Repository navigation
namespace wave 1: containment-tree resolution — layered census + name-derived loader (salvage) - #6848
Merged
Merged
Conversation
# Conflicts: # dag/gunbc/falsifier_workflow.dag # dag/test/claim/typed_witness_invocation_test.dag # dag/tools/merge_admission_gate.dag # src/v2/compiler/03_normalize.dag # src/v2/compiler/body_lowering_fold.dag # src/v2/lens/duplicate_computation.dag # src/v2/test/claim/self_host/wave1_gate1_a1_symbol_index_body_producer_witness_test.dag
… (194 -> 180) A value typed by a census-resolved fn sig carries its ANNOTATION nominal (the qualified name as written), not a resolved structure. expand_scrut_from_decl returned generic PRODUCT decls unexpanded (else-arm scrut_node), so record destructures over such values fell through name comparison (dotted scrut name vs bare ctor) into VariantNotFound — the UpsertClassification x14 family. The generic-product arm now instantiates the decl's fields with the use-site args (same substitute_type_slots the alias arm uses); record_destructure compares the scrutinee's base name (qualified_last_segment) so unexpanded dotted nominals still destructure. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls
force-pushed
the
namespace-wave1-reland
branch
from
July 18, 2026 14:11
40b72ad to
2d005ed
Compare
This reverts commit 485853c.
…ent-alias grounding (180 -> 154) TypeMismatch family root: nominal_call_arg_brand_mismatch compared authored name STRINGS, which broke two ways post-strip. (1) A qualified spelling on one side (extdeps.github.pulls.PullRequest formal vs PullRequest actual — the same decl) read as a brand conflict: names now compare by qualified_last_segment, which exactly restores pre-strip precision (bare-vs-bare). (2) Transparent primitive aliases (Timestamp = String) are brand-ERASING by design (is_transparent_primitive_alias_rhs), but census-path resolution grounds one side to the kernel type while the other keeps its authored spelling; a new brand_grounds_transparently_to exception treats a brand as equal to the kernel type its alias grounds to (both directions). kernel_value_declared_type_mismatch gets the same last-segment normalization. GUNBC_ARG_PROBE/GUNBC_PEEL_PROBE env-gated probes added (inert; removed before the re-land gate). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
# Conflicts: # dag/gunbc/srv3_install_media_fetch.dag # dag/std/effects.dag # dag/test/claim/effects_witness_test.dag # src/v2/std/effects.dag # src/v2/test/claim/create_if_absent_double_init_witness_test.dag
…iner dispatch Burndown 154 -> 149 (whole-tree compile-clean, honest corpus), net of the qualify-on-borrow landing (181 peak at the raw seed mirror): - type_name_compatible (00_core): both-dotted -> exact path equality; mixed bare/dotted -> last-segment (pre-migration precision, end-state precision when both sides qualify). Wired into node_type_compatible fallback, node_type_equals_core (all name arms), prefer_specific_type (join keeps the structured side over a name-compatible bare leaf). - module_path_segments + qualified_last_segment moved 04_env -> 00_core (single authority; 04_env re-exports for existing importers). - Container dispatch is qualification-invariant: canonical_template_name, is_declared_container_alias_spelling, node_is_set_collection normalize via qualified_last_segment before the container_template_algebra table (std.types.Map IS Map; -4 InternalError). - medium_fidelity_witness_test: qualify the 4 Medium<...> return annotations (bare Medium is census-ambiguous from test.claim.* -> correct tie-refusal; the D2 pass had qualified ctor heads but not annotations). - Probes GUNBC_VNF_PROBE / GUNBC_SIG_PROBE added (env-gated, removed before the reland gate). Known residue (measured, tracked): std.computation kernel_algebra_profile |> get pair (2, method-path, next lane); std.fermi |> first pair is pre-existing (visible pre-154); reference_deps generic-param leak family morphs (T-field rows). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Root cause was the inverse of the working theory: the 8 missing names
(nbd_proxy_serve_script, nbd_proxy_serve_program_statement_count,
nbd_proxy_serve_program_foreground_command_is_websocat,
nbd_proxy_serve_bash_emit_dissolution_trigger, install_media_fetch_script,
os_install_actuator_toolchain_ensure_script{,_uses_github_release_not_apt_for_websocat},
os_install_actuator_toolchain_ensure_is_privileged_gated_for_apt) were
deliberately deleted on main by the Shell->dag migration (#6587 8f57815,
#6596 c8169ef, #6629 9ffeb27, all ancestors of merge-base c2859a6),
with their consuming tests updated in the same PRs. The strip re-apply
(ab44ec2) clobbered 6 consuming files back to pre-migration content,
leaving dangling references. Re-adding the old decls would resurrect the
terminally-deleted bash sidecar (e06ea6a, operator ruling 2026-07-18).
Fix: restore the 6 consuming files to their merge-base c2859a6 content
(identical to merged-main tip 14c8d29), minus import blocks, plus the
8 qualification lines D1/D2 precedent requires (std.disposition.Terminal,
3x std.resources.Network, 3x gunbc.srv3_nbd_proxy_serve_intent.*,
extdeps.bmc.webui.nbd_proxy_serve.srv3_nbd_proxy_local_port).
Histogram: TOTAL_HARD 149 -> 136 (-13 = exactly the family sites);
all 8 family NAME rows gone; zero new SITE rows (site-level diff clean;
8 new NAME-table entries are top-50 truncation backfill, present as
baseline sites in untouched files).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ure unification 149 -> 123 whole-tree; witness roster 299 -> ~10 fatal. Two independent roots, one class: the strip re-apply (ab44ec2) resurrected pre-migration file content that main had since consolidated — a silent census poison (§3 forks by resurrection). - src/v2/std/algebra.dag: take main's (#6715 dissolved the v2 algebra tower onto std.algebra; the branch carried the old stacked fork, so flat literals in diagnostic/nat/logic refused, and after the first restore the stale stacked CONSUMERS integer.dag/seed_debt flipped red — both now main's). - src/v2/lens/{effect,idempotency,ownership,parallelism}.dag: take main's (lens-commons consolidation into algebraic_composition.dag; the branch had hand-cemented stub forks like `type EffectClassification {}`). - Cherry-pick a6e9f4f9cd: nbd/actuate/toolchain family — the 6 consuming files restored to merge-base-minus-imports (the decls were deliberately deleted on main by the Shell->dag migration; full provenance in that commit body). -13, exactly the family. - cli_run: extend_with_reference_closure extracted — the ONE reference- closure authority now serves BOTH the whole-tree walk and the per-entry claim/witness loader (was a §3 fork: the roster path missed reference-only deps entirely). - find_witness_project_to_core_controls + derivable_coercion_task_id: qualify one dotted reference per foreign module (Rule-1: references ARE the dep edges; a bare-only file has no closure) + Named->v2.std.node.Named (non-unique variant). Witness file 298 errors -> 5 (owned families). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…option (123 -> 89)
From the residue-classification agent's bucket list (all census-verified):
- Bucket (a) source qualifications: merge_admission Success/Failure ->
extdeps.github.checks.* (the borrowing-module alias path), review/review_codex
state Open -> extdeps.github.pulls.Open, upsert Absent (builtin-Witness
collision), srv3_install_media Present{observed_sha256} (bare Present hit
builtin Witness.Present), roadmap authored() -> gunbc.roadmap_authority
(nearest-ancestor picked the test sibling by design; source must qualify),
01_tokenize Empty/None/Accepted/Rejected -> std.algebra./v2.std.diagnostic.*,
coverage + grammar_coverage Empty.
- Bucket (b) stale strip-era copies -> origin/main content minus imports:
fleet_converge_cli (ProvisionBuildCache arm), falsifier_workflow test
(cadence rename + semantics), host_build_cache_provision test (rewritten on
main), behavioral.dag (DeterminismAxis -> std.determinism.Determinism, the
open-thread-E rename the stale hunk had reverted).
- Deliberately NOT qualified (reverted after measurement): 02_parse
OccurrenceIdAllocator/SpanIndex and grammar_coverage DeclFact/
whole_corpus_scope/normalize — those reference edges pull the v2-internals
subtree (occurrence_id/provenance/normalize -> compilers/sugar + standing_intent
closures) into the corpus: +75 latent debts and census uniqueness flips
(Accepted/Rejected aliases). That subtree opens as its own measured batch
with the witness-roster lane (Increment B), not as a side effect.
- env_with_type_variable_bindings extracted to 04_env (consolidates
resolve_item_types' inline type-param fold; no behavior change). The
borrowed-sig resolve-at-borrow experiment was REVERTED after measurement:
per-lookup resolve_node blows up wall-clock (>10min vs 103s) because the
borrower's env lacks the owner's recursive-type facts (FreeMonoid expands to
the depth bound per call). Needs the once-per-module hoist; benched.
Ordering/Equal/Less/Greater rows cleared for free with the algebra-fork
dissolution (previous commit), as the classifier predicted.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ier-invariant (89 -> 82)
Root (get-pair agent, proven by probe chain): the kernel algebra machinery is
keyed on raw canonical spellings ("Map"/"List") at MULTIPLE reads — the
profile lookup (enrich_kernel_type, lookup_structural_method), the
container_param_name table behind make_container_type/make_map_type, the
template-match compare (apply_type_substitution ContainerOf), and
is_container_type/container_expected_arity via receiver_name_str. A receiver
spelled by qualify-on-borrow (std.types.Map) or alias-expanded to its carrier
(FreeMonoid, std.algebra.FreeMonoid) sails past the invariant classifiers and
misses these reads; the method-pipe fallback then absorbs the miss by
returning the receiver type, surfacing two hops later as VariantNotFound
Present/Absent (std.computation kernel_algebra_profile |> get; std.fermi
|> first — the latter pre-existing with bare FreeMonoid).
Fix: container_kind_canonical(name) = last-segment, then carrier->canonical
inversion DERIVED from container_template_alias_rows (sorted fold, no minted
table) — applied at the profile lookup (kernel_profile_lookup) and every
authored-name entry into the kind-keyed tables. The interim
missing-kernel-container-profile guard rows this exposed (+66 at the halfway
point) confirmed the reads were reachable and are now all green.
Benched follow-up (own increment, own receipt): the method-pipe fallback's
final else still answers a dispatch miss with the receiver type — an
absorbing fallback to convert to a typed refusal; every currently-absorbed
miss becomes a counted diagnostic.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Jul 21, 2026
briansrls
pushed a commit
that referenced
this pull request
Jul 21, 2026
…ortcut Fix axis 2b from the #6848 floor-memory diagnosis (docs/plans/floor-memory-pool-parse-regression-diagnosis.md section 9): reconcile_with_typed_cache built build_symbol_index_for_reconcile — whose pool_qualified_fill pays the whole-pool census parse (~2,255 modules per process, parse TIME still paid after #6956's heads-only retention fix) — BEFORE try_reconcile_all_cache_hits, so even an all-hits entry paid the full census. The shortcut consumes no symbol index (its signature takes only the closure modules/names, source indices, and the index caches), so the build moves after the early return: all-hits entries — the warm single-process case, and cold gunbc children whose closures fully hit the typed/cross-process caches once subject digests stabilize — skip the census entirely; genuine misses build it exactly as before. Deliberate behavior note: previously an all-hits entry still refused if ANY pool file failed the census parse (coupling an entry to the health of modules it never executes — the same over-coupling the bare-closure doc comment calls out as measured over-pull); tree-wide parse health is the compile-clean gate's own job (floor batch 1), so the all-hits path passing without the census is the correct decoupling, not a lost check. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XZDbzW6ev1wqgfiQYgRUGD
briansrls
added a commit
that referenced
this pull request
Jul 21, 2026
* Delete per-occurrence advisory(typecheck) stderr flood from the floor Every UnlistedImportUse advisory in the discovery corpus was streamed as its own stderr line (log_discovery_advisory_typecheck), which at current corpus scale floods CI job logs with thousands of lines per floor pass (observed live on PR #6927's run) and pays Actions log-streaming overhead for zero gate signal. Operator ruling (2026-07-21): a prior silencing attempt failed; delete the printing path entirely, not aggregate. This removes the printer fn and its two call sites only — UnlistedImportUse keeps its non-blocking advisory classification (is_discovery_corpus_blocking_diagnostic and the DiscoveryCorpusAdvisory gate are untouched), and the diagnostics are still collected in typed.diagnostics for census-side consumers (resolution_divergence_census, namespace import-closure witness). No script, workflow, or .dag consumer parses the deleted stderr format (checked before deleting). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XZDbzW6ev1wqgfiQYgRUGD * Fix floor OOM-137: calibration/skip counts at loader grain, not full resolve #6938's 'Align calibration closure count with resolved-module grain' made collect_both_closure_module_names_for_entry run the full resolve_entry_with_index_for_discovery_corpus per entry. Since the calibration site calls it for EVERY roster row before the drain, and both skip-before-resolve paths call it for every skipped row, every floor run — including scoped PR runs whose point is eliding cold resolves — resolved the entire roster on the width-1 pump thread and retained every resolved graph co-resident in the uncapped resolved_graph_memo. Receipts: scoped green floors went ~17.3GB peak / 31m to >=38.4-38.5GB censored peaks with exit-137 SIGKILLs mid-batch-2 (runs 29827692954, 29829512709), and #6938's own run swap-died on a clamped runner (16.1GB + 32GiB swap exhausted, batch1+2 wall 11.4m -> 44.9m, resolved_memo_peak 101 -> 649 at identical witness counts, run 29824062620). The #6972 typed-cache drain fired 1,500+ emergency evictions in the killed runs without arresting growth because the retention lives in resolved_graph_memo, which has no cap. Fix: count the closure at the LOADER grain — load_sources_for_entry_with_pool (the exact both-closure fixpoint source set resolve_entry_with_parse_cache starts from) mapped to authored module names via extract_module_path. No parse, no typecheck, nothing installed in resolved_graph_memo, and the skip path's 'cold entry resolve elided' claim is true again. The definition-drift oracle keeps its teeth: pre-side = what the loader produces, post-side = what resolve actually loaded, so a loader fork or seeding change still refuses loudly — #6938's fix collapsed that oracle into resolve==resolve identity, which could never fire. The 261-vs-260 drift #6938 fixed stays fixed: the loader union includes the bare/census- derived modules the old import-only walk could not see. A headerless source in the pool now refuses with a located error rather than undercounting. Discriminating test: this PR's own CI floor — pre-fix main floors die at ~38GB or hang; with this change the floor should complete in the ~17GB class again. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XZDbzW6ev1wqgfiQYgRUGD * Axis 2b: build the reconcile symbol index after the all-cache-hits shortcut Fix axis 2b from the #6848 floor-memory diagnosis (docs/plans/floor-memory-pool-parse-regression-diagnosis.md section 9): reconcile_with_typed_cache built build_symbol_index_for_reconcile — whose pool_qualified_fill pays the whole-pool census parse (~2,255 modules per process, parse TIME still paid after #6956's heads-only retention fix) — BEFORE try_reconcile_all_cache_hits, so even an all-hits entry paid the full census. The shortcut consumes no symbol index (its signature takes only the closure modules/names, source indices, and the index caches), so the build moves after the early return: all-hits entries — the warm single-process case, and cold gunbc children whose closures fully hit the typed/cross-process caches once subject digests stabilize — skip the census entirely; genuine misses build it exactly as before. Deliberate behavior note: previously an all-hits entry still refused if ANY pool file failed the census parse (coupling an entry to the health of modules it never executes — the same over-coupling the bare-closure doc comment calls out as measured over-pull); tree-wide parse health is the compile-clean gate's own job (floor batch 1), so the all-hits path passing without the census is the correct decoupling, not a lost check. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XZDbzW6ev1wqgfiQYgRUGD --------- Co-authored-by: Claude <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Jul 21, 2026
…7001) * Diagnose whole-tree compile-clean time: memory-thrash, not compute. Execution-proven bisect pins #6848 pool_parse as the reconcile RSS driver (1.35→4.2GiB step); confirms compile-clean is ~3min on fleet but whole-floor batch-2 accumulation thrashes at 15GiB memory.high. Adds repro script. Co-authored-by: Cursor <cursoragent@cursor.com> * Link compile-clean time diagnosis into stability thread (orphan-doc hygiene). Inbound links from v1-run-stability-throughline and DESIGN open-thread so the new diagnosis doc passes doc reachability. Co-authored-by: Cursor <cursoragent@cursor.com> * Revert hand-edit to generated DESIGN.md (drift-gate hygiene). Orphan-doc reachability is satisfied by the inbound link from v1-run-stability-throughline.md alone. Co-authored-by: Cursor <cursoragent@cursor.com> * Add SCAFFOLD dissolve-on header to compile-clean profile script. Matches profile-cold-resolve.sh hand-shell gate: names retirement via realization_measurement_loop carrier and bash-emit #5828 modeled transport. Co-authored-by: Cursor <cursoragent@cursor.com> * Acknowledge shell-gate interim: transport dissolve-on only, .dag intent owed. Per review 40781 (non-blocking): document that the profile harness is an acceptable locate-only interim while .dag profile orchestration is still missing. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ci): move profile harness under docs/ to preserve floor skip scripts/profile_whole_tree_compile_clean.sh triggered the selectable-universe guard (non-docs path), forcing whole-tree batch-2 and OOM (exit 137) on srv3. Relocate to docs/scripts/ so this docs-only PR keeps documentation_only_skip. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls
added a commit
that referenced
this pull request
Jul 21, 2026
…erialization_carriers, program_assembly, source_authority, 02_parse, 03_ingest) refuse with UNRESOLVED_CompilerError in curated probes — census + receipts in #6872 TSVs (calm-boar-697). Read the actual probe error output per module (#6986) * Gate-A flip prep + Measure nested-generic emitter fix (rebased on main) Rebased session/neat-swift-795-flip-prep onto origin/main: drop superseded module-identity/integration history already landed via #6866; retain flip infrastructure (frontier 6→12 SelfEmitted, wet enrollment, behavioral transports/shims), Measure emitter generic-env threading (EmitGraphInfo fn_generic_param_names/fn_type_env, fold lambda param_nodes, container child recursion gated to generic-fn context), stage0 regen, and nested List<List<Measure>> emit witness. PR #6881 remains draft until sign-off receipts complete. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix PR #6881 CI: exclude wet behavioral receipts and repair census gates. Hermetic discovery was running the three new self-host behavioral witnesses (shell.Mktemp.Dir has no mock); add them to witness_exclusion_substrings like the other wet receipts. Discharge Band-A OtherGate rows when the frontier module is already SelfEmitted. Rename nested-fold witness so its stem covers the new v1 emit test module for the migration-debt ratchet. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: unresolved_compiler_error diagnosis + fix: 6 modules (00_compile, materi * WIP: unresolved_compiler_error diagnosis + fix: 6 modules (00_compile, materi * Revert unrelated effect-namespace-grants.md collateral from Gate-A PR. Restore origin/main section 6 (FLAG A interim): workspace Read grant, ownership-implies-read note, and PR-1/PR-2 LANDED paragraphs. The hunk was accidental doc drift with no tie to the flip or emitter work. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: unresolved_compiler_error diagnosis + fix: 6 modules (00_compile, materi * Add Measure sign-off POST-fix 6-module probe receipt TSV. Documents hash-verified gunbc rebuild probe results for the flip-wave baseline: emit 0-diag on all six, cargo at named next layers (std_dup on 5/6; materialization_carriers E0433 deferred per operator routing). Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: unresolved_compiler_error diagnosis + fix: 6 modules (00_compile, materi * WIP: unresolved_compiler_error diagnosis + fix: 6 modules (00_compile, materi * WIP: unresolved_compiler_error diagnosis + fix: 6 modules (00_compile, materi * WIP: unresolved_compiler_error diagnosis + fix: 6 modules (00_compile, materi * WIP: unresolved_compiler_error diagnosis + fix: 6 modules (00_compile, materi * WIP: unresolved_compiler_error diagnosis + fix: 6 modules (00_compile, materi * Fix PR #6881 CI: regen verify gate + stage0 infer sync. Remove duplicate empty_type_env fallout from stage0 infer emit drift, and normalize rustfmt-only diffs in regen_stage0 verify so workspace cargo fmt and fresh self-compile compare cleanly. Co-authored-by: Cursor <cursoragent@cursor.com> * ci: retrigger after regen verify + cargo fmt fix (44b23d6). Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: unresolved_compiler_error diagnosis + fix: 6 modules (00_compile, materi * frontier: sync stage0 crate layout after honest SelfEmitted baseline revert (12→6). Regenerated stage0_crate_layout_generated artifacts to drop the six prematurely-flipped modules from hand-maintained pub mod / filename rosters now that frontier.dag marks them SeedRetained again. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(frontier): restore sweep-order monotonicity after honest revert. Re-sort compiler_frontier_sweep_order after SeedRetained revert changed tractability ranks (materialization_carriers/program_assembly → NameResolutionGap band; 00_compile → EmitSurfaceGap). Fixes compiler_frontier_census_composite_test CI failure on #6881. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: unresolved_compiler_error diagnosis + fix: 6 modules (00_compile, materi * fix(frontier): align reverted behavioral transport docs with honest refresh. Six reverted-module transport docs now cite SeedRetained / honest_frontier_refresh_probe_note instead of stale "flip landed" prose. Remove three flip-wave seed stubs (parse/ingest/materialization_carriers) that were never wired into the frontier-derived crate layout. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Gate-1 emit regression (post-#6848): the Rust emit target renders namesp * WIP: Gate-1 emit regression (post-#6848): the Rust emit target renders namesp * emit_imports: field-struct import synth asks "provides", not "physically defines" An anonymous record literal takes its type from the FIELD it initializes, so the constructed type name appears nowhere in the source and can never sit in an authored import list. emit_imports derives use-lines only from import lists, so the emitted Rust refused: E0422 cannot find struct ... in this scope. module_data_field_struct_import_names gated candidates on has_physical_type_def_in_module_filename — field type PHYSICALLY DEFINED in the module being imported from. That is narrower than the question being asked. compile_stage_memo imports CacheInterfaceCatalogFacts from extdeps.cache.types but its io/placement field types are defined in the SIBLING modules extdeps.cache.catalog_io / catalog_placement and merely re-exported, so they were rejected and no use-line was synthesized. Now uses name_in_transitive_export_surface, the existing authority for "does this module provide this name" (get_exported_names counts specific-import names as exports, which is exactly re-export) — reused, not re-minted. Routing needed no change: graph_type_import_module_filename already groups emitted use-lines by the type's DEFINING module. export_sets is threaded as a parameter rather than rebuilt inside the filter, which would have been a per-field quadratic cost-shape defect. Verified by execution, both halves: regen_divergence_count=0 (two-stage bootstrap; stage 2 with the new emitter LIVE over the whole import-BEARING seed, which is the run that counts) materialization_carriers first error advanced CacheInterfaceCatalogIoSemantics -> CacheEvidence Known residue, documented in-code not hidden: a generic field type (evidence: List<CacheEvidence>) still misses, because build_field_type_map stores only the type node's HEAD name, so CacheEvidence is absent from field_type_map entirely and no string-level test can recover it. Distinct axis, separate increment. Honest frontier refresh (receipt must match measurement, independent of any flip): 01_tokenize / 04_infer / program_partition were recorded as import_closure but all three now MEASURE as the dotted namespace-qualified render class; rows corrected. Flip wave produced ZERO flips — 4 of 5 probed modules refuse on the dotted class, which is emitted into std.collection itself and so sits in every deep closure. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: unresolved_compiler_error diagnosis + fix: 6 modules (00_compile, materi * WIP: unresolved_compiler_error diagnosis + fix: 6 modules (00_compile, materi * emit_imports increment-2: recurse field-type node tree for import surface names. build_field_type_map now walks resolved generic/container argument nodes so List<CacheEvidence> contributes CacheEvidence to field_import_surface_names, not just the List head in field_type_map. emit_imports field-struct synth consumes the expanded surface list (rides on #6981 sibling-axis machinery). Oracle: materialization_carriers first cargo error advances past CacheEvidence E0422 (verified via cssl probe + emitted use of std_cache_interface::CacheEvidence). Co-authored-by: Cursor <cursoragent@cursor.com> * docs(emit_imports): refresh provider note after increment-2 generic axis. Replace stale KNOWN RESIDUE paragraph claiming CacheEvidence still misses — increment-2 now walks the resolved field-type node tree into field_import_surface_names. Update frontier_probe_types receipt to record materialization_carriers advancing past CacheEvidence E0422. Co-authored-by: Cursor <cursoragent@cursor.com> * ci: cargo fmt for increment-2 stage0 + test module ordering. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: unresolved_compiler_error diagnosis + fix: 6 modules (00_compile, materi * Regen stage0 infer_emit_info seed after main merge (#6983). Post-merge regen_stage0 --verify reported regen_divergence_count=1 (v1_compiler_infer_emit_info.rs stale vs live emitter). Re-emitted seed; verify now regen_divergence_count=0. Co-authored-by: Cursor <cursoragent@cursor.com> * Regen std_measure seed after main merge (#6991 measure.dag). Post-merge regen_stage0 --verify reported regen_divergence_count=1 (std_measure.rs; main's measure.dag delta, not #7002 cli_run). Re-emitted; verify now regen_divergence_count=0. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Jul 21, 2026
briansrls
added a commit
that referenced
this pull request
Jul 21, 2026
briansrls
added a commit
that referenced
this pull request
Jul 21, 2026
…ly defines" (+ honest frontier refresh, zero flips) (#6981) * WIP: Gate-1 emit regression (post-#6848): the Rust emit target renders namesp * WIP: Gate-1 emit regression (post-#6848): the Rust emit target renders namesp * emit_imports: field-struct import synth asks "provides", not "physically defines" An anonymous record literal takes its type from the FIELD it initializes, so the constructed type name appears nowhere in the source and can never sit in an authored import list. emit_imports derives use-lines only from import lists, so the emitted Rust refused: E0422 cannot find struct ... in this scope. module_data_field_struct_import_names gated candidates on has_physical_type_def_in_module_filename — field type PHYSICALLY DEFINED in the module being imported from. That is narrower than the question being asked. compile_stage_memo imports CacheInterfaceCatalogFacts from extdeps.cache.types but its io/placement field types are defined in the SIBLING modules extdeps.cache.catalog_io / catalog_placement and merely re-exported, so they were rejected and no use-line was synthesized. Now uses name_in_transitive_export_surface, the existing authority for "does this module provide this name" (get_exported_names counts specific-import names as exports, which is exactly re-export) — reused, not re-minted. Routing needed no change: graph_type_import_module_filename already groups emitted use-lines by the type's DEFINING module. export_sets is threaded as a parameter rather than rebuilt inside the filter, which would have been a per-field quadratic cost-shape defect. Verified by execution, both halves: regen_divergence_count=0 (two-stage bootstrap; stage 2 with the new emitter LIVE over the whole import-BEARING seed, which is the run that counts) materialization_carriers first error advanced CacheInterfaceCatalogIoSemantics -> CacheEvidence Known residue, documented in-code not hidden: a generic field type (evidence: List<CacheEvidence>) still misses, because build_field_type_map stores only the type node's HEAD name, so CacheEvidence is absent from field_type_map entirely and no string-level test can recover it. Distinct axis, separate increment. Honest frontier refresh (receipt must match measurement, independent of any flip): 01_tokenize / 04_infer / program_partition were recorded as import_closure but all three now MEASURE as the dotted namespace-qualified render class; rows corrected. Flip wave produced ZERO flips — 4 of 5 probed modules refuse on the dotted class, which is emitted into std.collection itself and so sits in every deep closure. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: Gate-1 emit regression (post-#6848): the Rust emit target renders namesp * emit: route qualified type names through their terminal segment (dotted-render fix) A namespace-qualified name in a type position arrived from authored_name_at as the full dotted spelling (std.algebra.FreeMonoid). Every routing lookup on the alias-RHS path is keyed on the BARE declared name, so a dotted spelling matched nothing, def_mod fell back to the local module, and the else arm rendered the dotted string VERBATIM into Rust: pub type List<T> = std.algebra.FreeMonoid<T>; // invalid Rust rustc reports that as "expected one of !, (, +, ::, ;, <, or where, found ." — a PARSE error, so it masked every later error in the module. Measured blast radius: the emitted 04_infer closure (50 files) contained exactly ONE such line, and it blocked 4 of 5 self-host flip candidates, because std.collection sits in essentially every deep-module closure. The control proving it was qualified-specific is the next declaration: type Set<T> = PointwisePower<T> (BARE) already routed to Rc<crate::v2_std_algebra::PointwisePower<T>>. Fix routes on the terminal segment via v1.std.core qualified_last_segment — the existing authority, not a minted helper: a qualified name IS a containment path and its last segment IS the declared name the registry knows. Explicitly NOT a string dot-to-colon rewrite, which would fabricate a path from the spelling rather than resolve the declaration, and would emit a wrong path whenever the qualifier does not match the defining module. Zero drift BY CONSTRUCTION rather than by hope: qualified_last_segment is the identity on an unqualified name, so every bare name renders byte-identically and only the qualified case changes. Verified by execution, both halves: regen_divergence_count=0 (two-stage bootstrap, stage 2 with the new emitter live) pub type List<T> = Rc<crate::std_algebra::FreeMonoid<T>>; zero dotted type paths remain in the emitted closure Deliberately NOT taken: collection.dag already imports FreeMonoid, so editing that one declaration to the bare name would have turned the chain green in one character. That is the cement anti-pattern — it hides the emitter defect and the next qualified name reintroduces it silently. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * regen: refresh std_measure.rs seed after #6991 measure.dag change Inherited drift, not from this PR. #6991 (59e5cbf, color palette catalogue) added `data percent_from_computed_int_frontier` to dag/std/measure.dag without regenerating the emitted seed, so main carries a stale std_measure.rs. Merging main into this branch inherited that staleness: regen_divergence_count=1 (std_measure.rs). Regenerated from the .dag authority via the two-stage bootstrap (write -> rebuild -> verify); regen_divergence_count=0. The delta is purely additive (9 lines) and is exactly #6991's declaration -- nothing from this PR's emitter changes. neat-swift hit the identical divergence merging the same main into #6986 and resolved it the same way. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * merge main (#6986 increment-2) into 6981; resolve 3 conflicts, regen seed #6986 merged ahead of #6981, so this integrates it. Three conflicts, NOT a clean merge: - src/v1/05_emit_rust.dag and src/v2/compiler/self_host/frontier_probe_types.dag both conflicted on a `data ..._note` describing the generic-argument residue. Mine documented it as OPEN ("deliberately not fixed here"); #6986 CLOSED it (increment 2: build_field_type_map walks the resolved field-type node tree via collect_type_node_import_surface_names, so List<CacheEvidence> now admits CacheEvidence). Took #6986's text on both — mine had become factually wrong. Resolved per-hunk, not per-file, so the rest of the auto-merge survived. - src/v1/stage0/src/v1_compiler_emit_rust.rs is the EMITTED SEED and was NOT hand-merged. Reset to main's known-good copy, rebuilt, then regenerated from the merged .dag via the two-stage bootstrap (write -> rebuild -> verify). A git text-merge of two independently regenerated seeds is not a valid regen. Verified both sides survived: this PR's dotted fix (qualified_last_segment) and emit_imports fix (name_in_transitive_export_surface) are present, and so is #6986's increment-2. regen_divergence_count=0. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Jul 21, 2026
…mo (#6999) * WIP: Floor time regression: bisect the +20min added by #6848 namespace walks * WIP: Floor time regression: bisect the +20min added by #6848 namespace walks * test(floor-time): deferral oracle compares outcomes without requiring Pass The hot-hit vs cold-oracle equivalence test only needs cold==hot; the witness under test may fail for unrelated corpus reasons. Drop the Pass gate and remove the now-unused ClaimOutcome import. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(docs): link floor-time diagnosis into doc graph doc_graph_has_no_orphan_docs failed on the new diagnosis doc — add a backlink from the already-reachable floor-memory diagnosis parent. Co-authored-by: Cursor <cursoragent@cursor.com> * docs(floor-time): clarify axis 2b landed on main via #6998 Diagnosis status line still claimed both fixes in this PR; reconcile deferral is on main, this PR is the entry-closure memo half. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Floor time regression: bisect the +20min added by #6848 namespace walks * fix(extdeps): canonical anchor rows on cited color palettes (#6991) #6991 landed okabe_ito and solarized with module-local authority names; the live clean-tree gate requires extdeps_external_authority_anchor. Rename both rows and qualify catalog provenance references. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com>
2 tasks done
briansrls
pushed a commit
that referenced
this pull request
Jul 21, 2026
briansrls
added a commit
that referenced
this pull request
Jul 21, 2026
#7028) * docs(floor-time): post-#6999 validation read + cap-saturation receipts §5 log-diff compares PRE/POST/POST-FIX batch walls (runs 29763408563, 29819122813, 29855080611): ~0% recovery at batch grain on capped hosts; residual attributed to once-per-entry #6848 fixpoint + governor throttle. design_document.dag open-thread updated (M1 landed). Co-authored-by: Cursor <cursoragent@cursor.com> * fix(docs): regen DESIGN.md after design_document.dag open-thread update Unblocks generated_artifact_drift_gate on PR #7028. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(docs): dedupe §1.4 cross-ref after section renumber §6 is Provenance; cap-saturation residual points to §5.2. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(docs): link emitter residual probe into doc graph PR #7028 CI failed doc_graph_has_no_orphan_docs because docs/probes/emitter_residual_site_map_2026-07-21.md landed on main (#7023) without a reachability edge; add a probe-receipts backlink from rc-ownership-wrap-decision-design.md. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
This was referenced Jul 22, 2026
This was referenced Jul 23, 2026
This was referenced Jul 25, 2026
This was referenced Jul 31, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Merge candidate state (2026-07-19, final round)
Branch-caused CI failures are at zero known root-causes; candidate
e9bd22e82eis the green-candidate CI round. What landed since the salvage summary below:Unit/Cardinality/Namedunresolvables, 5 orphaned strip-era producer fixtures deleted, spice fixture pair, systemd witness (sweep-qualified refs madeSystemdUnitStatusa stale inert-carrier roster entry).import_closurewas double-defined with different signatures (module_graph vs witness_cost_locality); the flat interpreter registry's last-insert-wins dispatch made the winner load-order-dependent — the branch's name-derived loader re-rolled that dice and 8 effect_reach rows died on the losing signature. Renamed towitness_import_closure(6 sites). The class-level fix (dispatch keyed on containment identity, ambiguous bare name = typed refusal) is handed to the operator's dispatch lane with a full inventory (fn emit(is triple-defined; builtin resolution is resolve-group-composition-dependent).artifact_path-on-bare-variant and the two committed-golden script comparisons) — import-block restores fixed both, proven on both surfaces.emit_host_run_transport_cachedbuiltin), the pre-merge local binary red-ed the gate on a builtin it didn't have. Rebuild cleared it — and cleared the 3 rust-emit "slow eval" rows, whose 8–12s FAILs proved environmental (the failing window moves between runs; CI and main's falsifier pass every one of them at ~100–170ms).GUNBC_ADVISORY_ROWS=1restores rows); ~9.8k-row ledger stays the burndown backlog.Reviews waived by operator for this PR (2026-07-19); merge on green CI.
Summary
Namespace wave 1: the containment tree starts serving as the naming authority. Import lists are stripped across the witness corpus (83% of
dag/test/claimand ofsrc/v2now carry noimportlines) and resolution moves to the SymbolIndex census — nearest-ancestor containment walk for bare names, dotted projection for qualified names (namespace-resolution-design.md).The branch spun for ~a week trapped in a big-bang corpus strategy; this is the salvage (operator-approved, session nimble-owl-658 took ownership from quiet-gull-833). The capability work was kept, the corpus strategy was replaced with a layered census that changes no compiled module's baseline meaning:
Fill = whole tree; policy gates lookup, never fill (§7.5): every compile carries the whole pool in the census, but in layers —
GET/Persistent/JsonValuevanished across 28 witness rows);Loader derives deps from names (Rule-1 direction): with imports stripped there are no edges to follow, so witness closures = imports + dotted refs + bare refs resolved exactly as typecheck will (unique → that module; ambiguous → nearest-ancestor; tie → load nothing, the typecheck refusal stays the loud authority). Pull discipline: callable-shaped references only (call position / census sig with params); test-claim modules never serve as providers.
Seed fixes en route: qualified payload-variant construction (infer: qualified payload-variant construction (roster items 1+8) — stamp parent_enum for dotted spellings #6869, merged separately), the same class in the discovery roster, M.mid type-param stamping at field extraction,
lookup_variant_parent_enumdotted fallback.Precedence + loader hardening (root-caused off the first CI round's reds, all reproduced and re-verified locally):
ExprCallsig lookup now gates on body-grain binders (InferScope.body_locals: let / match pattern / params) so a census-unique corpus homonym can never out-precede aletcallee (a v2 lens test'sfn classify -> Optional<Finding>was typing refinement.dag's match scrutinee);overlay_skips_kernel_nameis the single authority; a lone closure enum declaringAbsentwas hijacking the kernel Optional variant on shrunk closures — qualifiedmodule.Vnamealiases stay);cron.Tab.List()→extdeps.cron— the stripped import's only remaining edge), scans only import-stripped files (unstripped files are main-parity; scanning them manufactured over-pull), and skips binder/key positions (let repo,repo:) when collecting candidates.CI-vs-local alignment (rounds 2–4):
source_tree_root_ofnow normalizes source roots — CI passes absolute--source-rootpaths, so the bare loader and the census underlay had been silently no-oping in CI while working locally (the core divergence). The loader also gained a whole-pool census fallback for cross-tree bare refs (same-tree keeps priority) and dotted-head data-const pulls (gunbc_ci_spec.diff_policy). Deletion-only diff hunks attribute to the following line, so import-block strips no longer false-fire the affected-setdiff before first declarationrefusal (module-line deletion still refuses). The original strip-sweep had also deleted thematch: MatchInterpreterfield (not just imports) from 11InterpretationAlgebraliterals across 10 files, and stripped thefloor_skipfrontier fixtures — both restored to main's shape.Frontier + selection hardening (rounds 5–9):
entry_without_declared_edges_never_skips_note): an entry that declares no import/dependency edges is never selection-skippable — with imports stripped its real dependencies are name-derived and invisible to the import-edge model, so a precise "unaffected" answer would false-skip (fail-open cache impurity). Implemented inentry_file_touched_via_import_closure(host) andentry_affected_by_touched_paths(module_graph.dagauthority); the module-grain equivalence receipts + wiring-perturbation control (re-anchored on an import-carrying entry) and all 9dag_compile_clean_scopedisposition witnesses are green. Dissolves when the edge producer swaps to reference-derived resolution facts (thedependency_edge_source_migration_noteswap);resolve_entry_graph(uncached fixed-entry resolve: floor runner, executor plan entries, probes) now routes through the same shared-index loader engine asresolve_entry_graph_shared— the old import-edge walk could not resolve stripped fixed entries at all;CoreNodeat 03_ingest,None/Rejectedpayload rows in inhabitant_neutralization,extdeps.github.github.Userin roadmap_status + 2 more sites — items out-precede variant aliases in the bare census, so the wrong provider pulled);filter/any/contains/…) as a bare fn sig — a census entry for the never-loadedv2.std.algebrawas preempting infer's known-method bridge, typingfilter(xs, f)as a plain call that diedNoSuchFunctionat runtime where main rewrites to the builtin method (proven by main-built claim_batch controls: main bridges the list form, refuses the Int form at typecheck). Single authority = thestd_algebratemplate rows (algebra_method_template_names()), guarded infunc_sig_from_global_bare+global_bare_callable_node, mirrored in04_lookup.dag; loaded providers are unaffected (lookup_resolved_sigruns first). This greened the budget/keyed-delta/membership/gunbhub-keystone witness family;ci_budget_tree.dag(ci_host_overhead_claim,ci_session_pool_bytes): the flat interpreter fn registry is last-insert-wins, so when the name-derived loader put both carriers of the deliberate budget split in one closure, 0-arg callers ran the params-bearing bodies (undefined variable: overhead/active_sessions). Module-keyed dispatch is the namespace lane's terminal wall; the rename is the honest interim..dagauthority mirrors land with the Rust (04_infer node-base census + layer fns + census-extra twins; compile.dagcensus_only_sources+ parse-grade fill front end).cli_run.rsloader/index work is inside the existing HAND-RUST scaffold. The tests-crate helper missed the newCompilePipelineOptions.census_only_sourcesfield (workspace build red) — fixed via functional-update from the default options.Stale-witness-content restores: the strip era froze some witness files at pre-main-landing content (host_standup_spine at eleven steps vs main's twelve with
BuildCacheProvision) — re-took main's content with imports stripped, qualifying genuinely ambiguous bare variants the newer content introduced (std.upsert_decision.Converged; three std enums declareConverged). All 16 standup witnesses green.Stale-drift mass revert (the dominant red class, ~25 of 32 counted CI reds, one root): main REVERTED the Namespace integration branch: collapse strip PRs #6603 #6600 #6607 #6610 #6611 #6612 #6613 #6622 into one draft integration branch/PR on main; atomic Wave-1 landing target; close/supersede individual strip PRs; hold draft until G1+(c) then single rebase+merge #6640 strip-integration branch (Revert #6640 Wave-1 namespace strip — restore main to green #6847,
f355b134c3, 1633 files) and this branch's merge of that revert auto-resolved to the branch side — silently keeping Namespace integration branch: collapse strip PRs #6603 #6600 #6607 #6610 #6611 #6612 #6613 #6622 into one draft integration branch/PR on main; atomic Wave-1 landing target; close/supersede individual strip PRs; hold draft until G1+(c) then single rebase+merge #6640's frozen file bodies wherever the strip era had touched a file (pre-TargetText 06_translate char-exploding the emit serializer; pre-Body-emit Track B next slice: continue #6840 (general body producer, Stage B cross-decl) toward the 12 emit-shape-gated tail modules; re-probe after the slice converts refusals to flips #6859 rust.dag/dag.dag emit rows; the node_content_hash split main had re-inlined; stale commit_workflow enrollment rows; ...). Mechanical classification: (1) byte-equal to the pre-revert state where the revert changed the file; (2) body-vs-main modulo imports — body-identical = strip-only (KEPT, 864 files, the deliverable); body-drifted = stale (re-taken from main, 479 + 38 layered files); (3) qualify-normalized diff direction separated sweep-qualify layers (kept) from true staleness.node_content_hash.dagdeleted (main homes content_hash inv2.std.node; 12 importers reverted with it). Post-revert: whole-tree gate exit 0 / 0 hard rows (advisories 2206 → 1977 as ~500 files regained imports), and the entire serializer red family (orch emit goldens, fleet_converge, ci_yaml keystone, ci_deploy, floor_materialization ×6, live_deploy, bmc, host_standup ×16, falsifier, artifact-drift, gunbhub) went green by execution.Post-revert residue, each a typed class with an executed fix: (1)
Diagnosticitem-out-precedes-variant (theUserclass) — witness qualified; (2)bandwidth_countflat-registry homonym — the local nickname deleted (§3); (3) qualification changes builtin interception (new sweep hazard): qualifiedcontiguous_loop_elementwise_kernelcalls missed the interp's bare-name builtin and executed the pure-dag seam1/0— de-qualified, rule recorded; (4) int/float twineval_relu_mul_add_elem_at_index— float twin renamed after an instrumented eq-walk exposed mixed-representation output ([Int 7, Int 6, Float 0.0, Float 0.0]prints as the golden but fails== 0); (5) sweep-qualifiedNonecomparisons (dg == v2.std.diagnostic.None) construct a Variant where bareNoneisValue::Null— silently false; de-qualified (7 orch_if + 3 rust_add sites); (6) the CI discovery abort (no field 'expression' on type 'Holds'): the long/ bisect entry needed imports-from-the-declaring-module (strict re-export), a nativeis_emptyinterp method (bridge parity), and 02_parse's import block restored (bareTokenambiguous in the witness-closure census); (7) three strip-casualty witnesses (sol_console/string_cast/types_arch — the last one a hermetic-capability import the strip removed) reverted to main.Measured state
--target daggate): GREEN — 0 hard diagnostics (was 29 v2.* cross-tree rows at salvage start, 411 at branch peak). 2206UnlistedImportUseadvisories render now that the gate passes — pre-existing non-gating burndown class, grown by design as imports strip.orch_emit_join2now emits clean).gunbhub_serve_witness_test(import-stripped; 60+ typecheck errors and a runtimeno such functionat salvage start) PASSES through claim_batch.Known debt (typed, tracked)
field_of_type_vardeferral (generic payload interiors never typechecked — pre-existing on main, surfaced by this work).UnlistedImportUseburndown + qualify-now worklist stay the namespace lane's follow-ups.Test plan
gunbc compile --source-root dag --source-root src/v2 --dependency-pool-index primary-precedence --target dag→ exit 0, 0 hard diagnosticssrc/v1 + dag(mirror closure) → exit 0gunbc run --source-root dag --entry dag/tools/merge_admission_stamp.dag --function main→ exit 0 (was red: undefinedcron/llm, PositiveInt mismatch)refinement_ordered_iteration(the CI batch-1 red),cron_tagkeystone → all PASSclaim_batch --roster-from-discoveryfull corpus (two processes): 1454 PASS / 149 FAIL — both halves OOM-killed near their tails, so a floor on the true totals. FAIL histogram: 66contains-on-Variant type errors (main's known null-RED deploy/serializer debt), 40no such function(fn-registry residue: value-position refs the pull discipline doesn't cover), 6 undefined-variable, 2 each non-exhaustive/division-by-zero, plus orch/verdict smoke rows--source-root $PWD/dag …, the CI-shaped invocation) → PASScargo build --releasegreen;fail_closed_edit_before_first_decland diff-attribution unit tests green;cargo fmt --allapplied