From 22a83cffa15be47f3781ed25f998c5f5d4a14b28 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 5 Jul 2026 02:31:24 +0000 Subject: [PATCH 1/9] WIP: continue work on v1 burn down --- dag/gunbc/roadmap_authority.dag | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/dag/gunbc/roadmap_authority.dag b/dag/gunbc/roadmap_authority.dag index f7455a7c82d..5f46a5c0b2e 100644 --- a/dag/gunbc/roadmap_authority.dag +++ b/dag/gunbc/roadmap_authority.dag @@ -99,21 +99,21 @@ fn section_1() -> RoadmapSection { title: "1. Get off v1 — v2 self-hosts (TERMINAL: `src/v1` deleted)", elements: [ section_prose(content: "Anchor (do not flip-flop): `.dag` = truth; v2 emits its own seed (no stage0 hand-edits); the trust chain is discharged by execution; then the hand-written seed is deleted. Terminal is **hand-written compiler logic → 0**, not zero bytes of Rust: a pinned v2-emitted bootstrap kernel (~8–15k LOC — `claim_executor`, evaluator host-physics, the regen oracle) survives as the content-addressed seed. → [plan](docs/plans/v2-self-hosting.md) · [de-fork audit](docs/plans/dag-v2-defork-audit.md) · [seed census](docs/plans/seed-shrink-census.md)"), - section_prose(content: "Ground truth (2026-07-01): `src/v1` = ~174k hand-written `.rs` LOC (the ~154k figure in older docs is stale) + 44 `.dag` files of v1's own modeling; `src/v2` = 839 `.dag`, zero `.rs`. HAND_MAINTAINED roster is down 24 → 9 files + `module_path_index` (~20.6k LOC); `patch_*` 3 → 1. The regen gate proves byte-identity per the COMMITTED seed (two-generation): emitter improvements are latent until a cutover, and the cargo-green receipt is episodic (`#[ignore]`, ~3–5min), not continuous — today's continuous walls are byte-identity + the interim fixpoint + well-typed emit."), - section_prose(content: "**◆ Milestones:** front-end ✓ · emit-rust well-typed ✓ · cross-tree import ✓ (#5473) · emitted crate cargo-green, 0 rustc errors ✓ (#5777/#5873, re-verified #6099) · `regen --verify` in CI ✓ (#5873) · interim fixpoint gate, 2-of-92 roster ✓ (#6009) → **▸ NOW: regen-cutover cadence · HAND queue drain · full-roster real fixed point** → seed-honesty (DDC) → **TERMINAL: `src/v1` deleted**"), + section_prose(content: "Ground truth (2026-07-05): `src/v1` = ~174k hand-written `.rs` LOC (the ~154k figure in older docs is stale) + 44 `.dag` files of v1's own modeling; `src/v2` = 874 `.dag`, zero `.rs`. HAND_MAINTAINED roster is down 24 → 7 files + `module_path_index` (~22.3k LOC: the three lens projections drained #6158/#6211/#6212; `phase_profile.rs` ADDED 2026-07-04 with its own dissolution trigger); `patch_*` is fully dead in-tree. The regen gate proves byte-identity per the COMMITTED seed (two-generation): emitter improvements are latent until a cutover, and the cargo-green receipt is episodic (`#[ignore]`, ~3–5min), not continuous — today's walls are byte-identity + the full 92-file byte fixed point (#6218) + well-typed emit. INTERIM (operator-accepted, 2026-07-05): the CI floor cannot complete inside its 10-minute budget (#6232) while batch-1 compile-clean runs ~40+min, so these walls are proven by LOCAL execution with documented receipts, not by CI, until the §2 compile-clean work lands."), + section_prose(content: "**◆ Milestones:** front-end ✓ · emit-rust well-typed ✓ · cross-tree import ✓ (#5473) · emitted crate cargo-green, 0 rustc errors ✓ (#5777/#5873, re-verified #6099) · `regen --verify` in CI ✓ (#5873) · interim fixpoint gate, 2-of-92 roster ✓ (#6009) · full-roster 92-file byte-fold + host-grounded digest ✓ (#6218) · v1 self-resolution restored ✓ (#6250) → **▸ NOW: regen-cutover cadence · HAND queue drain · fixed-point residue (Node-level compare + placeholder hashes)** → seed-honesty (DDC) → **TERMINAL: `src/v1` deleted**"), section_group( label: "", nodes: [ authored_wi(id: "5-regen-cutover", done: false, content: "**regen-cutover cadence** — absorb latent emitter fixes into the committed seed (#6099 merged with the `machine_width` emit test still ignored: two-generation regen means every emitter improvement is invisible until a cutover). Each cutover un-ignores its witnesses; a stale seed hides emitter regressions.", intricacy: IntricacyMedium, volume: VolumeMedium, repo: "gunbc"), - authored(id: "5-real-fixpoint", done: false, content: "**real fixed point** — `content_hash` stage1==stage2 over the FULL seed: host-ground `source_text_code_unit_digest`, widen the `SelfHostRealizedComparisonGate` byte-fold from its 2-file roster (`lib.rs`, `v1_rt.rs`) to all 92 GENERATED files, dissolve the `bootstrap.dag` placeholder hashes. The #6009 gate is INTERIM by its own disposition; this milestone gates the bulk cutover-delete, seed-honesty, and the shelved TS self-host."), - authored(id: "5-dissolve-patches", done: false, content: "**drain the HAND_MAINTAINED queue** (9 files + `module_path_index`, ~20.6k LOC) + kill the last `patch_*` (`patch_complexity_linearity_audit_mod`) — order: `main.rs` flip-back → the three lens projections → `coproduct_reflection` (de-fork-coupled) → `v1_interpreter` pure-eval emit (kernel D [plan](docs/plans/interpreter-kernel-d.md)) → `cli_run.rs` (largest, ~9.2k LOC; #6046 hard-gates net-new logic INTO it — verified pure-projection HAND folds carved out per #6211/#6212/#6217). Host-physics files (`recorded_fixture` · `resolved_graph_cache`) are terminal-kernel pins, not dissolution targets."), - derivable(id: "5-dual-rep-lens", prs: [6104], title: "**no-dual-representation-test lens rebuilt pure-v2**", description: "— lens verdict moves off v1 Rust, the lens-E retirement pattern continued (in flight)"), + authored(id: "5-real-fixpoint", done: false, content: "**real fixed point** — `content_hash` stage1==stage2 over the FULL seed. LANDED (#6218): `source_text_code_unit_digest` host-grounded on `atom_identity_hash`, and the `SelfHostRealizedComparisonGate` byte-fold widened from the 2-file roster to all 92 GENERATED files via the regen manifest (self-updating roster; the gate's INTERIM disposition deleted). REMAINING: the Node-level comparison — emitted compiler Node vs emitted bytes (`generate_stage_candidate_from_ingest` has zero consumers today) — dissolve the `bootstrap.dag` placeholder hashes, and widen the provenance witness off its 1-file roster. This milestone gates the bulk cutover-delete, seed-honesty, and the shelved TS self-host."), + authored(id: "5-dissolve-patches", done: false, content: "**drain the HAND_MAINTAINED queue** (7 files + `module_path_index`, ~22.3k LOC; three lens projections drained ✓ #6158/#6211/#6212 · last `patch_*` dead in-tree ✓ · `phase_profile.rs` added 2026-07-04, dissolution trigger `realization_measurement_loop` Phase 0) — remaining dissolution order: `main.rs` flip-back (attempted #6226, self-reverted — the emitter lost Ci-subcommand/`extract_module_path` emission in #6053's dag_collect split; restore the emit gaps first) → `coproduct_reflection` (de-fork-coupled) → `v1_interpreter` pure-eval emit (kernel D [plan](docs/plans/interpreter-kernel-d.md); model+witness landed #6229, phase ModelAndWitnessOnly, blocked on emit_host transport wiring) → `cli_run.rs` (largest, ~12.1k LOC — grew as the absorption point for the drained projections' pure folds per #6211/#6212/#6217; #6046 hard-gates net-new logic INTO it). Host-physics files (`recorded_fixture` · `resolved_graph_cache`) are terminal-kernel pins, not dissolution targets."), + derivable(id: "5-dual-rep-lens", prs: [6104], title: "**no-dual-representation-test lens rebuilt pure-v2**", description: "— lens verdict moves off v1 Rust, the lens-E retirement pattern continued (landed #6104)"), authored(id: "5-defork", done: false, content: "**de-fork dag ↔ v2 grounding cluster** (one std authority — the fixed point must be well-defined over ONE algebra): `algebra` first (LIVE fail-open, 75 floor entries) → effects/float/integer/logic → `nat` LAST. Operator rulings stand: coproduct = structural authority; grounded-realization wins. The cost of not de-forking is no longer theoretical: the `extdeps.shell` dag↔v2 fork silently shadowed `shell.Which` in the two-root module index and kept main red from #6097 until the de-fork hotfix. [brief](docs/plans/dag-v2-defork-audit.md)"), authored(id: "5-root-b", done: false, content: "**Root B repoints** — def-unification (coproduct authority + aliases) → repoints (algebra/nat/integer/float/logic/effects/verification) → 🟡-marker dissolution (keystone #5552 merged)"), authored(id: "5-v1coupled", done: false, content: "v1-coupled `coercion`/`node` renames — deferred to v1-delete"), - authored_wi(id: "5-test-migration", done: false, content: "**test-migration lane** — ~90 v1 test modules / ~939 `#[test]` fns move to floor `*_test.dag` witnesses before their module deletes (hard gate per module, bulk-delete forbidden); ~71 modules have NO floor equivalent today (census §5B: infer_semantics 51 · source_audit 41 · effects 36 · pipeline.rs 418 concern-level only). Parallelizable now; gates the terminal collapse per module.", intricacy: IntricacyMedium, volume: VolumeLarge, repo: "gunbc"), + authored_wi(id: "5-test-migration", done: false, content: "**test-migration lane** — live debt per the `v2.lens.test_migration_debt` shrink-only ratchet: 73 v1 test modules / 731 `#[test]` fns / ~23k LOC with no exact-stem floor witness (baselines 77/912/28546 set 2026-07-02; `pipeline.rs` alone is 417 fns, the dominant unit); the delete-guard blocks removing a v1 test module without its floor witness (hard gate per module, bulk-delete forbidden). **Scrutinize before migrating (operator, 2026-07-05): tests are not inherently valuable — triage each module first (migrate · delete-as-redundant · delete-as-low-value); the guard currently requires an exact-stem witness for ANY delete, so the lane's first deliverable is a typed retirement path through the guard, never a bypass.** Parallelizable now; gates the terminal collapse per module. NOTE: migrated witnesses run on the local discovery path — CI enrollment is opt-in (#6232) until affected-set selection lands.", intricacy: IntricacyMedium, volume: VolumeLarge, repo: "gunbc"), authored(id: "5-cargo-green-continuous", done: false, content: "**make cargo-green continuous (or cheap)** — `route_a_emit_fresh_cargo_green_test` is ignored (~3–5min); an emitter regression that keeps bytes stable per the old seed but breaks a fresh build surfaces late. Decide: fold into `RegenVerifyGate` (doubles its cost) or a scheduled receipt."), - authored(id: "5-seed-honesty", done: false, content: "**seed-honesty discharge** (Diverse Double-Compiling) — modeled in `bootstrap.dag` (`SeedHonestyDischarge`), no execution exists; needs a reproducible artifact to double-compile. Design proposal (second-compiler candidate `ddc_reference_compiler` + computed fixed-point digest, reusing `self_host.dag`'s `canonical_emitted_bytes_digest`; flags open for operator sign-off): [seed-honesty discharge design](docs/plans/seed-honesty-discharge-design.md)"), + authored(id: "5-seed-honesty", done: false, content: "**seed-honesty discharge** (Diverse Double-Compiling) — modeled in `bootstrap.dag` (`SeedHonestyDischarge`), no execution exists; worse, the modeled witness is fail-open by construction (its evidence argument is the same atom it checks against — Holds trivially, no red case constructible) until Stage 3's executing consumer lands. Needs a reproducible artifact to double-compile. Design proposal (second-compiler candidate `ddc_reference_compiler` + computed fixed-point digest, reusing `self_host.dag`'s `canonical_emitted_bytes_digest`; FLAGs A–D open for operator sign-off): [seed-honesty discharge design](docs/plans/seed-honesty-discharge-design.md)"), authored(id: "5-collapse-v1", done: false, content: "**TERMINAL — collapse `src/v1`**: one atomic regen cutover-delete of the 92 GENERATED files (~117k of stage0's ~137k LOC) + per-module test deletes as migration lands + pin the terminal kernel. Requires: HAND queue empty · real fixed point · test-migration green · seed-honesty."), ], edges: [ From 1c1edec2e2cb0d71c6cd727aecd9a70e351248e5 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 5 Jul 2026 02:41:58 +0000 Subject: [PATCH 2/9] WIP: continue work on v1 burn down --- src/v1/02_parse.dag | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/v1/02_parse.dag b/src/v1/02_parse.dag index 9c47b1b137c..27f0494e5fc 100644 --- a/src/v1/02_parse.dag +++ b/src/v1/02_parse.dag @@ -76,7 +76,7 @@ fn token_stream_position(stream: TokenStream) -> Int { } fn token_stream_first(stream: TokenStream) -> Token? { - get(xs: stream.all, index: stream.pos) + skip(xs: stream.all, n: stream.pos) |> first } fn token_stream_advance(stream: TokenStream, n: Int) -> TokenStream { @@ -84,7 +84,7 @@ fn token_stream_advance(stream: TokenStream, n: Int) -> TokenStream { } fn token_stream_peek(stream: TokenStream, offset: Int) -> Token? { - get(xs: stream.all, index: stream.pos + offset) + skip(xs: stream.all, n: stream.pos + offset) |> first } type ParseContext { From ecc57b1accc204086b579b86c58d4a0ff585cc9f Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 5 Jul 2026 02:52:39 +0000 Subject: [PATCH 3/9] WIP: continue work on v1 burn down --- ROADMAP.md | 20 ++++++++++---------- dag/gunbc/design_document.dag | 7 ++++--- dag/gunbc/roadmap_authority.dag | 6 +++--- 3 files changed, 17 insertions(+), 16 deletions(-) diff --git a/ROADMAP.md b/ROADMAP.md index 4a6566c2864..7201e003f33 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -10,21 +10,21 @@ Legend: `[x]` done · `[ ]` todo · **indentation = depends on the item it sits Anchor (do not flip-flop): `.dag` = truth; v2 emits its own seed (no stage0 hand-edits); the trust chain is discharged by execution; then the hand-written seed is deleted. Terminal is **hand-written compiler logic → 0**, not zero bytes of Rust: a pinned v2-emitted bootstrap kernel (~8–15k LOC — `claim_executor`, evaluator host-physics, the regen oracle) survives as the content-addressed seed. → [plan](docs/plans/v2-self-hosting.md) · [de-fork audit](docs/plans/dag-v2-defork-audit.md) · [seed census](docs/plans/seed-shrink-census.md) -Ground truth (2026-07-01): `src/v1` = ~174k hand-written `.rs` LOC (the ~154k figure in older docs is stale) + 44 `.dag` files of v1's own modeling; `src/v2` = 839 `.dag`, zero `.rs`. HAND_MAINTAINED roster is down 24 → 9 files + `module_path_index` (~20.6k LOC); `patch_*` 3 → 1. The regen gate proves byte-identity per the COMMITTED seed (two-generation): emitter improvements are latent until a cutover, and the cargo-green receipt is episodic (`#[ignore]`, ~3–5min), not continuous — today's continuous walls are byte-identity + the interim fixpoint + well-typed emit. +Ground truth (2026-07-05): `src/v1` = ~174k hand-written `.rs` LOC (the ~154k figure in older docs is stale) + 44 `.dag` files of v1's own modeling; `src/v2` = 874 `.dag`, zero `.rs`. HAND_MAINTAINED roster is down 24 → 7 files + `module_path_index` (~22.3k LOC: the three lens projections drained #6158/#6211/#6212; `phase_profile.rs` ADDED 2026-07-04 with its own dissolution trigger); `patch_*` is fully dead in-tree. The regen gate proves byte-identity per the COMMITTED seed (two-generation): emitter improvements are latent until a cutover, and the cargo-green receipt is episodic (`#[ignore]`, ~3–5min), not continuous — today's walls are byte-identity + the full 92-file byte fixed point (#6218) + well-typed emit. INTERIM (operator-accepted, 2026-07-05): the CI floor cannot complete inside its 10-minute budget (#6232) while batch-1 compile-clean runs ~40+min, so these walls are proven by LOCAL execution with documented receipts, not by CI, until the §2 compile-clean work lands. -**◆ Milestones:** front-end ✓ · emit-rust well-typed ✓ · cross-tree import ✓ (#5473) · emitted crate cargo-green, 0 rustc errors ✓ (#5777/#5873, re-verified #6099) · `regen --verify` in CI ✓ (#5873) · interim fixpoint gate, 2-of-92 roster ✓ (#6009) → **▸ NOW: regen-cutover cadence · HAND queue drain · full-roster real fixed point** → seed-honesty (DDC) → **TERMINAL: `src/v1` deleted** +**◆ Milestones:** front-end ✓ · emit-rust well-typed ✓ · cross-tree import ✓ (#5473) · emitted crate cargo-green, 0 rustc errors ✓ (#5777/#5873, re-verified #6099 — for the THEN-seed; fresh emit is red today, see NOW) · `regen --verify` in CI ✓ (#5873) · interim fixpoint gate, 2-of-92 roster ✓ (#6009) · full-roster 92-file byte-fold + host-grounded digest ✓ (#6218) · v1 self-resolution restored ✓ (#6250 + #6253 `get`-form revert) → **▸ NOW: emitter restoration to fresh-emit cargo-green (#6243 C8 tail + residue — cutover #1 is BLOCKED on it; 1667 rustc errors measured 2026-07-05) · HAND queue drain · fixed-point residue (Node-level compare + placeholder hashes)** → seed-honesty (DDC) → **TERMINAL: `src/v1` deleted** -- [ ] **regen-cutover cadence** — absorb latent emitter fixes into the committed seed (#6099 merged with the `machine_width` emit test still ignored: two-generation regen means every emitter improvement is invisible until a cutover). Each cutover un-ignores its witnesses; a stale seed hides emitter regressions. - - [ ] **real fixed point** — `content_hash` stage1==stage2 over the FULL seed: host-ground `source_text_code_unit_digest`, widen the `SelfHostRealizedComparisonGate` byte-fold from its 2-file roster (`lib.rs`, `v1_rt.rs`) to all 92 GENERATED files, dissolve the `bootstrap.dag` placeholder hashes. The #6009 gate is INTERIM by its own disposition; this milestone gates the bulk cutover-delete, seed-honesty, and the shelved TS self-host. - - [ ] **seed-honesty discharge** (Diverse Double-Compiling) — modeled in `bootstrap.dag` (`SeedHonestyDischarge`), no execution exists; needs a reproducible artifact to double-compile. Design proposal (second-compiler candidate `ddc_reference_compiler` + computed fixed-point digest, reusing `self_host.dag`'s `canonical_emitted_bytes_digest`; flags open for operator sign-off): [seed-honesty discharge design](docs/plans/seed-honesty-discharge-design.md) +- [ ] **regen-cutover cadence** — absorb latent emitter fixes into the committed seed (#6099 merged with the `machine_width` emit test still ignored: two-generation regen means every emitter improvement is invisible until a cutover). Each cutover un-ignores its witnesses; a stale seed hides emitter regressions. RECEIPT (2026-07-05, local, #6253): with resolution repaired, regen write-mode completes and materializes the latent backlog — 40 generated files / ~4.3k lines of drift since their last per-file writes — but the fresh crate is cargo-RED: 1667 rustc errors (E0282/E0308/E0425/E0614/E0631; dominant class = #6243's deref-boxing + alias-brand C8 tail). Cutover #1 is BLOCKED on emitter restoration to fresh-emit cargo-green; until it lands, `regen --verify` is red on that drift by construction and every emitter fix stays latent (the broken cutover was measured and NOT committed). + - [ ] **real fixed point** — `content_hash` stage1==stage2 over the FULL seed. LANDED (#6218): `source_text_code_unit_digest` host-grounded on `atom_identity_hash`, and the `SelfHostRealizedComparisonGate` byte-fold widened from the 2-file roster to all 92 GENERATED files via the regen manifest (self-updating roster; the gate's INTERIM disposition deleted). REMAINING: the Node-level comparison — emitted compiler Node vs emitted bytes (`generate_stage_candidate_from_ingest` has zero consumers today) — dissolve the `bootstrap.dag` placeholder hashes, and widen the provenance witness off its 1-file roster. This milestone gates the bulk cutover-delete, seed-honesty, and the shelved TS self-host. + - [ ] **seed-honesty discharge** (Diverse Double-Compiling) — modeled in `bootstrap.dag` (`SeedHonestyDischarge`), no execution exists; worse, the modeled witness is fail-open by construction (its evidence argument is the same atom it checks against — Holds trivially, no red case constructible) until Stage 3's executing consumer lands. Needs a reproducible artifact to double-compile. Design proposal (second-compiler candidate `ddc_reference_compiler` + computed fixed-point digest, reusing `self_host.dag`'s `canonical_emitted_bytes_digest`; FLAGs A–D open for operator sign-off): [seed-honesty discharge design](docs/plans/seed-honesty-discharge-design.md) - [ ] **TERMINAL — collapse `src/v1`**: one atomic regen cutover-delete of the 92 GENERATED files (~117k of stage0's ~137k LOC) + per-module test deletes as migration lands + pin the terminal kernel. Requires: HAND queue empty · real fixed point · test-migration green · seed-honesty. -- [ ] **drain the HAND_MAINTAINED queue** (9 files + `module_path_index`, ~20.6k LOC) + kill the last `patch_*` (`patch_complexity_linearity_audit_mod`) — order: `main.rs` flip-back → the three lens projections → `coproduct_reflection` (de-fork-coupled) → `v1_interpreter` pure-eval emit (kernel D [plan](docs/plans/interpreter-kernel-d.md)) → `cli_run.rs` (largest, ~9.2k LOC; #6046 hard-gates net-new logic INTO it — verified pure-projection HAND folds carved out per #6211/#6212/#6217). Host-physics files (`recorded_fixture` · `resolved_graph_cache`) are terminal-kernel pins, not dissolution targets. - - [ ] **no-dual-representation-test lens rebuilt pure-v2** (#6104) — lens verdict moves off v1 Rust, the lens-E retirement pattern continued (in flight) — ⏳ awaiting sign-off +- [ ] **drain the HAND_MAINTAINED queue** (7 files + `module_path_index`, ~22.3k LOC; three lens projections drained ✓ #6158/#6211/#6212 · last `patch_*` dead in-tree ✓ · `phase_profile.rs` added 2026-07-04, dissolution trigger `realization_measurement_loop` Phase 0) — remaining dissolution order: `main.rs` flip-back (attempted #6226, self-reverted — the emitter lost Ci-subcommand/`extract_module_path` emission in #6053's dag_collect split; restore the emit gaps first) → `coproduct_reflection` (de-fork-coupled) → `v1_interpreter` pure-eval emit (kernel D [plan](docs/plans/interpreter-kernel-d.md); model+witness landed #6229, phase ModelAndWitnessOnly, blocked on emit_host transport wiring) → `cli_run.rs` (largest, ~12.1k LOC — grew as the absorption point for the drained projections' pure folds per #6211/#6212/#6217; #6046 hard-gates net-new logic INTO it). Host-physics files (`recorded_fixture` · `resolved_graph_cache`) are terminal-kernel pins, not dissolution targets. + - [ ] **no-dual-representation-test lens rebuilt pure-v2** (#6104) — lens verdict moves off v1 Rust, the lens-E retirement pattern continued (landed #6104) — ⏳ awaiting sign-off - [ ] **de-fork dag ↔ v2 grounding cluster** (one std authority — the fixed point must be well-defined over ONE algebra): `algebra` first (LIVE fail-open, 75 floor entries) → effects/float/integer/logic → `nat` LAST. Operator rulings stand: coproduct = structural authority; grounded-realization wins. The cost of not de-forking is no longer theoretical: the `extdeps.shell` dag↔v2 fork silently shadowed `shell.Which` in the two-root module index and kept main red from #6097 until the de-fork hotfix. [brief](docs/plans/dag-v2-defork-audit.md) - [ ] **Root B repoints** — def-unification (coproduct authority + aliases) → repoints (algebra/nat/integer/float/logic/effects/verification) → 🟡-marker dissolution (keystone #5552 merged) - [ ] v1-coupled `coercion`/`node` renames — deferred to v1-delete -- [ ] **test-migration lane** — ~90 v1 test modules / ~939 `#[test]` fns move to floor `*_test.dag` witnesses before their module deletes (hard gate per module, bulk-delete forbidden); ~71 modules have NO floor equivalent today (census §5B: infer_semantics 51 · source_audit 41 · effects 36 · pipeline.rs 418 concern-level only). Parallelizable now; gates the terminal collapse per module. -- [ ] **make cargo-green continuous (or cheap)** — `route_a_emit_fresh_cargo_green_test` is ignored (~3–5min); an emitter regression that keeps bytes stable per the old seed but breaks a fresh build surfaces late. Decide: fold into `RegenVerifyGate` (doubles its cost) or a scheduled receipt. +- [ ] **test-migration lane** — live debt per the `v2.lens.test_migration_debt` shrink-only ratchet: 73 v1 test modules / 731 `#[test]` fns / ~23k LOC with no exact-stem floor witness (baselines 77/912/28546 set 2026-07-02; `pipeline.rs` alone is 417 fns, the dominant unit); the delete-guard blocks removing a v1 test module without its floor witness (hard gate per module, bulk-delete forbidden). **Scrutinize before migrating (operator, 2026-07-05): tests are not inherently valuable — triage each module first (migrate · delete-as-redundant · delete-as-low-value); the guard currently requires an exact-stem witness for ANY delete, so the lane's first deliverable is a typed retirement path through the guard, never a bypass.** Parallelizable now; gates the terminal collapse per module. NOTE: migrated witnesses run on the local discovery path — CI enrollment is opt-in (#6232) until affected-set selection lands. +- [ ] **make cargo-green continuous (or cheap)** — `route_a_emit_fresh_cargo_green_test` is ignored (~3–5min); an emitter regression that keeps bytes stable per the old seed but breaks a fresh build surfaces late. Decide: fold into `RegenVerifyGate` (doubles its cost) or a scheduled receipt. (This exact failure mode materialized 2026-07-05: fresh emit = 1667 rustc errors, accumulated invisibly while the byte wall was dark — see the regen-cutover receipt.) ## 2. Compute fabric — own the infra (CI · deploy · control plane) @@ -51,7 +51,7 @@ State (2026-07-01): required CI is back on the fleet after the Ubicloud detour ( - [ ] **kill the serial compile-clean wall** *(the measured dominant cost — 2026-07-01 receipts from the first Ubicloud main run and its self-hosted twin)* — batch-1 `dag_compile_clean_gate` is ONE node in ONE resolve-group: ~47 of the ~50min step, immune to `spawn_width` (width=9 was live and only parallelizes the ~4min batch-2 tail; same wall on both runner types — the bottleneck is structural, not the host). Levers in leverage order: (a) affected-set-scope the compile-clean to the changed node-closure; (b) cross-run resolve memoization (the per-module resolve cache is within-process only — nothing persists across runs); (c) shard the gate per-module so the width budget finally applies to the dominant node. NOTE the 2026-06-24 profile (26m whole floor) and this receipt (~47min batch-1 alone) disagree — re-profile is part of the §3 audit. - [ ] **affected-set de-fork — `v2.lens.affected_set` as single authority** — witness-level run/skip live (#6061, v1 `force_run_all` hack retired); remaining: precompute-skip wired to the same one `.dag` query, the Rust parallel (`NodeFrontierSeeds`) deleted (N→1), and a wall-clock+RSS receipt on a scoped diff. [plan](docs/plans/affected-set-precompute-pruning.md) - - [ ] **provenance ingest live at floor runtime** — successor lane: resolver S2a + skip-before-resolve remaining fix (PR #6105 closed 2026-07-02 as measured work-neutral); the node-closure grounding for `v2.lens.affected_set` to be live during the floor pass; gates node-level pruning + the Rust-bridge deletion [plan](docs/plans/affected-set-precompute-pruning.md) + - [ ] **provenance ingest live at floor runtime** (#6105) — successor lane: resolver S2a + skip-before-resolve remaining fix (PR #6105 closed 2026-07-02 measured work-neutral); node-closure grounding for `v2.lens.affected_set` to be live during the floor pass; gates node-level pruning + the Rust-bridge deletion [plan](docs/plans/affected-set-precompute-pruning.md) - [ ] **host-scaffold witness classifier de-fork** (#6224) — dissolve the claim_executor Rust text classifier (`witness_test_fn_uses_live_host_scan` in `cli_run.rs`) into substrate-declared `reads_live_tree` disposition on `TestClaim` rows; interim `floor:host_scaffold` marker in `affected_set_floor_runner.dag` until then (#6224 landed fail-closed skip policy for live-tree witnesses) [plan](docs/plans/affected-set-precompute-pruning.md) - [ ] **the floor is a full recompute every run** — profiled 26m (2026-06-24): ~518s resolves all 870 witnesses cold, a second ~275s discovery pass, ~360s effect-bound gates, ~134s seed compile; on a one-file PR ~99% of the resolve recomputes witnesses whose inputs did not change. **Target: <1min.** The lever is resolve-phase incrementality, NOT cross-run caching — CI is cold-dominated (the exe-hash re-colds on every code change). - [ ] **compile-clean shard A — partition boundary + ONE shard + compose proof** — the direct attack on the serial wall (lever c above): identify the module partition boundary for `dag_compile_clean_gate`, run ONE module shard (manually or via minimal wrapper), and prove the shard verdict composes with the existing whole-tree gate (a shard-green ∧ … ∧ shard-green tree is whole-tree green, and a broken module reds its shard). Non-goals: NO floor-plan/scheduler integration, no width tuning. The partition receipt is the deliverable even if enrollment never follows. — ⏳ awaiting sign-off diff --git a/dag/gunbc/design_document.dag b/dag/gunbc/design_document.dag index 4ed1b273677..e01ce155088 100644 --- a/dag/gunbc/design_document.dag +++ b/dag/gunbc/design_document.dag @@ -101,8 +101,9 @@ fn section_5_blocks() -> List { [ h2(text: "5. Fail-closed (§1's safety axis — harm reduction)"), p(text: "Minimizing cost and complexity (§2–§4) is worthless if a wrong thing passes silently — this is §1's safety axis made concrete. This code is digital: a wrong answer is a **loud error, never a warning** — a bridge collapses, it does not warn. Every path succeeds fully or fails with a typed, located diagnostic; no fabricated plausible output (a bounded \"forever\" ≠ an \"unknown\" error). Relax toward application-layer leniency only under protest, and lean to infra so others can build on your work. Stronger than *catching* a wrong state is making it **unwritable** — **correctness by construction, not validation.** A check that re-states a constraint the model already carries is a *second representation* of it (§2/§3): so prefer a single authority from which the realization is *derived* — the bad state cannot be written — over a check that flags it after the fact, which concedes the bad state *is* writable. The tell that a check was validation standing where construction was available: it can be satisfied by editing the *declaration* while the realization still lies (a key-completeness check went green when the spec was edited while the realizer kept faking the cache key). Reserve post-hoc checks for the genuinely **unstructurable** residue (§6 complexity / necessity — you cannot structurally forbid an *unnecessary* loop). Construction makes a class unwritable only when membership is **decidable**, so every class is one of three: a *wall now* (decidable and grounded — nicknaming, dead scaffolds, effect leaks); a *wall after grounding* (decidable but waiting on its single authority — the cross-representation `==` straddle is one only once `Int = GroupCompletion` grounds it); or a *ratchet forever* (undecidable — optimality, by Rice, never reaches \"never\"). The word **\"never\" is the trap**: it lets a ratchet masquerade as a wall, so check decidability before claiming one — the undecidable residue is the §6 lens, honestly and permanently. The deepest trap is **specification-without-execution**: a typecheck and a `.contains()` grep are *not* consumers — \"done\" means a real consumer **green by execution** plus a discriminating input that goes *red* when the behavior is wrong. (For the LLM agent: fluent, type-checking, grep-passing output is precisely the artifact that looks finished without running. Treat your own output as unverified until a consumer runs it green.)"), + p(text: "A third named trap, the subtlest because it wears this section's own name: **the absorbing fallback — degradation is disguised fail-open.** When a mechanism cannot compute its precise answer, the tempting failure arm substitutes the *superset* instead: can't compute the affected set → rerun the entire suite; cache key uncertain → scan all keys; provenance unavailable → always run. Nothing is *missed*, so the arm gets labeled fail-closed — but it is the fabricated plausible output one level up: **⊤-as-answer conflated with ⊤-as-ignorance** (state-space conflation on the answer lattice — \"everything is affected\" and \"I could not compute what is affected\" are different states whose remedies differ), and it fails open twice. On safety: absorption destroys the only signal that the precise mechanism has a deficit — the failure's frequency is zero *by construction*, so the deficit never ranks for fixing (§6 prices by displaced cost, and a masked cost displaces nothing) and the anemia compounds (the scan-all-keys heuristic in the receipt below was this exact absorption; removing it exposed 8 deficits its silence had hidden). On cost: the fallback is denominated in the *corpus*, not the *change*, so it grows with the repo until the *budget* breaks instead of the build — later, loudly, at interest: §1's safety debt paid in §1's cost currency. And the confidence **threshold** that selects such an arm is a smuggled heuristic — §4 already rules a heuristic never necessary in a closed system — so the threshold's very existence *locates* the anemic modeling it papers over: a solution that must keep degrading to stay green is not a solution being cautious, it is a model being wrong. The rule, and the review tell: **a failure arm must refuse, never widen** — every degradation a typed, located, *countable* diagnostic, so its frequency is observable and prioritizable, never an absorbed rerun. Two neighbors are not this pattern (check the *trigger*: structure vs failure-state): a structural over-approximation computed *as* the answer (a dependency-closure superset is the model's precision frontier, not an absorption), and a deliberate interim fallback that is loud, budget-bounded, and lands with its §6 dissolution trigger. Silent unbounded absorption is never the third."), ul(items: [ - li(text: "*e.g.* a compiler-sized `.dag` corpus typechecked and passed its grep claims, yet `emit` hung >600s on `fn add` → rebuilt `emit = serialize_target ∘ translate` (43 lines), proven by *running* `emit(add)` against the literal `fn add(x: i32, y: i32) -> i32 \{ x + y \}`. Removing a scan-all-keys fail-open heuristic (`0331b526ee`) exposed 8 real inference deficits its fabrication had hidden; the parser's dummy `LitNull` nodes once fed inference bogus types."), + li(text: "*e.g.* a compiler-sized `.dag` corpus typechecked and passed its grep claims, yet `emit` hung >600s on `fn add` → rebuilt `emit = serialize_target ∘ translate` (43 lines), proven by *running* `emit(add)` against the literal `fn add(x: i32, y: i32) -> i32 \{ x + y \}`. Removing a scan-all-keys fail-open heuristic (`0331b526ee`) exposed 8 real inference deficits its fabrication had hidden; the parser's dummy `LitNull` nodes once fed inference bogus types. The absorbing fallback, live in tree: `floor_witness_run_disposition` (`src/v2/workflow/affected_set_floor_runner.dag:122-130`) answers `DiffObservationFailClosed`, `FrontierFailClosed`, *and* the empty diff with `RunWitness` — one arm literally `\"empty diff — run full corpus (fail-closed)\"`, with tests *asserting the string* (`affected_set_floor_runner_test.dag:194`, `provenance_fail_closed_contract_test.dag`) so the degradation is enshrined as the contract — and the corpus-denominated cost duly surfaced as CI's 90-minute timeout, not as a diagnostic (the Building-&-checks enrollment inversion is the loud half of the repair; converting those arms to typed refusals is the rest)."), ]), ] } @@ -131,7 +132,7 @@ fn section_7_blocks() -> List { fn failure_modes_blocks() -> List { [ h2(text: "Recurring failure modes (instances of §3–§5, kept for pattern-matching)"), - p(text: "hollow alias (minimality ≠ grounding) · state-space conflation (an `Option`/`None` meaning >2 things — split into named variants) · cache impurity (key on declared-input content; byte-identical cached-vs-cold is the purity oracle) · reflection evidence ≠ structural proof (prove a read axis by execution, with a no-host-enumeration control) · coercion proven by normalized round-trip, not a golden string · parallel-representation debt (an honestly-marked scaffold duplicating a canonical fact is still a violation) · internal review finds missing tests, external review finds missing checks."), + p(text: "hollow alias (minimality ≠ grounding) · state-space conflation (an `Option`/`None` meaning >2 things — split into named variants) · absorbing fallback (a failure arm that widens — rerun everything, scan all keys, always run — instead of refusing; ⊤-as-answer conflated with ⊤-as-ignorance; the deficit's frequency zeroed by construction, the corpus-denominated cost breaking the budget later) · cache impurity (key on declared-input content; byte-identical cached-vs-cold is the purity oracle) · reflection evidence ≠ structural proof (prove a read axis by execution, with a no-host-enumeration control) · coercion proven by normalized round-trip, not a golden string · parallel-representation debt (an honestly-marked scaffold duplicating a canonical fact is still a violation) · internal review finds missing tests, external review finds missing checks."), ] } @@ -141,7 +142,7 @@ fn open_threads_blocks() -> List { ul(items: [ li(text: "`v2.std.determinism` — §5 determinism mechanism P1 landed (#5941; operator shape-signed, FLAG A/C locked): [determinism mechanism design](docs/plans/determinism-mechanism-design.md)"), li(text: "model §1's axioms (A1–A3) explicitly in `.dag` and have a lens **enforce the syllogism** — every claim a consequence-chain back to an axiom, no orphan and no cycle (the §4 acyclicity test turned on the argument itself; the §7 recursion, with this document as the first target). (operator's next project) → candidate articulation for review: [intent-linearity draft](docs/plans/intent-linearity-design-draft.md)"), - li(text: "**enforcement intent — ask once, compile forever.** The operator's recurring standing directives (enforce complexity repo-wide; lenses must be live; lenses must self-apply; scope must not silently narrow; model must not carry dual representations) are redundant governance work (§2) re-paid each conversation — the operator performing the missing meta-lens by hand. Model each as a durable `StandingIntent` row and gate the relationship (intent ⇄ `LensContract` ⇄ coverage receipt) fail-closed: a mechanism *claiming enforcement* is complete only when it satisfies the `StandingIntent` — named live consumer, declared scope not narrowed, red control, self-application or explicit exemption — else Unknown/Refused, never silently green. One new authority (`StandingIntent`); everything else extends existing machinery — the registry (`LensRegistryEntryV0` → `LensContract`), reusing `ConstructionJustification` / `subject_roster` and consuming `intent_linearity` / `self_applying_lenses` for the fractal (§7) layer (the same property applied to the code, the lens, the subject producer, the registry, and the acceptance template). Default enforcement scope = whole corpus; under-scope is a failing receipt unless explicitly justified. → [enforcement-intent design](docs/plans/enforcement-intent-design.md)"), + li(text: "**enforcement intent — ask once, compile forever.** The operator's recurring standing directives (enforce complexity repo-wide; lenses must be live; lenses must self-apply; scope must not silently narrow; model must not carry dual representations; a failure arm must refuse, never widen — no absorbing fallbacks, §5) are redundant governance work (§2) re-paid each conversation — the operator performing the missing meta-lens by hand. Model each as a durable `StandingIntent` row and gate the relationship (intent ⇄ `LensContract` ⇄ coverage receipt) fail-closed: a mechanism *claiming enforcement* is complete only when it satisfies the `StandingIntent` — named live consumer, declared scope not narrowed, red control, self-application or explicit exemption — else Unknown/Refused, never silently green. One new authority (`StandingIntent`); everything else extends existing machinery — the registry (`LensRegistryEntryV0` → `LensContract`), reusing `ConstructionJustification` / `subject_roster` and consuming `intent_linearity` / `self_applying_lenses` for the fractal (§7) layer (the same property applied to the code, the lens, the subject producer, the registry, and the acceptance template). Default enforcement scope = whole corpus; under-scope is a failing receipt unless explicitly justified. → [enforcement-intent design](docs/plans/enforcement-intent-design.md)"), li(text: "can a lens mechanically diagnose the *leaf-side* of decomposition (§2)? (operator-parked)"), li(text: "the model↔realization fork is systemic, and where unfinished it fails open: every primitive is modeled as a coproduct and realized as a native `Value`, reconciled by per-site bridges, so coverage is accidental and non-compositional. `match` bridges `Int→Zero/Succ` but `Value::eq` has no `Int↔Variant` arm, so `nat_add(85, 32) == 117` silently compared `false` at its `_ => false` chokepoint — a §5 fail-open, not the §2/§7 redundancy the 🟡 dissolve-on markers track. **Landed:** the *numeric tower* fork now fails closed — `eval_binop`'s `BinOp::Eq`/`Ne` raises `InterpError::CrossRepresentationEquality` when a `false` result is *explained* by a native `Int`/`Float` vs `Nat`-coproduct straddle (recursive: catches `nat_add == nat_add` and `[nat_add(1,1)] == [2]`), with `Value::eq` left infallible so it stays the single `CanonKey` map-key authority. The discriminating witness is `cross_representation_equality_test` (forks → typed error; reconciled/native → `true`; genuine diffs `1 == 2`/`Succ\{..\} == Zero` → `false`, not error). **Remaining:** (a) the same straddle for `Bool True|False` over `Value::Bool` (no `==` site in the corpus today) and `Optional/Witness` over `Value::Null` — the latter resists a blanket guard because `Value::Null` is the overloaded `None`/`Absent`/miss sentinel and `present == None` (131 sites) is a *legitimate* `false`, so it needs grounding, not an error arm; (b) the root fix (§1/§2/§7) — ground each primitive into its realization. **Numeric tower: GROUNDED** (#5428, 2026-06-21) — Nat construction-side grounded (`Zero → Int(0)`, `Succ\{prev:Int(k)\} → Int(k+1)`); native form == modeled form; `eval_binop` `CrossRepresentationEquality` guard is dead-in-corpus for numerics, kept as fail-closed backstop until the `Value::Null` split lands (guard removal bundled with that work, fenced out of this window). **Remaining:** `Value::Null` split — Optional/Witness/miss into own carriers (~131 sites; the deeper root, its own runway). (operator: `==` fail-closed, 2026-06-20)"), li(text: "the remaining deleted-`docs/` references in `.dag` comments — provenance / `bind:` pointers into the bankrupted `docs/` tree (e.g. `docs/planning/*`, `design-*.md`) — fold into the dep-graph reform, not a blind repoint. (The named-corpus ledger marks — `Practice N`, and `INVARIANTS` / `THESIS` / `MODELING` / `RELEASE_TODO` / … citations — were swept: dropped, or re-homed to DESIGN.md §-anchors.)"), diff --git a/dag/gunbc/roadmap_authority.dag b/dag/gunbc/roadmap_authority.dag index 5f46a5c0b2e..cbd598b7543 100644 --- a/dag/gunbc/roadmap_authority.dag +++ b/dag/gunbc/roadmap_authority.dag @@ -100,11 +100,11 @@ fn section_1() -> RoadmapSection { elements: [ section_prose(content: "Anchor (do not flip-flop): `.dag` = truth; v2 emits its own seed (no stage0 hand-edits); the trust chain is discharged by execution; then the hand-written seed is deleted. Terminal is **hand-written compiler logic → 0**, not zero bytes of Rust: a pinned v2-emitted bootstrap kernel (~8–15k LOC — `claim_executor`, evaluator host-physics, the regen oracle) survives as the content-addressed seed. → [plan](docs/plans/v2-self-hosting.md) · [de-fork audit](docs/plans/dag-v2-defork-audit.md) · [seed census](docs/plans/seed-shrink-census.md)"), section_prose(content: "Ground truth (2026-07-05): `src/v1` = ~174k hand-written `.rs` LOC (the ~154k figure in older docs is stale) + 44 `.dag` files of v1's own modeling; `src/v2` = 874 `.dag`, zero `.rs`. HAND_MAINTAINED roster is down 24 → 7 files + `module_path_index` (~22.3k LOC: the three lens projections drained #6158/#6211/#6212; `phase_profile.rs` ADDED 2026-07-04 with its own dissolution trigger); `patch_*` is fully dead in-tree. The regen gate proves byte-identity per the COMMITTED seed (two-generation): emitter improvements are latent until a cutover, and the cargo-green receipt is episodic (`#[ignore]`, ~3–5min), not continuous — today's walls are byte-identity + the full 92-file byte fixed point (#6218) + well-typed emit. INTERIM (operator-accepted, 2026-07-05): the CI floor cannot complete inside its 10-minute budget (#6232) while batch-1 compile-clean runs ~40+min, so these walls are proven by LOCAL execution with documented receipts, not by CI, until the §2 compile-clean work lands."), - section_prose(content: "**◆ Milestones:** front-end ✓ · emit-rust well-typed ✓ · cross-tree import ✓ (#5473) · emitted crate cargo-green, 0 rustc errors ✓ (#5777/#5873, re-verified #6099) · `regen --verify` in CI ✓ (#5873) · interim fixpoint gate, 2-of-92 roster ✓ (#6009) · full-roster 92-file byte-fold + host-grounded digest ✓ (#6218) · v1 self-resolution restored ✓ (#6250) → **▸ NOW: regen-cutover cadence · HAND queue drain · fixed-point residue (Node-level compare + placeholder hashes)** → seed-honesty (DDC) → **TERMINAL: `src/v1` deleted**"), + section_prose(content: "**◆ Milestones:** front-end ✓ · emit-rust well-typed ✓ · cross-tree import ✓ (#5473) · emitted crate cargo-green, 0 rustc errors ✓ (#5777/#5873, re-verified #6099 — for the THEN-seed; fresh emit is red today, see NOW) · `regen --verify` in CI ✓ (#5873) · interim fixpoint gate, 2-of-92 roster ✓ (#6009) · full-roster 92-file byte-fold + host-grounded digest ✓ (#6218) · v1 self-resolution restored ✓ (#6250 + #6253 `get`-form revert) → **▸ NOW: emitter restoration to fresh-emit cargo-green (#6243 C8 tail + residue — cutover #1 is BLOCKED on it; 1667 rustc errors measured 2026-07-05) · HAND queue drain · fixed-point residue (Node-level compare + placeholder hashes)** → seed-honesty (DDC) → **TERMINAL: `src/v1` deleted**"), section_group( label: "", nodes: [ - authored_wi(id: "5-regen-cutover", done: false, content: "**regen-cutover cadence** — absorb latent emitter fixes into the committed seed (#6099 merged with the `machine_width` emit test still ignored: two-generation regen means every emitter improvement is invisible until a cutover). Each cutover un-ignores its witnesses; a stale seed hides emitter regressions.", intricacy: IntricacyMedium, volume: VolumeMedium, repo: "gunbc"), + authored_wi(id: "5-regen-cutover", done: false, content: "**regen-cutover cadence** — absorb latent emitter fixes into the committed seed (#6099 merged with the `machine_width` emit test still ignored: two-generation regen means every emitter improvement is invisible until a cutover). Each cutover un-ignores its witnesses; a stale seed hides emitter regressions. RECEIPT (2026-07-05, local, #6253): with resolution repaired, regen write-mode completes and materializes the latent backlog — 40 generated files / ~4.3k lines of drift since their last per-file writes — but the fresh crate is cargo-RED: 1667 rustc errors (E0282/E0308/E0425/E0614/E0631; dominant class = #6243's deref-boxing + alias-brand C8 tail). Cutover #1 is BLOCKED on emitter restoration to fresh-emit cargo-green; until it lands, `regen --verify` is red on that drift by construction and every emitter fix stays latent (the broken cutover was measured and NOT committed).", intricacy: IntricacyMedium, volume: VolumeMedium, repo: "gunbc"), authored(id: "5-real-fixpoint", done: false, content: "**real fixed point** — `content_hash` stage1==stage2 over the FULL seed. LANDED (#6218): `source_text_code_unit_digest` host-grounded on `atom_identity_hash`, and the `SelfHostRealizedComparisonGate` byte-fold widened from the 2-file roster to all 92 GENERATED files via the regen manifest (self-updating roster; the gate's INTERIM disposition deleted). REMAINING: the Node-level comparison — emitted compiler Node vs emitted bytes (`generate_stage_candidate_from_ingest` has zero consumers today) — dissolve the `bootstrap.dag` placeholder hashes, and widen the provenance witness off its 1-file roster. This milestone gates the bulk cutover-delete, seed-honesty, and the shelved TS self-host."), authored(id: "5-dissolve-patches", done: false, content: "**drain the HAND_MAINTAINED queue** (7 files + `module_path_index`, ~22.3k LOC; three lens projections drained ✓ #6158/#6211/#6212 · last `patch_*` dead in-tree ✓ · `phase_profile.rs` added 2026-07-04, dissolution trigger `realization_measurement_loop` Phase 0) — remaining dissolution order: `main.rs` flip-back (attempted #6226, self-reverted — the emitter lost Ci-subcommand/`extract_module_path` emission in #6053's dag_collect split; restore the emit gaps first) → `coproduct_reflection` (de-fork-coupled) → `v1_interpreter` pure-eval emit (kernel D [plan](docs/plans/interpreter-kernel-d.md); model+witness landed #6229, phase ModelAndWitnessOnly, blocked on emit_host transport wiring) → `cli_run.rs` (largest, ~12.1k LOC — grew as the absorption point for the drained projections' pure folds per #6211/#6212/#6217; #6046 hard-gates net-new logic INTO it). Host-physics files (`recorded_fixture` · `resolved_graph_cache`) are terminal-kernel pins, not dissolution targets."), derivable(id: "5-dual-rep-lens", prs: [6104], title: "**no-dual-representation-test lens rebuilt pure-v2**", description: "— lens verdict moves off v1 Rust, the lens-E retirement pattern continued (landed #6104)"), @@ -112,7 +112,7 @@ fn section_1() -> RoadmapSection { authored(id: "5-root-b", done: false, content: "**Root B repoints** — def-unification (coproduct authority + aliases) → repoints (algebra/nat/integer/float/logic/effects/verification) → 🟡-marker dissolution (keystone #5552 merged)"), authored(id: "5-v1coupled", done: false, content: "v1-coupled `coercion`/`node` renames — deferred to v1-delete"), authored_wi(id: "5-test-migration", done: false, content: "**test-migration lane** — live debt per the `v2.lens.test_migration_debt` shrink-only ratchet: 73 v1 test modules / 731 `#[test]` fns / ~23k LOC with no exact-stem floor witness (baselines 77/912/28546 set 2026-07-02; `pipeline.rs` alone is 417 fns, the dominant unit); the delete-guard blocks removing a v1 test module without its floor witness (hard gate per module, bulk-delete forbidden). **Scrutinize before migrating (operator, 2026-07-05): tests are not inherently valuable — triage each module first (migrate · delete-as-redundant · delete-as-low-value); the guard currently requires an exact-stem witness for ANY delete, so the lane's first deliverable is a typed retirement path through the guard, never a bypass.** Parallelizable now; gates the terminal collapse per module. NOTE: migrated witnesses run on the local discovery path — CI enrollment is opt-in (#6232) until affected-set selection lands.", intricacy: IntricacyMedium, volume: VolumeLarge, repo: "gunbc"), - authored(id: "5-cargo-green-continuous", done: false, content: "**make cargo-green continuous (or cheap)** — `route_a_emit_fresh_cargo_green_test` is ignored (~3–5min); an emitter regression that keeps bytes stable per the old seed but breaks a fresh build surfaces late. Decide: fold into `RegenVerifyGate` (doubles its cost) or a scheduled receipt."), + authored(id: "5-cargo-green-continuous", done: false, content: "**make cargo-green continuous (or cheap)** — `route_a_emit_fresh_cargo_green_test` is ignored (~3–5min); an emitter regression that keeps bytes stable per the old seed but breaks a fresh build surfaces late. Decide: fold into `RegenVerifyGate` (doubles its cost) or a scheduled receipt. (This exact failure mode materialized 2026-07-05: fresh emit = 1667 rustc errors, accumulated invisibly while the byte wall was dark — see the regen-cutover receipt.)"), authored(id: "5-seed-honesty", done: false, content: "**seed-honesty discharge** (Diverse Double-Compiling) — modeled in `bootstrap.dag` (`SeedHonestyDischarge`), no execution exists; worse, the modeled witness is fail-open by construction (its evidence argument is the same atom it checks against — Holds trivially, no red case constructible) until Stage 3's executing consumer lands. Needs a reproducible artifact to double-compile. Design proposal (second-compiler candidate `ddc_reference_compiler` + computed fixed-point digest, reusing `self_host.dag`'s `canonical_emitted_bytes_digest`; FLAGs A–D open for operator sign-off): [seed-honesty discharge design](docs/plans/seed-honesty-discharge-design.md)"), authored(id: "5-collapse-v1", done: false, content: "**TERMINAL — collapse `src/v1`**: one atomic regen cutover-delete of the 92 GENERATED files (~117k of stage0's ~137k LOC) + per-module test deletes as migration lands + pin the terminal kernel. Requires: HAND queue empty · real fixed point · test-migration green · seed-honesty."), ], From 8b525a1e7f6ad6ac12f7fde92244bca9873dd9f1 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 5 Jul 2026 03:04:42 +0000 Subject: [PATCH 4/9] WIP: continue work on v1 burn down --- dag/gunbc/roadmap_authority.dag | 4 ++-- src/v1/02_parse.dag | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/dag/gunbc/roadmap_authority.dag b/dag/gunbc/roadmap_authority.dag index cbd598b7543..e405fd9ff45 100644 --- a/dag/gunbc/roadmap_authority.dag +++ b/dag/gunbc/roadmap_authority.dag @@ -100,11 +100,11 @@ fn section_1() -> RoadmapSection { elements: [ section_prose(content: "Anchor (do not flip-flop): `.dag` = truth; v2 emits its own seed (no stage0 hand-edits); the trust chain is discharged by execution; then the hand-written seed is deleted. Terminal is **hand-written compiler logic → 0**, not zero bytes of Rust: a pinned v2-emitted bootstrap kernel (~8–15k LOC — `claim_executor`, evaluator host-physics, the regen oracle) survives as the content-addressed seed. → [plan](docs/plans/v2-self-hosting.md) · [de-fork audit](docs/plans/dag-v2-defork-audit.md) · [seed census](docs/plans/seed-shrink-census.md)"), section_prose(content: "Ground truth (2026-07-05): `src/v1` = ~174k hand-written `.rs` LOC (the ~154k figure in older docs is stale) + 44 `.dag` files of v1's own modeling; `src/v2` = 874 `.dag`, zero `.rs`. HAND_MAINTAINED roster is down 24 → 7 files + `module_path_index` (~22.3k LOC: the three lens projections drained #6158/#6211/#6212; `phase_profile.rs` ADDED 2026-07-04 with its own dissolution trigger); `patch_*` is fully dead in-tree. The regen gate proves byte-identity per the COMMITTED seed (two-generation): emitter improvements are latent until a cutover, and the cargo-green receipt is episodic (`#[ignore]`, ~3–5min), not continuous — today's walls are byte-identity + the full 92-file byte fixed point (#6218) + well-typed emit. INTERIM (operator-accepted, 2026-07-05): the CI floor cannot complete inside its 10-minute budget (#6232) while batch-1 compile-clean runs ~40+min, so these walls are proven by LOCAL execution with documented receipts, not by CI, until the §2 compile-clean work lands."), - section_prose(content: "**◆ Milestones:** front-end ✓ · emit-rust well-typed ✓ · cross-tree import ✓ (#5473) · emitted crate cargo-green, 0 rustc errors ✓ (#5777/#5873, re-verified #6099 — for the THEN-seed; fresh emit is red today, see NOW) · `regen --verify` in CI ✓ (#5873) · interim fixpoint gate, 2-of-92 roster ✓ (#6009) · full-roster 92-file byte-fold + host-grounded digest ✓ (#6218) · v1 self-resolution restored ✓ (#6250 + #6253 `get`-form revert) → **▸ NOW: emitter restoration to fresh-emit cargo-green (#6243 C8 tail + residue — cutover #1 is BLOCKED on it; 1667 rustc errors measured 2026-07-05) · HAND queue drain · fixed-point residue (Node-level compare + placeholder hashes)** → seed-honesty (DDC) → **TERMINAL: `src/v1` deleted**"), + section_prose(content: "**◆ Milestones:** front-end ✓ · emit-rust well-typed ✓ · cross-tree import ✓ (#5473) · emitted crate cargo-green, 0 rustc errors ✓ (#5777/#5873, re-verified #6099 — for the THEN-seed; fresh emit is red today, see NOW) · `regen --verify` in CI ✓ (#5873) · interim fixpoint gate, 2-of-92 roster ✓ (#6009) · full-roster 92-file byte-fold + host-grounded digest ✓ (#6218) · v1 self-resolution: #6235 arm fixed ✓ (#6250), #6241 `get`-registry arm → #6255 in flight (operator-resolved collision: register the builtin, preserving P2's O(1) token access) → **▸ NOW: emitter restoration to fresh-emit cargo-green (#6243 C8 tail + residue — cutover #1 is BLOCKED on it; 1667 rustc errors measured 2026-07-05) · HAND queue drain · fixed-point residue (Node-level compare + placeholder hashes)** → seed-honesty (DDC) → **TERMINAL: `src/v1` deleted**"), section_group( label: "", nodes: [ - authored_wi(id: "5-regen-cutover", done: false, content: "**regen-cutover cadence** — absorb latent emitter fixes into the committed seed (#6099 merged with the `machine_width` emit test still ignored: two-generation regen means every emitter improvement is invisible until a cutover). Each cutover un-ignores its witnesses; a stale seed hides emitter regressions. RECEIPT (2026-07-05, local, #6253): with resolution repaired, regen write-mode completes and materializes the latent backlog — 40 generated files / ~4.3k lines of drift since their last per-file writes — but the fresh crate is cargo-RED: 1667 rustc errors (E0282/E0308/E0425/E0614/E0631; dominant class = #6243's deref-boxing + alias-brand C8 tail). Cutover #1 is BLOCKED on emitter restoration to fresh-emit cargo-green; until it lands, `regen --verify` is red on that drift by construction and every emitter fix stays latent (the broken cutover was measured and NOT committed).", intricacy: IntricacyMedium, volume: VolumeMedium, repo: "gunbc"), + authored_wi(id: "5-regen-cutover", done: false, content: "**regen-cutover cadence** — absorb latent emitter fixes into the committed seed (#6099 merged with the `machine_width` emit test still ignored: two-generation regen means every emitter improvement is invisible until a cutover). Each cutover un-ignores its witnesses; a stale seed hides emitter regressions. RECEIPT (2026-07-05, local, #6253 — measured on a tree with the `get` sites resolvable; numbers independent of which #6241-gap fix lands, #6255 is the operator-chosen one): regen write-mode completes and materializes the latent backlog — 40 generated files / ~4.3k lines of drift since their last per-file writes — but the fresh crate is cargo-RED: 1667 rustc errors (E0282/E0308/E0425/E0614/E0631; dominant class = #6243's deref-boxing + alias-brand C8 tail). Cutover #1 is BLOCKED on emitter restoration to fresh-emit cargo-green; until it lands, `regen --verify` is red on that drift by construction and every emitter fix stays latent (the broken cutover was measured and NOT committed).", intricacy: IntricacyMedium, volume: VolumeMedium, repo: "gunbc"), authored(id: "5-real-fixpoint", done: false, content: "**real fixed point** — `content_hash` stage1==stage2 over the FULL seed. LANDED (#6218): `source_text_code_unit_digest` host-grounded on `atom_identity_hash`, and the `SelfHostRealizedComparisonGate` byte-fold widened from the 2-file roster to all 92 GENERATED files via the regen manifest (self-updating roster; the gate's INTERIM disposition deleted). REMAINING: the Node-level comparison — emitted compiler Node vs emitted bytes (`generate_stage_candidate_from_ingest` has zero consumers today) — dissolve the `bootstrap.dag` placeholder hashes, and widen the provenance witness off its 1-file roster. This milestone gates the bulk cutover-delete, seed-honesty, and the shelved TS self-host."), authored(id: "5-dissolve-patches", done: false, content: "**drain the HAND_MAINTAINED queue** (7 files + `module_path_index`, ~22.3k LOC; three lens projections drained ✓ #6158/#6211/#6212 · last `patch_*` dead in-tree ✓ · `phase_profile.rs` added 2026-07-04, dissolution trigger `realization_measurement_loop` Phase 0) — remaining dissolution order: `main.rs` flip-back (attempted #6226, self-reverted — the emitter lost Ci-subcommand/`extract_module_path` emission in #6053's dag_collect split; restore the emit gaps first) → `coproduct_reflection` (de-fork-coupled) → `v1_interpreter` pure-eval emit (kernel D [plan](docs/plans/interpreter-kernel-d.md); model+witness landed #6229, phase ModelAndWitnessOnly, blocked on emit_host transport wiring) → `cli_run.rs` (largest, ~12.1k LOC — grew as the absorption point for the drained projections' pure folds per #6211/#6212/#6217; #6046 hard-gates net-new logic INTO it). Host-physics files (`recorded_fixture` · `resolved_graph_cache`) are terminal-kernel pins, not dissolution targets."), derivable(id: "5-dual-rep-lens", prs: [6104], title: "**no-dual-representation-test lens rebuilt pure-v2**", description: "— lens verdict moves off v1 Rust, the lens-E retirement pattern continued (landed #6104)"), diff --git a/src/v1/02_parse.dag b/src/v1/02_parse.dag index 27f0494e5fc..9c47b1b137c 100644 --- a/src/v1/02_parse.dag +++ b/src/v1/02_parse.dag @@ -76,7 +76,7 @@ fn token_stream_position(stream: TokenStream) -> Int { } fn token_stream_first(stream: TokenStream) -> Token? { - skip(xs: stream.all, n: stream.pos) |> first + get(xs: stream.all, index: stream.pos) } fn token_stream_advance(stream: TokenStream, n: Int) -> TokenStream { @@ -84,7 +84,7 @@ fn token_stream_advance(stream: TokenStream, n: Int) -> TokenStream { } fn token_stream_peek(stream: TokenStream, offset: Int) -> Token? { - skip(xs: stream.all, n: stream.pos + offset) |> first + get(xs: stream.all, index: stream.pos + offset) } type ParseContext { From 397a2254fa3be010b324b3bddfa79f0cfbf2e5a7 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 5 Jul 2026 03:06:19 +0000 Subject: [PATCH 5/9] Drop get-form revert per operator collision resolution (#6255 owns the get arm); regen ROADMAP projection Co-Authored-By: Claude Fable 5 --- ROADMAP.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/ROADMAP.md b/ROADMAP.md index 7201e003f33..c0b8e7ae15f 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -12,9 +12,9 @@ Anchor (do not flip-flop): `.dag` = truth; v2 emits its own seed (no stage0 hand Ground truth (2026-07-05): `src/v1` = ~174k hand-written `.rs` LOC (the ~154k figure in older docs is stale) + 44 `.dag` files of v1's own modeling; `src/v2` = 874 `.dag`, zero `.rs`. HAND_MAINTAINED roster is down 24 → 7 files + `module_path_index` (~22.3k LOC: the three lens projections drained #6158/#6211/#6212; `phase_profile.rs` ADDED 2026-07-04 with its own dissolution trigger); `patch_*` is fully dead in-tree. The regen gate proves byte-identity per the COMMITTED seed (two-generation): emitter improvements are latent until a cutover, and the cargo-green receipt is episodic (`#[ignore]`, ~3–5min), not continuous — today's walls are byte-identity + the full 92-file byte fixed point (#6218) + well-typed emit. INTERIM (operator-accepted, 2026-07-05): the CI floor cannot complete inside its 10-minute budget (#6232) while batch-1 compile-clean runs ~40+min, so these walls are proven by LOCAL execution with documented receipts, not by CI, until the §2 compile-clean work lands. -**◆ Milestones:** front-end ✓ · emit-rust well-typed ✓ · cross-tree import ✓ (#5473) · emitted crate cargo-green, 0 rustc errors ✓ (#5777/#5873, re-verified #6099 — for the THEN-seed; fresh emit is red today, see NOW) · `regen --verify` in CI ✓ (#5873) · interim fixpoint gate, 2-of-92 roster ✓ (#6009) · full-roster 92-file byte-fold + host-grounded digest ✓ (#6218) · v1 self-resolution restored ✓ (#6250 + #6253 `get`-form revert) → **▸ NOW: emitter restoration to fresh-emit cargo-green (#6243 C8 tail + residue — cutover #1 is BLOCKED on it; 1667 rustc errors measured 2026-07-05) · HAND queue drain · fixed-point residue (Node-level compare + placeholder hashes)** → seed-honesty (DDC) → **TERMINAL: `src/v1` deleted** +**◆ Milestones:** front-end ✓ · emit-rust well-typed ✓ · cross-tree import ✓ (#5473) · emitted crate cargo-green, 0 rustc errors ✓ (#5777/#5873, re-verified #6099 — for the THEN-seed; fresh emit is red today, see NOW) · `regen --verify` in CI ✓ (#5873) · interim fixpoint gate, 2-of-92 roster ✓ (#6009) · full-roster 92-file byte-fold + host-grounded digest ✓ (#6218) · v1 self-resolution: #6235 arm fixed ✓ (#6250), #6241 `get`-registry arm → #6255 in flight (operator-resolved collision: register the builtin, preserving P2's O(1) token access) → **▸ NOW: emitter restoration to fresh-emit cargo-green (#6243 C8 tail + residue — cutover #1 is BLOCKED on it; 1667 rustc errors measured 2026-07-05) · HAND queue drain · fixed-point residue (Node-level compare + placeholder hashes)** → seed-honesty (DDC) → **TERMINAL: `src/v1` deleted** -- [ ] **regen-cutover cadence** — absorb latent emitter fixes into the committed seed (#6099 merged with the `machine_width` emit test still ignored: two-generation regen means every emitter improvement is invisible until a cutover). Each cutover un-ignores its witnesses; a stale seed hides emitter regressions. RECEIPT (2026-07-05, local, #6253): with resolution repaired, regen write-mode completes and materializes the latent backlog — 40 generated files / ~4.3k lines of drift since their last per-file writes — but the fresh crate is cargo-RED: 1667 rustc errors (E0282/E0308/E0425/E0614/E0631; dominant class = #6243's deref-boxing + alias-brand C8 tail). Cutover #1 is BLOCKED on emitter restoration to fresh-emit cargo-green; until it lands, `regen --verify` is red on that drift by construction and every emitter fix stays latent (the broken cutover was measured and NOT committed). +- [ ] **regen-cutover cadence** — absorb latent emitter fixes into the committed seed (#6099 merged with the `machine_width` emit test still ignored: two-generation regen means every emitter improvement is invisible until a cutover). Each cutover un-ignores its witnesses; a stale seed hides emitter regressions. RECEIPT (2026-07-05, local, #6253 — measured on a tree with the `get` sites resolvable; numbers independent of which #6241-gap fix lands, #6255 is the operator-chosen one): regen write-mode completes and materializes the latent backlog — 40 generated files / ~4.3k lines of drift since their last per-file writes — but the fresh crate is cargo-RED: 1667 rustc errors (E0282/E0308/E0425/E0614/E0631; dominant class = #6243's deref-boxing + alias-brand C8 tail). Cutover #1 is BLOCKED on emitter restoration to fresh-emit cargo-green; until it lands, `regen --verify` is red on that drift by construction and every emitter fix stays latent (the broken cutover was measured and NOT committed). - [ ] **real fixed point** — `content_hash` stage1==stage2 over the FULL seed. LANDED (#6218): `source_text_code_unit_digest` host-grounded on `atom_identity_hash`, and the `SelfHostRealizedComparisonGate` byte-fold widened from the 2-file roster to all 92 GENERATED files via the regen manifest (self-updating roster; the gate's INTERIM disposition deleted). REMAINING: the Node-level comparison — emitted compiler Node vs emitted bytes (`generate_stage_candidate_from_ingest` has zero consumers today) — dissolve the `bootstrap.dag` placeholder hashes, and widen the provenance witness off its 1-file roster. This milestone gates the bulk cutover-delete, seed-honesty, and the shelved TS self-host. - [ ] **seed-honesty discharge** (Diverse Double-Compiling) — modeled in `bootstrap.dag` (`SeedHonestyDischarge`), no execution exists; worse, the modeled witness is fail-open by construction (its evidence argument is the same atom it checks against — Holds trivially, no red case constructible) until Stage 3's executing consumer lands. Needs a reproducible artifact to double-compile. Design proposal (second-compiler candidate `ddc_reference_compiler` + computed fixed-point digest, reusing `self_host.dag`'s `canonical_emitted_bytes_digest`; FLAGs A–D open for operator sign-off): [seed-honesty discharge design](docs/plans/seed-honesty-discharge-design.md) - [ ] **TERMINAL — collapse `src/v1`**: one atomic regen cutover-delete of the 92 GENERATED files (~117k of stage0's ~137k LOC) + per-module test deletes as migration lands + pin the terminal kernel. Requires: HAND queue empty · real fixed point · test-migration green · seed-honesty. From 5734c2842908e552e99ad9df773516dba2142dae Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 5 Jul 2026 03:15:03 +0000 Subject: [PATCH 6/9] WIP: continue work on v1 burn down --- src/v1/04_method.dag | 1 + src/v1/stage0/src/v1_compiler_infer_method.rs | 5 +++++ 2 files changed, 6 insertions(+) diff --git a/src/v1/04_method.dag b/src/v1/04_method.dag index fd2345a797e..cb5cd096453 100644 --- a/src/v1/04_method.dag +++ b/src/v1/04_method.dag @@ -88,6 +88,7 @@ fn builtin_function_registry() -> Map { let m = map_insert(m, "map_keys", list_of_type_variable(id: "collection_element")) let m = map_insert(m, "map_values", list_of_type_variable(id: "collection_element")) let m = map_insert(m, "reverse", list_of_type_variable(id: "collection_element")) + let m = map_insert(m, "get", with_optional_cardinality(n: type_variable_node(id: "collection_element"))) let m = map_insert(m, "list_push", list_of_type_variable(id: "collection_element")) let m = map_insert(m, "hash_combine", hash_type) let m = map_insert(m, "atom_identity_hash", hash_type) diff --git a/src/v1/stage0/src/v1_compiler_infer_method.rs b/src/v1/stage0/src/v1_compiler_infer_method.rs index 25d635b19b1..96d9884ceb1 100644 --- a/src/v1/stage0/src/v1_compiler_infer_method.rs +++ b/src/v1/stage0/src/v1_compiler_infer_method.rs @@ -173,6 +173,11 @@ pub fn builtin_function_registry() -> Rc>> { "reverse".to_string(), list_of_type_variable("collection_element".to_string()), ); + let m = v1_rt::rc_map_insert( + m.clone(), + "get".to_string(), + with_optional_cardinality(type_variable_node("collection_element".to_string())), + ); let m = v1_rt::rc_map_insert( m.clone(), "list_push".to_string(), From d2b65e92ff9da3aea8bb9cf534a3fa590b1e5c51 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 5 Jul 2026 03:45:10 +0000 Subject: [PATCH 7/9] WIP: continue work on v1 burn down --- dag/test/claim/roadmap_authority_test.dag | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/dag/test/claim/roadmap_authority_test.dag b/dag/test/claim/roadmap_authority_test.dag index d798ee114e6..e7116fe4bc9 100644 --- a/dag/test/claim/roadmap_authority_test.dag +++ b/dag/test/claim/roadmap_authority_test.dag @@ -75,14 +75,14 @@ fn witness_a_prose_verbatim() -> Bool { fn witness_b_ordered_interleaving() -> Bool { let o = out() - string_contains(s: o, pattern: "[seed census](docs/plans/seed-shrink-census.md)\n\nGround truth (2026-07-01):") - && string_contains(s: o, pattern: "byte-identity + the interim fixpoint + well-typed emit.\n\n**◆ Milestones:** front-end ✓") + string_contains(s: o, pattern: "[seed census](docs/plans/seed-shrink-census.md)\n\nGround truth (2026-07-05):") + && string_contains(s: o, pattern: "until the §2 compile-clean work lands.\n\n**◆ Milestones:** front-end ✓") && string_contains(s: o, pattern: "[charter](docs/plans/ci-process-end-to-end.md)\n\n**The core design rule (operator-signed, 2026-07-01):**") && string_contains(s: o, pattern: "Phase 2, earned by receipts.\n\n**◆ Milestones:** OOM root-caused") } fn witness_b_order_discriminator() -> Bool { - !string_contains(s: out(), pattern: "**◆ Milestones:** front-end ✓ · emit-rust well-typed ✓ · cross-tree import ✓ (#5473)\n\nGround truth (2026-07-01):") + !string_contains(s: out(), pattern: "**◆ Milestones:** front-end ✓ · emit-rust well-typed ✓ · cross-tree import ✓ (#5473)\n\nGround truth (2026-07-05):") } fn witness_merge_perturb_does_not_flip_boxes() -> Bool { From fbf05730b8263ba4657af975b4aba642e46c8092 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 5 Jul 2026 03:45:19 +0000 Subject: [PATCH 8/9] Fix roadmap_authority_test pins: track the 2026-07-05 ground-truth refresh (cursor RC) + repoint pre-existing-stale charter-adjacency pin MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit witness_b_ordered_interleaving pinned the pre-refresh prose (Ground truth 2026-07-01 date + old walls sentence); updated to the refreshed authority. Also fixed a pin this PR did NOT stale: the charter->core-design-rule adjacency has been red on main since [host-converge inventory] was appended after [charter] — repointed to the real paragraph tail. Discriminator date kept in lockstep. All pins verified against the regenerated ROADMAP.md (byte-identical projection). Co-Authored-By: Claude Fable 5 --- dag/test/claim/roadmap_authority_test.dag | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/dag/test/claim/roadmap_authority_test.dag b/dag/test/claim/roadmap_authority_test.dag index e7116fe4bc9..485165d28f3 100644 --- a/dag/test/claim/roadmap_authority_test.dag +++ b/dag/test/claim/roadmap_authority_test.dag @@ -77,7 +77,7 @@ fn witness_b_ordered_interleaving() -> Bool { let o = out() string_contains(s: o, pattern: "[seed census](docs/plans/seed-shrink-census.md)\n\nGround truth (2026-07-05):") && string_contains(s: o, pattern: "until the §2 compile-clean work lands.\n\n**◆ Milestones:** front-end ✓") - && string_contains(s: o, pattern: "[charter](docs/plans/ci-process-end-to-end.md)\n\n**The core design rule (operator-signed, 2026-07-01):**") + && string_contains(s: o, pattern: "[host-converge inventory](docs/plans/host-converge-inventory.md)\n\n**The core design rule (operator-signed, 2026-07-01):**") && string_contains(s: o, pattern: "Phase 2, earned by receipts.\n\n**◆ Milestones:** OOM root-caused") } From ffc81d12862e0155aa0ba9f11c22b4ba20bfc012 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 5 Jul 2026 04:44:22 +0000 Subject: [PATCH 9/9] Regenerate ci.yml from the #6263 authority (step-level budgets + 20/30-min job caps were merged inert) #6263 changed the ci_spec authority (budget breach = step-level FAILURE, job caps ci 10->20 / rust_tests 10->30) but did not commit the regenerated workflow, so main still runs the old 10-minute silent-cancellation ci.yml and the merged fix is inert. This is the byte-exact main_wet output from merged main (generated_artifact_gate.dag); no hand edits. The ci.yml drift gate that would have caught this lives in batch-2, which dark CI never reaches -- found by running the gate locally. Co-Authored-By: Claude Fable 5 --- .github/workflows/ci.yml | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a94b20d4ee0..d836cd3d581 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -18,7 +18,7 @@ env: jobs: ci: runs-on: [self-hosted, linux, arm64] - timeout-minutes: 10 + timeout-minutes: 20 steps: - name: Checkout uses: actions/checkout@v5 @@ -92,14 +92,16 @@ jobs: STAMP_EXIT=$? if [ "$FLOOR_EXIT" -ne 0 ]; then exit "$FLOOR_EXIT"; fi exit "$STAMP_EXIT" + timeout-minutes: 10 - name: Merge-admission gate (receipt required; freshness block held until GatingEnforced) run: | ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd) git fetch --no-tags origin main "$ROOT/target/release/gunbc" run --source-root dag --source-root src/v2 --entry dag/tools/merge_admission_gate.dag --function main + timeout-minutes: 5 rust_tests: runs-on: [self-hosted, linux, arm64] - timeout-minutes: 10 + timeout-minutes: 30 steps: - name: Checkout uses: actions/checkout@v5 @@ -147,6 +149,7 @@ jobs: case "$(uname -m)" in aarch64|arm64) A=linux-arm ;; *) A=linux ;; esac curl -LsSf --retry 3 "https://get.nexte.st/0.9.138/$A" | tar zxf - -C "$CARGO_HOME/bin" fi + timeout-minutes: 5 - name: v1 rust gate (fmt + clippy + nextest) run: | ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd) @@ -193,11 +196,13 @@ jobs: fi fi rm -f "$BUILD_LOG" + timeout-minutes: 15 - name: rust_tests cgroup peak (placement divisor) run: | BIN="$(git rev-parse --show-toplevel 2>/dev/null || pwd)/target/release/claim_executor" if [ -x "$BIN" ]; then "$BIN" --measure-cgroup-peak; else echo "[measurement] cgroup peak: unavailable (claim_executor not built)"; fi if: always() + timeout-minutes: 5 deploy_dashboard_srv1: runs-on: [self-hosted, linux, arm64, srv1] needs: [ci]