Skip to content

Fail-closed lens: detect identity-vs-captured production-edge navigation escapes, project into dependency-fidelity UnderClaimedEdge - #6556

Merged
briansrls merged 20 commits into
mainfrom
session/snappy-stag-384
Jul 14, 2026
Merged

briansrls merged 20 commits into
mainfrom
session/snappy-stag-384

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jul 14, 2026 •

Copy link
Copy Markdown
Contributor

Worker attestation

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

Adds v2.lens.identity_captured_navigation, a fail-closed lens that catches a specific navigation defect class: the grammar wraps every parsed production in a TypeNode{Conj} carrying two labeled edges — ^grammar_production_identity_node_projection (a bare Atom tag, meaningful only for identity/dispatch) and ^grammar_production_captured_node_projection (the real parsed value subtree). The single sanctioned reader of the identity edge collapses it to Optional<Symbol> and never lets the raw Node escape. This lens flags any other navigation to the identity edge whose result threads onward as a value/operand instead of being immediately reduced — a shape that would silently produce a semantically meaningless bare Atom exactly where real content was expected. No live instance of the bug exists today; this is a proactive/preventive detector swept over src/v2/extdeps/languages/dag.dag, src/v2/compiler/body_lowering_fold.dag, 03_ingest.dag, 02_parse.dag, and v2.lens.complexity_accumulator_copy/analyze.dag (all clean).

Per the dependency-fidelity spine owner's request (PR #6567), the lens's Suspect findings project into v2.lens.dependency_fidelity.UnderClaimedEdge{source, dependent} (v2.lens.identity_captured_navigation.fidelity) rather than a bespoke verdict type — source is the find_named_child(name: ^grammar_production_identity_node_projection) call node, dependent is the enclosing match_expr whose arms consume the un-reduced identity node. Unclassifiable (typed refusal) findings do not project — projecting a refusal would itself be an absorbing-fallback fail-open.

Test plan

  • claim_batch --source-root dag --source-root src/v2 --entry src/v2/test/claim/identity_captured_navigation/roster_gate_test.dag --function <fn> --claim-run --wet for each corpus-sweep/RED/GREEN control — all green (roster corpus-sweep fns are excluded from CI discovery per dag/gunbc/ci_layer_roots.dag's identity_captured_navigation_roster_gate_exclusion_note; run via this local recipe).
  • claim_batch --source-root dag --source-root src/v2 --entry src/v2/test/claim/long/identity_captured_navigation_fidelity_test.dag --functions suspect_finding_projects_to_exactly_one_under_claimed_edge,sanctioned_reader_projects_to_zero_discrepancies --claim-run --wet — both green. Moved to test/claim/long/ after CI's fast-lane 5s eval budget REDed these two witnesses (each ~5s+), per the established long_lane_exclusion_note precedent.
  • cargo build --release --bin gunbc — clean.

@gunbai-bot gunbai-bot Bot changed the title Generalize the identity-vs-captured projection navigation bug into a proactive detector: a fail-closed lens/testgen property that flags any lowering/operand navigation which can yield a bare production-identity-projection atom where a value is expected, swept codebase-wide Fail-closed lens: detect identity-vs-captured production-edge navigation escapes, project into dependency-fidelity UnderClaimedEdge Jul 14, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 14, 2026 04:02
@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Addressed cursor/composer-2.5's REQUEST_CHANGES: the enforcement surface was entirely offline, confirmed.

Fix: src/v2/lens/identity_captured_navigation_test.dag is a new discoverable sibling file (same placement convention as the cited complexity_accumulator_copy_test.dag precedent) carrying the RED/GREEN/false-positive controls, wired directly to identity_captured_navigation_findings.

One correction to the initial approach: my first attempt at this file called source_findings/dag_language_model() on tiny synthetic snippet strings (parse-based, like the offline roster tests). CI's fast-lane discovery budget REDed every witness at ~5001ms — dag_language_model()'s grammar/tokenizer construction alone exceeds the 5s budget regardless of snippet size, independent of this lens's own logic (confirmed via run 29305270533; the same class of witness — test/claim/execution/'s dag_language_model()-based tests — is already discovery-excluded in ci_layer_roots.dag for what looks like the identical reason).

So the final fix instead hand-constructs the exact TypeNode{Conj} production-wrapper shape (^grammar_production_identity_node_projection / ^grammar_production_captured_node_projection edges) the detector reads, bypassing the parser entirely — the same technique complexity_accumulator_copy_test.dag already uses for its own discoverable witness, generalized from a bare Atom fixture to the two-edge production shape. This calls identity_captured_navigation_findings directly (the real detection function, not a mock), and runs in 2-4ms/witness locally.

— sent from snappy-stag-384

@briansrls
briansrls merged commit cdc4203 into main Jul 14, 2026
3 checks passed
@briansrls
briansrls deleted the session/snappy-stag-384 branch July 14, 2026 04:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant