Skip to content

Unbreak v1 self-resolution after #6242: hoist .dag comments to data rows + dag_collect registry dedup - #6262

Merged
briansrls merged 1 commit into
mainfrom
sharp-deer-310/unbreak-regen-6242
Jul 5, 2026
Merged

briansrls merged 1 commit into
mainfrom
sharp-deer-310/unbreak-regen-6242

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jul 5, 2026

Copy link
Copy Markdown
Contributor

Main's regen wall went red again with #6242 (third instance of the merge-while-CI-dark class this week). Two independent breaks, both fixed here with local receipts:

  1. Registry partition violation: P1 emit fix: dag_collect O(n^2) fingerprint memo #6242 added v1_compiler_dag_collect{,_support}.rs to HAND_MAINTAINED (to carry the hand-edited Rc::as_ptr memo, per its own comment) but left them in GENERATED_STAGE0_FILES — assert_registry_is_partitioned correctly fail-closes, aborting regen before anything runs. Fix: dedup to HAND-only (matching P1 emit fix: dag_collect O(n^2) fingerprint memo #6242's stated intent), with the gunbc.stage0_emit_model .dag mirror + witness pin (92→90) updated to match.

  2. .dag has no comment syntax (since Parser-wall: remove DAG comment trivia rules (fail-closed by construction) #5579): P1 emit fix: dag_collect O(n^2) fingerprint memo #6242 added three // comment blocks to dag_collect.dag / dag_collect_support.dag → expected expression, found Slash + expected item declaration, taking both modules down and cascading into 65 hard diagnostics (v1.compiler.dag_collect* unresolved; json_quote/dag_node_key/is_module_shell_node/collect_dag_nodes not in scope across compile.dag). Fix: hoist all three blocks to typed data ...: String rows (the post-Parser-wall: remove DAG comment trivia rules (fail-closed by construction) #5579 convention), content preserved verbatim — including both Dissolve-on markers.

Receipts (local; CI floor dark by operator-accepted 10-min interim)

Root-cause pattern for the operator: this is the third corpus merge in four days (#6235, #6241, #6242) that broke v1 self-resolution invisibly because the floor can't complete inside its budget. Until the compile-clean wall shrinks, a cheap norm would prevent recurrence: corpus-touching PRs carry a local regen_stage0 self-compile receipt in the body.

🤖 Generated with Claude Code

…ed data rows, dedup dag_collect registry (GENERATED -> HAND-only)

#6242 added // comments to dag_collect.dag / dag_collect_support.dag — .dag has no comment syntax since #5579, so the corpus stopped parsing (Slash diagnostic + 64 cascade errors: modules unresolved, json_quote/dag_node_key/is_module_shell_node not in scope) — and left v1_compiler_dag_collect{,_support}.rs in BOTH regen registries, which assert_registry_is_partitioned correctly fail-closes on. Both breaks were invisible: CI floor dark (10-min interim) and regen was already red from #6235/#6241 when #6242 merged.

- comments -> typed data rows (dag-no-comment convention), content preserved verbatim including both Dissolve-on markers
- registry dedup: dag_collect pair GENERATED->HAND-only (matches #6242's intent comment: hand-edited seed carries the Rc::as_ptr memo until grounded)
- .dag roster mirror (gunbc.stage0_emit_model) deduped to match; witness pin 92->90

Receipts (local; CI dark): regen self-compile 0 hard diagnostics (was 2-layer red: registry assert, then 65 diagnostics); --verify now reaches byte-compare and reds only on the PRE-EXISTING latent emitter drift (the 1667-error cutover backlog, tracked on the 5-regen-cutover carrier).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@briansrls
briansrls merged commit 9e7c3c1 into main Jul 5, 2026
0 of 2 checks passed
@briansrls
briansrls deleted the sharp-deer-310/unbreak-regen-6242 branch July 5, 2026 03:39
briansrls added a commit that referenced this pull request Jul 5, 2026
needs:[rust_tests] was forcing a second full v1-compiler release build in the
ci job, exhausting the 10m budget before claim_executor started. Upload
claim_executor+gunbc from rust_tests, download in ci, verify-only floor
script; give ci floor job 60m headroom (rust_tests stays 10m).

Also drops the erroneous WIP regen_stage0 dedup commit — that partial

Co-authored-by: Cursor <cursoragent@cursor.com>
#6242 registry fix belongs in #6262, not #6243.
briansrls pushed a commit that referenced this pull request Jul 5, 2026
briansrls added a commit that referenced this pull request Jul 5, 2026
CI ci job @ 182e4a0: rust_tests green; floor timed out in batch-1
dag_compile_clean (~7m+). Main carries emit O(n^2) memo and #6250/#6262
fixes that shrink the binding resolve+typecheck+emit axis.
gunbai-bot Bot pushed a commit that referenced this pull request Jul 5, 2026
Brings in #6262 self-resolution unbreak + dag_collect dedup so the
10-minute ci job can complete claim_executor; no contract.dag reconcile
needed (LensContract row already dropped).
briansrls pushed a commit that referenced this pull request Jul 5, 2026
briansrls pushed a commit that referenced this pull request Jul 5, 2026
CI was cancelling (not failing) at the 10-minute job kill during
dag_compile_clean_gate — zero gate verdict, same class of silent pass
the fix/floor-timeout-verdict lane addresses. Cherry-pick the operator
ruling: 30-minute step budgets on gate-bearing steps, 60-minute job
backstop, and sync ci.yml to dag/gunbc/ci_workflow.dag authority.
Also merge #6262 (dag_collect comment hoist) needed for regen health.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 5, 2026
…ment wave-1, cutover pre-reqs, CI step-budget posture)

Authority refresh after 2026-07-05's merges, ROADMAP.md regenerated via main_wet: spine marks #6255/#6262/#6243 landed and NOW = post-#6243 re-measure -> cutover #1 (pre-reqs #6243 + #6270 backfill met, defensive sweep pending); regen-cutover carrier gets the root-cause update (1482/1667 = one field_is_boxed predicate bug, receipt must be re-earned post-retraction); test-migration carrier gets #6261 + wave-1 (912->881 fns); ground truth: HAND roster 7->9 (dag_collect pair, #6262), GENERATED 92->90, CI INTERIM restated for #6273's loud step budgets. ci.yml: fold the 1-byte trailing-newline regen delta so committed == generated. All roadmap_authority_test pins verified against the regenerated projection (ALL PINS OK).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 5, 2026
…he live registry authority (7 HAND / 92 GENERATED)

The 9-HAND/90-GENERATED claims described the state between #6262 and #6239 — #6239 returned the dag_collect pair to GENERATED (verified: regen_stage0.rs GENERATED includes the pair, HAND count 7, stage0_emit_model witness pins 92). Ground truth now records the full history (#6262 HAND-only -> #6239 GENERATED again), the drain carrier drops the pair as a HAND target (its content_hash grounding stays tracked by the .dag dissolve-on rows), and terminal collapse is back to 92. Consistency proven by assertion over the regenerated projection: no 90/9-file/22.6k string survives, exactly one 7-file count, pins intact.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 5, 2026
…tirement wave-1, CI step-budget posture (#6287)

* WIP: continue work on v1 burn down

* WIP: continue work on v1 burn down

* WIP: continue work on v1 burn down

* WIP: continue work on v1 burn down

* Drop get-form revert per operator collision resolution (#6255 owns the get arm); regen ROADMAP projection

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: continue work on v1 burn down

* WIP: continue work on v1 burn down

* Fix roadmap_authority_test pins: track the 2026-07-05 ground-truth refresh (cursor RC) + repoint pre-existing-stale charter-adjacency pin

witness_b_ordered_interleaving pinned the pre-refresh prose (Ground truth 2026-07-01 date + old walls sentence); updated to the refreshed authority. Also fixed a pin this PR did NOT stale: the charter->core-design-rule adjacency has been red on main since [host-converge inventory] was appended after [charter] — repointed to the real paragraph tail. Discriminator date kept in lockstep. All pins verified against the regenerated ROADMAP.md (byte-identical projection).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: continue work on v1 burn down

* §1 roadmap receipts: today's landings (emitter mass fix #6243, retirement wave-1, cutover pre-reqs, CI step-budget posture)

Authority refresh after 2026-07-05's merges, ROADMAP.md regenerated via main_wet: spine marks #6255/#6262/#6243 landed and NOW = post-#6243 re-measure -> cutover #1 (pre-reqs #6243 + #6270 backfill met, defensive sweep pending); regen-cutover carrier gets the root-cause update (1482/1667 = one field_is_boxed predicate bug, receipt must be re-earned post-retraction); test-migration carrier gets #6261 + wave-1 (912->881 fns); ground truth: HAND roster 7->9 (dag_collect pair, #6262), GENERATED 92->90, CI INTERIM restated for #6273's loud step budgets. ci.yml: fold the 1-byte trailing-newline regen delta so committed == generated. All roadmap_authority_test pins verified against the regenerated projection (ALL PINS OK).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: continue work on v1 burn down

* Fix cursor RC on #6287: 5-dissolve-patches carrier now matches ground truth (9 HAND files / ~22.6k; dag_collect pair slotted into the drain order with its content_hash dissolution)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: continue work on v1 burn down

* Fix cursor RC round 2 on #6287: roster receipts re-grounded against the live registry authority (7 HAND / 92 GENERATED)

The 9-HAND/90-GENERATED claims described the state between #6262 and #6239 — #6239 returned the dag_collect pair to GENERATED (verified: regen_stage0.rs GENERATED includes the pair, HAND count 7, stage0_emit_model witness pins 92). Ground truth now records the full history (#6262 HAND-only -> #6239 GENERATED again), the drain carrier drops the pair as a HAND target (its content_hash grounding stays tracked by the .dag dissolve-on rows), and terminal collapse is back to 92. Consistency proven by assertion over the regenerated projection: no 90/9-file/22.6k string survives, exactly one 7-file count, pins intact.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 4, 2026
…w-value prose

Banning // made comment syntax unwritable but not commentary unwritable.
It removed the only structural signal separating commentary from program
data, so the corpus smuggled prose into data String rows where intent is
mechanically undecidable. Verified as three merged PRs:

  #5579 f9cc238  remove DAG comment trivia rules
  #6262 9e7c3c1  hoist .dag // comments to typed data rows
  #6424 c14e001  sweep 215 dead prose data-String rows

Reframes the destination as a modeled source annotation -- a sidecar on
ParseArtifact, never restored trivia, never a namespace binding -- with
the semantic/authored-source projection pair as the load-bearing law.

Corrects the sample's standing: #6424 swept 215 dead rows before it was
drawn, so it measures survivors and cannot refute the dead population or
settle representation. Value and representation are independent axes: a
note can be irreducible and still wrong as data Foo: String.

Replaces D1-D4 (delete rate, ceilings) with D-A..D-D (carrier,
attachment, erasure, migration). Carries the proposed DESIGN paragraph
for review without landing it. Nothing deleted, migrated, or reconciled.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Aug 4, 2026
…urce data (audit complete, D-A..D-D ruled) (#7797)

* WIP: prose cleanup

* Add the reconciliation worklist section to the prose policy audit

Where a split pass would start: 50% of the time-bound marker mass sits
in 63 of 617 files, and 124 mega-notes carry a marker between them.
Names the two head files that are load-bearing per DESIGN so they do
not lead the pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Recut the prose audit: the defect is lost source-level intent, not low-value prose

Banning // made comment syntax unwritable but not commentary unwritable.
It removed the only structural signal separating commentary from program
data, so the corpus smuggled prose into data String rows where intent is
mechanically undecidable. Verified as three merged PRs:

  #5579 f9cc238  remove DAG comment trivia rules
  #6262 9e7c3c1  hoist .dag // comments to typed data rows
  #6424 c14e001  sweep 215 dead prose data-String rows

Reframes the destination as a modeled source annotation -- a sidecar on
ParseArtifact, never restored trivia, never a namespace binding -- with
the semantic/authored-source projection pair as the load-bearing law.

Corrects the sample's standing: #6424 swept 215 dead rows before it was
drawn, so it measures survivors and cannot refute the dead population or
settle representation. Value and representation are independent axes: a
note can be irreducible and still wrong as data Foo: String.

Replaces D1-D4 (delete rate, ceilings) with D-A..D-D (carrier,
attachment, erasure, migration). Carries the proposed DESIGN paragraph
for review without landing it. Nothing deleted, migrated, or reconciled.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Land the source-annotation policy in DESIGN.md 4c; rule D-A..D-D

Canonical guidance lands through gunbc.design_document section_4c_blocks
with DESIGN.md regenerated, never hand-edited. The rule: prose is not
forbidden; unclassified prose is. // becomes the explicit quarantine
boundary.

Four structural corrections to the destination:

  2a  a THIRD lexical channel (AnnotationRule), not an ordinary
      TokenRule -- a token still joins the semantic stream and buys
      parser filtering, token-order effects, allocator risk
  2b  AuthoredParseArtifact WRAPS the semantic artifact rather than
      widening it, so ordinary compilation receives a type that cannot
      hold annotations; erasure becomes structural. The equality law is
      over the semantic graph projection, excluding textual provenance,
      because inserting a comment necessarily moves byte ranges
  2c  an annotation must NOT consume a semantic OccurrenceId -- the
      allocator is graph-scoped, so a comment could shift declaration
      identities in the same source and in later modules. First carrier
      has no annotation identity; ordered graph carries multiplicity
  2e  attachment narrows to module-item grain only, with an explicit
      AnnotationPlacement observation so trailing stays distinguishable
      after whitespace removal

D-D approved debt-only: SourceAnnotationRationale is not declared in
Slice 1, since a variant with no authoring path or consumer is
speculative vocabulary.

Doc-graph row rebinds from the generic StandingIntent to the seams this
work actually changes: LexRule, ParseArtifact, dag_line_comment_fidelity,
dag_comment_wall_line_comment_refused.

Nothing deleted, migrated, or reconciled; no slice started.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Align the doc-graph dissolution trigger with the ruled D-A/D-C design

review 48112 (cursor/composer-2.5) caught the trigger naming TokenRule
as the target carrier -- the design D-A explicitly rejects. The trigger
was authored before the operator's correction and not updated with the
audit doc and DESIGN 4c, so a typed scaffold marker was steering Slice 2
at the wrong carrier.

Fixes a second stale claim in the same string the review did not reach:
"semantic-erasure proven by identical emitted bytes". Byte equality is
exactly what D-C says is insufficient -- the emitter may ignore
occurrence ids and stay byte-identical while the identity graph moves.
The trigger now names the seven D-C proofs instead.

Trigger now states: AnnotationRule on a third lexical channel (never
TriviaRule, never TokenRule), authored wrapper over an unchanged
semantic artifact, no semantic occurrence identity consumed, module-item
attachment with trailing/body/unattached/block refusing, erasure by the
seven D-C proofs, and the representation partition complete.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
…rasure (#7807)

* WIP: prose cleanup

* Add the reconciliation worklist section to the prose policy audit

Where a split pass would start: 50% of the time-bound marker mass sits
in 63 of 617 files, and 124 mega-notes carry a marker between them.
Names the two head files that are load-bearing per DESIGN so they do
not lead the pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Recut the prose audit: the defect is lost source-level intent, not low-value prose

Banning // made comment syntax unwritable but not commentary unwritable.
It removed the only structural signal separating commentary from program
data, so the corpus smuggled prose into data String rows where intent is
mechanically undecidable. Verified as three merged PRs:

  #5579 f9cc238  remove DAG comment trivia rules
  #6262 9e7c3c1  hoist .dag // comments to typed data rows
  #6424 c14e001  sweep 215 dead prose data-String rows

Reframes the destination as a modeled source annotation -- a sidecar on
ParseArtifact, never restored trivia, never a namespace binding -- with
the semantic/authored-source projection pair as the load-bearing law.

Corrects the sample's standing: #6424 swept 215 dead rows before it was
drawn, so it measures survivors and cannot refute the dead population or
settle representation. Value and representation are independent axes: a
note can be irreducible and still wrong as data Foo: String.

Replaces D1-D4 (delete rate, ceilings) with D-A..D-D (carrier,
attachment, erasure, migration). Carries the proposed DESIGN paragraph
for review without landing it. Nothing deleted, migrated, or reconciled.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Land the source-annotation policy in DESIGN.md 4c; rule D-A..D-D

Canonical guidance lands through gunbc.design_document section_4c_blocks
with DESIGN.md regenerated, never hand-edited. The rule: prose is not
forbidden; unclassified prose is. // becomes the explicit quarantine
boundary.

Four structural corrections to the destination:

  2a  a THIRD lexical channel (AnnotationRule), not an ordinary
      TokenRule -- a token still joins the semantic stream and buys
      parser filtering, token-order effects, allocator risk
  2b  AuthoredParseArtifact WRAPS the semantic artifact rather than
      widening it, so ordinary compilation receives a type that cannot
      hold annotations; erasure becomes structural. The equality law is
      over the semantic graph projection, excluding textual provenance,
      because inserting a comment necessarily moves byte ranges
  2c  an annotation must NOT consume a semantic OccurrenceId -- the
      allocator is graph-scoped, so a comment could shift declaration
      identities in the same source and in later modules. First carrier
      has no annotation identity; ordered graph carries multiplicity
  2e  attachment narrows to module-item grain only, with an explicit
      AnnotationPlacement observation so trailing stays distinguishable
      after whitespace removal

D-D approved debt-only: SourceAnnotationRationale is not declared in
Slice 1, since a variant with no authoring path or consumer is
speculative vocabulary.

Doc-graph row rebinds from the generic StandingIntent to the seams this
work actually changes: LexRule, ParseArtifact, dag_line_comment_fidelity,
dag_comment_wall_line_comment_refused.

Nothing deleted, migrated, or reconciled; no slice started.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Align the doc-graph dissolution trigger with the ruled D-A/D-C design

review 48112 (cursor/composer-2.5) caught the trigger naming TokenRule
as the target carrier -- the design D-A explicitly rejects. The trigger
was authored before the operator's correction and not updated with the
audit doc and DESIGN 4c, so a typed scaffold marker was steering Slice 2
at the wrong carrier.

Fixes a second stale claim in the same string the review did not reach:
"semantic-erasure proven by identical emitted bytes". Byte equality is
exactly what D-C says is insufficient -- the emitter may ignore
occurrence ids and stay byte-identical while the identity graph moves.
The trigger now names the seven D-C proofs instead.

Trigger now states: AnnotationRule on a third lexical channel (never
TriviaRule, never TokenRule), authored wrapper over an unchanged
semantic artifact, no semantic occurrence identity consumed, module-item
attachment with trailing/body/unattached/block refusing, erasure by the
seven D-C proofs, and the representation partition complete.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* M1 slice 1: AnnotationRule third lexical channel, captured with placement

DESIGN 4c requires a comment to reach neither destination the lexer
already has. TriviaRule consumes and emits nothing, so a comment routed
there is invisible to every parser, lens, census and SCM operation.
TokenRule emits into the semantic stream, so a comment routed there
becomes something every parser must filter and sits in the path of
occurrence allocation. This adds the third:

  LexRule = TokenRule | TriviaRule | AnnotationRule

plus UnboundSourceAnnotation (no identity of its own -- binding is the
parser's job, and minting one here would draw from the semantic
occurrence allocator, which 4c forbids), AnnotationPlacement, and
LexArtifact { tokens, annotations }.

lex_walk_artifact is the authored result; lex_walk is its semantic
projection and is what every existing caller keeps using. One traversal
read two ways, derived in that direction only, so a semantic consumer
cannot reach annotation text.

Placement is observed at capture because it cannot be reconstructed:
whitespace is trivia, so once it is gone a trailing comment and a
leading comment on the next declaration are indistinguishable. The walk
tracks line_has_semantic_token -- set by a token, reset by trivia
carrying a line feed.

Adding the variant redded six matches across three files; each got a
real arm rather than a wildcard, which is the closed-coproduct
discipline working as intended.

Green by execution: lex_match_thunk_claims_holds, and all seven
dag_comment_wall_test probes still pass -- line comments in real .dag
source still REFUSE, because the v1 production tokenizer is untouched
until the realization slice.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* M1 slice 2: one std authority for source annotations, not a v1/v2 fork

Correcting slice 1: AnnotationPlacement was declared inside
v2.std.compilers.lexing, and the v1 seed tokenizer cannot import v2
modules -- so realizing the v1 half would have forced a second spelling
of one concept. That is precisely the nicknaming defect this lane
exists to remove, and it would have been minted BY the lane removing it.

dag/std/source_annotation.dag is now the language-agnostic authority.
It names no .dag syntax and no lexical rule; both seeds import it. v1
files already import std.* (std.types, std.occurrence_identity), so the
seam exists.

Carries AnnotationPlacement, SourceAnnotationDebt, SourceAnnotationGraph
(ordered -- order and multiplicity are the whole of an annotation's
identity when rows carry no key), the typed attachment refusals, and
annotation_placement_is_attachable as the single predicate saying the
first cut admits leading only.

SourceAnnotationDebt deliberately has NO identity field. An OccurrenceId
would draw from the graph-scoped semantic allocator, so inserting a
comment could shift declaration identities later in the same source and
in later-parsed modules. `subject` refers; it never mints. Debt is the
type's standing law rather than a variant, so no rationale category
ships without an authoring path or consumer.

v2.std.compilers.lexing keeps only what is lexical and imports the rest.

Green: lex_match_thunk_claims_holds and the comment wall probes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* chore: regenerate drifted generated artifacts (ci auto-heal)

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* chore: regenerate drifted generated artifacts (ci auto-heal)

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* Thread authored artifact through both v1 frontend paths; five D-C erasure controls

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Physical-line placement, admission wall, single frontend seam

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* Regen stage0: emit annotation channel into the seed; fix import + portability defects regen exposed

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* Restore roster rows dropped by generated-file merge; place std.source_annotation in the stage0 crate partition

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* Rename LATER-cased witness: emitted Rust must be snake_case under -D warnings

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)

* WIP: prose cleanup

* WIP: prose cleanup

* P0-1 blank lines split authored blocks; P0-2 lower the claim to its honest rung

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* chore: regenerate drifted generated artifacts (ci auto-heal)

* D-C property 4: establish semantic erasure at the emitted-bytes boundary

The two byte-equality arms could not be enrolled as .dag witnesses, so they
were established by host execution and the measurement recorded in-carrier
rather than dropped.

Measured: annotated and bare twins emit byte-identical Rust across all six
emitted files (exit 0, zero diagnostics), while a real semantic change to the
same bare twin emits different bytes -- so the equality is not a statement
about an emitter that ignores its input. The enrolled arm proves the annotated
fixture really carried prose (2 rows) where its twin carried none.

Why not enrolled: no .dag-reachable surface returns emitted bytes.
compile_to_resolved from interpreted .dag raises `map_keys expects a map, got
Record` in the RESOLVE half -- reproduced on the smallest possible input, so it
is a pre-existing model-versus-realization fork outside this lane, not a
property of the fixture. The working host arms return a Bool and a diagnostic
census; asserting "both twins compile" through the Bool would wear this
property's name while passing for any pair of compiling programs, and adding a
bytes-returning arm would grow hand-maintained cli_run.rs against its hollowing
plan to satisfy a witness. Next trigger named in the carrier.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* Regenerate ci.yml for the new stage0 witness module

Derived-only: the heal exclude list gains
v1_tests_claim_v1_annotation_target_emission_test.rs, projected from the
same stage0 emit roster that regen writes. Committed as author because
workflow paths cannot auto-heal (the App lacks workflows:write).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Regenerate v1_std_core.rs after merging main's function-value call wall

The merge resolved this GENERATED file by taking this branch's copy, which
carries SourceAnnotationRefused but not main's CallNamedArgOnFunctionValue
(#7834) — so the enum lost a variant that main's hand-maintained cli_run.rs
and the generated infer projection both construct, and the workspace stopped
compiling. Regenerated rather than hand-merged: a generated file's authority
is its .dag source, and hand-picking hunks across a merge is how rows go
missing silently.

Both variants are present and the emission is stable across generations.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 19, 2026
…sanctions

Both review findings verified against the code and both are correct.

QUADRATIC FOLD. measurement_run_causes folded over samples while
measurement_sample_causes filtered the whole sample list twice per sample -
once for duplicate detection, once for parent presence - and
measurement_expected_span_causes filtered it once per expected span. Occurrence
count, duplicate, parent presence and expected presence are four questions with
one answer: how many times did this span report? That count is now built in one
pass and the rest are lookups, which is linear. DESIGN section 6 fixes a
cost-shape defect regardless of the realized n, because 'n is small here' is not
a time-stable fact - and a measurement carrier is exactly the thing that will
later be pointed at a run with thousands of spans.

Only lookups are performed against the map, never an iteration, so cause
ordering still follows the sample fold and nothing here becomes an
order-exposing operation.

PROSE ROWS. measurement_subject_rung_note and witness_note were
data ...: String rows, which is the shape 4c names as misplaced or dead data -
mechanically indistinguishable from program data, and the exact convention
#6262 introduced and #6424 had to sweep 215 rows of.

I argued the previous instance of this finding on the grounds that the typed
home did not exist, which was true of the dissolution half and beside the point
for the rest: 4c's sanctioned form for irreducible rationale is a standalone
leading // block attached to a module-scope declaration, and this file already
used that form for its other commentary. Both rows are now such blocks - the
rung note above admit_measurement_run, the witness note above the first helper.
Nothing was deleted; the prose moved to the grain that classifies it as prose.
gunbai-bot Bot pushed a commit that referenced this pull request Aug 27, 2026
…TACHMENT POINT (review 56593)

review 56593 is correct: two `data ..._note: String` rows carrying nothing
but commentary are exactly what DESIGN §4c names as misplaced or dead
semantic data, and §4c's own history says why -- the corpus already tried
hoisting comments into String rows (#6262) and the first cleanup that
forced swept 215 dead prose rows across ~130 files (#6424).

The interesting part is how they got there, because the symptom pointed at
the wrong fix. The first cut wrote these as `//` blocks, and the parser
refused them: they sat INSIDE the `service git.Core { ... }` body, and §4c
admits only standalone leading `//` attached to MODULE-SCOPE declarations.
I concluded `//` was unavailable and changed the carrier. The actual defect
was the attachment point -- git.dag already carries 48 module-scope `//`
blocks, so the annotation channel was available the whole time and I had
measured only that one position was not.

Both rationales now attach to the module-scope ExternalAuthority anchors
for the git commands they describe, which are the declarations whose
subject they actually are.

Verified by execution, and the counter moves in the direction that proves
the point rather than merely not breaking: 4123 files parse-clean, and the
declaration count drops 79438 -> 79436, exactly the two String rows
removed. The prose left the semantic program instead of being reworded
inside it -- §4c's annotation capture is disjoint from semantic occurrence
allocation, so an annotation must not appear in that count at all.

Diff confined to the three intended regions; an incidental whole-file
newline collapse that had removed a blank line under the module header was
reverted.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 27, 2026
…ree and not list one, resolve a ref and not enumerate refs (#9431)

* Model git's two enumeration reads: the substrate could create a worktree and not list one, resolve a ref and not enumerate refs

extdeps.git declares 66 operations and neither `for-each-ref` nor
`worktree list`. The asymmetry is the finding: worktree ADD is modeled in
both its branch and detached forms, so a linked worktree can be CREATED
and never ENUMERATED; ObserveRef resolves one ref the caller already
names, and RemoteBranches returns remote-tracking names only, offline,
with no object id.

Neither gap is a defect in those operations -- they answer "where is this
ref" and "which remote branches does this clone know about". The missing
question is "what is the COMPLETE set, and where does each member point",
and a check built without it is a check over an authored list, which by
construction cannot see an addition.

ForEachRefIn formats NUL-separated fields on newline-separated records.
That is safety rather than convenience: git-check-ref-format(1) forbids
space, newline and ASCII control characters inside a ref name, so a
record cannot be split by its own content, and the symref field is empty
for an ordinary ref -- a trailing empty field must stay observable rather
than collapse into the separator.

It is deliberately a LOGICAL ref read, not a storage read. Whether a ref
lives loose under .git/refs or inside packed-refs is git storage policy
that changes under ordinary maintenance with no ref having moved. Both
directions were measured on srv1: a digest over storage reports a
difference where nothing changed, and misses one where a loose ref
shadows a stale packed entry.

WorktreeListIn uses --porcelain -z, the form git-worktree(1) directs
callers to rather than interpreting paths under GIT_DIR themselves. Each
entry carries absolute path, HEAD, branch-or-detached, and the locked and
prunable standings -- the tuple a preservation comparison needs, none of
it recoverable from the filesystem without re-deciding git's own layout.

Both are readonly and report exit_code + stderr rather than a success
Bool, per this module's integration_write_operations_note: the seed
derives exit_success as exactly exit_code == 0, so carrying both would
represent one fact twice.

Verified: 4123 files parse-clean; declaration count moves 79434 -> 79438,
exactly the four top-level declarations added.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Pin for-each-ref's order in the operation: an unpinned enumeration hashes the same ref set two ways

The projection was already fixed to refname/objectname/symref rather than
taken as a caller format string. The ORDER was not, and for the consumer
this operation exists to serve that is the same defect one step later: a
consumer comparing two enumerations digests them, so an unpinned order
makes the digest a function of git's default ordering rather than of the
ref set, and the same set can hash two ways.

--sort=refname is pinned in the operation for that reason, and refname
specifically because it is the one field guaranteed unique across the
set -- which makes the order total rather than merely deterministic.

Also records why there is no -z here. git-for-each-ref(1) documents no -z
option; the NUL separator comes from %00 inside its own format language.
Spelling a -z that upstream does not have would be a fabricated
interface: it would fail at the transport rather than in review, and the
extdeps duty is to model what the tool actually accepts. WorktreeListIn
does carry -z because git-worktree(1) documents it.

Verified: 4123 files parse-clean; declaration count unchanged at 79438,
as expected for a string extension plus one argv element.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The prose was in the wrong CARRIER because I fixed it at the wrong ATTACHMENT POINT (review 56593)

review 56593 is correct: two `data ..._note: String` rows carrying nothing
but commentary are exactly what DESIGN §4c names as misplaced or dead
semantic data, and §4c's own history says why -- the corpus already tried
hoisting comments into String rows (#6262) and the first cleanup that
forced swept 215 dead prose rows across ~130 files (#6424).

The interesting part is how they got there, because the symptom pointed at
the wrong fix. The first cut wrote these as `//` blocks, and the parser
refused them: they sat INSIDE the `service git.Core { ... }` body, and §4c
admits only standalone leading `//` attached to MODULE-SCOPE declarations.
I concluded `//` was unavailable and changed the carrier. The actual defect
was the attachment point -- git.dag already carries 48 module-scope `//`
blocks, so the annotation channel was available the whole time and I had
measured only that one position was not.

Both rationales now attach to the module-scope ExternalAuthority anchors
for the git commands they describe, which are the declarations whose
subject they actually are.

Verified by execution, and the counter moves in the direction that proves
the point rather than merely not breaking: 4123 files parse-clean, and the
declaration count drops 79438 -> 79436, exactly the two String rows
removed. The prose left the semantic program instead of being reworded
inside it -- §4c's annotation capture is disjoint from semantic occurrence
allocation, so an annotation must not appear in that count at all.

Diff confined to the three intended regions; an incidental whole-file
newline collapse that had removed a blank line under the module header was
reverted.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 27, 2026
…§4c annotation, and stop calling a pre-existing defect a workaround

TWO REVIEW FINDINGS, one accepted as a defect and one accepted as a wording defect over a correct
substance. Emitted bytes re-verified BYTE-IDENTICAL against a real main baseline after both edits.

1. §4c VIOLATION, ACCEPTED AND FIXED. reference_derived_census_rung_note was a
`data ... : String` row carrying a declared rung, three next-rung triggers, a dated receipt and a
dissolution condition -- the §4c list verbatim, and the #6262 hoisted-prose shape that section names
as the measured failure, where intent is mechanically indistinguishable from program data. It is now
a leading `//` annotation. The review offered the typed rung carrier as the first alternative and
that is the right destination, but no such carrier exists to route to today: DESIGN's own declared
rung drops sit as prose in Building-&-checks, and the executable claims carrier that would hold them
is Stage 1 of the compiler-guarantee recovery plan and is unbuilt. The annotation says so and names
the migration as its dissolution. The conversion also removes a `pub fn` from the emitted seed
(mirror -9 lines), so the seed shrinks rather than grows. The other 30 `data _note` rows in this file
are the pre-existing convention and are NOT touched -- widening into them is a separate change.

2. SELF-AUTHORIZED SCAFFOLD, SUBSTANCE REFUSED, WORDING FIXED. The order-dependence is PRE-EXISTING:
a property of the emitter before this change, not introduced by it, and the ordering kept is the
ordering that was already there, so no artifact is added that must later be deleted and there is no
admitted debt for an operator to approve. The 2026-08-10 ruling governs CREATING temporary work; what
§4b(2) requires of a DISCOVERED class below its ceiling is exactly a named next-rung trigger, so the
trigger is an obligation rather than a permission. The word "workaround" invited the reviewer's
reading and is removed -- and DESIGN's workaround rule is about routing around an obstacle without
diagnosing it, which is the opposite of what happened: the line was stopped, the bytes measured, the
cause located to the preamble, the original order restored. The annotation now states all of this.

VERIFIED after both edits: required-regen first_generation_equal=true planned=137 executed=137;
scoped emit of src/v2/compiler/00_compile.dag against a main baseline fetched at 9917d4a --
BYTE-IDENTICAL, with a same-binary two-run control confirming the instrument discriminates.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 27, 2026
…typed disposition and count it (#9439)

* Factor the emitter's per-candidate import decision into a four-armed typed disposition and count it: the population it silently repairs was already computed every Rust emit and never named

Since PR 6848 a cross-module name resolves whether or not it is imported. At TYPE positions the
resolver says so advisorily (UnlistedImportUse, is_error_diagnostic false). At VALUE positions it
says nothing at all, and v1.compiler.emit_rust reference_derived_use_lines synthesizes the use-line
the author did not write. The emitter's own note already recorded the gap in its own words -- "a
candidate that registry-resolves to nothing, or resolves but fails export proof, is left
unsynthesized (typed refusal at step-2 is future work)" -- and the deficit's frequency was zero by
construction, so it never ranked for fixing.

WHAT CHANGED: the per-candidate decision was inline in a flat_map whose every non-surviving arm
returned the empty list. It is now reference_derived_candidate_disposition, one function, one call
per candidate, four arms -- CandidateSurvived, CandidateOwnModule, CandidateRegistryAbsent,
CandidateExportProofFailed -- with two consumers of the SAME rows: the use-lines are the survived
arm's names, and reference_derived_census counts them. A census disagreeing with the emitter is
unrepresentable rather than unlikely; there is no second copy of the decision to drift from.

FOUR ARMS, NOT THREE. CandidateOwnModule is not-applicable -- the module provides the name itself, no
import was ever owed -- while CandidateRegistryAbsent is a genuine unresolvable cross-module
reference. Opposite owners, opposite repairs; folding them is the state-space conflation DESIGN keeps
recording.

BYTE-IDENTITY, MEASURED RATHER THAN ARGUED, AND THE FIRST CUT FAILED IT. On a scoped emit of
src/v2/compiler/00_compile.dag (175 files, roots dag + src/v2), the first cut moved one file:
v2_lens_enforcement_vocab.rs, two pub use lines swapped in order, reproduced across three builds
against a byte-identical same-source control. The cause was not the decision -- it was the evaluation
ORDER of emit_rust's preamble, which the factoring had rearranged. Restoring the original order
restored byte-identity. The order-sensitivity is RECORDED as an annotation on the preamble with its
specimen, its reproduction and its next-rung trigger, and the ordering is named as
order-preserving-by-necessity so it is not "simplified" back. The structural argument -- bytes cannot
move unless the decision moves -- was true and covered only the decision, not the scaffolding.

VERIFIED: required-regen first_generation_equal=true; required-ci --required-lane build green
(v2-emission blocking=0, partition-crates 14/14, phases_run=3 failed=0); baseline-vs-change emit
BYTE-IDENTICAL.

WHAT IS NOT CLAIMED. No corpus figure is quoted anywhere, because none is producible: reaching the
census needs a resolved graph, and the only .dag route is a nested compile the interpreter refuses
(NoSuchField Node.ident, measured on three subjects) -- which is why the corpus's two nested-compile
instruments both go through a host builtin. An instrument that cannot execute was written and then
deleted rather than landed and cited. The declared rung is mitigatable, with three independent
next-rung triggers: the class joining the fail-closed wall, an executing home for src/v1 witnesses,
and a nested-compile route to a figure. Five witness rows over the four arms pass when run directly
and are declared NOT run by CI, because src/v1/tests/claim has had no executing consumer since the
2026-08-15 floor cut.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Review 56613: move the declared rung out of a data String row into a §4c annotation, and stop calling a pre-existing defect a workaround

TWO REVIEW FINDINGS, one accepted as a defect and one accepted as a wording defect over a correct
substance. Emitted bytes re-verified BYTE-IDENTICAL against a real main baseline after both edits.

1. §4c VIOLATION, ACCEPTED AND FIXED. reference_derived_census_rung_note was a
`data ... : String` row carrying a declared rung, three next-rung triggers, a dated receipt and a
dissolution condition -- the §4c list verbatim, and the #6262 hoisted-prose shape that section names
as the measured failure, where intent is mechanically indistinguishable from program data. It is now
a leading `//` annotation. The review offered the typed rung carrier as the first alternative and
that is the right destination, but no such carrier exists to route to today: DESIGN's own declared
rung drops sit as prose in Building-&-checks, and the executable claims carrier that would hold them
is Stage 1 of the compiler-guarantee recovery plan and is unbuilt. The annotation says so and names
the migration as its dissolution. The conversion also removes a `pub fn` from the emitted seed
(mirror -9 lines), so the seed shrinks rather than grows. The other 30 `data _note` rows in this file
are the pre-existing convention and are NOT touched -- widening into them is a separate change.

2. SELF-AUTHORIZED SCAFFOLD, SUBSTANCE REFUSED, WORDING FIXED. The order-dependence is PRE-EXISTING:
a property of the emitter before this change, not introduced by it, and the ordering kept is the
ordering that was already there, so no artifact is added that must later be deleted and there is no
admitted debt for an operator to approve. The 2026-08-10 ruling governs CREATING temporary work; what
§4b(2) requires of a DISCOVERED class below its ceiling is exactly a named next-rung trigger, so the
trigger is an obligation rather than a permission. The word "workaround" invited the reviewer's
reading and is removed -- and DESIGN's workaround rule is about routing around an obstacle without
diagnosing it, which is the opposite of what happened: the line was stopped, the bytes measured, the
cause located to the preamble, the original order restored. The annotation now states all of this.

VERIFIED after both edits: required-regen first_generation_equal=true planned=137 executed=137;
scoped emit of src/v2/compiler/00_compile.dag against a main baseline fetched at 9917d4a --
BYTE-IDENTICAL, with a same-binary two-run control confirming the instrument discriminates.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 27, 2026
…obligations (§4c)

Addresses review 57011 (REQUEST_CHANGES, narrowly on §4c). Both findings verified against
the code and both fixed rather than argued.

FINDING 1 -- the two `data ...: String` notes were hoisted prose. Correct, and the
precedent I had followed does not excuse it: I modeled this carrier on
`gunbc.whole_corpus_compile_admission`, which uses the same pattern on main. §4c records
that hoisting comments into `data ...: String` rows was itself the failure (#6262), and
that the first cleanup it forced swept 215 dead prose rows across ~130 files (#6424). An
existing instance is not a licence. Both notes are now `//` annotation blocks, which is the
sanctioned quarantine channel, and the module carries zero commentary String rows.

The machine-consumed counts the review asked to be lifted are now a typed row,
`ConformanceDivergence`, with the site count and state count as separate members because
two states refuse at two sites each -- a site total read as a state total overstates the
divergence. `conformance_divergence_is_observed` derives the verdict rather than storing
it, so the finding EXPIRES LOUDLY: if a conformance relation later lands and the carrier
names every state the host refuses, the witness goes red instead of the census standing as
a claim about a state that has ended.

FINDING 2 -- the String payloads on the coproduct arms. The review called these less
severe; they were the load-bearing half, and fixing them made a case testable that had been
unrepresentable.

`Retired` carried free-form `*_empty_receipt: String` fields, which can ASSERT discharge
without exhibiting it. It now carries `discharged: List<RetirementObligation>` over a closed
two-member vocabulary, and `retirement_fully_discharged` requires both. So a retirement that
names itself while discharging only one obligation now admits NEITHER deletion -- which is
this carrier's own thesis enforced one level in: naming a disposition is not proving it.
That case could not be written before, so it could not be tested;
`witness_partial_retirement_admits_neither_deletion` covers it now.

`RouteRefuted` / `RouteUnexamined` are payload-free. Each route is a named `data`
declaration with its reasoning in a `//` block above it, so the rationale sits in the
channel §4c sanctions and where a reader actually encounters it, rather than in a string
nothing consumes.

WHAT DID NOT CHANGE: the lifecycle coproduct, the asymmetric admittance pair, and the
witnesses the review found well-modeled. The asymmetry is still asserted as a DISAGREEMENT
under Transferred and an agreement under a fully discharged Retired, because separate
assertions are satisfied by a pair that answers false to everything -- the fused row again
in typed clothing.

Verified by execution: 0 blocking errors, contributing zero advisory diagnostics of its own
(7 sources, 12 files emitted, 95 advisories all from the shared std closure).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 28, 2026
…ransfer and retirement are fused (#9521)

* File a contradiction between two authorities: DESIGN records a climb trigger for the pair the hollowing plan schedules for deletion

DESIGN records the regen host's hand-written ordering at *mitigatable* with "the
host being derived from the carrier" as its next-rung trigger.
`gunbc.plans.cli_run_hollowing_plan` carries a row whose subject is exactly that
pair -- authority `v2.workflow.required_regen` / `v1_compiler.required_regen_host`
-- and dispositions it `delete-with-v1`, trigger "Wave 4 real-fixpoint cutover",
adding "bulk GENERATED cutover, not piecemeal". One authority asserts a climb, the
other schedules a deletion, neither cites the other, and nothing refuses over the
pair.

This carrier records that and nothing else. It is not a repair, not a plan, and not
a proposal for the Wave 4 work: resolving the contradiction means editing DESIGN
against a plan, which is an operator decision. It gates nothing and says so, since a
carrier named for a wall while occupying none is inflation (DESIGN 4b).

Three findings, all measured:

1. THE AUTHORITY RELATIONSHIP IS A COMMENT. `required_regen_run` and
   `required_regen_sync_admission` occur exactly once across all of
   src/v1/stage0/src/*.rs, and the occurrence is prose naming the carrier as
   authority for an ordering. No production Rust calls into it; its only executor is
   its own witness. That is specification-without-execution on the production path,
   and it explains the divergence better than the host's Vec<String> refusal channel
   does -- 23 production refusal sites covering ~21 distinct states against six named
   by the carrier is what a comment-held correspondence produces given time, because
   nothing ever forced the two together.

2. THE TRIGGER HAS FAILED THREE PRECONDITIONS, each found only by attempting the step
   the previous one unblocked: the carrier sits in a tree the regen closure does not
   root; a relocated carrier still needs a seed-side consumer that does not exist; and
   the only honest candidate consumer is hand-Rust already scheduled for deletion at
   the same gate. A trigger nobody can satisfy is worse than a declared stall -- 4b(2)
   exists to separate "cannot climb" from "can climb but unbuilt", and this row reads
   as the second while being the first, so it never ranks and never retires.

3. CLOSURE MEMBERSHIP IS BY IMPORT, NOT BY RESIDENCE. The control table carries both
   arms -- two modules with seed importers, emitted; three with none, not emitted --
   so precondition two is checkable by the next reader rather than re-derivable only
   by trying it.

The witness makes the record self-invalidating: it asserts the trigger is
unsatisfiable, so repairing a precondition turns it RED and forces the census to be
revisited instead of decaying silently. It declares SubstrateInputsOnly explicitly,
because the fail-closed default would make it ReadsLiveTree and DECLINED -- discovered,
counted, never executed -- which is exactly the inert decoration this census warns
about. Both control arms are asserted in each direction plus an anti-vacuity check,
since either arm alone passes over an empty table.

Verified by execution: 0 blocking errors for both modules, contributing zero advisory
diagnostics of their own.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Wave 4 lacks a total disposition for the required-regen obligation: transfer and retirement are fused

Recut of this PR's original claim, which overreached in two ways. Both were mine and
both are removed rather than softened.

WHAT THIS NOW CLAIMS. `gunbc.plans.cli_run_hollowing_plan` carries one row -- authority
`v2.workflow.required_regen` / `v1_compiler.required_regen_host` -- dispositioned
`delete-with-v1` at the Wave 4 cutover. That row answers for two different futures with
different obligations: TRANSFER, where the operation survives under a successor and owes
an equivalence receipt, and RETIRE, where the operation ceases and owes proof its subject
is empty. Both end in deleting the same two files, which is why one row can cover them and
why nothing notices that it does. `delete-with-v1` states the ACTION and leaves the
JUSTIFICATION unstated.

The plan may still choose retirement. What it may not do is let `delete-with-v1` stand in
for PROVING the subject retired.

THE ASYMMETRY IS THE CONTENT. The host is one realization, so a transfer moves its work to
the successor and a retirement ends it -- both admit deletion. The carrier is the
operation's DEFINITION, so deleting it under a transfer destroys the referent of the very
equivalence receipt that transfer owes. Only retirement admits it. A symmetric pair of
predicates would be the fused row again in typed clothing, so the witness asserts the two
must DISAGREE under Transferred and AGREE under Retired.

WHAT WAS WRONG BEFORE.

1. THREE FAILED ROUTES ARE NOT AN IMPOSSIBILITY PROOF. The original concluded the trigger
   was unsatisfiable and the class could not climb. The evidence licenses only
   CurrentSeedImportDerivationUnavailable. "Host derived from carrier" does not require
   the host to import a Rust type generated into the v1 stage0 closure; that is one
   construction, and it is the one refuted. Four others -- build-time generation,
   interpreting the carrier and passing a typed receipt, moving the operation to the
   promoted v2 product, and the operation retiring with its subject -- are reachable and
   UNEXAMINED, and are now enumerated as such. This was the same equivalence-across-a-gap
   this lane had already caught itself making about the closure stubs.

2. COMMENT-HELD CONFORMANCE IS NOT ABSENT ENFORCEMENT. The grep establishes that no
   production Rust CONSUMES the carrier. It does not establish that required-regen
   behaviour is absent: the hand-written host is an INDEPENDENT REALIZATION and it does
   enforce the operation. The honest pair is OperationEnforcedByIndependentRealization
   with CarrierRealizationConformanceUnobserved. What is missing is a mechanically enforced
   RELATION between two realizations, not the enforcement, and that changes both severity
   and repair.

3. DESIGN AND THE PLAN ARE NOT NECESSARILY CONTRADICTORY. A next-rung trigger is an
   obligation while its subject remains LIVE, and a terminal migration may remove the
   subject entirely -- deleting an operation whose subject is gone is retiring it, not
   declining to climb. They are compatible under exactly that condition, and nobody had
   checked whether it holds. The unchecked condition is the defect; the arbitration
   request between the two authorities is withdrawn.

WHAT SURVIVES, with its measurements: the seed-import route is genuinely unavailable
(closed two-variant regen roots, zero emitted files declaring a v2.* source module, and
the both-arms closure-membership control table showing membership is by import rather than
residence); carrier/host conformance is comment-held, at a cost of 23 production refusal
sites covering ~21 distinct states against six the carrier names; and the plan's row is
not total.

The witness guards the specific overclaim that caused this recut: if anyone later marks
every derivation route refuted, the impossibility claim returns silently, so
`witness_exactly_one_route_is_refuted` and `witness_no_impossibility_claim_is_reachable`
go red instead. One gap stated rather than papered over: nothing detects the plan GAINING
a disposition later, so that half remains review diligence.

Verified by execution: 0 blocking errors, contributing zero advisory diagnostics of its own.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Convert the carrier's prose to annotations and its receipts to typed obligations (§4c)

Addresses review 57011 (REQUEST_CHANGES, narrowly on §4c). Both findings verified against
the code and both fixed rather than argued.

FINDING 1 -- the two `data ...: String` notes were hoisted prose. Correct, and the
precedent I had followed does not excuse it: I modeled this carrier on
`gunbc.whole_corpus_compile_admission`, which uses the same pattern on main. §4c records
that hoisting comments into `data ...: String` rows was itself the failure (#6262), and
that the first cleanup it forced swept 215 dead prose rows across ~130 files (#6424). An
existing instance is not a licence. Both notes are now `//` annotation blocks, which is the
sanctioned quarantine channel, and the module carries zero commentary String rows.

The machine-consumed counts the review asked to be lifted are now a typed row,
`ConformanceDivergence`, with the site count and state count as separate members because
two states refuse at two sites each -- a site total read as a state total overstates the
divergence. `conformance_divergence_is_observed` derives the verdict rather than storing
it, so the finding EXPIRES LOUDLY: if a conformance relation later lands and the carrier
names every state the host refuses, the witness goes red instead of the census standing as
a claim about a state that has ended.

FINDING 2 -- the String payloads on the coproduct arms. The review called these less
severe; they were the load-bearing half, and fixing them made a case testable that had been
unrepresentable.

`Retired` carried free-form `*_empty_receipt: String` fields, which can ASSERT discharge
without exhibiting it. It now carries `discharged: List<RetirementObligation>` over a closed
two-member vocabulary, and `retirement_fully_discharged` requires both. So a retirement that
names itself while discharging only one obligation now admits NEITHER deletion -- which is
this carrier's own thesis enforced one level in: naming a disposition is not proving it.
That case could not be written before, so it could not be tested;
`witness_partial_retirement_admits_neither_deletion` covers it now.

`RouteRefuted` / `RouteUnexamined` are payload-free. Each route is a named `data`
declaration with its reasoning in a `//` block above it, so the rationale sits in the
channel §4c sanctions and where a reader actually encounters it, rather than in a string
nothing consumes.

WHAT DID NOT CHANGE: the lifecycle coproduct, the asymmetric admittance pair, and the
witnesses the review found well-modeled. The asymmetry is still asserted as a DISAGREEMENT
under Transferred and an agreement under a fully discharged Retired, because separate
assertions are satisfied by a pair that answers false to everything -- the fused row again
in typed clothing.

Verified by execution: 0 blocking errors, contributing zero advisory diagnostics of its own
(7 sources, 12 files emitted, 95 advisories all from the shared std closure).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Dissolve the transcribed conformance counts and the retirement predicate, and split transfer by what the successor replaces

Review 57020 raised two findings and both are correct.

The five conformance counts were transcribed off a live-tree scan with no
instrument naming them -- the 2026-08-24 ruling's exact prohibition. The repair
is not to re-source them. The standing this carrier needs is qualitative: has a
conformance relation been observed at all. The predicate that consumed the
counts answered false regardless of whether they were current, so the numbers
could rot without changing any decision, which is the evidence they were not
carrying one. They are replaced by a typed RealizationConformance whose live
value asserts an ABSENCE of observation and therefore owes no instrument.
Conformance is modeled as its own axis rather than an arm of the lifecycle,
because the operation's fate and the state of the relation between its
realizations are independent questions.

The retirement predicate was a hand-rolled Bool over a closed coproduct. Rather
than respell it, the state that made it necessary is gone: a partially
discharged retirement is now its own arm, Retired carries nothing, and the
predicate dissolved rather than being reformulated. This also removes a state
with no meaning -- Retired with an empty discharge list was neither retired nor
prepared.

Separately, a defect of my own found before review reached it: the transfer arm
carried a successor AUTHORITY while denying carrier deletion, so the carrier
encoded a terminal state in which two definitions answer for one operation.
Split into RealizationTransferred (carrier stays canonical) and
AuthorityTransferred (both delete), with a witness asserting the two DISAGREE,
so re-fusing them in either direction goes red.

Verified by execution, not by compiling: all seven affected witnesses return
true, against an oracle first shown to discriminate by a planted false control.
Compiles 0 blocking / 95 advisory, unchanged baseline.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Delete the control table's transcribed magnitude, keeping the distinction its consumers actually read

Review 57043 approved but noted that the closure-membership control table
reintroduced transcribed integers in a file that elsewhere retracts them.
Measured against the consumers rather than argued: every reader tested
seed_importers == 0 or > 0, so the MAGNITUDE was read by nothing and a row
could drift from one importer to seven with no witness changing.

That is the same test this file applies to the conformance counts a few
declarations up -- a member that can rot without changing any decision was
never carrying one -- so the magnitude is deleted rather than defended as a
fixture. The field becomes seed_reachable: Bool, which is the zero/non-zero
distinction the rule actually turns on and a structural fact about the import
graph rather than a measurement of a population.

emitted stays a stored Bool because it IS read directly: it is the observed
consequence the control exists to pair against reachability. Expressing
reachability as a coproduct was considered and rejected -- filtering on it
would have required a match returning true for one arm and false for the
other, which is the predicate-dissolution shape review 57020 objected to.

All three affected witnesses verified by execution, not by compiling.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Force a fresh merge ref: this PR's checks were pinned to a base that predates #9560

The three failing checks on 4d22d6d started 01:10-02:10Z, so refs/pull/9521/merge
was computed against main as it stood before ba27746 (#9560) landed. That base no
longer exists. A rerun replays the pinned ref and would reproduce the red exactly;
only a push forces recomputation.

The trigger for pushing was a settled, non-cancelled witnesses run on a head
containing #9560: run 33140335064 on ba27746, with required-witnesses-build,
required-witnesses-floor and witnesses all green.

No content change. The tree is byte-identical to 4d22d6d.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Absorption was fused into AuthorityTransferred, and its incompleteness was one symbol over two owners

The carrier exists to name a fused disposition, and it fused one two levels in.

ABSORPTION IS A THIRD CONTINUATION. An obligation can survive while ceasing to be an
INDEPENDENTLY NAMED operation, performed as one inseparable part of a broader transaction.
That is not an authority transfer: a transfer hands the operation to a successor that still
answers for it by name, while absorption dissolves the name and owes a COVERAGE receipt over
every old input population, ordering guarantee, refusal and consumer obligation.

WHY THE COMPLETED ARM ALONE WOULD HAVE BEEN A DECORATION. A completed absorption has the same
deletion truth table as an authority transfer -- the absorber is canonical, so both files go --
so an Absorbed arm on its own changes no predicate outcome and no witness over it can go red
for the right reason. The INCOMPLETE state is what makes it a wall: coverage that has not been
demonstrated admits NEITHER deletion, which authority transfer never does.

AND INCOMPLETENESS ITSELF SPLITS, IN TWO, WHICH IS THE ARM COUNT AND ITS REASON. An unproduced
coverage receipt is an ABSENT OBSERVATION -- the absorber may cover everything, the remedy is
to produce the receipt, owned by whoever lands the absorption. A receipt that SHOWS a gap is an
observation with a negative result -- the remedy is to widen the absorber or refuse the
absorption, owned by whoever owns the broader operation, and the design is wrong. Opposite
owners, opposite repairs: DESIGN's not-applicable-rendered-as-malformed conflation. The two
AGREE on both deletion predicates, which is exactly why collapsing them is tempting and exactly
why a truth-table test cannot see the split.

THE PRECEDENT IS IN THIS FILE, AND IT IS NOT THE ONE FIRST PROPOSED. A peer suggested
retirement's three arms as precedent for distinguishing kinds of incompleteness. Checked: they
are MirrorPopulationStillOccupied / RequiredConsumersRemain / BothObligationsOutstanding --
subsets over two named obligations, not kinds of incompleteness. The analogy fails and did not
carry the split. What carried it is that this module ALREADY separates absent-observation from
negative-result twice: RouteStatus (RouteRefuted vs RouteUnexamined) and RealizationConformance
(unobserved vs observed). Collapsing absorption's would leave one module speaking two
vocabularies about one concept.

NO THIRD ARM. "Absorber not yet identified" is not a coverage state -- an obligation with no
named absorber is Active, not absorbed.

THE SPLIT IS READ, NOT MERELY DECLARED. Without a consumer, AbsorptionCoverage would be the
richer name over an unchanged wall this module objects to elsewhere, so
absorption_coverage_is_refuted answers the question whose two states have different owners.

EVIDENCE, EXECUTED. Six witnesses green. Mutation: fusing prepared absorption with authority
transfer on the carrier axis (one arm, false -> true) turns the disagreement witness and the
closed-vocabulary gap sweep RED, while the agree-on-deletion-differ-on-refutation witness
correctly stays green because it tests the other axis -- evidence the witnesses are not
restatements of one assertion. Carrier restored byte-identical to its pre-mutation bytes and
both reds return to green.

ONE ANNOTATION RECORDS A WORKAROUND FOR A FILED PARSER DEFECT. The parser refuses a newline
between the parameter list and the return arrow, at ANY name length -- executed on a controlled
pair, a one-character name with the break refuses and the same name with the arrow on one line
compiles clean. A test fn name here is therefore short in order to keep the ARROW on one line,
not because short names are preferred; the defect is filed and owned elsewhere.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant