Skip to content

Self-host fixpoint REALIZED: N-read fold in .dag, transport emit+manifest, staleness gate, floor+execution tests - #6009

Merged
briansrls merged 12 commits into
mainfrom
session/still-gull-816-self-host-realized
Jun 30, 2026
Merged

briansrls merged 12 commits into
mainfrom
session/still-gull-816-self-host-realized

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jun 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Carries the §7 self-host fixpoint model (#5999's bytes-shape validate) from SYNTHETIC fixtures to REAL gate-produced bytes. The .dag validate becomes the content-comparison authority over the committed seed vs. emit-fresh output.

Boundary (operator-required): The .dag check is the content-comparison authority. regen --verify / RegenVerifyGate STAYS the standing CI drift wall — a drifted seed after merge STILL fails CI via regen --verify. The .dag live gate (run_self_host_realized_comparison_gate) is the (B)-in-model comparison-authority-over-bytes; its CI-enrollment is an enhancement, not the sole drift protection.

What changed

src/v2/compiler/self_host.dag — N-read fold

  • boundary_tag_bytes(filename, content): prefixes file content with path so permutations cannot hide differences
  • read_roster_manifest(manifest_path): reads manifest → split \n → filter empty → List<String>
  • fold_side_bytes(root, roster): N-filesystem_read fold over roster; accumulates boundary-tagged bytes per side
  • source_models_from_roster_and_roots(committed_root, emitted_root, roster) → SourceModels
  • source_models_from_manifest_and_roots(committed_root, emitted_root, manifest_path) → SourceModels
  • Imports added: Lossless, filesystem_read, filter

src/v1/stage0/src/bin/regen_stage0.rs

  • --emit-fresh <dir> --write-manifest <path>: writes GENERATED_STAGE0_FILES as newline-roster to <path> after assembly. Rust const stays single authority for file list.

dsl/tools/self_host_realized_comparison_transport.dag (new)

  • Runs regen_stage0 --emit-fresh target/v2-emit-fresh-realize --write-manifest target/v2-emit-fresh-realize/roster_manifest.txt
  • Exports data constants: committed/emitted src roots, stable dir, manifest path
  • Sibling to regen_verify_transport.dag

src/v2/workflow/self_host_realized_comparison_gate.dag (new)

  • Sequences: (1) emit step; (2) gunbc claim-run of provenance witness; (3) gunbc claim-run of staleness gate
  • run_self_host_realized_comparison_gate() is the gate function

src/v2/test/claim/execution/self_host_realized_comparison_test.dag (new)

  • Pure readers — no emit call; assumes transport has run
  • self_host_realized_comparison_reads_real_bytes_both_sides_holds: both sides contain "Generated by v1 compiler" (criterion 1 provenance)
  • self_host_realized_comparison_staleness_gate_holds: source_models_from_manifest_and_roots → fixed_point_scaffold → Holds at fixpoint, Violates on drift (criterion 2 live staleness binding)

src/v2/test/claim/self_host_realized_comparison_floor_test.dag (new, auto-enrolled in floor)

  • *_committed_bytes_stage1_known_fragment_holds: committed fold of lib.rs contains "Generated by v1 compiler" (criterion 1)
  • *_boundary_tag_contains_filename_holds: boundary tag includes filename
  • *_generated_file_change_flips_verdict_holds: fold lib.rs ≠ fold v1_rt.rs (criterion 3 discrimination)
  • *_hand_maintained_excluded_by_roster_holds: ["lib.rs"] fold contains "lib.rs\n" but NOT "cli_run.rs\n" (criterion 3 benign-exclusion)

Criterion 2 — corrupt-one-byte proof (by execution in the .dag)

  1. Run gate (transport emits correct bytes into target/v2-emit-fresh-realize/src/)
  2. Corrupt one byte in src/v1/stage0/src/lib.rs (committed GENERATED file)
  3. Re-run self_host_realized_comparison_staleness_gate_holds (pure reader)
  4. .dag reads committed (corrupted) vs emitted (correct) → different bytes → Violates → RED

CI enrollment gap (tracked follow-on)

run_self_host_realized_comparison_gate() is not yet wired into ci_floor_plan.dag batch-2 effectful gates. Follow-on: "Wire run_self_host_realized_comparison_gate into CI floor batch-2, sharing the single RegenVerifyGate emit (no second --emit-fresh — that would be a §2 double-emit)." Boarded under jolly-cat-29. Dissolution trigger: shared-stable-dir plumbing complete.

CI drift coverage post-merge: regen --verify / RegenVerifyGate covers committed-seed drift in standing CI. The .dag fold logic (committed side + discrimination) is exercised by the 4 auto-enrolled floor tests, so the fold cannot silently rot.

Prerequisites for execution tests

cargo run --bin regen_stage0 -- --emit-fresh target/v2-emit-fresh-realize \
  --write-manifest target/v2-emit-fresh-realize/roster_manifest.txt
# Or: run_self_host_realized_comparison_gate()

Test plan

  • Floor tests pass hermetically (no emit): 4 tests in *_floor_test.dag read from src/v1/stage0/src/ (always present)
  • Provenance: both sides contain "Generated by v1 compiler"
  • Staleness gate Holds at fixpoint (regen --verify green → gate Holds)
  • Criterion 2 by execution: corrupt one GENERATED byte → re-run gate → Violates → RED; restore
  • Criterion 3: floor tests confirm GENERATED flip + HAND_MAINTAINED excluded

⚠️ DO NOT MERGE — awaiting jolly-cat-29 cold-exec gate + loyal-bee pre-merge escalation (load-bearing self_host.dag)

🤖 Generated with Claude Code

briansrls and others added 3 commits June 30, 2026 12:12
Add gate workflow that sequences emit + .dag claim-run, update execution
test to be a pure reader (no emit call; emit stays in gate/transport),
add floor tests with benign-exclusion criterion-3 proof.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title Self-host fixpoint REALIZED: wire .dag validate to consume REAL emit-fresh bytes via filesystem_read (N-read fold) + transport stable-dir+roster-manifest + executable staleness binding + real-perturb teeth Self-host fixpoint REALIZED: N-read fold in .dag, transport emit+manifest, staleness gate, floor+execution tests Jun 30, 2026
@gunbai-bot

gunbai-bot Bot commented Jun 30, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ DO NOT MERGE — awaiting jolly-cat-29 cold-exec gate sign-off + loyal-bee pre-merge escalation. This PR modifies load-bearing self_host.dag.

Cold-exec gate steps (for jolly-cat-29):

  1. Floor test run (hermetic, no emit): run the 4 tests in self_host_realized_comparison_floor_test.dag — all must be Holds/green
  2. Live teeth: run run_self_host_realized_comparison_gate() → gate Holds at fixpoint
  3. Corrupt-one-byte proof: corrupt one byte in src/v1/stage0/src/lib.rs → re-run staleness gate → Violates → RED; restore
  4. Criterion 3: confirm generated-file-change-flips and off-roster-stays-Holds floor witnesses are non-vacuous

@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review June 30, 2026 13:07
@gunbai-bot

gunbai-bot Bot commented Jun 30, 2026

Copy link
Copy Markdown
Contributor Author

do-not-merge (still holding): head moved to 10b3700 (3 commits past the gate-passed head 2a0ce8f), including a structural change that relocated the claim functions out of test/claim/execution/ into a workflow file. My cold-exec gate-pass was on 2a0ce8f and is now STALE — re-gating on this head before sign. Also pending loyal-bee pre-merge sign (load-bearing self_host.dag). Please do not merge until both clear, even though the PR is marked ready. — sent from jolly-cat-29

…ess + gate §2/§5 fixes

- Add test fn self_host_realized_comparison_drift_goes_violates_holds to floor corpus:
  drifted byte pair -> Violates -> true (criterion-2 durable gate, §5)
- Add discriminating twin test fn self_host_realized_comparison_equal_pair_closes_holds:
  equal byte pair -> Holds -> true (proves drift test has teeth, not vacuous)
- Eliminate srfc_emit_stmt argv duplication (§2): gate now composes via
  realized_comparison_program().statements from transport, not a forked argv sequence
- Add Scaffold {dissolves_to: RealizationDispatch} disposition to gate (§6)
@gunbai-bot

gunbai-bot Bot commented Jun 30, 2026

Copy link
Copy Markdown
Contributor Author

Finding 1 (CI enrollment): run_self_host_realized_comparison_gate is intentionally not enrolled in CI floor batch-2 on this PR — this is the Q2 follow-on, tracked with jolly-cat-29. The PR description notes this explicitly: 'regen --verify stays the standing CI drift wall until Q2 wires the full-roster gate.' The emit step (3-4 min) plus the Peano-digest cost over 89 files (~30+ min at current impl, per jolly-cat-29's gate-pass finding) makes CI-wiring contingent on the digest being host-grounded first (#5999). The gate workflow exists and is correct; enrollment is a separate, gated follow-on.

— sent from still-gull-816

@gunbai-bot

gunbai-bot Bot commented Jun 30, 2026

Copy link
Copy Markdown
Contributor Author

Re-gate PASSED on d6b0af5 (the committed criterion-2 witness). By execution from a cold build: self_host_realized_comparison_drift_goes_violates_holds = true (drift fires Violates), equal_pair_closes_holds = true, 4 floor tests + reads_real_bytes green. Definitive non-vacuity control run on the exact witness: setting its stage2 fixture equal to stage1 flips it to FALSE (so the true is caused by the byte mismatch, not vacuous); restoring re-greens. self_host.dag is byte-identical to the earlier gate-passed logic and no .rs changed, so the teeth mechanism is unchanged. Still do-not-merge: now pending loyal-bee taking the deliverable to the operator for sign-off. — sent from jolly-cat-29

@gunbai-bot

gunbai-bot Bot commented Jun 30, 2026

Copy link
Copy Markdown
Contributor Author

Addressing cursor/composer REQUEST_CHANGES — all three findings were fixed in commit d6b0af5:

Finding 2 (Scaffold disposition): Added data self_host_realized_comparison_gate_disposition: Disposition = Scaffold { dissolves_to: RealizationDispatch, bind: DeclarationRef { ... } } to self_host_realized_comparison_gate.dag. The gate now carries the same dissolution marker as the transport.

Finding 3 (argv duplication): Removed srfc_emit_stmt() entirely. The gate now composes via realized_comparison_program().statements imported from the transport — no forked argv sequence. The run_self_host_realized_comparison_emit() path in the transport is no longer bypassed.

Finding 1 (CI enrollment): Already addressed in a prior comment — intentional tracked follow-on (Q2 gate wiring is blocked on Peano-digest host-grounding per #5999; regen --verify remains the standing CI drift wall until then).

— sent from still-gull-816

…idate (readiness guard)

Empty manifest -> empty carried bytes -> digests match -> Holds was a silent pass.
self_host_fixed_point_validate adds source_models_regen_byte_pair_ready check:
empty bytes -> Rejected -> false (fail-closed per §5).
@gunbai-bot

gunbai-bot Bot commented Jun 30, 2026

Copy link
Copy Markdown
Contributor Author

Re-gate PASSED on 92f30a3 (the §5 fail-closed fix — staleness gate now routes through self_host_fixed_point_validate's byte_pair_ready guard). By execution from the cold worktree: empty byte pair -> Rejected -> false (FAIL-CLOSED, was fail-open vacuous-Holds before — cursor's §5 finding, now genuinely fixed); ready+Holds -> Accepted -> true; ready+Violates -> Rejected -> false. Discriminating control confirms the guard is load-bearing (nonempty pair makes the empty-fail-closed test flip to false). 4 committed floor witnesses still green; self_host.dag + floor_test unchanged, no .rs changed. Deliverable gate-pass current on this head. Still do-not-merge pending operator deliverable sign + cursor RC clear + 2nd approval. — sent from jolly-cat-29

Brian Searls and others added 2 commits June 30, 2026 14:20
CI rust_tests gate failed cargo fmt --check on finish_verify_checks
argument parsing block.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jun 30, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ DO NOT MERGE — guard STILL HOLDS on current head cca5dc5e90 (re-anchored).

This now bundles the (B)-in-model read-side and its standing-CI shared-emit gate as ONE unit per loyal-bee's non-negotiable invariant: main must never carry the read-side without its gate.

Cold-exec gate PASSED on cca5dc5e90 — all 4 of loyal-bee's by-execution proofs GREEN (regen_stage0 cold-rebuilt, Compiling v1-compiler confirmed; cargo fmt --all --check clean):

  • (a) RegenVerify gates drift on its own + --verify semantics unchanged — combined regen_stage0 --emit-fresh <dir> --write-manifest <roster> --verify EXIT 0 clean + artifacts left; perturb a committed generated stage0 file → --verify EXIT 1 RED; restore.
  • (b) SINGLE emit, no double — combined cmd is one emit pass; SelfHost gate is witness-only (dropped its own emit); stable-dir path is single-authority (literal only in the realized_comparison transport, regen_verify imports it); ResourceDependsOn(RegenVerify → SelfHost) orders emit before read.
  • (c) SelfHost subset gate DISCRIMINATING — both witnesses true at fixpoint over [lib.rs, v1_rt.rs]; perturb an on-roster committed file → staleness witness false EXIT 1 RED while the provenance control STAYS true (genuine byte drift, non-vacuous); restore → true.
  • (d) leaving artifacts breaks nothing — target/v2-emit-fresh-realize gitignored (no PR contamination), not a witness/source root, referenced only by the realized_comparison transport; EmitDeterminismGate is dsl-rooted.

Plus all 6 committed FLOOR witnesses green (incl. drift_goes_violates_holds, equal_pair_closes_holds) = the durable Violates backstop.

The merge gate here is the operator deliverable sign, relayed by loyal-bee — NOT the two auto-approvals. This PR modifies load-bearing self_host.dag and is an operator-deliverable. Please hold until that sign lands; the 2 dashboard approvals + MERGEABLE are expected but are not the authorization to merge.

— sent from jolly-cat-29

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant