Skip to content

Shell→dag P6 Part 2 ONLY (predecessor item closed after Part 1 #6619; this half is undone): nbd_proxy_serve_program's RawLine body (&/trap/$! backgrounding, 8 RawLines in dag/extdeps/bmc/webui/nbd_proxy_serve.dag) dissolves into a typed long-running-process/session-lease effect on host_effect_apply - #6629

Merged
briansrls merged 13 commits into
mainfrom
session/eager-heron-499
Jul 15, 2026

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session eager-heron-499.
Pushing to session/eager-heron-499 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 14, 2026 20:02
@gunbai-bot
gunbai-bot Bot force-pushed the session/eager-heron-499 branch 2 times, most recently from 907bac2 to e64e44e Compare July 14, 2026 21:12
@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review 38085 — verified on e64e44e6:

  1. TrapOnSignals trap-body quoting — Confirmed: serializer emits trap 'kill $NBDKIT_PID' EXIT INT TERM vs hand-shell trap 'kill "$NBDKIT_PID"' EXIT INT TERM. Agree this is equivalent for a numeric PID (bash re-parses the trap body at fire time; deferred expansion still works). No change — flagged correctly as minor semantic drift, not a blocker. Noted for future handlers over expandable payloads.

  2. shell_stmt_is_rawline — Confirmed witness-only predicate tied to nbd_proxy_serve_program_has_no_rawline / P6 RawLine countdown. Acceptable scaffold: dissolves with the same nbd_proxy_serve_bash_emit_dissolution_trigger (dissolve-on: bash-emit #5828) that retires the program's concat transport. No separate marker needed beyond the existing program-level Scaffold + witness that asserts zero RawLines.

  3. host_effect_nbd_proxy_serve wrapper — Confirmed correctly rostered (medium_structure_exception_roster +1, realization_vocab_exception_roster), dissolve-on: bash-emit (#5828) trigger present, Srv3NbdProxyServe {intent, lease_key} threaded through all match sites with typed BmcController refusal and witness coverage.

No code changes required for these non-blocking observations.

— sent from eager-heron-499

@gunbai-bot
gunbai-bot Bot force-pushed the session/eager-heron-499 branch from e64e44e to b2e5f18 Compare July 14, 2026 21:38
@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review 38110 (Composer 2.5 REQUEST_CHANGES) — verified on 13ecb90ba4:

Findings 1–5 were valid on the pre-wiring commit reviewed at 22:07Z; all addressed in 8c9bee547d (pivot completion) before this reply. Current HEAD adds one more fix for finding 6.

  1. realize_nbd_proxy_session_on_host / missing host_effect_nbd_proxy_serve_apply_script — Already fixed (8c9bee). host_effect_realize.dag:713 calls host_effect_nbd_proxy_serve_apply(binding, transport); import is host_effect_nbd_proxy_serve_apply (no apply_script symbol in tree).

  2. srv3_os_install_actuate still calls nbd_proxy_serve_script — Already fixed (8c9bee). emit_nbd_script deleted; srv3_nbd_proxy_serve() is apply-only via srv3_nbd_proxy_serve_apply(). No nbd_proxy_serve_script import remains.

  3. nbd_proxy_serve_transport_witness_test stale symbols — Already fixed (8c9bee). Witness now asserts argv/unit helpers + nbd_proxy_serve_systemd_realization_dissolution_trigger (no program/script/bash_emit symbols).

  4. srv3_os_install_actuate_witness_test stale symbols — Already fixed (8c9bee). Witness now uses nbd_proxy_serve_{websocat,nbdkit}_argv + nbd_proxy_serve_has_no_shell_supervision_grammar.

  5. nbd_proxy_virtual_media_install_witness_test bash_emit trigger — Already fixed (8c9bee). References nbd_proxy_serve_systemd_realization_dissolution_trigger.

  6. host_effect_nbd_proxy_serve_observe_port always PortAbsent — Valid fail-open; fixed (13ecb90). Unimplemented observe now returns PortInaccessible → classifier Refuse (never silent Absent/Start). host_effect_nbd_proxy_serve_apply_with_observation remains the injection path for classifier REDs (foreign/stale) until cited systemctl/port read-back dissolves the scaffold per host_effect_nbd_proxy_serve_dissolution_trigger. Witness: witness_srv3_nbd_proxy_apply_observe_unimplemented_refuses_fail_closed in srv3_host_effect_apply_holds.

Local green: srv3_host_effect_apply_holds on 13ecb90.

— sent from eager-heron-499

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review 38114 (Claude Opus APPROVE) — addressed on 2ede44b11d:

  • bash_program_serialize_stmt_direct unused — Fixed. Dropped bash_program_serialize_stmt_direct and the now-unused serialize_stmt / single_quote imports from src/v2/workflow/bash_program_emit.dag (leftover from retracted ShellStmt supervision variants; zero callers).

  • observe_port → PortInaccessible (non-blocking) — Acknowledged, no further change. Intentional fail-closed scaffold: real host_effect_nbd_proxy_serve_apply refuses until cited systemctl/port read-back lands (host_effect_nbd_proxy_serve_dissolution_trigger). Start/drain paths are exercised via host_effect_nbd_proxy_serve_apply_with_observation + classifier RED witnesses; live observe grounding will wire the default path when the dissolution trigger fires.

— sent from eager-heron-499

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review 38115 (Composer 2.5 REQUEST_CHANGES) — fixed on 861f076418:

  • host_effect_realize.dag:190 stale bare Srv3NbdProxyServe => arm — Valid; fixed. Updated to Srv3NbdProxyServe { intent: _, lease_key: _ } => srv3_host_effect_script_resolution_failed_cell() to match the parameterized variant shape used at :153, :164, and srv3_host_effect_script.dag. Witness srv3_host_effect_apply_holds green locally.

— sent from eager-heron-499

Brian Searls and others added 12 commits July 14, 2026 22:38
Dissolve nbd_proxy_serve_program RawLine background/trap/$! into typed
bash ShellStmt variants and route Srv3NbdProxyServe through a dedicated
NbdProxySessionOnHost realize cell with HeldSessionLease binding.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ator mapping, vocab roster, long-lane kind/path.

Co-authored-by: Cursor <cursoragent@cursor.com>
Returning PortAbsent from the unimplemented observe path was fail-open (always Start); refuse via PortInaccessible instead and witness the apply-path refusal.

Co-authored-by: Cursor <cursoragent@cursor.com>
Leftover from retracted ShellStmt supervision variants; no callers after P6 pivot.

Co-authored-by: Cursor <cursoragent@cursor.com>
Aligns the BmcController Absent script-resolution arm with the parameterized variant shape used everywhere else in P6.

Co-authored-by: Cursor <cursoragent@cursor.com>
host_effect_nbd_proxy_serve no longer imports bash.program after the systemd pivot; keeping it on the exception roster tripped roster_soundness_holds.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot
gunbai-bot Bot force-pushed the session/eager-heron-499 branch from 19c3d65 to 633dd75 Compare July 14, 2026 22:40
Replace tautological nbd_proxy_serve_has_no_shell_supervision_grammar with argv-surface marker scan + RED control; start_units reads srv3_bmcweb_token_path into websocat argv (no shell env-ref left at realize time).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review 38118 (Composer 2.5 REQUEST_CHANGES) — fixed on current HEAD:

  1. Tautological nbd_proxy_serve_has_no_shell_supervision_grammar() — Valid; fixed. Replaced constant true with argv-surface scan via nbd_proxy_serve_argv_surface_contains_supervision_marker (trap / $! / & / nohup). Witness nbd_proxy_serve_supervision_marker_red_control_holds discriminates (trap/&/$! → true; clean websocat surface → false). Transport/actuate witnesses now pass intent.

  2. Unused srv3_bmcweb_token_path import + missing token bridge — Valid; fixed. host_effect_nbd_proxy_serve_read_session_token() reads srv3_bmcweb_token_path via Filesystem.Read; start_units materializes token into websocat argv (no literal $BMCWEB_SESSION_TOKEN at realize time). Dissolution trigger names the bridge. Witness: witness_srv3_nbd_proxy_websocat_argv_materializes_token_not_shell_env_ref in srv3_host_effect_apply_holds.

Local green: srv3_host_effect_apply_holds, nbd_proxy_serve_supervision_marker_red_control_holds.

— sent from eager-heron-499

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Merge conflict check (dashboard 19c3d65 alert) — already resolved on 270665ee04:

Rebased session/eager-heron-499 onto origin/main (c8169ef93b, Shell→dag B1) earlier this session; git rebase origin/main now reports up to date. git merge-tree simulation shows zero file conflicts vs main. GitHub compare: 13 ahead / 0 behind, mergeable=true (state blocked = checks/reviews, not conflict).

Current head: 270665ee04 (supervision-marker + BMCWEB token materialization fixes for review 38118). Remote synced.

— sent from eager-heron-499

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review 38124 (Claude Opus APPROVE) — verified on 270665ee04, no further code change:

APPROVE acknowledged — routing, fail-closed observe (PortInaccessible → Refuse), systemd transient realize, roster baseline 59→60, classifier REDs, token materialization from srv3_bmcweb_token_path, and supervision-marker gate all match current tree.

Residue: intent.session_token placeholder ($BMCWEB_SESSION_TOKEN) never consumed at apply — Valid observation; bounded, no fix this PR. The field is the transport-intent contract for witness/argv tests (nbd_proxy_serve_transport_witness_test, actuate argv witnesses) that assert the env-ref form is declared in intent; the realize path never calls raw nbd_proxy_serve_websocat_argv(intent) — only host_effect_nbd_proxy_serve_websocat_argv_materialized after Filesystem.Read(srv3_bmcweb_token_path), gated by host_effect_nbd_proxy_serve_websocat_argv_materialized_omits_shell_env_ref. Dissolution trigger names the token bridge. Cleaning the dual representation (intent carrier vs materialized token) is deferred to the observe-grounding / systemd-dispatch dissolution — same trigger that retires WitnessBin scaffolding.

— sent from eager-heron-499

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review 38126 (Composer 2.5 APPROVE) — verified on 270665ee04, no code change:

APPROVE acknowledged. Confirmed on current tree: RawLine supervision dissolved to typed argv + Srv3NbdProxyServe session-lease routing; realize scaffold + roster (medium_structure_containment baseline 60); fail-closed observe (PortInaccessible → typed Refuse, witnessed); script resolution withdrawn (Srv3NbdProxyServe → Absent); fleet_converge duplicate arms cleaned.

Latent note: per-cause refusal when observe lands (start_units token absence vs generic "systemd-run transient start failed") — Valid follow-on; not blocking this PR. Dissolution trigger already names token bridge + observe grounding; when observe read-back lands, split refusal causes (empty/missing token vs systemd-run failure) as part of that same dissolution slice.

— sent from eager-heron-499

@briansrls
briansrls merged commit 9ffeb27 into main Jul 15, 2026
2 checks passed
@briansrls
briansrls deleted the session/eager-heron-499 branch July 15, 2026 00:27
gunbai-bot Bot pushed a commit that referenced this pull request Jul 15, 2026
…rge)

The auto-committed merge (7e60dce) captured a bad lens resolution (kept BOTH
baseline=0 and the old baseline=60 roster). Correct it to the parent-approved
prune: exception_roster=[] baseline=0.

Main's #6629 migrated nbd_proxy_serve RawLine->modeled Command/ShellWord/Lit, so
the merged tree has ZERO RawLine.text/Heredoc.body literal sinks in scope — the
2 AmbiguousParse holes dissolved (the exact dissolution trigger the residue note
predicted). Updated:
- decode_fidelity_residue witness: assert ambiguous_count_live==0 (was ==2), with
  the dissolution recorded; stays a live ledger (new residue reds it).
- roster_prune_note: record nbd_proxy migration; roster==violating==EMPTY still
  honest, classifier still proven non-vacuous via fixtures + lens_unit controls.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 15, 2026
…context): generalize medium_structure_containment per the signed design doc — grammar-as-classifier over string literals in substrate layers (composition of a modeled language = typed located COUNTED violation; atom = clean), count (#6637)

* WIP: No-smuggled-programs HALF B (follow-on to #6589, same worker retains con

* WIP: No-smuggled-programs HALF B (follow-on to #6589, same worker retains con

* WIP: No-smuggled-programs HALF B (follow-on to #6589, same worker retains con

* WIP: No-smuggled-programs HALF B (follow-on to #6589, same worker retains con

* HALF B: fix Hole assume-Clean fallback (§5) + add recognizer construction_justification (CI gate)

Two fixes:
1. Correctness (parent §5 catch): a parts-projection Hole is a .dag compose-time
   value spliced into the source string BEFORE bash parses it — NOT a bash-runtime
   $var (that is a literal ConstPart bash does not re-parse). An UNQUOTED Hole could
   itself be/complete a separator, so it is undecidable -> AmbiguousParse (T3), never
   assume-Clean. scan_part now sets hole_straddle when a Hole appears in unquoted
   context (quote_is_out); classify routes it AFTER P2 static-token composition
   (a Violation decided by real tokens stays Violation). Earnable escape: a QUOTED
   Hole is bounded (operators cannot apply inside quotes) -> Clean.
   Tests: rec_hole_arg_is_clean -> rec_hole_arg_unquoted_is_ambiguous; add
   rec_hole_quoted_is_clean and rec_literal_dollar_var_const_is_clean controls.
2. CI gate: v2.lens.bash_composition_recognizer had no construction_justification;
   added WallAfterGrounding{dissolves_to: RealizationDispatch} (marker heuristic ->
   grammar-derived classifier), mirroring the containing lens.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: No-smuggled-programs HALF B (follow-on to #6589, same worker retains con

* WIP: No-smuggled-programs HALF B (follow-on to #6589, same worker retains con

* WIP: No-smuggled-programs HALF B (follow-on to #6589, same worker retains con

* WIP: No-smuggled-programs HALF B (follow-on to #6589, same worker retains con

* WIP: No-smuggled-programs HALF B (follow-on to #6589, same worker retains con

* WIP: No-smuggled-programs HALF B (follow-on to #6589, same worker retains con

* HALF B: fix brace-interpolation in notes, exclude empty-init/pattern ExprRecordLit, add DecodeFidelity residue witness

- lens/recognizer notes: replace {ident} spans that .dag string-interpolation
  read as undefined variables (RawLine{text}/Heredoc{body}/{NoLanguageDecision}/
  {HoleStraddlesToken}) with plain prose (parent CI red run 29373614299).
- census producer: skip empty-parts facts (RawLine{text:""} fold sentinels have
  no program to classify); match-arm patterns (RawLine{text:t}=>) are
  MatchPattern::VariantPattern held in match_pattern, never walked, so excluded
  by construction (parent review check 1).
- new scanner/decode_fidelity_residue_test: assert ambiguous_count_live == 2
  (the 2 nbd_proxy_serve unquoted-Hole RawLines) && violation_count_live == 0,
  with the dissolution trigger (quote or type the holes -> Clean/Violation).
  Counted+reported residue, not a silent gap (DESIGN.md §5).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: No-smuggled-programs HALF B (follow-on to #6589, same worker retains con

* WIP: No-smuggled-programs HALF B (follow-on to #6589, same worker retains con

* Fix merge resolution + track nbd_proxy migration dissolution (main merge)

The auto-committed merge (7e60dce) captured a bad lens resolution (kept BOTH
baseline=0 and the old baseline=60 roster). Correct it to the parent-approved
prune: exception_roster=[] baseline=0.

Main's #6629 migrated nbd_proxy_serve RawLine->modeled Command/ShellWord/Lit, so
the merged tree has ZERO RawLine.text/Heredoc.body literal sinks in scope — the
2 AmbiguousParse holes dissolved (the exact dissolution trigger the residue note
predicted). Updated:
- decode_fidelity_residue witness: assert ambiguous_count_live==0 (was ==2), with
  the dissolution recorded; stays a live ledger (new residue reds it).
- roster_prune_note: record nbd_proxy migration; roster==violating==EMPTY still
  honest, classifier still proven non-vacuous via fixtures + lens_unit controls.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Prune dead import disposition_is_clean from medium_structure_containment lens

Review nit (claude/claude-opus-4-7 on #6637): the lens uses only
disposition_is_violation and disposition_is_ambiguous; disposition_is_clean was
imported but never referenced. Pruned. Verified the other 10 recognizer imports
are all used. No logic change.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Correct do/done boundary note in bash_ingest_only_lex_rules_note

Review finding (claude/claude-opus-4-7 on #6637, valid): the note claimed
'maximal-munch takes done over do', but do is spelled with a REQUIRED leading
space (" do") while done is "done", so at the d of done, do's spelling can never
be a prefix candidate — they do not collide at the same start position and no
maximal-munch arbitration between them occurs. Corrected the note to state the
actual mechanism (the leading-space boundary). Doc-only; no logic/emit change.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: No-smuggled-programs HALF B (follow-on to #6589, same worker retains con

* Address advisory review findings (claude opus-4-7 #6637): §2 dedup + ledger notes

All 3 findings were advisory/non-blocking; addressed comprehensively:
- §2: quote_terminated and quote_is_out were byte-identical QuoteMode folds. Folded
  to the single quote_terminated predicate (read two ways: munch-termination at
  end-of-scan, unquoted-position at a Hole); deleted quote_is_out, rewired scan_part
  and hole_straddle_note. No behavior change (both were match q { QuoteOut=>true; _=>false }).
- §3: named the dissolution trigger for RawLiteralPartsFact.{constructor,field} — the
  in-band String discriminator becomes a typed sink COPRODUCT discriminant when the
  projection moves in-substrate (census.rs scaffold note).
- §5: added operand_framing_residue_note — backticks / dollar-paren / brace-groups fall
  through as OperandFraming (accidental-splicing threat model, acceptable per the reviewer);
  named so the residue is counted, not silent, with a widen-scope dissolution trigger.

Doc + a no-op §2 dedup; no logic/emit change.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Remove // comment lines from recognizer (.dag has no comment syntax)

Floor parse aborted at bash_composition_recognizer.dag:313 (expected item
declaration): the §2 dedup comment I added used // lines, but .dag supports
NO comment syntax (neither // nor #) — marks live in data _note String fields.
The dedup rationale is already carried by hole_straddle_note ('the same single
QuoteOut predicate the munch-termination check reads'). No logic change.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Jul 15, 2026
…6637)

The affected-set-falsifier has been red on every cold sweep since 2026-07-15
04:32 UTC (last green 07-14 23:10, run 29374839251). It was doing its job:
three discovery witnesses returned Bool(false) against the whole corpus that
per-PR selection had predict-skipped. This clears the two non_fold_residue
ones; the inert_carrier one is a separate lens-precision question, left red
deliberately rather than papered over.

Stale rows deleted (roster 120 unique -> live 118; each verified as genuinely
migrated, NOT merely gone lens-invisible -- the converge_cli_applied_knob_count
trap):
  - nbd_proxy_serve.dag::shell_command_leading_lit_text
  - nbd_proxy_serve.dag::shell_rawline_starts_with_tool
    both fns DELETED by #6629 (P6 Part 2: RawLine body -> typed session-lease
    effect), firing the dissolve-on their rows carried.
  - emit_host.dag::run_test_claim_emit_vs_eval_verdict
    fn still exists (emit_host.dag:335) but #6650 enumerated its wildcard into
    three explicit constructor arms -- residue genuinely folded, no bare `_ =>`
    remains. Ratchet tightens.

Unrostered row backfilled: bash_composition_recognizer.dag::apply_role, landed
by #6637. Two-special-variant dispatch over TokenRole's 5 variants; the other
three all reduce to the closed run, so enumerating would clone the general arm
3x. Same class as the orch_emit_let_step row above it (receipt #10).

Green-by-execution (claim_batch, local):
  PASS non_fold_residue_no_unrostered_or_stale (src/v2/lens)
  PASS non_fold_residue_clean_holds            (dag/test/claim)
  FAIL inert_carrier_no_unrostered_or_stale    <- unchanged, see PR body
Discriminating RED control: both nfr witnesses were red on this same tree
before the roster edit and green after; no witness or assertion was weakened.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 16, 2026
…; re-enroll cargo fmt in CI (de-fused from nextest) (#6691)

* WIP: falsifier is failing

* non_fold_residue roster: burn down 3 stale rows, backfill apply_role (#6637)

The affected-set-falsifier has been red on every cold sweep since 2026-07-15
04:32 UTC (last green 07-14 23:10, run 29374839251). It was doing its job:
three discovery witnesses returned Bool(false) against the whole corpus that
per-PR selection had predict-skipped. This clears the two non_fold_residue
ones; the inert_carrier one is a separate lens-precision question, left red
deliberately rather than papered over.

Stale rows deleted (roster 120 unique -> live 118; each verified as genuinely
migrated, NOT merely gone lens-invisible -- the converge_cli_applied_knob_count
trap):
  - nbd_proxy_serve.dag::shell_command_leading_lit_text
  - nbd_proxy_serve.dag::shell_rawline_starts_with_tool
    both fns DELETED by #6629 (P6 Part 2: RawLine body -> typed session-lease
    effect), firing the dissolve-on their rows carried.
  - emit_host.dag::run_test_claim_emit_vs_eval_verdict
    fn still exists (emit_host.dag:335) but #6650 enumerated its wildcard into
    three explicit constructor arms -- residue genuinely folded, no bare `_ =>`
    remains. Ratchet tightens.

Unrostered row backfilled: bash_composition_recognizer.dag::apply_role, landed
by #6637. Two-special-variant dispatch over TokenRole's 5 variants; the other
three all reduce to the closed run, so enumerating would clone the general arm
3x. Same class as the orch_emit_let_step row above it (receipt #10).

Green-by-execution (claim_batch, local):
  PASS non_fold_residue_no_unrostered_or_stale (src/v2/lens)
  PASS non_fold_residue_clean_holds            (dag/test/claim)
  FAIL inert_carrier_no_unrostered_or_stale    <- unchanged, see PR body
Discriminating RED control: both nfr witnesses were red on this same tree
before the roster edit and green after; no witness or assertion was weakened.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: falsifier is failing

* WIP: falsifier is failing

* Re-enroll cargo fmt in CI as a standalone step, de-fused from the nextest bundle

Operator ruling 2026-07-15. Restores fmt enforcement without re-enrolling
RustMonolithGate (still rejected).

WHY IT WAS GONE: tools.rust_gates_ci.run_gates welds two separable facts into
one ProcessExit -- fmt (4.3s measured, parse-only, no build, green) and nextest
(~37 GiB, compile+run, red on main). The 2026-07-11 ruling removed the bundle
for reasons that are ALL facts about nextest; fmt was collateral damage of that
fusion (DESIGN 3).

WHY THE HOOK ISN'T COVERAGE: the ruling's declared replacement was the pre-push
hook. That is an escape hatch (DESIGN 5) -- opt-in per clone via a manual
core.hooksPath, bypassable with --no-verify, absent in container worktrees --
and PROVEN ineffective, not just theoretically weak: in this very worktree
core.hooksPath points at a directory with no pre-push hook at all, and #6658
landed an unformatted .rs on main 2026-07-15 with nothing catching it. The hook
stays as fast local feedback, never as the wall.

SHAPE: standalone RunStep, FIRST in the build job -- a 4-second violation now
fails in 4 seconds instead of after the ~33min release build. build is not
protection-required itself, but ci needs:[build], so a red fmt blocks the
required job by construction. Toolchain already installs the rustfmt component
in ci_prelude_steps, so marginal cost is ~4s and no build.

Step-budget discipline (gunbc_ci_job_timeout_policy_disposition: "the backstop
is the exact step-sum + prelude"): the new step carries the aux cap and
gunbc_ci_build_job_backstop_timeout_minutes() gains exactly one aux term
(65 -> 70), so no step is uncapped and the sum stays exact.

Authority updated, not left lying: commit_gate_rust_suite_removed_disposition
declared "cargo fmt stays enforced by the pre-push hook". That claim is now
retracted in-row and the fmt half marked reversed; the nextest half and the
RustMonolithGate rejection are preserved verbatim.

ci.yml regenerated through the emit authority (expected_ci_yml), never hand-
edited; trailing-newline gotcha handled.

GREEN-BY-EXECUTION:
  PASS generated_artifact_drift_witnesses   <- the real drift gate, ci.yml byte-exact
  0 FAILs across ci_yaml_serializer, ci_compile_jobs, placement_grain,
    rust_gates_ci, ci_budget_tree witnesses
DISCRIMINATING RED: planted a fmt violation, ran the EXACT emitted step command
  -> exit 1 (caught); restored tree -> exit 0. The gate discriminates.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Resolve merge conflict: drop duplicate nfr roster work, main landed it first

main (#6680 lane) independently made the identical nfr roster fix while this PR
was in review: same two nbd_proxy_serve stale rows deleted, same
emit_host::run_test_claim_emit_vs_eval_verdict stale row deleted, and the same
apply_role backfill added (its own wording, different position in the roster).

Resolution takes MAIN's side wholesale. Keeping mine would have produced two
apply_role rows -- harmless at use (the roster collapses to a BTreeSet) but a
pointless redundancy, and re-litigating identical work for authorship is not a
reason to diverge. cli_run.rs is now byte-identical to origin/main.

This PR therefore reduces to the work main does NOT have, verified against
origin/main:
  - the cargo fmt CI gate (de-fused from the nextest bundle) + its authority
    note amendment + regenerated ci.yml
  - the latent main fmt red fix (main still carries the unformatted import)

Independent convergence on the roster is a receipt for the falsifier itself:
two lanes hit the same cold-sweep reds and reached the same verdicts on which
rows were genuinely migrated vs still live.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: falsifier is failing

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 18, 2026
Root cause was the inverse of the working theory: the 8 missing names
(nbd_proxy_serve_script, nbd_proxy_serve_program_statement_count,
nbd_proxy_serve_program_foreground_command_is_websocat,
nbd_proxy_serve_bash_emit_dissolution_trigger, install_media_fetch_script,
os_install_actuator_toolchain_ensure_script{,_uses_github_release_not_apt_for_websocat},
os_install_actuator_toolchain_ensure_is_privileged_gated_for_apt) were
deliberately deleted on main by the Shell->dag migration (#6587 8f57815,
#6596 c8169ef, #6629 9ffeb27, all ancestors of merge-base c2859a6),
with their consuming tests updated in the same PRs. The strip re-apply
(ab44ec2) clobbered 6 consuming files back to pre-migration content,
leaving dangling references. Re-adding the old decls would resurrect the
terminally-deleted bash sidecar (e06ea6a, operator ruling 2026-07-18).

Fix: restore the 6 consuming files to their merge-base c2859a6 content
(identical to merged-main tip 14c8d29), minus import blocks, plus the
8 qualification lines D1/D2 precedent requires (std.disposition.Terminal,
3x std.resources.Network, 3x gunbc.srv3_nbd_proxy_serve_intent.*,
extdeps.bmc.webui.nbd_proxy_serve.srv3_nbd_proxy_local_port).

Histogram: TOTAL_HARD 149 -> 136 (-13 = exactly the family sites);
all 8 family NAME rows gone; zero new SITE rows (site-level diff clean;
8 new NAME-table entries are top-50 truncation backfill, present as
baseline sites in untouched files).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 20, 2026
…-derived loader (salvage) (#6848)

* reland increment: expand generic-product scrutinees from census decls (194 -> 180)

A value typed by a census-resolved fn sig carries its ANNOTATION nominal (the
qualified name as written), not a resolved structure. expand_scrut_from_decl
returned generic PRODUCT decls unexpanded (else-arm scrut_node), so record
destructures over such values fell through name comparison (dotted scrut name vs
bare ctor) into VariantNotFound — the UpsertClassification x14 family. The
generic-product arm now instantiates the decl's fields with the use-site args
(same substitute_type_slots the alias arm uses); record_destructure compares the
scrutinee's base name (qualified_last_segment) so unexpanded dotted nominals
still destructure.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* Revert "WIP: namespace migration"

This reverts commit 485853c.

* WIP: namespace migration

* reland increment: qualification-invariant brand comparison + transparent-alias grounding (180 -> 154)

TypeMismatch family root: nominal_call_arg_brand_mismatch compared authored
name STRINGS, which broke two ways post-strip. (1) A qualified spelling on one
side (extdeps.github.pulls.PullRequest formal vs PullRequest actual — the same
decl) read as a brand conflict: names now compare by qualified_last_segment,
which exactly restores pre-strip precision (bare-vs-bare). (2) Transparent
primitive aliases (Timestamp = String) are brand-ERASING by design
(is_transparent_primitive_alias_rhs), but census-path resolution grounds one
side to the kernel type while the other keeps its authored spelling; a new
brand_grounds_transparently_to exception treats a brand as equal to the kernel
type its alias grounds to (both directions). kernel_value_declared_type_mismatch
gets the same last-segment normalization. GUNBC_ARG_PROBE/GUNBC_PEEL_PROBE
env-gated probes added (inert; removed before the re-land gate).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* Qualify-on-borrow hardening: qualification-invariant compares + container dispatch

Burndown 154 -> 149 (whole-tree compile-clean, honest corpus), net of the
qualify-on-borrow landing (181 peak at the raw seed mirror):

- type_name_compatible (00_core): both-dotted -> exact path equality; mixed
  bare/dotted -> last-segment (pre-migration precision, end-state precision
  when both sides qualify). Wired into node_type_compatible fallback,
  node_type_equals_core (all name arms), prefer_specific_type (join keeps
  the structured side over a name-compatible bare leaf).
- module_path_segments + qualified_last_segment moved 04_env -> 00_core
  (single authority; 04_env re-exports for existing importers).
- Container dispatch is qualification-invariant: canonical_template_name,
  is_declared_container_alias_spelling, node_is_set_collection normalize via
  qualified_last_segment before the container_template_algebra table
  (std.types.Map IS Map; -4 InternalError).
- medium_fidelity_witness_test: qualify the 4 Medium<...> return annotations
  (bare Medium is census-ambiguous from test.claim.* -> correct tie-refusal;
  the D2 pass had qualified ctor heads but not annotations).
- Probes GUNBC_VNF_PROBE / GUNBC_SIG_PROBE added (env-gated, removed before
  the reland gate).

Known residue (measured, tracked): std.computation kernel_algebra_profile
|> get pair (2, method-path, next lane); std.fermi |> first pair is
pre-existing (visible pre-154); reference_deps generic-param leak family
morphs (T-field rows).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* WIP: namespace migration

* Restore nbd/actuate/toolchain decl family (import-stripped)

Root cause was the inverse of the working theory: the 8 missing names
(nbd_proxy_serve_script, nbd_proxy_serve_program_statement_count,
nbd_proxy_serve_program_foreground_command_is_websocat,
nbd_proxy_serve_bash_emit_dissolution_trigger, install_media_fetch_script,
os_install_actuator_toolchain_ensure_script{,_uses_github_release_not_apt_for_websocat},
os_install_actuator_toolchain_ensure_is_privileged_gated_for_apt) were
deliberately deleted on main by the Shell->dag migration (#6587 8f57815,
#6596 c8169ef, #6629 9ffeb27, all ancestors of merge-base c2859a6),
with their consuming tests updated in the same PRs. The strip re-apply
(ab44ec2) clobbered 6 consuming files back to pre-migration content,
leaving dangling references. Re-adding the old decls would resurrect the
terminally-deleted bash sidecar (e06ea6a, operator ruling 2026-07-18).

Fix: restore the 6 consuming files to their merge-base c2859a6 content
(identical to merged-main tip 14c8d29), minus import blocks, plus the
8 qualification lines D1/D2 precedent requires (std.disposition.Terminal,
3x std.resources.Network, 3x gunbc.srv3_nbd_proxy_serve_intent.*,
extdeps.bmc.webui.nbd_proxy_serve.srv3_nbd_proxy_local_port).

Histogram: TOTAL_HARD 149 -> 136 (-13 = exactly the family sites);
all 8 family NAME rows gone; zero new SITE rows (site-level diff clean;
8 new NAME-table entries are top-50 truncation backfill, present as
baseline sites in untouched files).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Convergence sweep 1: un-resurrect main's de-forks + witness-lane closure unification

149 -> 123 whole-tree; witness roster 299 -> ~10 fatal. Two independent roots,
one class: the strip re-apply (ab44ec2) resurrected pre-migration file
content that main had since consolidated — a silent census poison (§3 forks
by resurrection).

- src/v2/std/algebra.dag: take main's (#6715 dissolved the v2 algebra tower
  onto std.algebra; the branch carried the old stacked fork, so flat literals
  in diagnostic/nat/logic refused, and after the first restore the stale
  stacked CONSUMERS integer.dag/seed_debt flipped red — both now main's).
- src/v2/lens/{effect,idempotency,ownership,parallelism}.dag: take main's
  (lens-commons consolidation into algebraic_composition.dag; the branch had
  hand-cemented stub forks like `type EffectClassification {}`).
- Cherry-pick a6e9f4f9cd: nbd/actuate/toolchain family — the 6 consuming
  files restored to merge-base-minus-imports (the decls were deliberately
  deleted on main by the Shell->dag migration; full provenance in that
  commit body). -13, exactly the family.
- cli_run: extend_with_reference_closure extracted — the ONE reference-
  closure authority now serves BOTH the whole-tree walk and the per-entry
  claim/witness loader (was a §3 fork: the roster path missed reference-only
  deps entirely).
- find_witness_project_to_core_controls + derivable_coercion_task_id:
  qualify one dotted reference per foreign module (Rule-1: references ARE
  the dep edges; a bare-only file has no closure) + Named->v2.std.node.Named
  (non-unique variant). Witness file 298 errors -> 5 (owned families).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* Mechanical burndown: classifier-driven qualifications + stale-file adoption (123 -> 89)

From the residue-classification agent's bucket list (all census-verified):
- Bucket (a) source qualifications: merge_admission Success/Failure ->
  extdeps.github.checks.* (the borrowing-module alias path), review/review_codex
  state Open -> extdeps.github.pulls.Open, upsert Absent (builtin-Witness
  collision), srv3_install_media Present{observed_sha256} (bare Present hit
  builtin Witness.Present), roadmap authored() -> gunbc.roadmap_authority
  (nearest-ancestor picked the test sibling by design; source must qualify),
  01_tokenize Empty/None/Accepted/Rejected -> std.algebra./v2.std.diagnostic.*,
  coverage + grammar_coverage Empty.
- Bucket (b) stale strip-era copies -> origin/main content minus imports:
  fleet_converge_cli (ProvisionBuildCache arm), falsifier_workflow test
  (cadence rename + semantics), host_build_cache_provision test (rewritten on
  main), behavioral.dag (DeterminismAxis -> std.determinism.Determinism, the
  open-thread-E rename the stale hunk had reverted).
- Deliberately NOT qualified (reverted after measurement): 02_parse
  OccurrenceIdAllocator/SpanIndex and grammar_coverage DeclFact/
  whole_corpus_scope/normalize — those reference edges pull the v2-internals
  subtree (occurrence_id/provenance/normalize -> compilers/sugar + standing_intent
  closures) into the corpus: +75 latent debts and census uniqueness flips
  (Accepted/Rejected aliases). That subtree opens as its own measured batch
  with the witness-roster lane (Increment B), not as a side effect.
- env_with_type_variable_bindings extracted to 04_env (consolidates
  resolve_item_types' inline type-param fold; no behavior change). The
  borrowed-sig resolve-at-borrow experiment was REVERTED after measurement:
  per-lookup resolve_node blows up wall-clock (>10min vs 103s) because the
  borrower's env lacks the owner's recursive-type facts (FreeMonoid expands to
  the depth bound per call). Needs the once-per-module hoist; benched.

Ordering/Equal/Less/Greater rows cleared for free with the algebra-fork
dissolution (previous commit), as the classifier predicted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* Kernel container dispatch: one canonicalizer, qualification- and carrier-invariant (89 -> 82)

Root (get-pair agent, proven by probe chain): the kernel algebra machinery is
keyed on raw canonical spellings ("Map"/"List") at MULTIPLE reads — the
profile lookup (enrich_kernel_type, lookup_structural_method), the
container_param_name table behind make_container_type/make_map_type, the
template-match compare (apply_type_substitution ContainerOf), and
is_container_type/container_expected_arity via receiver_name_str. A receiver
spelled by qualify-on-borrow (std.types.Map) or alias-expanded to its carrier
(FreeMonoid, std.algebra.FreeMonoid) sails past the invariant classifiers and
misses these reads; the method-pipe fallback then absorbs the miss by
returning the receiver type, surfacing two hops later as VariantNotFound
Present/Absent (std.computation kernel_algebra_profile |> get; std.fermi
|> first — the latter pre-existing with bare FreeMonoid).

Fix: container_kind_canonical(name) = last-segment, then carrier->canonical
inversion DERIVED from container_template_alias_rows (sorted fold, no minted
table) — applied at the profile lookup (kernel_profile_lookup) and every
authored-name entry into the kind-keyed tables. The interim
missing-kernel-container-profile guard rows this exposed (+66 at the halfway
point) confirmed the reads were reachable and are now all green.

Benched follow-up (own increment, own receipt): the method-pipe fallback's
final else still answers a dispatch miss with the receiver type — an
absorbing fallback to convert to a typed refusal; every currently-absorbed
miss becomes a counted diagnostic.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* Borrowed-sig hoist: census pass 2 resolves generic fn sig returns once per decl at owner position (82 -> 71)

The census stored raw pre-typecheck fn nodes, so borrowed generic fns leaked
bare type-param leaves (T/V/E) into consumers. Pass 2 (census_with_resolved_fn_sigs)
resolves each borrowable generic sig's return ONCE at census build in a synthetic
owner-position env (module_path = declaring module, symbol_index = completed pass-1
census, type params bound as TypeVariables via env_with_type_variable_bindings) —
order-independent, once per decl (the per-lookup variant re-resolved recursive
carriers to the depth bound per call, >10min), fail-closed staged: any resolution
diagnostic keeps the raw binding (upgraded | raw is a typed frontier, not a widen).
Wall-clock unchanged (~97s). Cleared: payload-on-V x8, refusals-on-T x2, facts-on-T x1.
Remaining: service-op output family (~30, next increment widens pass 2 to services),
T-family residue kept raw by the diagnostic gate (~19, diagnosing).

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* Qualify only reference positions: declaration names (variants, fields) are never rewritten (25 -> 16)

Root: qualified_value_projection passed a projected COPRODUCT decl through
qualify_borrowed_type_names, whose whole-subtree walk renamed variant
DECLARATION leaves (Independent -> std.realization.Independent) - every bare
match arm then missed (VariantNotFound + exhaustiveness demanding dotted names,
firing in the OWNER file std/realization.dag itself). Fix at the authority:
qualify_borrowed_type_names now switches on structure - a NoConnective node's
children are generic args (references, rename-eligible); a structured node's
children are DECLARATIONS, walked by qualify_decl_reference_positions (keep the
name, qualify the inferred payload, recurse) - the same walk the census type-decl
pass (2b) uses, consolidated into 04_env as the one authority
(qualify_declaration_position_invariant note). Also cleared: LitNull exhaustiveness
(none => counts as Absent) in the same push, plus the anonymous-Conj nonempty row.

16 = Increment-B subtree 7 (SpanIndex/OccurrenceIdAllocator/DeclFact/whole_corpus_scope/normalize)
+ Frame x2, Job id, mid-on-M, NanosecondDuration x2, Secret-vs-String x2, Terminal.

* WIP: namespace migration

* Expected-driven variant ctor + Frame source qualification (16 -> 13)

record_lit_variant_from_expected: when a ctor's bare name is census-ambiguous but
the EXPECTED type resolves to a coproduct carrying a variant with that last
segment, the ctor types against that variant (fields + result type + presence) -
the sanctioned namespace-only-Y position-info rule (expected type filters to one,
never picks among unrelated candidates). Clears Terminal (data _: Disposition =
Terminal{...} with Terminal census-ambiguous). Frame x2: extdeps/render/terminal
sigs qualify std.render.Frame (genuine homonym vs std.materialization_ladder.Frame,
lcp-0 tie from extdeps position refuses correctly).

13 = Increment-B subtree 7 + Job-id 1 + mid-on-M 1 + NanosecondDuration 2 + Secret 2.

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* Kernel-brand preservation through census resolution + pure-alias transparency (13 -> 9)

Secret x2: Secret is IN kernel_type_set, so kernel_value_declared_type_mismatch
walls String-vs-Secret deliberately - but peel/preserve treated brand-over-
primitive as transparent and stripped Secret -> String (an OLD contradiction the
namespace exposure surfaced; previously masked by output opacity). Fix at the
authority: preserve_nominal_brand_on_resolve / peel_nominal_alias_identity keep a
brand whose last segment is itself a kernel type; the census op-output/sig
upgrades route through preserve_nominal_brand_on_resolve (ad-hoc erasure guard
deleted). NanosecondDuration x2: brand_grounds_transparently_to widened to
template-name equality - a pure alias (type X = Measure<...>) is transparent to
its template per section 4, so List<NanosecondDuration> flows where
List<Measure<Time,S,Nat>> is expected.

9 = Increment-B v2-internals subtree 7 + Job-id 1 + mid-on-M 1.

* WIP: namespace migration

* Witness-roster cascade: rust_wire_serde entry chain qualified through v2 core (roster advances past 2 files)

The roster's fail-closed walk advanced past the old T-family fatals (cleared by
the sig hoist) into rust_wire_serde_naming_policy_test: qualified the file's
annotations (v2.std.verification.UnifiedTestClaim x3, v2.std.live_tree.LiveTreeDisposition),
fixture refs (v2.extdeps.languages.rust_wire_serde.*), fn refs
(v2.compiler.translate.target_serialize_source_from_model, v2.std.compilers.target_model.TargetModel),
and the pulled modules' own bare foreign refs (rust_wire_serde -> std.serialization
naming variants + extdeps.languages.rust.emit serde attrs; rust.dag ->
v2.std.grounding fact-bundle fns). Current fatal: 'variant Cons not found in
FreeMonoid' at v2.std.collection List alias - probe shows every bare variant
lookup's scrut DOES carry the variant (the variant_not_found_result calls are
EAGER fallback evaluations discarded on direct-match hit - v1 is strict), so the
surviving diagnostic comes from another emitter; next increment starts there.
Temp VNF child-dump probe left env-gated (GUNBC_VNF_PROBE, removed before gate).

* Hygiene walker: live_tree_disposition row accepts qualified annotation/value spellings (fixes CI early-exit at ec18d98)

The witness naming-hygiene pre-plan text scan (parse_entry_live_tree_disposition,
cli_run.rs hand-seed) compared the annotation and variant by LITERAL prefix, so
the namespace lane's qualified spelling (data live_tree_disposition:
v2.std.live_tree.LiveTreeDisposition = SubstrateInputsOnly, present in 2 witness
files) tripped 'malformed row' and killed CI at 64s before the floor ran. Same
defect class as the session's compare fixes: a raw name compare that is not
qualification-invariant. The scan now compares the last dot-segment of both the
annotation and the initializer variant (mirroring type_name_compatible's
mixed-spelling rule); the typechecked roster compile stays the authority behind
the text scan. Verified locally: claim_executor pre-plan hygiene walk completes
and the floor proceeds (its redness is the known burndown state, 9 rows +
roster fatal).

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* Increment B frontier: qualify map_get/None (kernel-tier bypass), standing_intent+vocab universe, artifact refinement refs, memo carriers, Frame, dag-test cross-corpus collisions (GeneratedArtifact/DesignArtifact/Grounding) — histogram 30 -> measuring; census probe now takes name list via GUNBC_CENSUS_PROBE

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* map_get kernel-vs-v2 fork: qualify all 31 Outcome-shaped bare map_get callers to v2.std.collection.map_get; grounding host_run/verdict quals; rust.dag TargetGenericApply missing field_label_separator (latent defect unmasked); census leaf-binding qualify arm (data/0-param-fn/alias inferred, .dag + seed)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* roster: pattern alias-arm re-expansion (expand_scrut_from_decl has_inferred_alias recurses expansion on substituted target — clears List/FreeMonoid VNF class); qualify sg2_type_expression_projection refs (main-merged file, per-entry closure)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* sg2 test: qualify all borrowed rust.dag refs + cross-test rust_add fixtures (caret symbol literals untouched)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* sg2 test: comprehensive owner-resolved qualification (translate/target_model/verification/content_hash refs)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* rust_add_emit_translate + sg2 tests: owner-resolved qualification sweep (eval/translate/emit/rust/live_tree/verification refs)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* determinism lens owner-split quals (std.determinism verbs+variants, v2.std.determinism DeterminismFact); infer_ground_add InterpretationAlgebra literal completed with match: MatchInterpreter (latent missing-field defect unmasked by deeper typing)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* DeterminismAxis ghost-name re-grounded on std.determinism.Determinism (open-thread task E consumer-safe rename, unmasked by closure); compile_gate accumulator_copy_findings qual

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* merge-stripped files: apply main's import maps as qualifications (analyze 123, contract 339, sg_claims_test 62, fold_analysis_test 33); rust_enum_derives -> extdeps.languages.rust.emit

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* compiler-layer frontier quals: cross_tree resolution/import_model, cache_identity ids, SymbolicCost

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* cross_tree resolution: qualify LayerPrefix variant values to v2.std.layer

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* complete Wave-1 Gate-1 C1 migration branch-side: delete stale copied_port_fact_registry fold locals in complexity_accumulator_copy.dag, re-ground classify_call on v2.lens.cost.copied_port_citations.copied_port_index_of; qualify materialization_carriers memo ids (extdeps.realization.*, extdeps.cache.materialization)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* qualify PerturbationVerdict (std.perturbation authority), Diagnostics None values in 03_name_resolve + rust_add test

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* census: variant alias enters global_bare only when no item decl claims the name (Job type-vs-variant tie); roster owned-data walk keys on per-module item_registry (lens_module_gate homonym); qualify accelerator witness test

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* pre-qualify cross-module fn calls in import-stripped accelerator demo modules

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* qualify accelerator demo layer: approximate_field/numerical_fidelity/gpu.types/vendor.nvidia/live_tree owners; revert kernel to_string quals

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* interpreter: register fn_nodes under qualified module.name keys (dotted runtime calls); qualify gpu witness layer

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* qualified value projection: kernel_span ident so authored_name reads spine.dotted everywhere; interpreter eval_var dotted fallback via qualified fn_nodes; revert kernel to_string qual in gpu module

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* WIP: namespace migration

* patterns: drop destructive re-resolution of substituted Disj scrut (resolver rebuilt arm payloads from raw decl); scope TypeVariable slot-binding to pattern expansion (resolver unchanged — corpus-wide cost regression); interpreter: qualified unit-variant values from compile-side inferred owner; qualify model witness test

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* qualify iam validation test + simd data ref; SIGPATH4 probe

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* iam test: Deny is std.access.Deny (payload variant), not aws_iam Effect.Deny; SIGPATH5 probe

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* revert substitute_generics inferred-walk (param capture; M.mid stays declared pre-existing residue)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* qualify access_layer_extension test

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* qualify redfish_rbac_policy refs

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* bulk-qualify all import-stripped dag/test/claim files (252 files, 8386 refs) via unique-owner sweep

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* revert 160 field-label qualification artifacts; interpreter: variant identity compares last dot-segment (qualified ctor/pattern spellings)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* interpreter: variant identity normalized to bare arm name at construction (qualified ctor heads and value bindings)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* revert 31 parse-broken files from bulk sweep to pre-sweep state (dots in label/pattern/decl positions); re-qualify individually later

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* pre-gate: finish GUNBC probe-block strip (remove dangling multi-line condition fragments)

Completes the operator-agreed pre-gate scope on top of the auto-WIP snapshot
c4872e2 (which carried the comparator narrowing to pattern-side-only and
the bulk of the probe strip, but raced the strip mid-edit and pushed 6
dangling '&& ...' condition fragments that broke the seed build — the CI
build failure at c4872e2).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* restore prose reference inside merge_lifecycle incident-note string (over-stripped by the 160-artifact regex revert)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* infer: qualified payload-variant construction (roster items 1+8) — stamp parent_enum for dotted spellings (#6869)

* WIP: 6848 cleanup

* ci: re-run against current namespace-wave1-reland base (prior run predates 4 base commits)

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* remove stray n89.txt (WIP-harness histogram dump; forced whole-tree compile-clean scope on every CI run)

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* M.mid green: stamp decl-param field types TypeVariable at extraction (main parity); census fill = whole indexed pool

Two fixes, both measured against the gate-equivalent whole-tree compile:

1. M.mid (batch-1 blocker, roster item 4): a field type extracted from a
   param-carrying decl whose spelling is the decl's own type param IS that
   decl's type variable — stamp it Tv at extraction
   (stamp_field_type_from_decl_params, seed + 04_infer.dag authority).
   Main serves exactly this shape (measured ftype[M inf=Tv(M)]) and stays
   green via the Tv deferral arm; the branch's whole-tree path served the
   param bare and unstamped, turning the latent generic-payload hole into
   the loud 'no field mid on type M'. Red control: the witness row present
   -> absent under the whole-tree gate with ZERO other set-diff. Note: main
   is deferral-green, not correct — r.member.mid has never been typechecked
   anywhere; the L1 unchecked-access class stays open as typed debt
   (follow-up: shadowing-aware inferred-walk substitution).
   Also: local_binding_for_item Tv-stamps decl-body param occurrences at
   census-entry construction, and census_upgrade_type_decl_binding tv-binds
   the decl's own params in its env (was []) — census copies now carry the
   local-resolver shape.

2. Census fill = whole indexed pool (namespace design 7.5: fill = whole
   tree; policy gates lookup, never fill): build_symbol_index_for_reconcile
   builds ONE parse-grade census over every indexed module (sorted,
   deterministic), cached per process; merge_symbol_indices deleted — its
   fold dropped provider global_bare (fail-open). Zero diagnostic set-diff
   on the gate; reconcile wall-clock 117s -> 98s.

Whole-tree gate: 35 -> 29 hard diagnostics this session; all 29 remaining
are the single v2.* cross-tree reference class (dotted refs to src/v2
modules outside the import closure — next fix is reference-derived deps in
resolve_transitively, the Rule-1 end-state).

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* namespace census layering: bare = own tree-closure, qualified = whole pool

Batch-1 (whole-tree --target dag gate) GREEN for the first time on this branch:
0 hard diagnostics (was 29 v2.* cross-tree rows), 2206 UnlistedImportUse
advisories (pre-existing non-gating burndown class, grown by design as the wave
strips imports).

Mechanism (namespace-resolution-design.md 7.5: fill = whole tree; policy gates
lookup, never fill):
- closure census stays byte-identical to the no-fill build (bare visibility,
  variant-alias corpus gating, services all closure-scoped) — a pool homonym
  cannot shift what a compiled module's bare names mean (measured: whole-pool
  single census vanished bare GET/Persistent/JsonValue across 28 witness rows)
- census-only fill modules are PARSE-GRADE (tokenize+parse, never resolve:
  resolving fill against a fill-only pool fabricated 797 unresolved-import
  diagnostics about the view, not the modules) and enter a qualified-only
  entries underlay (build_symbol_index_qualified_fill)
- cli_run typecheck additionally underlays each module's OWN tree-closure bare
  census (root modules + import-reached pool modules — gate parity by
  construction, e.g. dag witnesses' bare LiveTreeDisposition declared only in
  v2.std.live_tree), lazily per root (tree_bare_census_for_root)

Proven by execution: gate exit 0 (2m14s); claim_batch on the GET witness now
resolves fully green (was 60+ typecheck errors) and fails only at the known
interpreter fn-registry gap (no such function at runtime — the loader does not
yet derive deps from bare references; batch-2 will quantify that class).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* loader: bare-reference closure via tree census (Rule-1 direction) + discovery qualified-variant fix + .dag mirrors

The import-stripped corpus (83% of dag/test/claim and src/v2) had no import
edges to follow, so witness closures loaded 1 file: typecheck resolved names
through the census while the interpreter never loaded their bodies — 106 of 107
batch-2 FAILs were 'no such function'. The loader now derives deps from names
(namespace Rule-1 direction): entry closure = imports + dotted refs + BARE refs
resolved exactly as typecheck will (census-unique -> that module; ambiguous ->
nearest-ancestor from the referencing module's containment position; tie ->
load nothing, typecheck stays the loud authority), iterated with the dotted
scan to a joint fixpoint (load_sources_for_entry_with_pool).

Pull discipline (measured, not guessed):
- callable-shaped references only: call position 'name(' (the discriminator a
  census stub cannot provide — fn bodies are stripped, so a 0-arg fn and a
  type alias share a census shape) or a census sig with value params (named fn
  passed as argument); types/variants never pull (census-served at typecheck,
  value tags at runtime)
- test-claim modules never serve as providers (execution roots, not deps; an
  over-pulled quarantined v2 test module red under the entry's view killed an
  unrelated dag witness via its 2-param 'edge' helper)

Also: discovery roster accepts qualified coproduct constructors (the #6869
payload-variant class — arm check + stored decl name use the bare last
segment); .dag authority mirrors for the census layering (04_infer.dag
node-base census refactor + layer fns + census-extra twins, compile.dag
census_only_sources + parse_census_fill_sources) — v1 closure typechecks clean.

Proven by execution: gunbhub GET witness (import-stripped, 60+ typecheck errors
at session start, then runtime no-such-function) now PASSES end-to-end through
claim_batch.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* claim_batch: continue past group resolve failures (counted FAIL rows, exit stays 1) + bare-pull diagnostic trace

Abort-on-first-red truncated the corpus measurement to one red class per run;
a failed group's witnesses now report FAIL and the batch continues. Read-only
GUNBC_BARE_PULL_TRACE=1 prints each bare-name pull edge (file -> name ->
module) for locating over-pull homonyms.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* typecheck: body-scope binders shadow census fn sigs; loader: service-chain pulls, stripped-file scan gate, binder/key-position lexer; census: kernel names never bare-aliased

Root-causes the CI batch-1 + post-floor reds (dual-surface divergence between
the gunbc-compile gate and the cli_run floor/run surfaces):

- ExprCall sig lookup gates on new InferScope.body_locals (let/match/params) —
  nearest-first precedence; a census-unique homonym (v2 lens test fn classify
  -> Optional<Finding>) no longer out-precedes a let callee (refinement.dag
  match scrutinee red: variant not found in Optional + missing Absent/Present).
- Loader pulls service providers via dotted-chain prefixes against the services
  census (cron.Tab.List() -> extdeps.cron; llm.Codex -> extdeps.llm.cli) — the
  stripped import's only remaining edge.
- Name-derived pulls run for import-stripped files only; binder (let/data) and
  key (name:) positions no longer collect candidates — kills the over-pull that
  coupled unrelated runs to review-agent tooling health ('repo', 'row').
- Census bare variant aliases never claim kernel names (overlay_skips_kernel_name
  authority): a lone closure enum declaring Absent hijacked the kernel Optional
  variant on shrunk closures; qualified module.Vname aliases stay.

Verified: whole-tree gate (dag+v2) exit 0; v1 mirror gate exit 0; exact CI
command gunbc run merge_admission_stamp exit 0; gunbhub/refinement/cron
witnesses PASS. .dag authorities mirrored (04_infer, 05_emit).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* loader: normalize source roots for tree lookup (CI absolute-root no-op), pool-census cross-tree fallback, dotted-head data-const pulls; fixtures: restore floor_skip imports; frontier: deletion hunks attribute to the following line

- source_tree_root_of now normalizes roots to workspace-relative before
  comparing: CI's claim_executor passes absolute --source-root paths, so the
  bare-reference loader AND the per-module census underlay silently no-oped in
  CI while working locally — the core CI-vs-local divergence.
- Loader falls back to a whole-pool census on an own-tree miss (same-tree names
  keep priority) so cross-tree bare refs pull their provider (a v2 module's
  gunbc_ci_spec -> dag/gunbc/ci_spec.dag).
- Dotted-chain heads that are never body-bound resolve as bare data-const
  references (gunbc_ci_spec.diff_policy pulls ci_spec.dag); bound heads
  (let repo; repo.x) stay excluded.
- floor_skip fixtures restored to main's import-bearing form (import-only
  diffs; the frontier resolves them through the raw path).
- Deletion-only diff hunks (+L,0) attribute to line L+1 (the gap sits between
  L and L+1), unifying -U0 and with-context semantics; import-block strips
  under a module header no longer false-fire the line-1 fail-closed refusal;
  +0,0 (module line deleted) still refuses.

Verified: fail_closed_edit_before_first_decl green; both whole-tree gates
exit 0; gunbhub/stamp/refinement/cron witnesses PASS; absolute-root control
(CI-shaped invocation) PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* remove temporary free-call probe witness

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* remove temporary serializer probe witness

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* accelerator: de-qualify builtin-intercepted kernel calls + rename float elem twin; output_policy Diagnostic qualify; hardware_selection bandwidth_count nickname dissolved; drop probe

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* corpus residue: de-qualify None compares (orch_if x7, rust_add x3); restore 02_parse+bisect+rust_add imports; native is_empty interp method (bridge parity); revert 3 strip-casualty witnesses; re-stamp 5 ReadsLiveTree

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* Merge origin/main (11 commits: cssl/std_dup, belt 2b, shell-intent P0/P1); conflicts resolved main-side for strip-only files; module_path field re-applied at 4 new TypeEnv sites

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* 6848: revert os_systemd_witness_test to main (sweep-qualified refs made SystemdUnitStatus a stale roster entry); drop tmp probe

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* 6848: drop tmp probe plan

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* 6848 cleanup: revert cli_run advisory-batch + governor width-seed hacks to main (operator will rework separately); restore provenance/diagnostic std import blocks (occurrence_id executor-surface fix)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* cleanup: remove GUNBC_FLOOR_INITIAL_WIDTH governor seed again (auto-committer re-captured it during a scratch build); param-leak fix: build_type_env param_bindings excludes body-carrying fns (module-wide value-param Tv leak, main-parity restored); ToolResultText fixture to positional authority shape

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* regen convergence round: emitter lowers Present/Absent with unknown parent to Some/None (both pattern twins, dag+seed mirror; bare variant pattern was never-valid Rust); algebra_method_template_name homed beside AlgebraProfile in dag/std/algebra.dag (was cross-module bare ref in 04_lookup, emit-unqualifiable); compile.dag imports reconcile_with_census_extra; presence wall: census-ambiguity may only skip when no local/import binding resolves the shape (absorbing-skip fix, 04_infer); tests: parse-cache pool-census contract, tier2 census pins to KnownAmbiguous post-triage, module_authority to namespace-only contract; seed restored to 54e24de baseline (auto-committer had captured a broken accept-fresh)

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* regen fixed-point round: split_sig_params sig-typed helper (SigParamSplit) replaces filter/fold idioms the emitter cannot classify over an unresolved receiver; explicit Present wrap at the two census Tv-stamp node_with_inferred sites; CostAccount.time axis spelled at owner Quantity (emitter field-vs-sig variant-as-type-arg fork, note + dissolve trigger); seed = regen_stage0 output, workspace builds clean

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* bare-reference closure: declaration-grain execution-root guard + bound-name filter (review finding 2)

File-grain test-fn skip silently dropped plain-fn providers living beside test rows
(infer_emit_compile_anchor -> anchor_rust_add_emit_accepts died no-such-function at
runtime). Skip is now declaration-grain: only when the resolved name itself is a
test fn / test data row in the provider. Symmetric precision fix on the collector:
plain bare names now subtract the file's own bound set (params, named-arg keys,
let/data binders) exactly as dotted-chain heads already did - lens unit_modeling's
edge param no longer pulls v2.test.manual.ownership_movable (unresolvable src/v1
imports) into unrelated entries. Verified: anchor entry resolves and executes the
cross-file fn; bad pull absent from GUNBC_BARE_PULL_TRACE.

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* test contracts updated to the branch authorities (coproduct wire wall-promotion, reexport control dissolution)

coproduct wire x2: the missing-field presence wall now stops malformed
InternallyTaggedObject literals at TYPECHECK (census-ambiguity absorbing skip closed);
tests assert the typed refusal instead of the decode-time compile_error backstop,
which remains for shapes the literal wall cannot see (bare naming-policy variants).
variant_reexport red control: perturbation dissolved twice over - empty
variant_surfaces+symbol_index resolve via the ancestry global_bare merge, and
dropping the declaring module binds imported names declared-weak (L1 typed-debt
deferral) - converted to purity witnesses + a documented RED-control debt pending
the strict missing-name wall. tier2 census reachability pin (2 AmbiguousBare sites
on extdeps_external_authority_anchor) parked on the non-required rust_tests lane
for post-merge triage.

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* closure: service-backed builtins declare their provider pull (side-effect-import class)

A builtin that dispatches through a service (filesystem_read -> Filesystem.Read)
needs the provider module loaded for its service registration, but contributes no
name any census can resolve - the builtin identifier is the interpreters, not a
modules. Under imports that edge was the name-less import
extdeps.filesystem.filesystem_io; the strip removed it and NOTHING can re-derive it
from names. This is the one genuine hole in the name-derived closure story, and it
is now a declared table (BUILTIN_REQUIRED_SERVICE_KEYS) resolved through the same
services census a dotted service head uses. Rows mirror the interpreters hard
service REQUIREMENT gates only; the optional ones (Clock.UnixSecs, shell.Env.Get)
fall back to a transport and create no closure obligation. A missing row never
fabricates - the builtins own gate still refuses, typed and located, which is
exactly how this row was found (CI 29722434993 batch 3, via interp_recorded_fixture
nested replay). Verified: closure 1 module -> 7, witness_read_via_builtin_roundtrip
PASS.

* WIP: 6848 cleanup

* revert an unjustified guard: the variant/standalone homonym mis-emission is PRE-EXISTING, not a regression

An audit flagged the nullary-variant parent stamp for mis-emitting a standalone
struct literal whose name collides with a nullary variant arm of some coproduct
(fn make() -> Standalone emitting Coll::Standalone { a, b }). Reproduced it, then
tested the attribution: with the stamp redirect forced OFF (main-equivalent), the
emission is BYTE-IDENTICAL. The defect lives on the parent_enum/emit path
(lookup_variant_parent_enum feeding ExprRecordLit.parent_enum), which this branch
does not touch - it is pre-existing on main and belongs in its own typed row, not
here. The guard I had added therefore fixed nothing and is reverted; probes
(variant join, fold-lambda join, collision) all recompile clean without it.

* WIP: 6848 cleanup

* restore the type-confusion wall the variant stamp dropped (audit finding, CONFIRMED)

The nullary-variant parent stamp applied unconditionally, so a name that is a
GENUINE top-level declaration AND a nullary variant arm of some coproduct got
stamped as the coproduct. Reproduced with a main-parity control: type Color = Red |
Blue + type Red { hue: Int } + if f { Red { hue: 5 } } else { Blue } -> main REFUSES
(Product(Red) vs Coproduct(Color)); the branch emitted 0 diagnostics and invalid
Rust (Color::Red { hue } on a nullary arm, E0559, plus a duplicate pub struct Red).
My first attribution of this to a pre-existing emit path was WRONG - that probe used
a non-discriminating shape; the paired redirect-disabled control settles it.

Fix reuses the existing single authority rather than adding a second rule: the
redirect now fires only when binding_declares_name is FALSE for the literal's name -
exactly the predicate lookup_type_by_name already uses to decide declaration vs
variant-arm projection (04_env.dag). Both arms verified: the wall refuses again at
main parity, and the motivating variant-join probes (nullary-vs-payload if-join,
fold-lambda join) stay clean. Regen byte-stable, workspace builds, fmt clean.

Audited-by: adversarial workflow wf_cc7dd19e-87e (two independent reproductions).

* WIP: 6848 cleanup

* Revert probe edit: drop the temporary import extdeps.cloud.gcp.gcp restored in credentials.dag while running the gcp_oauth discriminating control (the control was NEGATIVE - restoring the import does not fix the mock-key failure, so the strip is exonerated for that witness)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* Wire strict-tier reference-derived edges into the affected set; delete the widen arm

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: 6848 cleanup

* Split loader and selection edge tiers; fix the precompute regression the shared tier caused

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: 6848 cleanup

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
briansrls pushed a commit that referenced this pull request Jul 20, 2026
…6947)

* Wave C3: retire nbd_proxy_serve shell-script residue after typed host-effect migration.

Core RawLine→Srv3NbdProxyServe migration landed in #6629; this removes the orphaned script path, updates host_standup gap-ledger prose, and aligns the operator runbook with one-shot host_effect_apply (systemd transient units).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Align srv3_os_install_actuate scope note with held-session nbd_proxy_serve model.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix compile-clean Secret/String mismatch on token response types.

StsTokenResponse and TcgplayerTokenResponse still declared access_token as
String while their service output mappings already project Secret; align
the type definitions so optional_impersonation and tcgplayer consumers
typecheck (unblocks dag_compile_clean_gate_passes on CI).

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls pushed a commit that referenced this pull request Jul 20, 2026
…6947)

* Wave C3: retire nbd_proxy_serve shell-script residue after typed host-effect migration.

Core RawLine→Srv3NbdProxyServe migration landed in #6629; this removes the orphaned script path, updates host_standup gap-ledger prose, and aligns the operator runbook with one-shot host_effect_apply (systemd transient units).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Align srv3_os_install_actuate scope note with held-session nbd_proxy_serve model.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix compile-clean Secret/String mismatch on token response types.

StsTokenResponse and TcgplayerTokenResponse still declared access_token as
String while their service output mappings already project Secret; align
the type definitions so optional_impersonation and tcgplayer consumers
typecheck (unblocks dag_compile_clean_gate_passes on CI).

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant