Skip to content

Complexity as a compile citizen: accumulator-copy enrolled as a required root-grain compile lens - #6527

Merged
briansrls merged 23 commits into
mainfrom
session/smart-eagle-362
Jul 13, 2026
Merged

briansrls merged 23 commits into
mainfrom
session/smart-eagle-362

Conversation

@briansrls

@briansrls briansrls commented Jul 13, 2026 •

Copy link
Copy Markdown
Contributor

What (reworked per operator direction 2026-07-13)

Complexity enforcement as a compile citizen: the accumulator-copy lens enrolls as a required compile lens — a Poly2 copied-accumulator suspect now fails compilation at the model's gated door (validate_then_compile), the same citizenship as a type error. Enforcement inherits compile's affected-set scoping instead of rebuilding attribution in the witness lane; the witness lane reverts to what it should be — the red control.

This replaces this PR's earlier shape (a per-lens diff-scoped witness-lane gate), which was the parallel-plumbing anti-pattern: a third re-ingest pipeline beside compile-clean and witness discovery. That runner module is dissolved here. Contract per sharp-bee-290 (self-host lead): interpreted door only, single gate authority, no seed-side Rust realization, no fallbacks.

  • v2.lens.complexity_accumulator_copy.compile_gate (new): Poly2Suspect → Rejected (diagnostic located at the finding node; full finding ledger in the rejection tail). Unclassifiable refusal causes ride the Accepted diagnostics channel — typed per-cause, located, counted, non-gating (§5 stopped-line ledger; never silently dropped).
  • 00_compile.dag: always_required_root_lenses() — a second required-roster grain on the same door (run once at the root), because the lens is a rooted carrier-threading walk: per-subtree-node invocation would be O(n²) — the enforcement of the complexity lens must not itself violate the complexity lens (§7 self-application). Fires on every validate_then_compile call regardless of caller lenses.
  • Witnesses (long lane, all green by execution locally): quadratic snippet rejects with accumulator_copy_poly2_suspect; identity fold accepts clean; unregistered-combiner-carrying-carrier accepts with counted refusal ledger; resolved add fixture passes the door with empty caller lenses (roster runs; clean trees pass). Door-consumer regressions: empty_required_lenses_skip_gate PASS, hollow_alias_vtc_empty_lenses_rejected PASS.

Known pre-existing red (not introduced here)

lens/application/rejecting_lens_blocks_before_compile_claim_holds FAILs on the unmodified tree too (verified by stash-run) — a rotted offline claim (not CI-discovered), the same inert-enforcement pattern this lane is fixing. Tracked separately.

Not in this PR

  • PR-2 (CI transport stage): compile-clean's affected entry closures through interpreted validate_then_compile — AuditOnly stopped-line ledger, per-lens flip-to-Blocking triggers. Its red control ingests a real corpus module through the full chain (tokenize→resolve→infer→gate) — the end-to-end door RED is homed there, since an import-free snippet cannot pass resolve (proven by execution).
  • Whether resolve qualifies call-head symbols (affecting registry-row matching at the door on real modules) is answered by PR-2's transport red control.

Brian Searls and others added 17 commits July 13, 2026 01:29
…ator-copy) + gate probe

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…e (model + witness)

Enrollment mechanism for complexity enforcement scoped to the affected set (the
changed .dag paths the floor already observes), not the corpus:

- v2.lens.complexity_accumulator_copy.roster_gate: FileSuspectVerdict +
  file_suspect_verdict(path) — typed suspect-only verdict (no ceiling, no -1
  ingest-regression sentinel a caller can misread as zero suspects).
- v2.workflow.complexity_affected_gate: affected_complexity_verdict(changed_paths)
  runs the accumulator-copy lens over changed .dag paths, SUSPECTS-ONLY (refusal
  ratchet is per-file offline-roster residue, not gated on an arbitrary diff);
  ingest-regress -> Unanalyzable refusal (fail-closed §5, never a silent widen).
  affected_complexity_floor_gate() is a nullary self-observing gate: it reads the
  diff via the floor's own git-diff host effect, so it enrolls as one gate row
  with no Rust executor change.
- Fixture + witness test with a discriminating RED control (a proven Poly2
  accumulator-copy refuses; the suspect-free floor runner passes; non-.dag paths
  filtered; a mixed diff refuses on the suspect). All green by execution locally.

Not yet wired into ci_floor_plan (the flip lands separately, after this fixture is
in main, so the live gate does not self-red on the RED-control fixture).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title complexity enforcement for affected set floor Diff-scoped complexity enforcement: affected-set accumulator-copy gate (mechanism) Jul 13, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 13, 2026 06:28
Brian Searls and others added 6 commits July 13, 2026 06:38
…s fast-lane budget)

The gate witnesses do source_findings (parse+normalize) per real file, ~5s each,
over the 5000ms per-PR discovery fast-lane budget (operator 5s rule 2026-07-12).
Slow witnesses live in a long/ test dir and run via the dedicated lane, not per-PR
discovery — same home as the sibling accumulator_copy_fold_analysis_test. Module
renamed to v2.test.long.complexity_affected_gate.
…lexity violation = compile failure

Operator direction 2026-07-13: complexity enforcement is a normal feature of
compilation (a Poly2 suspect FAILS compile, same citizenship as a type error),
and compilation is already affected-set-scoped in CI — so enrolled lenses
inherit diff scoping from compile. The witness lane reverts to red control.
Interpreted-door contract per sharp-bee-290: single gate authority
(validate_then_compile), no seed-side Rust realization, no fallbacks.

- v2.lens.complexity_accumulator_copy.compile_gate (new): the lens as a compile
  citizen. Poly2Suspect REJECTS (diagnostic located at the finding node, full
  finding ledger in the rejection tail); Unclassifiable refusal causes ride the
  Accepted diagnostics channel — typed per-cause, located, counted, non-gating
  (the stopped-line ledger, never silently dropped).
- 00_compile.dag: always_required_root_lenses() — a second required-roster
  GRAIN on the same door (root-grain, run once), because the lens is a rooted
  carrier-threading walk and per-subtree-node invocation would be O(n^2): the
  enforcement of the complexity lens must not violate the complexity lens.
  Wired by prepending root-required lenses to the caller-lens run inside
  validate_then_compile; fires on every door call regardless of caller lenses.
- Witnesses (long lane, green by execution): quadratic snippet REJECTS with
  accumulator_copy_poly2_suspect; identity fold ACCEPTS clean; unregistered-
  combiner-carrying-carrier ACCEPTS with counted refusal ledger; resolved add
  fixture passes the door with empty caller lenses (roster runs, clean passes).
- Dissolved: the #6527 per-lens witness-lane runner (complexity_affected_gate
  workflow module, FileSuspectVerdict roster_gate additions, diff-scoped gate
  test, suspect fixture) — the parallel-plumbing anti-pattern this replaces.

Known pre-existing red (NOT introduced here, verified by stash-run on the
unmodified tree): lens/application rejecting_lens_blocks_before_compile
_claim_holds FAILs on main — a rotted offline claim, tracked separately.

End-to-end door RED (real module through tokenize->resolve->infer->gate) is
homed in the PR-2 CI transport stage whose red control ingests a real corpus
module; an import-free snippet cannot pass resolve (proven by execution).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title Diff-scoped complexity enforcement: affected-set accumulator-copy gate (mechanism) Complexity as a compile citizen: accumulator-copy enrolled as a required root-grain compile lens Jul 13, 2026
@briansrls
briansrls merged commit f3e0713 into main Jul 13, 2026
3 checks passed
@briansrls
briansrls deleted the session/smart-eagle-362 branch July 13, 2026 20:33
briansrls added a commit that referenced this pull request Jul 14, 2026
* WIP: complexity enforcement for affected set floor

* Floor runner: list_flat_map for claim eval-node flatten (kill accumulator-copy) + gate probe

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* probe: enumerate accumulator-copy refusal causes on floor runner

* WIP: complexity enforcement for affected set floor

* WIP: complexity enforcement for affected set floor

* WIP: complexity enforcement for affected set floor

* Remove scratch ingest-diagnostic probe (findings captured in PR notes)

* WIP: complexity enforcement for affected set floor

* WIP: complexity enforcement for affected set floor

* Remove scratch complexity-gate diagnostic probe

* WIP: complexity enforcement for affected set floor

* Diff-scoped complexity enforcement: affected-set accumulator-copy gate (model + witness)

Enrollment mechanism for complexity enforcement scoped to the affected set (the
changed .dag paths the floor already observes), not the corpus:

- v2.lens.complexity_accumulator_copy.roster_gate: FileSuspectVerdict +
  file_suspect_verdict(path) — typed suspect-only verdict (no ceiling, no -1
  ingest-regression sentinel a caller can misread as zero suspects).
- v2.workflow.complexity_affected_gate: affected_complexity_verdict(changed_paths)
  runs the accumulator-copy lens over changed .dag paths, SUSPECTS-ONLY (refusal
  ratchet is per-file offline-roster residue, not gated on an arbitrary diff);
  ingest-regress -> Unanalyzable refusal (fail-closed §5, never a silent widen).
  affected_complexity_floor_gate() is a nullary self-observing gate: it reads the
  diff via the floor's own git-diff host effect, so it enrolls as one gate row
  with no Rust executor change.
- Fixture + witness test with a discriminating RED control (a proven Poly2
  accumulator-copy refuses; the suspect-free floor runner passes; non-.dag paths
  filtered; a mixed diff refuses on the suspect). All green by execution locally.

Not yet wired into ci_floor_plan (the flip lands separately, after this fixture is
in main, so the live gate does not self-red on the RED-control fixture).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: complexity enforcement for affected set floor

* Move gate witness test to long/ lane (file-reading witnesses exceed 5s fast-lane budget)

The gate witnesses do source_findings (parse+normalize) per real file, ~5s each,
over the 5000ms per-PR discovery fast-lane budget (operator 5s rule 2026-07-12).
Slow witnesses live in a long/ test dir and run via the dedicated lane, not per-PR
discovery — same home as the sibling accumulator_copy_fold_analysis_test. Module
renamed to v2.test.long.complexity_affected_gate.

* WIP: complexity enforcement for affected set floor

* WIP: complexity enforcement for affected set floor

* Enroll accumulator-copy as a required compile lens (root grain): complexity violation = compile failure

Operator direction 2026-07-13: complexity enforcement is a normal feature of
compilation (a Poly2 suspect FAILS compile, same citizenship as a type error),
and compilation is already affected-set-scoped in CI — so enrolled lenses
inherit diff scoping from compile. The witness lane reverts to red control.
Interpreted-door contract per sharp-bee-290: single gate authority
(validate_then_compile), no seed-side Rust realization, no fallbacks.

- v2.lens.complexity_accumulator_copy.compile_gate (new): the lens as a compile
  citizen. Poly2Suspect REJECTS (diagnostic located at the finding node, full
  finding ledger in the rejection tail); Unclassifiable refusal causes ride the
  Accepted diagnostics channel — typed per-cause, located, counted, non-gating
  (the stopped-line ledger, never silently dropped).
- 00_compile.dag: always_required_root_lenses() — a second required-roster
  GRAIN on the same door (root-grain, run once), because the lens is a rooted
  carrier-threading walk and per-subtree-node invocation would be O(n^2): the
  enforcement of the complexity lens must not violate the complexity lens.
  Wired by prepending root-required lenses to the caller-lens run inside
  validate_then_compile; fires on every door call regardless of caller lenses.
- Witnesses (long lane, green by execution): quadratic snippet REJECTS with
  accumulator_copy_poly2_suspect; identity fold ACCEPTS clean; unregistered-
  combiner-carrying-carrier ACCEPTS with counted refusal ledger; resolved add
  fixture passes the door with empty caller lenses (roster runs, clean passes).
- Dissolved: the #6527 per-lens witness-lane runner (complexity_affected_gate
  workflow module, FileSuspectVerdict roster_gate additions, diff-scoped gate
  test, suspect fixture) — the parallel-plumbing anti-pattern this replaces.

Known pre-existing red (NOT introduced here, verified by stash-run on the
unmodified tree): lens/application rejecting_lens_blocks_before_compile
_claim_holds FAILs on main — a rotted offline claim, tracked separately.

End-to-end door RED (real module through tokenize->resolve->infer->gate) is
homed in the PR-2 CI transport stage whose red control ingests a real corpus
module; an import-free snippet cannot pass resolve (proven by execution).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: complexity enforcement for affected set floor

* PR-2 milestone 1: execution-measured frontier receipts — a REAL corpus module compiles through the gated v2 door to the lens gates

Feasibility receipts for the CI transport stage (interpreted door, real bytes),
each pinned as a witness that goes red when its cause zeroes:

- std.determinism (real bytes via filesystem_read, zero imports) passes
  assemble->resolve->infer and reds at the PRE-EXISTING per-node fact_density
  lens (fact_density_hollow_alias_locus). The door WORKS on real corpus
  modules; the existing required roster is not corpus-calibrated.
- std.error_primitives reds at resolve (resolve_reason_unbound_symbol —
  generic type params).
- A synthetic import+peer pair reds at resolve (resolve_ambiguous_export);
  also found: packaged parse() reds import-carrying source
  (parse_grammar_choice_overlap_residue) where parse_production accepts it.

Consequence by receipt (not caution): the transport stage must be the
AuditOnly stopped-line ledger — per-(module, stage, cause) counted refusals
over the affected set — whose cause histogram is the burn-down list toward
v2-compiles-the-repo, each cause-zero a named flip-to-Blocking trigger.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Mark migration-owned causes on the frontier receipts (sharp-bee reconciliation)

* Receipt carrier: nimble-boar root-cause + phase specifics for migration-owned causes

* WIP: complexity enforcement for affected set floor

* WIP: complexity enforcement for affected set floor

* WIP: complexity enforcement for affected set floor

* WIP: complexity enforcement for affected set floor

* WIP: complexity enforcement for affected set floor

* Ledger histogram also asserts all_refused_causes_attributed over real door output

Wires the previously-unexercised all_refused_causes_attributed helper into the
mixed-affected-set witness: every cause the ledger counts is attributed to an
owning lane, proven over live door output (not just the synthetic ownership
table). Removes a dead helper and links the histogram to the flip-trigger table.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: complexity enforcement for affected set floor

* WIP: complexity enforcement for affected set floor

* Wire door_ledger over the real affected set (fail-closed diff observation)

door_ledger_over_affected_set reads the PR's changed .dag modules off the git
diff (floor_observe_git_diff_name_status_for_ci — the same name-status
observation the CI floor uses) and ledgers exactly those through the door.
Pure core affected_ledger_from_diff (diff-as-data) is split from the shell
wrapper so both arms are provable by execution: a diff-observation FAILURE
refuses fail-closed (AffectedDiffRefused, carries the observation's reason,
never widens to the whole corpus — the §5 absorbing-fallback guard the
affected-set floor was repaired to remove); a diff OK ledgers the .dag-filtered
changed paths. AuditOnly: a counted histogram over the affected set, never a
gate (no stopped line while the seed is the compile path).

Tests (fast, no shell/door): dag_module_paths filter (5→3, 2→0, 0→0),
affected_set_diff_failure_refuses_fail_closed, affected_set_non_dag_changes_ledger_empty.
The live git-observation half is floor_diff_observe's own tested code; door_ledger
itself is the histogram witness.

Removes the throwaway timing probe (measurement receipt, not a witness):
small-closure module ~53s through the interpreted door, one large-closure module
(04_infer) did not finish in 10min — whole-corpus is days+, dominated by the
interpreted door and redundant per-module closure re-resolution, which is why the
affected set is the viable unit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Split affected_ledger_from_diff (pure core) from the shell wrapper; prove both arms

Both arms of the affected-set entry are now green by execution over synthetic
diff data: diff-failure refuses fail-closed (no whole-corpus widen), diff-ok
ledgers the .dag-filtered changed paths. The live git-observation half remains
floor_diff_observe's tested code.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 14, 2026
…sity lane)

Measurement (release claim_batch, GUNBC_INTERP_PROFILE=1): fact_density_hollow_alias_gate
is node-local O(degree) — not a rooted whole-tree walk, so root-graining like #6527 does
not apply. The O(n²) defect lived in the shared run_required_lens_gates_on_subtree path:
unit_modeling nested node_subtree_nodes per fold_node visit, and witness list_append in the
fold step. Fix: carrier-first unit_modeling gate + prepend-then-reverse witness fold.
All 11 fact_density and 10 unit_modeling lens witnesses green by execution.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jul 14, 2026
…sity lane) (#6579)

* WIP: fact_density lens cost-shape fix

* fix(compile): subtree required-lens roster O(n²) cost-shape (fact_density lane)

Measurement (release claim_batch, GUNBC_INTERP_PROFILE=1): fact_density_hollow_alias_gate
is node-local O(degree) — not a rooted whole-tree walk, so root-graining like #6527 does
not apply. The O(n²) defect lived in the shared run_required_lens_gates_on_subtree path:
unit_modeling nested node_subtree_nodes per fold_node visit, and witness list_append in the
fold step. Fix: carrier-first unit_modeling gate + prepend-then-reverse witness fold.
All 11 fact_density and 10 unit_modeling lens witnesses green by execution.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant