequency is observable per §5.
- =allow: interim escape hatch.

tier-1 compile enumerates 205 degraded sites; top: rc_map_merge at
infer_env.rs:413 (14,360 clones), dag_collect.rs:234/239 (5,049 each) —
the profiled O(n^2) cold-compile root cause.

Template (runtime_rust.dag) and seed (v1_rt.rs) edited in sync, same
pattern as #6249.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: gunb compilation test

* Fail-closed hardening: ban escape hatches, close guard bypasses, encode the factory model in DESIGN.md §5

Operator rulings 2026-07-05:
- GUNBC_CLONE_FALLBACK=allow removed. Modes are fail (default, refuses) and
  count (stopped-line audit: full ledger, still not a green run). No mode
  silences a refusal.
- DESIGN.md §5: no-escape-hatches corollary + the factory model as a merge
  REQUIREMENT — a diff landing a non-fail-closed failure arm (silent widen,
  fabricated default, uncounted degradation, escape hatch) is a hard reject
  in review.
- 6 inline pre-#6249 `Rc::try_unwrap(..).unwrap_or_else(clone)` fold sites
  in the generated seed (compile/infer_cycle/resolve x2/ownership/emit_rust)
  hand-synced to take_owned_counted — the guard's known bypasses closed;
  regen supersedes the hand-sync.
- take_owned_counted count arm ledgered into the same exit report as rc_*
  (one stopped-line audit surface).
- Interpreter: Bool True|False vs Value::Bool cross-representation `==`
  straddle now refuses (CrossRepresentationEquality), mirroring the numeric
  arm; DESIGN §5 named it the remaining decidable straddle. Its by-execution
  receipt joins the cross_representation receipts behind the stopped line.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: gunb compilation test

* WIP: gunb compilation test

* WIP: gunb compilation test

* Persistent maps: Map realization = im_rc HAMT (one authority with interpreter Value::Map)

Root fix for the clone-fallback class on maps (operator go-ahead 2026-07-05).
The compiled runtime realized Map as Rc<std HashMap> — O(n) copy on any
shared update — while the interpreter already realized Value::Map as
im_rc::HashMap (a §3 model↔realization fork). One swap of which HashMap the
generated code imports (extdeps/languages/rust/types.dag import row +
runtime_rust.dag header + seed hand-sync; type spellings and call sites
unchanged): Rc::make_mut's clone arm is now O(1) structural sharing and each
insert copies an O(log n) node path — shared update becomes the designed
path, so rc_map_insert/rc_map_merge leave the clone-fallback guard (lists
and sets keep it until they migrate too).

By-execution receipts (frozen-unit cold-compile benchmark):
- tier-1: 2.26s -> 0.66s; ledger 205 degraded sites -> 18 (all map sites gone)
- tier-10: 239s -> 41.7s (5.7x); 1.74M map clone-fallbacks -> 0
- remaining ledger is exactly rc_list_push/rc_list_concat/rc_set_insert —
  the named follow-up (List/Set -> persistent carriers need emitter type
  template work, not just the import row)

im-rc serde feature enabled for the artifact-serialization derives; hand
seams (cli_run, interpreter, bins, test mods) repointed per direction —
host-internal std maps stay std. fmt + clippy -D warnings green across all
targets. Run-to-run artifact nondeterminism predates this change (open
v2.std.determinism thread), verified by pre-change A/B.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Persistent carriers: lists+sets -> im_rc Vector/OrdSet; delete clone-fallback guard + per-site move licenses

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix import order in v2 manual ownership_movable mirror (imports precede items)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* Fix sweep-corrupted emit golden; inhabitant import_path rows prelude-provided (generation-agnostic)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Merge origin/main into session/sharp-wolf-473

Resolves #6269 test-migration collision: accept main's deletion of
src/v1/ownership_movable_test.dag (v2 manual mirror carries the license-removal
edit); reconcile dag_collect_fingerprint_witness.rs bin with im_rc carriers
(hashes -> Rc<im_rc::Vector>, Node children/params via .into()).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Review fixes: interpreter Value::Set -> im_rc::OrdSet; emit_non_empty_wrappers BTreeSet alias; stale guard comment

Addresses PR #6307 review findings (cursor/composer-2.5 + claude-opus-4-7):
- v1_interpreter.rs: Value::Set was std BTreeSet (forked from runtime im_rc::OrdSet)
  and deep-cloned on every set_insert/set_union. Migrated to im_rc::OrdSet, closing
  the live model<->realization fork and the O(n) clone (now O(1) structural + O(log n)
  COW). Makes runtime_rust.dag's 'one realization with Value::Map/List/Set' true.
- 05_emit_rust.dag emit_non_empty_wrappers: std::collections::BTreeSet -> bare BTreeSet
  alias (matches the seed + prelude OrdSet alias; forward-compatible; kills the
  bidirectional regen hazard).
- v1_rt.rs: fixed the stale rc_map_insert sibling comment that still claimed lists/sets
  'remain O(n)-copy carriers and keep the guard'.

Seed-emitter import drift (emit_prelude/emit_main_mod_uses/rt_header/extdeps JSON still
emit std) is the coherent-whole emitter-fix-needs-2-gens cutover: pre-existing on main
(maps PR), tracked against RegenVerifyGate #5873, coordinated with regen lane
(loyal-dove-903). Not fixable as isolated import swaps (emitted runtime bodies need
focus/push_back/VecCompat + the trait emission itself).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Revert speculative import addition in network_identity_subsumption (refusal is a pre-existing alias-expansion deficit, A/B-verified on the pre-diff binary)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* Back-port #6329's operator-signed DESIGN.md edits into design_document.dag; corpus import hygiene; artifact regens

The compile-clean and artifact-drift gates, unmasked by #6331's floor speedup,
found accumulated debt: 43 unlisted-import diagnostics (12 files, mechanical
import-list additions), the network_identity param typed to the alias it
actually receives (DhcpClientHostNameOption12), and DESIGN.md drifted from its
generating authority because #6329 hand-edited the artifact without
back-porting (receipt: main_wet now regenerates DESIGN.md byte-identical to
the committed operator-signed version). falsifier.yml/.gitignore regens are
main_wet output. The complexity_r1 citation-string repoints are reverted out
of this PR: touching those files enrolls a fixture whose lens hits a
pre-existing fold_list lambda-param typing deficit (no field 'label' on 'T');
moved to follow-up with that deficit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* complexity_r1 lens: type the children fold on the demand path (builtin fold idiom); keep truthful post-deletion citations

The diff-scoped discovery frontier (enrolled via the v2.std.diagnostic import
fix) demand-resolves this lens; fold_list<T,A> over n.children left T
un-instantiated on that path (no field 'label' on 'T') while batch reconcile
typed it fine — a batch/demand inference divergence. The children fold now
uses the builtin fold idiom fact_density.dag already uses (resolves on both
paths, receipt: complexity_r1_green_merge_envs_base_holds witness green by
execution); the registry fold_list over a concrete FreeMonoid in the same
module types fine and stays.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* Revert "WIP: emit -> realization"

This reverts commit 3ad16c9.

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* intern_str build-green: list-get resolves Optional via free_monoid_collection get template

Root cause of the list-get-by-index inference deficit: free_monoid_collection_templates
(the List method table in dag/std/algebra.dag) declared first/last returning
OptionalOf<ReceiverElement> but had NO get row — so `list |> get(index)` never resolved
structurally and its result type defaulted to the receiver (FreeMonoid), leaving the match
Bind arm un-Some-wrapped. Map-get works because PartialFunction declares get: fn(K) -> V?.

- dag/std/algebra.dag: add get: [ReceiverSelf, Int] -> OptionalOf<ReceiverElement> row,
  mirroring the existing first/last rows (completes the model, mints nothing). [already committed]
- src/v1/stage0/src/std_algebra.rs: splice the get template into the seed so the running
  binary's inference resolves list-get as Optional.
- src/v1/00_core.dag: intern_str now matches explicit Present/Absent (was catch-all
  `other => other` which binds the whole Option); emits Some(s)/None, builds green.

Fresh-crate cargo check: 26 -> 2 errors; the 2 remaining are the single std_integer Nat
where-refinement alias-resolution root (Nat<Magnitude>). intern_str builds.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* seed-prime: sorted_map_keys builtin (registry + bridge + runtime generator)

Functional gen-0' prime of the new sorted_map_keys builtin across the 3
remaining seed twins (v1_rt.rs fn + infer arms already present):
- v1_compiler_infer_method.rs: builtin_function_registry row (type = list of collection_element, mirrors map_keys)
- extdeps_languages_rust_emit.rs: rt bridge row (passes_by_ref+wraps_result, mirrors map_keys)
- v1_compiler_runtime_rust.rs: runtime-generator emits the fn body after map_keys

Enables the 2-gen bootstrap: regen_stage0 built from this seed can resolve/
emit sorted_map_keys, so a fresh regen produces the canonical seed. Ordering
within gen-0' is irrelevant; canonical order comes from runtime_rust.dag:177.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* fix: .dag emits im-rc dep + qualified std::collections::BTreeSet for stage0_core/emit_core boundary files (workspace build)

* test: build_movable_set 2-arg (empty param_names) — align stale test with .dag authority

The .dag defines build_movable_set(proof, param_names) as 2-arg; main's seed
carried a stale 1-arg divergence and pipeline.rs was written against it.
accept-fresh correctly converged the seed to the 2-arg .dag form, so the
hand-maintained test crate call needed updating. param_names only extends
movability to sole-owned params; empty set = the param-blind count the
movable_but_cloned<=45 ratchet was calibrated against.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Brian Searls <briansrls@gunb.ai>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant