Skip to content

Delete flatten_visible_bindings + merge_envs + env-counter instrument: one-level visibility by construction (floor resolve 286.7s -> 2.4s) - #6331

Merged
briansrls merged 53 commits into
mainfrom
session/sharp-wolf-473
Jul 7, 2026
Merged

briansrls merged 53 commits into
mainfrom
session/sharp-wolf-473

Conversation

@briansrls

@briansrls briansrls commented Jul 6, 2026 •

Copy link
Copy Markdown
Contributor

Delete flatten_visible_bindings / merge_envs and the whole env-counter instrument — the fallback becomes unwritable by construction (operator ruling 2026-07-06).

What

Model (src/v1/04_env.dag, 04_infer.dag):

  • flatten_visible_bindings (recursive whole-ancestry re-flatten) and merge_envs (dead — zero call sites) are deleted. Visibility reads are one-level by construction: local str_bindings/ancestry_str_bindings, or a fold over parent.str_bindings only. With no whole-env flatten left to call, the state the counter guarded is unwritable.
  • The env-counter instrument dissolves as one unit: the constant-0 getter stubs, reset/maybe_print stubs, and the 04_infer import rows. Main had already deleted the record_* statement calls from the model; the getters' stated reason to exist ("until the phase_profile consumer drops them") expires in this PR because that consumer is dropped here.

Generated seeds (primed to the model; fn bodies spliced from fresh emit):

  • v1_compiler_infer_env.rs: the five AtomicU64 statics, all getter/reset/print/record fns, flatten_visible_bindings, and merge_envs deleted. These were hand-injected divergence in a generated file — the exact parallel-representation shape the operator ruled against.
  • v1_compiler_infer.rs: zombie record_lit_variant_fields_from_visible_env deleted (no .dag counterpart, zero callers); 4 record_* calls deleted; field_in_any_variant_named primed to the variant_owner_node form (04_infer.dag authority — no ancestry flatten).
  • v1_compiler_infer_resolve.rs: collect_unit_variant_phantom_matches primed to the one-level parent fold (04_resolve.dag:81 authority). This was the hot site: the stale seed full-flattened the entire ancestry DAG per unit-variant lookup.

Hand-maintained consumers:

  • cli_run.rs: reset/maybe_print calls and import dropped (the GUNBC_TYPE_ENV_PROFILE surface is gone).
  • phase_profile.rs: heartbeat env_* counter reads dropped — with record_* gone they would print fabricated zeros.
  • type_env_scope_chain_test.rs: the three counter-equality witnesses deleted (flatten==0, build_calls==DEPTH, merge_cache<=DEPTH) — counter proxies of the instrument being dissolved. The time-based sub-quadratic import-chain test in the same file remains the live scaling witness. Known gap, on lively-raven-355's SymbolIndex-surgery ledger by agreement: a deep-ancestry / real-corpus time-denominated red control (synthetic shallow chains do not redden on the real ancestry wall).

v2 lens citations: two complexity_r1_accumulator_copy* strings cited deleted merge_envs lines as the blessed base-port example — repointed to historical form; the citation now names the live overlay-port census suspect (collect_unit_variant_phantom_matches fold, 04_resolve.dag).

Why

The floor/demand-driven realize path re-flattened every imported env's parent DAG per module: one real module (test.claim.ci_budget_tree_witness) typechecked in 218.7 s with flatten_parent_recurses=82,713 — the CI-10-minute-kill wall on that path. The .dag model had already fixed all the call sites; the stale seeds kept executing the old flatten. The counter guarding the fallback was a parallel representation ("2-factor authentication") — the §5-correct fix is making the fallback unwritable by construction.

Receipts

  • Floor probe (claim_batch --roster-from-discovery, same host): ci_budget_tree_witness_test.dag resolve 286,731 ms → 2,376 ms (~121×), witness PASS. The baseline run died 28/229 entries in; the after-run covers the full discovery roster with slowest resolve 6.5 s.
  • Batch shape: v2-pool (--source-root dag --source-root src/v2 --target dag, the CI compile-clean pool) reconcile finishes in ~85–103 s on this branch's binary; the pre-diff binary was killed after 50+ minutes still inside the same reconcile.
  • Corpus diagnostics parity (src/v1+dag pool): exit 0, same 7 pre-existing ErrorNode/dag_collect diagnostics — no new refusals, no absorbed ones.
  • cargo test -p v1-compiler -p v1-compiler-tests: 146 passed / 5 ignored / 1 failed — the failure (fail_closed_non_dag_file_forces_run_all) fails identically on the pre-diff tree (A/B worktree at the merge-base): pre-existing on merged main, not this PR.
  • regen_stage0 --verify: 30 stale files before → 30 after, same roster (the mixed-remainder convergence lane) — no new staleness introduced.
  • Binary check: strings target/release/claim_batch | grep -c flatten_visible → 0.
  • Pre-existing corpus refusal surfaced (not caused) by faster coverage: dag/gunbc/network_identity_subsumption.dag:58 gets a typed refusal (expected Product(HostName), got Primitive(DhcpClientHostNameOption12)) on the demand-driven path — A/B-verified byte-identical on the pre-diff binary. It is a cross-module alias-expansion deficit (the type DhcpClientHostNameOption12 = HostName alias in field position never expands), reported to the alias-brand lane. Not absorbed, not patched around here.

Coordination: namespace-as-sole-authority split locked with lively-raven-355 — he drives build_type_env → SymbolIndex (floor path) serialized behind this PR; I drive emit_imports → SymbolIndex (82% batch path) as the follow-on.

🤖 Generated with Claude Code

Brian Searls and others added 30 commits July 5, 2026 22:28
…|allow)

Operator ruling 2026-07-05: the silent clone arm in the rc_* update family
is a degradation that must stop the pipeline, not widen. Every shared-Rc
update (rc_map_insert/merge, rc_list_push/concat, rc_set_insert/union) and
take_owned_counted's clone arm now routes through rc_shared_update_guard:

- GUNBC_CLONE_FALLBACK=fail (default): typed, located panic naming the
  generated caller (#[track_caller]) — the work-queue key for licensing.
- =count: per-site ledger, first-hit line + ranked exit report (Drop on the
  thread_local), so degradation frequency is observable per §5.
- =allow: interim escape hatch.

tier-1 compile enumerates 205 degraded sites; top: rc_map_merge at
infer_env.rs:413 (14,360 clones), dag_collect.rs:234/239 (5,049 each) —
the profiled O(n^2) cold-compile root cause.

Template (runtime_rust.dag) and seed (v1_rt.rs) edited in sync, same
pattern as #6249.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…de the factory model in DESIGN.md §5

Operator rulings 2026-07-05:
- GUNBC_CLONE_FALLBACK=allow removed. Modes are fail (default, refuses) and
  count (stopped-line audit: full ledger, still not a green run). No mode
  silences a refusal.
- DESIGN.md §5: no-escape-hatches corollary + the factory model as a merge
  REQUIREMENT — a diff landing a non-fail-closed failure arm (silent widen,
  fabricated default, uncounted degradation, escape hatch) is a hard reject
  in review.
- 6 inline pre-#6249 `Rc::try_unwrap(..).unwrap_or_else(clone)` fold sites
  in the generated seed (compile/infer_cycle/resolve x2/ownership/emit_rust)
  hand-synced to take_owned_counted — the guard's known bypasses closed;
  regen supersedes the hand-sync.
- take_owned_counted count arm ledgered into the same exit report as rc_*
  (one stopped-line audit surface).
- Interpreter: Bool True|False vs Value::Bool cross-representation `==`
  straddle now refuses (CrossRepresentationEquality), mirroring the numeric
  arm; DESIGN §5 named it the remaining decidable straddle. Its by-execution
  receipt joins the cross_representation receipts behind the stopped line.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…erpreter Value::Map)

Root fix for the clone-fallback class on maps (operator go-ahead 2026-07-05).
The compiled runtime realized Map as Rc<std HashMap> — O(n) copy on any
shared update — while the interpreter already realized Value::Map as
im_rc::HashMap (a §3 model↔realization fork). One swap of which HashMap the
generated code imports (extdeps/languages/rust/types.dag import row +
runtime_rust.dag header + seed hand-sync; type spellings and call sites
unchanged): Rc::make_mut's clone arm is now O(1) structural sharing and each
insert copies an O(log n) node path — shared update becomes the designed
path, so rc_map_insert/rc_map_merge leave the clone-fallback guard (lists
and sets keep it until they migrate too).

By-execution receipts (frozen-unit cold-compile benchmark):
- tier-1: 2.26s -> 0.66s; ledger 205 degraded sites -> 18 (all map sites gone)
- tier-10: 239s -> 41.7s (5.7x); 1.74M map clone-fallbacks -> 0
- remaining ledger is exactly rc_list_push/rc_list_concat/rc_set_insert —
  the named follow-up (List/Set -> persistent carriers need emitter type
  template work, not just the import row)

im-rc serde feature enabled for the artifact-serialization derives; hand
seams (cli_run, interpreter, bins, test mods) repointed per direction —
host-internal std maps stay std. fmt + clippy -D warnings green across all
targets. Run-to-run artifact nondeterminism predates this change (open
v2.std.determinism thread), verified by pre-change A/B.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…fallback guard + per-site move licenses

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…de items)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…provided (generation-agnostic)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Resolves #6269 test-migration collision: accept main's deletion of
src/v1/ownership_movable_test.dag (v2 manual mirror carries the license-removal
edit); reconcile dag_collect_fingerprint_witness.rs bin with im_rc carriers
(hashes -> Rc<im_rc::Vector>, Node children/params via .into()).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Brian Searls and others added 4 commits July 6, 2026 20:09
…efusal is a pre-existing alias-expansion deficit, A/B-verified on the pre-diff binary)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title emit -> realization Delete flatten_visible_bindings + merge_envs + env-counter instrument: one-level visibility by construction (floor resolve 286.7s -> 2.4s) Jul 6, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 6, 2026 21:11
@gunbai-bot

gunbai-bot Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

CI triage for the two red runs on the draft: the ci job @ 40447da was cancelled by the deliberate #6323 job-level 10-minute kill during the floor step — the fleet-wide compile wall this PR attacks (the floor's worst entry drops 286.7s -> 2.4s here). The rust_tests job @ af61d44 failed in the sccache warm infra step (build-cache prime), not in fmt/clippy/tests; the merged tree checks clean locally (cargo check --workspace 25.8s green, targeted cargo test green except one A/B-verified pre-existing failure detailed in the PR body). Fresh CI is running on 13a51f9. — sent from sharp-wolf-473

Brian Searls and others added 4 commits July 6, 2026 21:31
…t.dag; corpus import hygiene; artifact regens

The compile-clean and artifact-drift gates, unmasked by #6331's floor speedup,
found accumulated debt: 43 unlisted-import diagnostics (12 files, mechanical
import-list additions), the network_identity param typed to the alias it
actually receives (DhcpClientHostNameOption12), and DESIGN.md drifted from its
generating authority because #6329 hand-edited the artifact without
back-porting (receipt: main_wet now regenerates DESIGN.md byte-identical to
the committed operator-signed version). falsifier.yml/.gitignore regens are
main_wet output. The complexity_r1 citation-string repoints are reverted out
of this PR: touching those files enrolls a fixture whose lens hits a
pre-existing fold_list lambda-param typing deficit (no field 'label' on 'T');
moved to follow-up with that deficit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…n fold idiom); keep truthful post-deletion citations

The diff-scoped discovery frontier (enrolled via the v2.std.diagnostic import
fix) demand-resolves this lens; fold_list<T,A> over n.children left T
un-instantiated on that path (no field 'label' on 'T') while batch reconcile
typed it fine — a batch/demand inference divergence. The children fold now
uses the builtin fold idiom fact_density.dag already uses (resolves on both
paths, receipt: complexity_r1_green_merge_envs_base_holds witness green by
execution); the registry fold_list over a concrete FreeMonoid in the same
module types fine and stays.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

CI-red root-cause chain, for the record: this PR's floor speedup let the ci job get past the compile wall for the first time in a while, and each layer it reached surfaced latent debt that had been invisible behind the 10-minute kill. Fixed in order, each with a local receipt: (1) dag_compile_clean_gate — 1 hard type error (the pre-existing alias-expansion refusal in network_identity_subsumption; param retyped to the DhcpClientHostNameOption12 it actually receives, witness green) plus 43 unlisted-import diagnostics across 12 corpus files (mechanical import-list additions; pool now compiles with 0 diagnostics). (2) generated_artifact_drift_gate — DESIGN.md had drifted from its generating authority because #6329 hand-edited the artifact without back-porting; the operator-signed text is now in design_document.dag and main_wet regenerates DESIGN.md byte-identical to the committed version (falsifier.yml/.gitignore regens included). (3) discovery corpus — the v2.std.diagnostic import fix enrolled complexity_r1_accumulator_copy.dag, whose fold_list over n.children fails to instantiate the type parameter on the demand-driven path while batch reconcile types it fine (batch/demand inference divergence, pre-existing); the children fold now uses the builtin fold idiom fact_density.dag already uses, and the lens witness runs green by execution. Local full floor now passes batches 1–2 completely; the two batch-3 effectful gates (emit_host, source_root_ingest) return false locally only because this container lacks go/tsc — CI's runners have them, so the running CI on c673336 is the authoritative check for those. — sent from sharp-wolf-473

briansrls added a commit that referenced this pull request Jul 6, 2026
#6331 cleanup)

#6331 deletes flatten_visible_bindings + merge_envs (one-level visibility by
construction). Sweep the docs so no reference implies they're live code:
- DESIGN.md §6 + design_document.dag mirror: name-drop (git-history receipt kept as '6-line root fix')
- fold-ergonomics.md/.dag: name-drop the thesis header
- post-engine-pr-roadmap.md: note the flatten 'loaded gun' is removed
- func-env-sigs / enforcement-intent: drop / repoint to green_merge_envs_base_acc
- type-env-single-authority-design.md: note flatten deleted, precompute is the remaining target
- compiler-algorithm-survey-2026-07-04.md: superseded banner (dated snapshot kept verbatim)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

rust_tests red root-caused, and it is not this PR: the 6 failing tests (parse_table_memo x4, interpreted_parse_bisect, ownership_violation_ratchet) fail identically on pure main at 21fb5d1 in a clean control worktree with zero changes from this branch. They regressed with #6314 (parse engine: FIRST-set choice dispatch), which merged while the rust-gate step timeout had drifted to 10 minutes — so its CI (and everyone's since) was killed before nextest ran. #6339 just restored the 45m timeout on main, so main's own next runs will surface the same 6 failures. Handed off to the #6314 owner (clever-hawk-315) with the receipt; merged latest main here (including the dag_wave1 ambiguity audit 44e6fff) and retested — still red, so the fix is pending on their side. Everything attributable to this PR is green locally: fmt, clippy (full workspace, 0 warnings), compile-clean gate, artifact-drift gate, discovery corpus. — sent from sharp-wolf-473

@gunbai-bot

gunbai-bot Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

On the non-blocking field_in_any_variant_named spot-check: verified, and the narrowing is real but intended — it is the landed .dag model's semantics, not this PR's invention. variant_owner_node (04_infer.dag:500, seed v1_compiler_infer.rs:816) resolves via scope.locals then lookup_type_for, and field_in_any_variant_named's .dag authority (04_infer.dag:2851) has routed through it on main since before this PR; the seed executing the old every-visible-binding scan was exactly the model/realization divergence this PR closes. If a caller passes an enum name with no local binding the answer is now false — which fails toward 'no such field', surfacing as a typed diagnostic rather than fabricating a match. Empirical coverage on the full corpus: the dag+src/v2 pool compiles with 0 diagnostics under the converged seed, and floor batches 1–2 (batch reconcile + demand-driven discovery resolve) are green; the one visibility-class refusal that did surface corpus-wide (network_identity_subsumption) was A/B-proven pre-existing and orthogonal to this function (the pre-diff binary with the wide scan refuses it identically). If a real caller ever needs non-local enum names here, the fix belongs in the .dag authority, not by resurrecting the stale seed scan. — sent from sharp-wolf-473

@gunbai-bot

gunbai-bot Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

Fixed in 02a4d34: the census clause in the design_document.dag back-port is synced to the current operator-signed DESIGN.md wording — 'no consolidate-now forks (the census's 2 same-name flags proved to be a homonym + whole-file v1-seed duplication, not genuine cross-tree §3 forks)' — after merging the #6334 census-resolution commit from main. The back-port carried the pre-resolution phrasing because main's DESIGN.md update landed after my merge point; good catch. Receipt: main_wet regenerates DESIGN.md byte-identical to the committed operator-signed version, so the artifact-drift gate holds and there is again exactly one authority for the census fact. — sent from sharp-wolf-473

@briansrls
briansrls merged commit 5d1348a into main Jul 7, 2026
1 of 3 checks passed
@briansrls
briansrls deleted the session/sharp-wolf-473 branch July 7, 2026 01:08
briansrls added a commit that referenced this pull request Jul 7, 2026
* WIP: gunb compilation test

* Clone-fallback guard: shared-Rc updates refuse by default (fail|count|allow)

Operator ruling 2026-07-05: the silent clone arm in the rc_* update family
is a degradation that must stop the pipeline, not widen. Every shared-Rc
update (rc_map_insert/merge, rc_list_push/concat, rc_set_insert/union) and
take_owned_counted's clone arm now routes through rc_shared_update_guard:

- GUNBC_CLONE_FALLBACK=fail (default): typed, located panic naming the
  generated caller (#[track_caller]) — the work-queue key for licensing.
- =count: per-site ledger, first-hit line + ranked exit report (Drop on the
  thread_local), so degradation frequency is observable per §5.
- =allow: interim escape hatch.

tier-1 compile enumerates 205 degraded sites; top: rc_map_merge at
infer_env.rs:413 (14,360 clones), dag_collect.rs:234/239 (5,049 each) —
the profiled O(n^2) cold-compile root cause.

Template (runtime_rust.dag) and seed (v1_rt.rs) edited in sync, same
pattern as #6249.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: gunb compilation test

* Fail-closed hardening: ban escape hatches, close guard bypasses, encode the factory model in DESIGN.md §5

Operator rulings 2026-07-05:
- GUNBC_CLONE_FALLBACK=allow removed. Modes are fail (default, refuses) and
  count (stopped-line audit: full ledger, still not a green run). No mode
  silences a refusal.
- DESIGN.md §5: no-escape-hatches corollary + the factory model as a merge
  REQUIREMENT — a diff landing a non-fail-closed failure arm (silent widen,
  fabricated default, uncounted degradation, escape hatch) is a hard reject
  in review.
- 6 inline pre-#6249 `Rc::try_unwrap(..).unwrap_or_else(clone)` fold sites
  in the generated seed (compile/infer_cycle/resolve x2/ownership/emit_rust)
  hand-synced to take_owned_counted — the guard's known bypasses closed;
  regen supersedes the hand-sync.
- take_owned_counted count arm ledgered into the same exit report as rc_*
  (one stopped-line audit surface).
- Interpreter: Bool True|False vs Value::Bool cross-representation `==`
  straddle now refuses (CrossRepresentationEquality), mirroring the numeric
  arm; DESIGN §5 named it the remaining decidable straddle. Its by-execution
  receipt joins the cross_representation receipts behind the stopped line.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: gunb compilation test

* WIP: gunb compilation test

* WIP: gunb compilation test

* Persistent maps: Map realization = im_rc HAMT (one authority with interpreter Value::Map)

Root fix for the clone-fallback class on maps (operator go-ahead 2026-07-05).
The compiled runtime realized Map as Rc<std HashMap> — O(n) copy on any
shared update — while the interpreter already realized Value::Map as
im_rc::HashMap (a §3 model↔realization fork). One swap of which HashMap the
generated code imports (extdeps/languages/rust/types.dag import row +
runtime_rust.dag header + seed hand-sync; type spellings and call sites
unchanged): Rc::make_mut's clone arm is now O(1) structural sharing and each
insert copies an O(log n) node path — shared update becomes the designed
path, so rc_map_insert/rc_map_merge leave the clone-fallback guard (lists
and sets keep it until they migrate too).

By-execution receipts (frozen-unit cold-compile benchmark):
- tier-1: 2.26s -> 0.66s; ledger 205 degraded sites -> 18 (all map sites gone)
- tier-10: 239s -> 41.7s (5.7x); 1.74M map clone-fallbacks -> 0
- remaining ledger is exactly rc_list_push/rc_list_concat/rc_set_insert —
  the named follow-up (List/Set -> persistent carriers need emitter type
  template work, not just the import row)

im-rc serde feature enabled for the artifact-serialization derives; hand
seams (cli_run, interpreter, bins, test mods) repointed per direction —
host-internal std maps stay std. fmt + clippy -D warnings green across all
targets. Run-to-run artifact nondeterminism predates this change (open
v2.std.determinism thread), verified by pre-change A/B.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Persistent carriers: lists+sets -> im_rc Vector/OrdSet; delete clone-fallback guard + per-site move licenses

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix import order in v2 manual ownership_movable mirror (imports precede items)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* Fix sweep-corrupted emit golden; inhabitant import_path rows prelude-provided (generation-agnostic)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Merge origin/main into session/sharp-wolf-473

Resolves #6269 test-migration collision: accept main's deletion of
src/v1/ownership_movable_test.dag (v2 manual mirror carries the license-removal
edit); reconcile dag_collect_fingerprint_witness.rs bin with im_rc carriers
(hashes -> Rc<im_rc::Vector>, Node children/params via .into()).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Review fixes: interpreter Value::Set -> im_rc::OrdSet; emit_non_empty_wrappers BTreeSet alias; stale guard comment

Addresses PR #6307 review findings (cursor/composer-2.5 + claude-opus-4-7):
- v1_interpreter.rs: Value::Set was std BTreeSet (forked from runtime im_rc::OrdSet)
  and deep-cloned on every set_insert/set_union. Migrated to im_rc::OrdSet, closing
  the live model<->realization fork and the O(n) clone (now O(1) structural + O(log n)
  COW). Makes runtime_rust.dag's 'one realization with Value::Map/List/Set' true.
- 05_emit_rust.dag emit_non_empty_wrappers: std::collections::BTreeSet -> bare BTreeSet
  alias (matches the seed + prelude OrdSet alias; forward-compatible; kills the
  bidirectional regen hazard).
- v1_rt.rs: fixed the stale rc_map_insert sibling comment that still claimed lists/sets
  'remain O(n)-copy carriers and keep the guard'.

Seed-emitter import drift (emit_prelude/emit_main_mod_uses/rt_header/extdeps JSON still
emit std) is the coherent-whole emitter-fix-needs-2-gens cutover: pre-existing on main
(maps PR), tracked against RegenVerifyGate #5873, coordinated with regen lane
(loyal-dove-903). Not fixable as isolated import swaps (emitted runtime bodies need
focus/push_back/VecCompat + the trait emission itself).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Revert speculative import addition in network_identity_subsumption (refusal is a pre-existing alias-expansion deficit, A/B-verified on the pre-diff binary)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* Back-port #6329's operator-signed DESIGN.md edits into design_document.dag; corpus import hygiene; artifact regens

The compile-clean and artifact-drift gates, unmasked by #6331's floor speedup,
found accumulated debt: 43 unlisted-import diagnostics (12 files, mechanical
import-list additions), the network_identity param typed to the alias it
actually receives (DhcpClientHostNameOption12), and DESIGN.md drifted from its
generating authority because #6329 hand-edited the artifact without
back-porting (receipt: main_wet now regenerates DESIGN.md byte-identical to
the committed operator-signed version). falsifier.yml/.gitignore regens are
main_wet output. The complexity_r1 citation-string repoints are reverted out
of this PR: touching those files enrolls a fixture whose lens hits a
pre-existing fold_list lambda-param typing deficit (no field 'label' on 'T');
moved to follow-up with that deficit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* complexity_r1 lens: type the children fold on the demand path (builtin fold idiom); keep truthful post-deletion citations

The diff-scoped discovery frontier (enrolled via the v2.std.diagnostic import
fix) demand-resolves this lens; fold_list<T,A> over n.children left T
un-instantiated on that path (no field 'label' on 'T') while batch reconcile
typed it fine — a batch/demand inference divergence. The children fold now
uses the builtin fold idiom fact_density.dag already uses (resolves on both
paths, receipt: complexity_r1_green_merge_envs_base_holds witness green by
execution); the registry fold_list over a concrete FreeMonoid in the same
module types fine and stays.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* Revert "WIP: emit -> realization"

This reverts commit 3ad16c9.

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* intern_str build-green: list-get resolves Optional via free_monoid_collection get template

Root cause of the list-get-by-index inference deficit: free_monoid_collection_templates
(the List method table in dag/std/algebra.dag) declared first/last returning
OptionalOf<ReceiverElement> but had NO get row — so `list |> get(index)` never resolved
structurally and its result type defaulted to the receiver (FreeMonoid), leaving the match
Bind arm un-Some-wrapped. Map-get works because PartialFunction declares get: fn(K) -> V?.

- dag/std/algebra.dag: add get: [ReceiverSelf, Int] -> OptionalOf<ReceiverElement> row,
  mirroring the existing first/last rows (completes the model, mints nothing). [already committed]
- src/v1/stage0/src/std_algebra.rs: splice the get template into the seed so the running
  binary's inference resolves list-get as Optional.
- src/v1/00_core.dag: intern_str now matches explicit Present/Absent (was catch-all
  `other => other` which binds the whole Option); emits Some(s)/None, builds green.

Fresh-crate cargo check: 26 -> 2 errors; the 2 remaining are the single std_integer Nat
where-refinement alias-resolution root (Nat<Magnitude>). intern_str builds.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 7, 2026
… gate) + sorted_map_keys builtin (#6357)

* WIP: gunb compilation test

* Clone-fallback guard: shared-Rc updates refuse by default (fail|count|allow)

Operator ruling 2026-07-05: the silent clone arm in the rc_* update family
is a degradation that must stop the pipeline, not widen. Every shared-Rc
update (rc_map_insert/merge, rc_list_push/concat, rc_set_insert/union) and
take_owned_counted's clone arm now routes through rc_shared_update_guard:

- GUNBC_CLONE_FALLBACK=fail (default): typed, located panic naming the
  generated caller (#[track_caller]) — the work-queue key for licensing.
- =count: per-site ledger, first-hit line + ranked exit report (Drop on the
  thread_local), so degradation frequency is observable per §5.
- =allow: interim escape hatch.

tier-1 compile enumerates 205 degraded sites; top: rc_map_merge at
infer_env.rs:413 (14,360 clones), dag_collect.rs:234/239 (5,049 each) —
the profiled O(n^2) cold-compile root cause.

Template (runtime_rust.dag) and seed (v1_rt.rs) edited in sync, same
pattern as #6249.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: gunb compilation test

* Fail-closed hardening: ban escape hatches, close guard bypasses, encode the factory model in DESIGN.md §5

Operator rulings 2026-07-05:
- GUNBC_CLONE_FALLBACK=allow removed. Modes are fail (default, refuses) and
  count (stopped-line audit: full ledger, still not a green run). No mode
  silences a refusal.
- DESIGN.md §5: no-escape-hatches corollary + the factory model as a merge
  REQUIREMENT — a diff landing a non-fail-closed failure arm (silent widen,
  fabricated default, uncounted degradation, escape hatch) is a hard reject
  in review.
- 6 inline pre-#6249 `Rc::try_unwrap(..).unwrap_or_else(clone)` fold sites
  in the generated seed (compile/infer_cycle/resolve x2/ownership/emit_rust)
  hand-synced to take_owned_counted — the guard's known bypasses closed;
  regen supersedes the hand-sync.
- take_owned_counted count arm ledgered into the same exit report as rc_*
  (one stopped-line audit surface).
- Interpreter: Bool True|False vs Value::Bool cross-representation `==`
  straddle now refuses (CrossRepresentationEquality), mirroring the numeric
  arm; DESIGN §5 named it the remaining decidable straddle. Its by-execution
  receipt joins the cross_representation receipts behind the stopped line.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: gunb compilation test

* WIP: gunb compilation test

* WIP: gunb compilation test

* Persistent maps: Map realization = im_rc HAMT (one authority with interpreter Value::Map)

Root fix for the clone-fallback class on maps (operator go-ahead 2026-07-05).
The compiled runtime realized Map as Rc<std HashMap> — O(n) copy on any
shared update — while the interpreter already realized Value::Map as
im_rc::HashMap (a §3 model↔realization fork). One swap of which HashMap the
generated code imports (extdeps/languages/rust/types.dag import row +
runtime_rust.dag header + seed hand-sync; type spellings and call sites
unchanged): Rc::make_mut's clone arm is now O(1) structural sharing and each
insert copies an O(log n) node path — shared update becomes the designed
path, so rc_map_insert/rc_map_merge leave the clone-fallback guard (lists
and sets keep it until they migrate too).

By-execution receipts (frozen-unit cold-compile benchmark):
- tier-1: 2.26s -> 0.66s; ledger 205 degraded sites -> 18 (all map sites gone)
- tier-10: 239s -> 41.7s (5.7x); 1.74M map clone-fallbacks -> 0
- remaining ledger is exactly rc_list_push/rc_list_concat/rc_set_insert —
  the named follow-up (List/Set -> persistent carriers need emitter type
  template work, not just the import row)

im-rc serde feature enabled for the artifact-serialization derives; hand
seams (cli_run, interpreter, bins, test mods) repointed per direction —
host-internal std maps stay std. fmt + clippy -D warnings green across all
targets. Run-to-run artifact nondeterminism predates this change (open
v2.std.determinism thread), verified by pre-change A/B.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Persistent carriers: lists+sets -> im_rc Vector/OrdSet; delete clone-fallback guard + per-site move licenses

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix import order in v2 manual ownership_movable mirror (imports precede items)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* Fix sweep-corrupted emit golden; inhabitant import_path rows prelude-provided (generation-agnostic)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Merge origin/main into session/sharp-wolf-473

Resolves #6269 test-migration collision: accept main's deletion of
src/v1/ownership_movable_test.dag (v2 manual mirror carries the license-removal
edit); reconcile dag_collect_fingerprint_witness.rs bin with im_rc carriers
(hashes -> Rc<im_rc::Vector>, Node children/params via .into()).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Review fixes: interpreter Value::Set -> im_rc::OrdSet; emit_non_empty_wrappers BTreeSet alias; stale guard comment

Addresses PR #6307 review findings (cursor/composer-2.5 + claude-opus-4-7):
- v1_interpreter.rs: Value::Set was std BTreeSet (forked from runtime im_rc::OrdSet)
  and deep-cloned on every set_insert/set_union. Migrated to im_rc::OrdSet, closing
  the live model<->realization fork and the O(n) clone (now O(1) structural + O(log n)
  COW). Makes runtime_rust.dag's 'one realization with Value::Map/List/Set' true.
- 05_emit_rust.dag emit_non_empty_wrappers: std::collections::BTreeSet -> bare BTreeSet
  alias (matches the seed + prelude OrdSet alias; forward-compatible; kills the
  bidirectional regen hazard).
- v1_rt.rs: fixed the stale rc_map_insert sibling comment that still claimed lists/sets
  'remain O(n)-copy carriers and keep the guard'.

Seed-emitter import drift (emit_prelude/emit_main_mod_uses/rt_header/extdeps JSON still
emit std) is the coherent-whole emitter-fix-needs-2-gens cutover: pre-existing on main
(maps PR), tracked against RegenVerifyGate #5873, coordinated with regen lane
(loyal-dove-903). Not fixable as isolated import swaps (emitted runtime bodies need
focus/push_back/VecCompat + the trait emission itself).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* Revert speculative import addition in network_identity_subsumption (refusal is a pre-existing alias-expansion deficit, A/B-verified on the pre-diff binary)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* Back-port #6329's operator-signed DESIGN.md edits into design_document.dag; corpus import hygiene; artifact regens

The compile-clean and artifact-drift gates, unmasked by #6331's floor speedup,
found accumulated debt: 43 unlisted-import diagnostics (12 files, mechanical
import-list additions), the network_identity param typed to the alias it
actually receives (DhcpClientHostNameOption12), and DESIGN.md drifted from its
generating authority because #6329 hand-edited the artifact without
back-porting (receipt: main_wet now regenerates DESIGN.md byte-identical to
the committed operator-signed version). falsifier.yml/.gitignore regens are
main_wet output. The complexity_r1 citation-string repoints are reverted out
of this PR: touching those files enrolls a fixture whose lens hits a
pre-existing fold_list lambda-param typing deficit (no field 'label' on 'T');
moved to follow-up with that deficit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* complexity_r1 lens: type the children fold on the demand path (builtin fold idiom); keep truthful post-deletion citations

The diff-scoped discovery frontier (enrolled via the v2.std.diagnostic import
fix) demand-resolves this lens; fold_list<T,A> over n.children left T
un-instantiated on that path (no field 'label' on 'T') while batch reconcile
typed it fine — a batch/demand inference divergence. The children fold now
uses the builtin fold idiom fact_density.dag already uses (resolves on both
paths, receipt: complexity_r1_green_merge_envs_base_holds witness green by
execution); the registry fold_list over a concrete FreeMonoid in the same
module types fine and stays.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: emit -> realization

* Revert "WIP: emit -> realization"

This reverts commit 3ad16c9.

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* intern_str build-green: list-get resolves Optional via free_monoid_collection get template

Root cause of the list-get-by-index inference deficit: free_monoid_collection_templates
(the List method table in dag/std/algebra.dag) declared first/last returning
OptionalOf<ReceiverElement> but had NO get row — so `list |> get(index)` never resolved
structurally and its result type defaulted to the receiver (FreeMonoid), leaving the match
Bind arm un-Some-wrapped. Map-get works because PartialFunction declares get: fn(K) -> V?.

- dag/std/algebra.dag: add get: [ReceiverSelf, Int] -> OptionalOf<ReceiverElement> row,
  mirroring the existing first/last rows (completes the model, mints nothing). [already committed]
- src/v1/stage0/src/std_algebra.rs: splice the get template into the seed so the running
  binary's inference resolves list-get as Optional.
- src/v1/00_core.dag: intern_str now matches explicit Present/Absent (was catch-all
  `other => other` which binds the whole Option); emits Some(s)/None, builds green.

Fresh-crate cargo check: 26 -> 2 errors; the 2 remaining are the single std_integer Nat
where-refinement alias-resolution root (Nat<Magnitude>). intern_str builds.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: emit -> realization

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* seed-prime: sorted_map_keys builtin (registry + bridge + runtime generator)

Functional gen-0' prime of the new sorted_map_keys builtin across the 3
remaining seed twins (v1_rt.rs fn + infer arms already present):
- v1_compiler_infer_method.rs: builtin_function_registry row (type = list of collection_element, mirrors map_keys)
- extdeps_languages_rust_emit.rs: rt bridge row (passes_by_ref+wraps_result, mirrors map_keys)
- v1_compiler_runtime_rust.rs: runtime-generator emits the fn body after map_keys

Enables the 2-gen bootstrap: regen_stage0 built from this seed can resolve/
emit sorted_map_keys, so a fresh regen produces the canonical seed. Ordering
within gen-0' is irrelevant; canonical order comes from runtime_rust.dag:177.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* WIP: realization (SymbolIndex)

* fix: .dag emits im-rc dep + qualified std::collections::BTreeSet for stage0_core/emit_core boundary files (workspace build)

* test: build_movable_set 2-arg (empty param_names) — align stale test with .dag authority

The .dag defines build_movable_set(proof, param_names) as 2-arg; main's seed
carried a stale 1-arg divergence and pipeline.rs was written against it.
accept-fresh correctly converged the seed to the 2-arg .dag form, so the
hand-maintained test crate call needed updating. param_names only extends
movability to sole-owned params; empty set = the param-blind count the
movable_but_cloned<=45 ratchet was calibrated against.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Brian Searls <briansrls@gunb.ai>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant