Skip to content

Plan: space lens — confident memory prediction from the static .dag (Node B walking skeleton) - #6442

Closed
gunbai-bot[bot] wants to merge 13 commits into
mainfrom
session/merry-owl-649
Closed

gunbai-bot[bot] wants to merge 13 commits into
mainfrom
session/merry-owl-649

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jul 10, 2026 •

Copy link
Copy Markdown
Contributor

Plan doc only — awaiting operator sign-off, deliberately left draft. No code, no .dag edits.

What this is

A minimal-project plan for the space lens: a fold over the static .dag graph that returns predicted peak resident memory, fed to realization to pick shard width. The time analog (complexity lens) already exists; this is the space sibling.

Key finding — this is a resume, not a greenfield

The architecture is already operator-signed across compute-envelope-model.md, input-envelope-roadmap.md, and resource-aware-scheduler.md (the ruling "derivation is the authority; measurement is the falsifier"). The carriers exist: CostAccount.space / CostBasis::Predicted, the floor(budget ÷ per_shard_peak) width formula, and the landed InputEnvelope fail-closed admission. The gap is exactly one hollow spot: CostAccount.space is always byte_size(0), and width reads a static hardcoded row instead of a fold. This session's merged measurement PR (#6425) built the falsifier half; this plans the derivation half.

Decisions I need from you

  1. Calibrate now vs. gate on cross-shard sharing (S2b). Each shard currently duplicates the std/spec prefix in RAM (!Send barrier), so the per-node constant re-calibrates when sharing lands. Calibrate against today's reality (useful now, re-measure later) or wait?
  2. Homing. This lane is multi-owner and touches load-bearing substrate (std.realization*, scheduler). It should be a work item under the envelope owners, not run out of a closed measurement session. Where do you want it?

Flip to ready (gh pr ready 6442) only if you want automated review of the prose; the intended gate is your sign-off on the plan.

briansrls and others added 12 commits July 9, 2026 22:17
A temporary red probe (union_resolve_receipts_test.rs) used to characterize the
width==1 typecheck-compute-counter semantics was captured by the auto-committer
in 533e473 while it sat in the working tree. It asserts a deliberate RED, so it
fails rust_tests. It was never intended to land.

Restores the file to its state at 674381f.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…echeck counter

`typecheck_compute_count()` counts typecheck cache MISSES on the current thread and
is never reset in production (only tests reset it), so it equals a closure size only
from a cold start. The measurement window cannot assume that:

  - width == 1 returns `run_discovery_rows` on the discovery thread, which has already
    resolved every changed file via `floor_diff_edits_from_line_ranges` plus both prefix
    entries. The reported count was therefore |closure(changed files) u closure(prefix)
    u closure(rows)| -- a function of the diff under test, not of the roster.
  - `floor_skip_discovery_witness` calls run_discovery_corpus three times on one thread,
    so the 2nd and 3rd calls read a counter warmed by the 1st.

Count the union of authored module names across the graphs the shard actually resolves
(prefix contexts + each roster entry) instead. That is a property of the source closure:
independent of cache warmth, resolve order, and the diff. Prefix modules stay counted --
they are resident for the shard's lifetime, so they belong in the memory pairing.

Note the parallel path was never the problem: run_walk dispatches DiscoveryBatch via
thread::spawn, so shards do start cold. The defect was the pre-row work on the discovery
thread, which shards never repeat.

Adds a discriminating control: a prior same-thread resolve moves the compute counter
(asserted, so the control stays discriminating) but must not move the closure count.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title ci floor measurement Plan: space lens — confident memory prediction from the static .dag (Node B walking skeleton) Jul 10, 2026
@gunbai-bot

gunbai-bot Bot commented Jul 10, 2026

Copy link
Copy Markdown
Contributor Author

The CI failure here is not a defect in this PR — it's a pre-existing gap in the CI substrate that any docs-only PR trips. Root cause, confirmed from the job log (run 29117568824, job 86444691071):

  • This branch's tree is exactly origin/main + one markdown file under docs/plans/. Nothing under dag/ or src/v2/ changed.
  • ci.yml's interim documentation-only shortcut fired correctly: claim_executor: documentation-only diff — floor skipped (CI_FLOOR_DISPOSITION=documentation_only_skipped). The floor is intentionally not run for a docs-only diff.
  • Because the floor didn't run, write_resolve_receipt was never called, so target/floor-resolve-receipt.txt doesn't exist.
  • The "Floor resolve receipt gate" step then fails closed: "floor resolve receipt missing - fail closed."

The gap: the merge-admission gate does honor the docs-only disposition (it stamps Skipped, not Success), but the resolve-receipt gate does not — it requires the receipt unconditionally. The two sibling steps disagree about a docs-only skip.

The correct fix is in the CI substrate, not this doc: the receipt gate should short-circuit (skip) when CI_FLOOR_DISPOSITION=documentation_only_skipped, mirroring the merge-admission gate. That step is generated from dag/gunbc/ci_materialization.dag (ci_floor_resolve_receipt_gate_script) and ci.yml is drift-gated, so the fix is a .dag edit + regen — a separate, small PR against load-bearing CI substrate, which I've flagged to the operator rather than bolt onto a plan-doc branch.

This PR is a plan doc awaiting sign-off and is intentionally draft; it does not need to merge before that fix lands.

— sent from merry-owl-649

… knobs)

The host OOM is systematic, not intermittent: a width==1 shard is killed by
host-level oversubscription under its own slot cap, so narrowing width cannot
help. The per-shard prediction therefore feeds TWO knobs — within-job width and
cross-job packing/admission — and the systematic case is served by admission-
refusal, not width. Records RSS-at-kill as a lower-bound calibration point.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jul 10, 2026

Copy link
Copy Markdown
Contributor Author

Closing as parked, not abandoned — the content is fully preserved and this reopens in one click.

This is a complete plan doc (docs/plans/space-lens-minimal-project.md) awaiting operator sign-off on two things: (a) calibrate-now vs gate on the interface/body split, and (b) homing under the compute-envelope owners as the fused measurement+predictor work item that loyal-wren-398's affected-set lane is ready to bind receipts to. It is not implementation waiting to merge, so "mark ready" doesn't apply — and it can't cleanly go non-draft anyway until the separate docs-only-skip resolve-receipt gate bug is fixed (that's why ci is red here; root-caused in the comment above, it's a CI-substrate gap, not a defect in this doc).

Rather than sit as a nagging red draft, I'm parking it: the doc lives on session/merry-owl-649 and in history, nothing is lost, and reopening (or re-PRing from a fresh branch under the fused work item) resumes it immediately. The design conversation and the loyal-wren coordination that shaped it are captured; the first calibration datum (16.3 MiB/node censored-at-cap, run 29119564221) is already flowing to it.

Reopen when the homing decision is made.

— sent from merry-owl-649

@gunbai-bot gunbai-bot Bot closed this Jul 10, 2026
briansrls added a commit that referenced this pull request Jul 10, 2026
…ew catch)

The two cli_run.rs comments cited docs/plans/space-lens-minimal-project.md, which does
not exist on main — the predictor design is in flight on PR #6442 (merry-owl-649's lane)
and was never landed under that path. Rebound: the shared closure-definition authority is
stated as this function itself, with the in-flight design cited by PR number and the
landed parent-lane authorities cited by real paths (compute-envelope-model.md fleet
envelope; input-envelope-roadmap.md admission). No behavior change; cargo check clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 10, 2026
…hrunk by affected set) + falsifier host-OOM receipt (#6438)

* WIP: Re-land affected-set CI enrollment flip once shard resolve footprint is

* WIP: Re-land affected-set CI enrollment flip once shard resolve footprint is

* Fix CI OOM: pin discovery corpus spawn_width_cap to 1.

Run 28999086030 OOM-killed at width=2 on the 24GiB live slot during the
discovery-flip corpus batch. Gate workloads still fit at width=2; only the
tree-wide discovery batch serializes via spawn_width_cap=1, with a receipt
witness and dissolve-on note.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix type error in corpus discovery spawn width cap helper.

Both if-branches must return Nat (hardware_thread_count_value), not a
bare Int literal.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Merge affected-set enrollment flip (takeover of PR #6403 from session/gentle-stag-677-flip)

Conflict resolutions onto post-#6422/#6431/#6432/#6435 main:
- ci_witness_optin_inversion: main's typed Scaffold Disposition -> Terminal (dissolve fired at the flip; roster stays as explicit-entry home, exclusivity dissolved)
- floor step timeout: 45 (main) vs 60 (flip) -> 60 with provenance note
- ci_spec notes: kept flip notes, stale fixed-8 phrasing dated
- falsifier width note: + RESIDUE paragraph (5x exit-137 on srv2-class slots = converge lane, not plan width)

Verified before commit: discovery batches charge corpus_resolve_nanos (own key), resolve_nanos=0 -> resolves_total declared 3 is NOT moved by the flip.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: affected set processing

* WIP: affected set processing

* WIP: affected set processing

* WIP: affected set processing

* Correct the false flip receipt + kill-surviving calibration receipts (space-lens loop)

CORRECTED RECEIPT: run 29000557166's floor never completed - the executor was
host-OOM-killed mid-discovery-corpus at ~8min; the log's ExitSuccess belongs to
the merge-admission stamp tool stamping CI_FLOOR_EXIT=137. No flipped corpus
has completed in CI (0/1 ci + 0/5 falsifier). Both carrier notes corrected.

Calibration (coordinated with merry-owl-649's space-lens lane):
- roster_import_closure_nodes_pre_resolve: shared closure-count authority
  (pure import walk, closure grain not entry grain), emitted BEFORE the heavy
  resolve so killed runs still yield the (nodes, peak) lower-bound pair
- width-1 definition-drift oracle: pre-resolve walk must equal post-resolve
  resolved union on completed runs; refuses on divergence. Proven by execution:
  pre == post == 190/213 nodes across Off/Applied modes
- kill-surviving cgroup memory.peak pre/post steps (post is always()) in the
  ci job and falsifier.yml; scope semantics labeled on the emission lines
  (reset=ok floor-scoped; span compares post>pre; never silently conflated)
- job backstop timeouts extended by the two aux steps in both jobs

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: affected set processing

* Calibration pairs carry censored-vs-exact labels (methodology: killed runs are censored observations)

Floor steps get id=floor; the always() post-peak step emits floor_outcome so
each (closure_nodes, peak) pair is explicitly labeled: success = exact point,
anything else = censored lower bound (true demand strictly greater than read).
Prevents the fit from treating cap-kill reads as point estimates, which would
drag the slope down and make the predictor underestimate - the dangerous
direction (merry-owl methodology catch, 2026-07-10).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: affected set processing

* Review fixes: explicit witness import + complete step-budget ledger

- ci_floor_plan_witness_test.dag: import witness_ci_corpus_discovery_serializes_at_width_one
  explicitly (cursor catch on #6438). The call resolved pre-fix via the seed resolver's flat
  namespace, so the witness ran green by execution; the explicit import restores the file's
  per-symbol import convention.
- ci_workflow.dag: the resolve-receipt gate step had NO step cap — a hang there could only die
  by job-cancel (the #6323 starvation-kill class). It now carries the aux cap (script is a
  sub-second receipt read) and the ci job backstop counts four aux terms (peak pre/post,
  resolve-receipt gate, merge-admission gate): every step budgeted, backstop = step-sum + prelude
  (claude review catch on #6438, sharpened).
- falsifier_workflow_witness_test.dag: falsifier_backstop_is_step_sum_plus_prelude asserted the
  pre-calibration formula — latent red proven by execution (FAIL receipt), fixed to the live
  two-aux sum, re-run PASS.
- ci.yml regenerated byte-stable from the carrier (backstops 125->130, gate step timeout 5m).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Rebind calibration provenance comments to real artifacts (cursor review catch)

The two cli_run.rs comments cited docs/plans/space-lens-minimal-project.md, which does
not exist on main — the predictor design is in flight on PR #6442 (merry-owl-649's lane)
and was never landed under that path. Rebound: the shared closure-definition authority is
stated as this function itself, with the in-flight design cited by PR number and the
landed parent-lane authorities cited by real paths (compute-envelope-model.md fleet
envelope; input-envelope-roadmap.md admission). No behavior change; cargo check clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: affected set processing

* Remove stray empty file (shell-redirect artifact the auto-committer flushed)

An internal-messaging command's backtick content was command-substituted by bash; a
'-> fail-closed' fragment became a stdout redirect and created an empty file at the
repo root, which the auto-committer then committed as 38f0a46. No tree content
beyond the empty file; removing it restores the branch to e99c757's content.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: affected set processing

* Scaffold-mark the cgroup peak calibration shell (cursor review catch)

The three concat-built calibration runners (ci_cgroup_peak_locate_shell,
ci_floor_peak_pre_script, ci_floor_peak_post_script) landed without the on-carrier
scaffold markers repo convention requires for hand-shell. Each now carries a
Disposition = Scaffold { dissolves_to: RealizationDispatch } row binding the decl
(the ci_materialization pattern), and both scripts embed the shared dissolve-on
note as a shell comment (the ci_spec pattern): dissolution = bash-emit (#5828 /
gap-B emit(intent, Bash)) realizing the observation as an emitted ShellProgram
intent or a typed host Observe effect. ci.yml + falsifier.yml regenerated;
falsifier_workflow_witness_holds and the flip witnesses re-run PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Merge origin/main into session/loyal-wren-398 (resolve #6441 step-list conflict)

Conflict resolution, all consciously declared:
- ci_job steps: union — the calibration peak pre/post steps wrap the floor step (this
  branch) and #6441's materialization receipt gate slots between the resolve-receipt
  gate and the merge-admission gate (main).
- The incoming materialization receipt gate step landed with timeout none — the same
  uncapped-step starvation-kill class this branch's review fix eliminated — so it now
  carries the aux cap, and the ci backstop counts FIVE aux terms (peak pre, peak post,
  resolve-receipt gate, materialization receipt gate, merge-admission gate); the budget
  disposition note records the merge provenance.
- ci_run_step_natures_are_claims_counted_not_silent: RunStep count pin bumped 17 -> 19,
  acknowledging the two peak calibration steps #6441's count predates (conscious-count
  discipline; proven red at 17 then green at 19 by execution).
- ci.yml regenerated from the merged carriers (backstops 130 -> 135).

Verified on the merged tree: release bins rebuilt on merged Rust; falsifier workflow
witness, flip witnesses, floor-plan/optin/width witnesses, and all 8 ci_materialization
witnesses PASS; generated-artifact regen ExitSuccess.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 10, 2026
… gated) (#6455)

* Inferred materialization increment 1: floor demand ledger + receipt gate (#6441)

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* WIP: Duplicate Computation

* Analysis spine: spine_receipt composes dependency_view + materialize (increment 1)

The Rc-safe half of run ≜ realize ∘ materialize ∘ dependency_view: compose
the two catamorphisms that need no interpreter thread-safety.

- src/v2/std/spine.dag: level-profile fold over the DependencyView DAG →
  critical_path_depth (longest dependency chain / the reduce spine) +
  independence_width (max nodes at one level / what parallelizes to hw width).
  spine_receipt emits the §9 numbers by COMPUTATION, not assertion, joining
  materialize's content-hash Share/dedup counts.
- Discriminating RED (§9): single chain A→B→C → depth 3 / width 1 (serial);
  root over N independent leaves → depth 2 / width N.
- Witnesses 9/9 (spine) green by execution; materialize 6/6 unchanged.

The RUNNER (wall-clock parallel execution, §8 steps 3-4) stays increment 2+,
gated on interpreter Rc→Arc (v1 interp is !Send). This increment measures the
achievable width/critical-path floor the runner targets; it does not fabricate
wall-clock N×.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Unbundle recompute-trace interpreter extension from the analysis-spine PR

CI root cause: the recompute-trace extension edited v1_interpreter.rs, which
hosts the atom_identity_hash/hash_combine fnv1a64 intrinsics that
dag_collect_fingerprint_witness executes. That correctly invalidated the
re-verify 'assumed-green node-frontier' SKIP of that witness (cone-touch,
fail-closed) — but the witness is a pre-existing 806s (13min) fnv1a64
whole-corpus walk, so un-skipping it blew the 30-min floor budget. Main stays
green only because its interpreter cone is untouched (witness stays skipped).

The interpreter extension is a separable, env-gated (GUNBC_RECOMPUTE_TRACE=1),
READ-mode diagnostic — not a dependency of the spine/materialize analysis
substrate (pure .dag, content_hash-based). Reverting v1_interpreter.rs to main
restores byte-identical interpreter content → the fingerprint witness returns to
assumed-green SKIP → floor budget restored. The recompute-trace extension lands
as its own follow-up PR where the fingerprint-witness re-run is expected.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Materialization ladder: the state x decision law, as executable witnesses

The operator's 4-rule business logic generalized on one axis: the decision is
a function of WHEN the redundancy is knowable and WHETHER what was knowable
was prepared for. Errors fire only on knowable-but-unprepared; genuine
emergence and declared triviality are typed acceptances, never silence.

std.materialization_ladder (dag/std):
- Frame/FrameKind: SharedStateFrame | IsolatedChildrenFrame |
  ReplayedFrame{attempts} | UnboundedSiblingsFrame — the nested-scope axis;
  a 'run' at any layer is a frame, never a different kind of thing.
- DemandNature: Pure | IdempotentEffect | WorldRead{envelope_declared} |
  FreshEffect — the D3 effect gate; TTL = unmodeled dependency XOR declared
  staleness, never an eviction knob.
- CacheProvider: keying (ContentKeyed|ExistenceKeyed) + EvictionPolicy
  (ScopeExit|SpacePacked) REQUIRED by construction — rule 3 unwritable-bad.
- LadderVerdict (total): AuthoredDuplication | Discharged | RefusedNoProvider
  | RefusedScopeTooNarrow | RefusedExistenceKeyed (the build-if-absent #6352
  wall) | RefusedUnmodeledWorldRead | ExemptFreshEffect |
  AcceptedBelowCostFloor | AcceptedSingleRecompute.
- Declared-emergent frames obligate UP FRONT: retry frames derive
  checkpointing, unbounded-sibling frames (server loops, CI-runs-over-time)
  derive persistent caches — prepare-before-demand.

12/12 witnesses green by execution; each test is one cell of the table,
fixtures mirror the live worked example (workflow/jobs/steps, retry, fleet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Docs crystallization: derived materialization placement into roadmap ④ + the state x decision table

- roadmap_authority ④ (ROADMAP.md regenerated via main_wet, drift-consistent):
  the nested-frame law, plurality cells, declared-emergent prepare-up-front,
  keying/staleness walls, the caching-completion un-shelve, the ①-vs-§2
  cross-run-caching contradiction subsumed into per-node derived verdicts,
  and the v1.compiler.ownership §3-convergence row.
- duplicate-work design doc: the state x decision table as the qualifier's
  final verdict logic + the ownership consolidation subsection.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Consolidation plan: realization + materialization + ownership are one law

Operator synthesis (2026-07-09): Materialization = the verdict vocabulary;
ownership = the verdict computation at the eval frame; realization = provider
selection discharging the verdict at each frame's carrier. Share's handler is
layer-aware — the cheapest cache is a REFERENCE (same program + ref-capable
carrier + readonly => point-at-it, no copy, no destroyed memory), demoting
through HAMT structural share / process memo / artifact / CAS, and demotion
must be priced, never silent (#6249 clone-fallback is the receipt).

Census of every hand-rolled instance found in-tree (16 rows): each named with
its frame, ladder cell, action, and dissolution trigger — ownership
(consolidated), Rc/HAMT (reference tier), clone-fallback (demotion wall),
ParseTable + cached_stage (C5 grounding), M1 memo / intern / assumed-green /
sccache / cargo-cache (C2 provider rows), PROCESS_RESOLVE_STORE (C3 = the 9GB
scope fix), build-if-absent (landed as the keying wall), resolve-cache #5789
(rule-4 requirements), recompute-trace (state-4 finding source). Peers kept
distinct: affected-set, Independence/Placement, mutable state.

Sequence C1-C5 with C1 = this PR (ladder + live CI gate).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* Ownership refactored onto materialization: the value tier, tested as providers

First consolidation increment (operator-directed): v1.compiler.ownership's
decision IS provider selection at the value grain, now expressed in the ladder
and proven by mirror witnesses.

- ProviderTier: Reference | Copy | Memo{keying} | Artifact{keying} | Cas{keying}
  — keying folded INTO store tiers, so an existence-keyed reference is
  unwritable BY SHAPE (§5 construction); frame obligations at isolation LCAs
  are dischargeable only by store tiers (a reference cannot cross an isolation
  boundary — witnessed).
- Value tier: AccessMode (Read|Consume|Carry|Project), ValueUsage,
  value_materialization -> ValueDead | ValueMoved | ValueSharedByReference |
  ValueDemotedToCopy (PRICED, requires a declared CopyTier provider — the
  #6249 silent clone-fallback made refusable) | ValueRefusedAffine |
  ValueRefusedNoCarrierProvider.
- Faithful to v1's THREE distinct plurality readings, kept separate:
  take_count = semantic_consumer_count (Consumed only, affine axis);
  value_access_plurality = binding_fan_out (Carry excluded, reference axis);
  borrow_count = whole_value_borrow_count (Read+Carry not Project, movability).
- Fold-accumulator case mirrored at conservative pre-FoldAccUnwrap semantics:
  carries excluded from plurality but blocking the move -> demoted-to-copy.

23/23 witnesses green (14 frame cells + 9 value cells). Corpus-level
equivalence against live v1 ownership folds = the C4 receipt.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Duplicate Computation

* WIP: Duplicate Computation/Materialization

* G: exhaustive cache/share census (52 mechanisms, 6 groups) + C0 catalog-grounding of provider rows + forward-wiring walls

The sweep found the tree already models caches: extdeps/cache cache_catalog
(CacheInterfaceCatalogFacts, 9 rows) + extdeps/realization carrier facts +
the warm==cold purity oracle. C0 grounds CacheProvider on that catalog
(provider_from_catalog projection; CacheProvider.id -> CacheInterfaceId)
so the ladder and the catalog never restate each other's half. Three
forward walls (demands-from-DependencyView, hand-cache shape lens,
live-provider-or-red) make new caches born as provider rows only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* C0: provider rows derive from the cited cache catalog (extdeps/cache/materialization.dag projection)

Operator ruling 2026-07-09: extdeps stays the ground-truth/interface layer;
every USE of a cache goes through materialization so memo never gets
re-invented. provider_from_catalog is the only door from a catalog row into
the ladder: keying/tier/eviction derived from cited facts (mechanism->class:
InProcess=>ScopeExit; Ttl/Lru/SizeBounded=>SpacePacked; Never/Manual outside
a process => typed ProjectionRefused, counted by the new enrolled witness;
HandAuthored/prefix-fallback keys => ExistenceKeyed until key-completeness
upgrades them). CI sccache row now derived, hand-typed tier facts deleted,
6/6 + 23/23 witnesses green. 10b re-scoped: v1-internal caches = inventory
only (retire with seed); ParseTable/cached_stage promoted to next.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* Fail-closed hardening: RefusedNatureConflict arm, weakest-claim nature default, UsesStep silence counted, ladder cells enrolled in CI

The complexity-lens false-clean lesson applied to this gate before anyone
relies on it: (1) heterogeneous natures on one identity were first-wins —
now a typed RefusedNatureConflict (24th ladder cell, RED witness); (2) an
unrostered run-step claimed PureComputation — now IdempotentEffect, the
weakest claim (verdict-identical, no purity overclaim; a misdeclared
WorldRead can no longer be legally memoized by default); (3) UsesStep
foreign actions produced silence — now a pinned denominator (==9; a new
foreign action must consciously bump it); (4) the ladder's 24 cells enroll
on the CI surface so the law's own witnesses gate every run. 24/24 + 7/7.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* M1 ratchet bump: declared resolve count 1 -> 3 (gate's first live catch — enrollment pays counted resolves)

Run 29058798771: enrolling the ladder witness file moved resolves_total
1 -> 3 (each enrolled entry file pays one closure resolve against the
shared index) and the receipt gate redded that exact run — the designed
semantics, receipted in the note. Bump acknowledges the two witness-entry
resolves as declared debt; M2 (one closure resolve per roots set)
ratchets back toward 1.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Retire the M1/M2 labels from carriers (no-codename rule; collided with DESIGN's floor-memoization M1/M2)

Step renamed to 'Floor resolve receipt gate (declared cold-resolve count)';
notes and the gate echo now say what the things are: the counted
cold-resolve receipt, and the shared-resolve rewire (one closure resolve
per source-roots set). Naming-retirement note left on the carrier.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* Run-step natures pinned as counted claims, not affordances

Operator ruling 2026-07-10: hardcoded shell scripts get no affordances
— run-steps are supposed to be modeled as typed intents and emitted
(shell-emission-model slice 4 covers ci_workflow RunSteps). Until that
slice lands, every nature in job_run_demands is a claim (rostered
FreshEffect / weakest-default IdempotentEffect), never derived from a
modeled effect row. Count the whole claimed-nature surface (16 by
execution) and pin it in the enrolled witness: a new raw-script step
must consciously bump the pin, and slice-4 migration becomes a
countable ratchet ending at zero, where the pin becomes a wall.
Rejected alternative recorded in the carrier note: a per-step
declared-natures roster (a second parallel ledger over scripts the
shell-emission plan already governs).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Regen DESIGN.md after main merge (duplicate-work row + #6373 body-lowering row coexist)

Conflict was both sides editing the open-threads list in design_document.dag:
ours added the duplicate-work thread, main's #6373 rewrote body-lowering to
Stages 1-3 LANDED. Resolution keeps both rows in the .dag authority; DESIGN.md
regenerated from it, never hand-edited.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* Inferred materialization increment 1: floor demand ledger + receipt-or-red gate

Running IS enrolling: the interpreter ledgers every keyed pure call and every
InterpContext absorbs its totals into a process accumulator on Drop — by
construction, no eval path escapes the receipt. claim_executor writes
target/floor-materialization-receipt.txt at walk end; trace defaults ON in
the executor, and an explicit =0 zeroes keyed_calls which the gate refuses.

Gate arms this push (all verified under dash from the emitted ci.yml):
receipt missing/malformed/keyed_calls=0 fail closed. Exact pins for
unkeyed_calls and duplicated_keys land from the FIRST CI receipt (the
resolve gate's measure-then-pin path) — unkeyed is known nonzero on the
floor (count_matching takes a predicate closure; closures are the one
disclosed identity-less class, dissolve-on captured-env content identity).

Unit witness green: resolve -> eval -> ctx Drop -> absorb -> drain-once.
Step addition bumped the claimed-natures pin 16 -> 17 consciously.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Review fix: drop the racy drain-once assertion from the receipt unit test

opus-4-7 finding on #6441: under plain cargo test (still the documented
runner) tests share a process, the env latch is OnceLock-sticky, and
sibling ctx drops could absorb between the two takes — making the
drain-empty assertion racy. Absorb-on-Drop stays asserted (monotone under
concurrent absorbs: siblings only ADD); drain-once is Option::take by
construction, not asserted through the shared global. Comment states the
sharing semantics explicitly.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

* WIP: Duplicate Computation/Materialization

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Turn on affected-set CI: re-land witness enrollment flip (discovery shrunk by affected set) + falsifier host-OOM receipt (#6438)

* WIP: Re-land affected-set CI enrollment flip once shard resolve footprint is

* WIP: Re-land affected-set CI enrollment flip once shard resolve footprint is

* Fix CI OOM: pin discovery corpus spawn_width_cap to 1.

Run 28999086030 OOM-killed at width=2 on the 24GiB live slot during the
discovery-flip corpus batch. Gate workloads still fit at width=2; only the
tree-wide discovery batch serializes via spawn_width_cap=1, with a receipt
witness and dissolve-on note.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix type error in corpus discovery spawn width cap helper.

Both if-branches must return Nat (hardware_thread_count_value), not a
bare Int literal.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Merge affected-set enrollment flip (takeover of PR #6403 from session/gentle-stag-677-flip)

Conflict resolutions onto post-#6422/#6431/#6432/#6435 main:
- ci_witness_optin_inversion: main's typed Scaffold Disposition -> Terminal (dissolve fired at the flip; roster stays as explicit-entry home, exclusivity dissolved)
- floor step timeout: 45 (main) vs 60 (flip) -> 60 with provenance note
- ci_spec notes: kept flip notes, stale fixed-8 phrasing dated
- falsifier width note: + RESIDUE paragraph (5x exit-137 on srv2-class slots = converge lane, not plan width)

Verified before commit: discovery batches charge corpus_resolve_nanos (own key), resolve_nanos=0 -> resolves_total declared 3 is NOT moved by the flip.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: affected set processing

* WIP: affected set processing

* WIP: affected set processing

* WIP: affected set processing

* Correct the false flip receipt + kill-surviving calibration receipts (space-lens loop)

CORRECTED RECEIPT: run 29000557166's floor never completed - the executor was
host-OOM-killed mid-discovery-corpus at ~8min; the log's ExitSuccess belongs to
the merge-admission stamp tool stamping CI_FLOOR_EXIT=137. No flipped corpus
has completed in CI (0/1 ci + 0/5 falsifier). Both carrier notes corrected.

Calibration (coordinated with merry-owl-649's space-lens lane):
- roster_import_closure_nodes_pre_resolve: shared closure-count authority
  (pure import walk, closure grain not entry grain), emitted BEFORE the heavy
  resolve so killed runs still yield the (nodes, peak) lower-bound pair
- width-1 definition-drift oracle: pre-resolve walk must equal post-resolve
  resolved union on completed runs; refuses on divergence. Proven by execution:
  pre == post == 190/213 nodes across Off/Applied modes
- kill-surviving cgroup memory.peak pre/post steps (post is always()) in the
  ci job and falsifier.yml; scope semantics labeled on the emission lines
  (reset=ok floor-scoped; span compares post>pre; never silently conflated)
- job backstop timeouts extended by the two aux steps in both jobs

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: affected set processing

* Calibration pairs carry censored-vs-exact labels (methodology: killed runs are censored observations)

Floor steps get id=floor; the always() post-peak step emits floor_outcome so
each (closure_nodes, peak) pair is explicitly labeled: success = exact point,
anything else = censored lower bound (true demand strictly greater than read).
Prevents the fit from treating cap-kill reads as point estimates, which would
drag the slope down and make the predictor underestimate - the dangerous
direction (merry-owl methodology catch, 2026-07-10).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: affected set processing

* Review fixes: explicit witness import + complete step-budget ledger

- ci_floor_plan_witness_test.dag: import witness_ci_corpus_discovery_serializes_at_width_one
  explicitly (cursor catch on #6438). The call resolved pre-fix via the seed resolver's flat
  namespace, so the witness ran green by execution; the explicit import restores the file's
  per-symbol import convention.
- ci_workflow.dag: the resolve-receipt gate step had NO step cap — a hang there could only die
  by job-cancel (the #6323 starvation-kill class). It now carries the aux cap (script is a
  sub-second receipt read) and the ci job backstop counts four aux terms (peak pre/post,
  resolve-receipt gate, merge-admission gate): every step budgeted, backstop = step-sum + prelude
  (claude review catch on #6438, sharpened).
- falsifier_workflow_witness_test.dag: falsifier_backstop_is_step_sum_plus_prelude asserted the
  pre-calibration formula — latent red proven by execution (FAIL receipt), fixed to the live
  two-aux sum, re-run PASS.
- ci.yml regenerated byte-stable from the carrier (backstops 125->130, gate step timeout 5m).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Rebind calibration provenance comments to real artifacts (cursor review catch)

The two cli_run.rs comments cited docs/plans/space-lens-minimal-project.md, which does
not exist on main — the predictor design is in flight on PR #6442 (merry-owl-649's lane)
and was never landed under that path. Rebound: the shared closure-definition authority is
stated as this function itself, with the in-flight design cited by PR number and the
landed parent-lane authorities cited by real paths (compute-envelope-model.md fleet
envelope; input-envelope-roadmap.md admission). No behavior change; cargo check clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: affected set processing

* Remove stray empty file (shell-redirect artifact the auto-committer flushed)

An internal-messaging command's backtick content was command-substituted by bash; a
'-> fail-closed' fragment became a stdout redirect and created an empty file at the
repo root, which the auto-committer then committed as 38f0a46. No tree content
beyond the empty file; removing it restores the branch to e99c757's content.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: affected set processing

* Scaffold-mark the cgroup peak calibration shell (cursor review catch)

The three concat-built calibration runners (ci_cgroup_peak_locate_shell,
ci_floor_peak_pre_script, ci_floor_peak_post_script) landed without the on-carrier
scaffold markers repo convention requires for hand-shell. Each now carries a
Disposition = Scaffold { dissolves_to: RealizationDispatch } row binding the decl
(the ci_materialization pattern), and both scripts embed the shared dissolve-on
note as a shell comment (the ci_spec pattern): dissolution = bash-emit (#5828 /
gap-B emit(intent, Bash)) realizing the observation as an emitted ShellProgram
intent or a typed host Observe effect. ci.yml + falsifier.yml regenerated;
falsifier_workflow_witness_holds and the flip witnesses re-run PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Merge origin/main into session/loyal-wren-398 (resolve #6441 step-list conflict)

Conflict resolution, all consciously declared:
- ci_job steps: union — the calibration peak pre/post steps wrap the floor step (this
  branch) and #6441's materialization receipt gate slots between the resolve-receipt
  gate and the merge-admission gate (main).
- The incoming materialization receipt gate step landed with timeout none — the same
  uncapped-step starvation-kill class this branch's review fix eliminated — so it now
  carries the aux cap, and the ci backstop counts FIVE aux terms (peak pre, peak post,
  resolve-receipt gate, materialization receipt gate, merge-admission gate); the budget
  disposition note records the merge provenance.
- ci_run_step_natures_are_claims_counted_not_silent: RunStep count pin bumped 17 -> 19,
  acknowledging the two peak calibration steps #6441's count predates (conscious-count
  discipline; proven red at 17 then green at 19 by execution).
- ci.yml regenerated from the merged carriers (backstops 130 -> 135).

Verified on the merged tree: release bins rebuilt on merged Rust; falsifier workflow
witness, flip witnesses, floor-plan/optin/width witnesses, and all 8 ci_materialization
witnesses PASS; generated-artifact regen ExitSuccess.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* ShellProgram -> DAG: transport intent collapse + live importer ratchet (phase 0 of the sidecar dissolution) (#6449)

* WIP: ShellProgram -> DAG

* WIP: ShellProgram -> DAG

* WIP: ShellProgram -> DAG

* WIP: ShellProgram -> DAG

* WIP: ShellProgram -> DAG

* bash fold: native Concat/CmdSubst/WithRedir coverage + measured cost wall on the whole-tree emit path

Fold-family productions extended so the fold no longer refuses word
Concat/CmdSubst or stmt WithRedir (all four Redir variants): new
concat_parts/word-compound/with_redir production families, lex tokens,
kind-tag emit transforms, and recursive bundle arms. Byte-identity vs
serialize_bash proven by execution: five depth-2 oracle tests plus the
depth-4 assign_root_stmt manual probe (ROOT=$('git' 'rev-parse'
'--show-toplevel' 2>/dev/null || 'pwd') byte-exact). The delegated
fail-closed RED control repoints from WithRedir (now native) to Heredoc
(still delegated) so the boundary guard stays discriminating.

Measured cost wall, declared on-carrier (bash_program_emit_cost_wall_note):
whole-tree backward row-selection is ~alternatives^depth (1s flat stmt,
64s for the single depth-4 stmt, DNF >8min for the full witness_bin
program) because formal_production_unique_lhs_exact_match deep-validates
every candidate per level and the descent re-validates each level again.
Real-program oracles therefore stay MANUAL probes, not test fns (a
discovery-run test would hang the local floor); the probe note on the
test carrier names the dissolution triggers.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* WIP: Wave 1A - namespace-only name resolution: make the syntactic containment

* B1: NameResolutionPolicy row + position-tracked resolve (NamespaceOnlyY gated).

Add v2.std.resolution_policy (ImportScoped default | NamespaceOnlyY). Thread
ResolveContext { position, expected, policy } through resolve walk; namespace-only
skips import module bindings and uses symbol_index at position. Policy pilot
witness: green under NamespaceOnlyY at type position, RED under ImportScoped at
module position. Import-scoped global default unchanged — zero corpus churn.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Wave 1A - namespace-only name resolution: make the syntactic containment tree the single naming authority (qualified name = nesting position, reference = lexical lookup up ancestors, . = projection one level down). Path: confirm loyal-heron SymbolIndex scaling receipt FIRST, then SymbolIndex = conta (#6451)

* WIP: Wave 1A - namespace-only name resolution: make the syntactic containment

* v2.std.symbol_index: materialize containment tree as single naming authority

Add SymbolIndex fill from nesting (qualified path → Node), qualified-name
path algebra bridges, and discriminating witnesses. Retarget #6436 variant-
visibility scaffold to dissolve into symbol_index_lexical_lookup; harvest_unique
stays interim until module-scoped index scan lands.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Wave 1A - namespace-only name resolution: make the syntactic containment

* Fix rust fmt on qualified-name bridge host functions (CI rust_tests gate).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Wave 1A - namespace-only name resolution: make the syntactic containment

* Remove symbol_index_has_path; tests match symbol_index_lookup directly

Dissolve Optional→Bool predicate in new std/ surface per review. Lexical
lookup root termination already uses qualified_name_is_empty (not dotted
string projection).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Wave 1A - namespace-only name resolution: make the syntactic containment

* Address review: is_empty authority, host scaffold binds, layer split

- Remove qualified_name_is_empty; lexical lookup uses is_empty(xs: position)
- Host dispositions bind to from/to_dotted_string bridges; add P5 receipt tests
- Move extdeps-coupled fill to v2.compiler.symbol_index_fill (layer DAG fix)

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Wave 1A - namespace-only name resolution: make the syntactic containment

* WIP: Wave 1A - namespace-only name resolution: make the syntactic containment

* Wire resolver through SymbolIndex; dissolve harvest_unique_disj interim.

Build SymbolIndex at admission and thread it through Namespace. resolve_atom
falls back to symbol_index_lexical_lookup for unbound atoms after import-scoped
lookup_chain. Fill-time unique-variant aliases (suffix-scan equivalent) replace
#6436 harvest_unique_disj. Equivalence witnesses prove SymbolIndex-alone covers
variant visibility (green + without-alias RED control); end-to-end wire green.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Wave 1A - namespace-only name resolution: make the syntactic containment

* Drop unused ResolveContext.expected until expected-type lane lands.

Removes the dead field and uncalled resolve_ctx_with_expected helper
flagged in #6454 review 36717 — B1 uses position-only disambiguation;
expected-type filtering returns when that slice is scoped.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant