Skip to content

Body-emit Track B next slice: continue #6840 (general body producer, Stage B cross-decl) toward the 12 emit-shape-gated tail modules; re-probe after the slice converts refusals to flips - #6859

Merged
briansrls merged 3 commits into
mainfrom
session/wise-bee-713-stage-b-projection-lens
Jul 18, 2026

Conversation

@briansrls

@briansrls briansrls commented Jul 18, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Stage B cross-decl for #6840 / Track B: fold-family calls desugar to seam Loop before generic Transform lowering (body_lowering_fold.dag), and the accumulator-copy lens walks lowered Loop/Transform substrate plus surface postfix projection calls (helper.step) so carrier classification is fail-closed inside ingested fold bodies (projection_call_carrier_is_classified).

Test plan

  • claim_batch --source-root src/v2 --source-root dag --entry src/v2/test/claim/long/accumulator_copy_fold_analysis_test.dag — projection + fold regression witnesses PASS locally
  • CI floor (pending on latest push 8c1cfdbe9)

Long-lane witness completion receipt (8c1cfdbe9)

Moved wave1_gate1_a1_projection_call_witness_test.dag from self_host/ → long/ because tokenize→parse→normalize exceeds the 5s per-PR discovery cap (~10s). Re-laning requires a green completion run, not just a timeout:

claim_batch --source-root src/v2 --source-root dag \
  --entry src/v2/test/claim/long/wave1_gate1_a1_projection_call_witness_test.dag \
  --functions wave1_gate1_a1_projection_call_lowers_witness_holds,wave1_gate1_a1_projection_call_normalize_accepts_witness_holds,wave1_gate1_a1_projection_field_access_refuses_witness_holds
PASS wave1_gate1_a1_projection_call_lowers_witness_holds          (~10608ms)
PASS wave1_gate1_a1_projection_call_normalize_accepts_witness_holds (~10589ms)
PASS wave1_gate1_a1_projection_field_access_refuses_witness_holds (~10631ms)
[resolve-summary] 1 resolve(s) in 3296ms; 3 witness(es) in 31828ms

Scope wall: no emitter (05_emit_rust.dag) changes in this PR.

…projections.

Reorder body lowering so fold-family calls desugar to seam Loop before generic
Transform lowering; extend the accumulator-copy analyze walk with lowered Loop/
Transform arms plus surface postfix projection classification (helper.step).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot
gunbai-bot Bot force-pushed the session/wise-bee-713-stage-b-projection-lens branch from 242e10f to cc81fdc Compare July 18, 2026 17:34
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 18, 2026 17:34
…very budget).

self_host/ per-PR discovery enforces a 5s eval cap; tokenize→parse→normalize
projection receipts run ~10s and belong in long/ like peer fn_body seam witnesses.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

Review 39663 (cursor/composer-2.5 APPROVE) — verified on current HEAD 8c1cfdbe9

Re-checked each claim against the tree; no code changes needed for this review.

Claim Status
fold_loop tried before generic ident-call lowering (incl. shell-stripped path) ✅ body_lowering_fold.dag body_lower_try_body_lowered
Lens walks lowered Loop/Transform + projection via body_lowering_fold helpers ✅ analyze.dag analyze_absent_primary_expr / analyze_postfix_projection_call
projection_call_carrier_is_classified requires non-empty combiner_unregistered_carrier_reaches ✅ accumulator_copy_fold_analysis_test.dag
No emitter / hand-Rust / absorbing fallbacks ✅ diff is 4 files, all Stage B cross-decl

Post-review commit (8c1cfdbe9): moved wave1_gate1_a1_projection_call_witness_test.dag from self_host/ → long/ — those tokenize→parse→normalize witnesses exceed the 5s per-PR discovery budget (~10s locally). Classification witness stays in long/accumulator_copy_fold_analysis_test.dag.

Awaiting CI green on run 29654443333.

— sent from wise-bee-713

Drop unused tree_contains_surface_postfix_expr and tree_contains_lowered_transform; the latter's test import was never referenced.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

Reviews 39665 + 39666 — addressed on 8969d8377

  • review 39665 (claude-opus-4-7, APPROVE): Verified on current HEAD — no findings, no code changes needed.
  • review 39666 (composer-2.5, APPROVE): Confirmed the two cleanup-only items — unused tree_contains_surface_postfix_expr and unused tree_contains_lowered_transform import. Removed both in 8969d8377; key witnesses (projection_call_carrier_is_classified, quadratic_ingest_has_no_surface_fold_call) re-run PASS locally.

— sent from wise-bee-713

@gunbai-bot

gunbai-bot Bot commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

Review 39669 (composer-2.5, APPROVE) — verified on current HEAD 8969d8377

Re-checked each claim against the tree; no code changes needed.

  • Lowered-substrate arms (analyze_lowered_loop, analyze_lowered_transform_call) dispatch from analyze over ComputationNode Loop/Transform, not only surface primary_expr.
  • Projection classification routes through body_lowering_fold helpers (projection_method_call_optional, projection_call_port_readings) — no ad-hoc re-parse in the lens.
  • body_lower_try_body_lowered tries body_lower_try_fold_loop before body_lower_try_primary_ident_call at both the outer and stripped-shell nesting levels (lines ~1211–1268 in body_lowering_fold.dag), so an Absent from fold-loop does not short-circuit later lowerers.
  • Witness coverage: projection_call_carrier_is_classified, lowered-loop vs surface-fold assertions, and long-lane wave1_gate1_a1_projection_call_witness_test.dag (completion receipt already in PR body).

No merge-blocking issues; dead-code cleanup from review 39666 already landed in the same HEAD.

— sent from wise-bee-713

@gunbai-bot

gunbai-bot Bot commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

Review 39670 (claude-opus-4-7, APPROVE) — verified on current HEAD 8969d8377

Re-checked each claim against the tree; no code changes needed.

  • body_lower_try_body_lowered tries body_lower_try_fold_loop before body_lower_try_primary_ident_call at both outer (~1211→1221) and stripped-shell (~1257→1268) levels in body_lowering_fold.dag.
  • Accumulator-copy lens Stage-B arms (analyze_lowered_loop, analyze_lowered_transform_call, postfix projection path) classify inside lowered ComputationNode { Loop | Transform } trees; count_fold_sites / tree_contains_lowered_loop helpers align with the new substrate.
  • Discriminating witnesses present: projection_call_carrier_is_classified, quadratic_ingest_has_lowered_loop, quadratic_ingest_has_no_surface_fold_call, plus long-lane wave1_gate1_a1_projection_call_witness_test.dag (completion receipt in PR body).
  • projection_call_residue_note honestly marked DISSOLVED with witness pointer.
  • No substrate coproducts, unit-modeling, or hand-shell surfaces in the diff.

CI run 29655014078: build + ci PASS on this HEAD.

— sent from wise-bee-713

@briansrls
briansrls merged commit 67dea75 into main Jul 18, 2026
3 checks passed
@briansrls
briansrls deleted the session/wise-bee-713-stage-b-projection-lens branch July 18, 2026 21:02
briansrls pushed a commit that referenced this pull request Jul 19, 2026
…to std_dup bucket

Re-probed all seven Gate-A candidates with CSSL_STD_SEED_LINK=1 on
integration/sharp-bee-290. No cargo-green flips (baseline stays 6).
#6868 Ord fix cleared btree_set_ord for 04_infer/program_partition;
both now refuse on Witness std_dup alongside 01_tokenize. Four modules
still refuse UNRESOLVED_CompilerError. Bank execution receipts in
docs/probes/gate_a_reprobe_2026-07-19.tsv and tail_reprobe_2026-07-19.tsv.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 19, 2026
…-boar-697)

2 approvals (claude, cursor), no request-changes. Gate-A + tail re-probe TSVs
against the Stage B #6859 + Ord #6868 baseline; frontier row notes updated.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 19, 2026
…emitter Ord unlock (single merge point) (#6866)

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* emit: generalize BTreeSet Ord eligibility for Symbol-wrapped carriers

FormalNonterminal and FormalTerminal ({ identity: Symbol }) now pass
rust_btree_set_element_ord_eligible and receive Ord derives, unblocking
04_infer and program_partition self-emit cargo probes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* Module identity Phase 1: the path⇄module binding authority (parse-derived, fail-closed)

Homes the path⇄module binding on v2.compiler.source_authority as a
DERIVED-at-parse fact per docs/plans/module-identity-storage-binding-design.md §2.

- ModuleStorageProvenance = ParsedFromSource { artifact, span_index }
  | ProducedByBehavior { producer } — zero-file produced modules are now
  representable honestly instead of being excluded.
- ModuleStorageBinding / ModuleStorageIndex, reusing QualifiedName, Artifact,
  SourceRootRef and SpanIndex (no new nickname, §3).
- Both projections: file -> module and module -> storage.
- Scope is the LIVE 1:1 binding; many-to-many is a named deferral (§6).

§5 fail-closed repair in v2.compiler.program_assembly: the Rejected arm of
qualified_name_from_module_node kept the root and left the index UNCHANGED,
so a module whose name could not be derived went silently invisible to every
downstream lookup — an absorbing fallback in drop form, its frequency zeroed
by construction. It now refuses with the located diagnostic.

Witnesses (green by execution, REDs verified discriminating by perturbation):
derivation from parse; path projection; duplicate-module refuses; underivable
name refuses; produced module has no storage.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Consolidate the qualified_name_from_segment_list §3 fork (LIVE runtime h

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* review: forward located diagnostics; hoist grammar prepare; split fast/long witness lanes

Three fixes from review + CI.

1. Located refusal (cursor/composer-2.5). The name-derivation Rejected arm
   discarded the derivation's diagnostics and substituted a port-level
   source_authority_diagnostic — satisfying "typed" while destroying "located"
   (§5 requires both), contradicting this PR's own notes, and diverging from the
   sibling arm in program_assembly which forwards d. It now forwards d unchanged,
   so one failure yields one diagnostic regardless of entry point.

2. Grammar prepare hoisted above the fold, mirroring
   program_assembly_prepare_once_note. The derivation called parse_module per
   read, re-validating the grammar K times over a K-module ingest; it now
   prepares once and uses parse_module_prepared. Empty ingest is guarded so it
   never pays the prepare for zero reads. Same cost-shape defect the assembly
   fold already documents (§6 always-fix).

3. Witness lanes split per the operator 5-second rule (CI EvalBudgetExceeded:
   4 witnesses at ~5002ms). Measured by differencing against the non-parsing
   witness, parse-derived eval is ~13s — inherently over the fast-lane budget
   even after fix 2. Per gunbc.ci_layer_roots long_lane_exclusion_note ("fast
   receipts stay discovered, execution proofs live in long/"), the parse-derived
   proofs move to src/v2/test/claim/long/, and the fast lane keeps NEW witnesses
   that exercise the §5 construction wall over hand-built rows at zero parse
   cost: duplicate-module refusal, its accept control, and the produced/zero-file
   arm. Duplicate detection keys on module identity independently of provenance,
   which is why the wall is provable without a parse.

All eight witnesses green by execution across both lanes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* Gate-A re-probe post-#6859+#6868: repoint 04_infer/program_partition to std_dup bucket

Re-probed all seven Gate-A candidates with CSSL_STD_SEED_LINK=1 on
integration/sharp-bee-290. No cargo-green flips (baseline stays 6).
#6868 Ord fix cleared btree_set_ord for 04_infer/program_partition;
both now refuse on Witness std_dup alongside 01_tokenize. Four modules
still refuse UNRESOLVED_CompilerError. Bank execution receipts in
docs/probes/gate_a_reprobe_2026-07-19.tsv and tail_reprobe_2026-07-19.tsv.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(probes): add cssl_std_seed_link and shim_lib_rel columns to re-probe TSVs

Invocation metadata for std_dup fix lane: all 19 probes were raw-closure
(CSSL_STD_SEED_LINK=1, shim_lib_rel empty — no lane shims passed).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Weak Self Host -> Strong Self Host (Wave 1 -> 4, on 1 exit)

* WIP: Weak Self Host -> Strong Self Host (Wave 1 -> 4, on 1 exit)

* integration: address review 39722/39727 — admission scanner refuses (never widens), provenance de-fork, stale note, KeySource import

Review 39722 (claude, RC) three findings + review 39727 (cursor, RC) two findings, all verified:

1. §5 absorbing fallback in the witness-admission scanner: rewritten as per-form structural extraction that is fail-closed BOTH ways — every occurrence of a recognized row head (bin_wet, probe_red, self_host_wet_entry, SelfHostWetReceiptBinding) either parses to a key, is a verified definition/non-literal pass-through site, or PANICS with source label + byte offset; the catch-all entry/function loop (the widen arm that could silently excuse orphans) is DELETED. A consumer in an unrecognized form now surfaces as a loud orphan, never an absorbed excuse. Call sites carry source labels (the 39727 arity finding was the auto-WIP intermediate state; complete here).

2. §3 parallel authority (borderline per reviewer): the dissolve-on marker now names the tracked lane (module-binding supply-carrier pattern; host consumes emitted manifest rows) and the interim scan's fail-closed semantics.

3. §2 byte-identical provenance pair: source_ir_node_artifact_provenance_add_from_model + _add wrapper DELETED (pre-existing on main, not introduced by the wave — verified via git show origin/main); consumers repointed (edit_locus_resolver_test import + 2 calls, internal :627 site). Zero references remain.

4. Stale fork note in module_storage_binding_derivation_test updated: the qualified_name fork it described was dissolved in this wave (renamed apart); note now records the resolution.

5. Operator-requested: dag/std/realization.dag KeySource unlisted-import x3 (pre-existing main defect) fixed — KeySource added to the std.effects import list; source_authority closure compile-clean 3 -> 0 diagnostics.

Receipts: cargo build release clean; admission unit tests 2/2 (witness_admission_deferred_rows_have_consumers, witness_admission_orphan_synthetic_row_refuses); module_storage_binding witnesses PASS; edit_locus_resolver witnesses PASS on the repointed name.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* integration: rustfmt the admission scanner

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* plan: v1-deletion dependency graph as .dag — milestones, serial-vs-fanout, critical path (operator 2-week target)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* plan: record 2026-07-19 census discharges — Ord fix cleared btree_set_ord, KeySource import fix cleared the whole unresolved bucket; ~19 modules now on the one std_dup fix

Verified by execution at f071536: all 6 formerly-UNRESOLVED closures
(00_compile, materialization_carriers, program_assembly, source_authority,
02_parse, 03_ingest) compile 0 diagnostics; re-probe TSVs (#6872) show
04_infer/program_partition emit clean with std_dup as sole refusal.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 19, 2026
…n-note disposition (single merge point) (#6885)

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* emit: generalize BTreeSet Ord eligibility for Symbol-wrapped carriers

FormalNonterminal and FormalTerminal ({ identity: Symbol }) now pass
rust_btree_set_element_ord_eligible and receive Ord derives, unblocking
04_infer and program_partition self-emit cargo probes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* Module identity Phase 1: the path⇄module binding authority (parse-derived, fail-closed)

Homes the path⇄module binding on v2.compiler.source_authority as a
DERIVED-at-parse fact per docs/plans/module-identity-storage-binding-design.md §2.

- ModuleStorageProvenance = ParsedFromSource { artifact, span_index }
  | ProducedByBehavior { producer } — zero-file produced modules are now
  representable honestly instead of being excluded.
- ModuleStorageBinding / ModuleStorageIndex, reusing QualifiedName, Artifact,
  SourceRootRef and SpanIndex (no new nickname, §3).
- Both projections: file -> module and module -> storage.
- Scope is the LIVE 1:1 binding; many-to-many is a named deferral (§6).

§5 fail-closed repair in v2.compiler.program_assembly: the Rejected arm of
qualified_name_from_module_node kept the root and left the index UNCHANGED,
so a module whose name could not be derived went silently invisible to every
downstream lookup — an absorbing fallback in drop form, its frequency zeroed
by construction. It now refuses with the located diagnostic.

Witnesses (green by execution, REDs verified discriminating by perturbation):
derivation from parse; path projection; duplicate-module refuses; underivable
name refuses; produced module has no storage.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Consolidate the qualified_name_from_segment_list §3 fork (LIVE runtime h

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* review: forward located diagnostics; hoist grammar prepare; split fast/long witness lanes

Three fixes from review + CI.

1. Located refusal (cursor/composer-2.5). The name-derivation Rejected arm
   discarded the derivation's diagnostics and substituted a port-level
   source_authority_diagnostic — satisfying "typed" while destroying "located"
   (§5 requires both), contradicting this PR's own notes, and diverging from the
   sibling arm in program_assembly which forwards d. It now forwards d unchanged,
   so one failure yields one diagnostic regardless of entry point.

2. Grammar prepare hoisted above the fold, mirroring
   program_assembly_prepare_once_note. The derivation called parse_module per
   read, re-validating the grammar K times over a K-module ingest; it now
   prepares once and uses parse_module_prepared. Empty ingest is guarded so it
   never pays the prepare for zero reads. Same cost-shape defect the assembly
   fold already documents (§6 always-fix).

3. Witness lanes split per the operator 5-second rule (CI EvalBudgetExceeded:
   4 witnesses at ~5002ms). Measured by differencing against the non-parsing
   witness, parse-derived eval is ~13s — inherently over the fast-lane budget
   even after fix 2. Per gunbc.ci_layer_roots long_lane_exclusion_note ("fast
   receipts stay discovered, execution proofs live in long/"), the parse-derived
   proofs move to src/v2/test/claim/long/, and the fast lane keeps NEW witnesses
   that exercise the §5 construction wall over hand-built rows at zero parse
   cost: duplicate-module refusal, its accept control, and the produced/zero-file
   arm. Duplicate detection keys on module identity independently of provenance,
   which is why the wall is provable without a parse.

All eight witnesses green by execution across both lanes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* Gate-A re-probe post-#6859+#6868: repoint 04_infer/program_partition to std_dup bucket

Re-probed all seven Gate-A candidates with CSSL_STD_SEED_LINK=1 on
integration/sharp-bee-290. No cargo-green flips (baseline stays 6).
#6868 Ord fix cleared btree_set_ord for 04_infer/program_partition;
both now refuse on Witness std_dup alongside 01_tokenize. Four modules
still refuse UNRESOLVED_CompilerError. Bank execution receipts in
docs/probes/gate_a_reprobe_2026-07-19.tsv and tail_reprobe_2026-07-19.tsv.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(probes): add cssl_std_seed_link and shim_lib_rel columns to re-probe TSVs

Invocation metadata for std_dup fix lane: all 19 probes were raw-closure
(CSSL_STD_SEED_LINK=1, shim_lib_rel empty — no lane shims passed).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Weak Self Host -> Strong Self Host (Wave 1 -> 4, on 1 exit)

* WIP: Weak Self Host -> Strong Self Host (Wave 1 -> 4, on 1 exit)

* integration: address review 39722/39727 — admission scanner refuses (never widens), provenance de-fork, stale note, KeySource import

Review 39722 (claude, RC) three findings + review 39727 (cursor, RC) two findings, all verified:

1. §5 absorbing fallback in the witness-admission scanner: rewritten as per-form structural extraction that is fail-closed BOTH ways — every occurrence of a recognized row head (bin_wet, probe_red, self_host_wet_entry, SelfHostWetReceiptBinding) either parses to a key, is a verified definition/non-literal pass-through site, or PANICS with source label + byte offset; the catch-all entry/function loop (the widen arm that could silently excuse orphans) is DELETED. A consumer in an unrecognized form now surfaces as a loud orphan, never an absorbed excuse. Call sites carry source labels (the 39727 arity finding was the auto-WIP intermediate state; complete here).

2. §3 parallel authority (borderline per reviewer): the dissolve-on marker now names the tracked lane (module-binding supply-carrier pattern; host consumes emitted manifest rows) and the interim scan's fail-closed semantics.

3. §2 byte-identical provenance pair: source_ir_node_artifact_provenance_add_from_model + _add wrapper DELETED (pre-existing on main, not introduced by the wave — verified via git show origin/main); consumers repointed (edit_locus_resolver_test import + 2 calls, internal :627 site). Zero references remain.

4. Stale fork note in module_storage_binding_derivation_test updated: the qualified_name fork it described was dissolved in this wave (renamed apart); note now records the resolution.

5. Operator-requested: dag/std/realization.dag KeySource unlisted-import x3 (pre-existing main defect) fixed — KeySource added to the std.effects import list; source_authority closure compile-clean 3 -> 0 diagnostics.

Receipts: cargo build release clean; admission unit tests 2/2 (witness_admission_deferred_rows_have_consumers, witness_admission_orphan_synthetic_row_refuses); module_storage_binding witnesses PASS; edit_locus_resolver witnesses PASS on the repointed name.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* integration: rustfmt the admission scanner

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* plan: v1-deletion dependency graph as .dag — milestones, serial-vs-fanout, critical path (operator 2-week target)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* plan: record 2026-07-19 census discharges — Ord fix cleared btree_set_ord, KeySource import fix cleared the whole unresolved bucket; ~19 modules now on the one std_dup fix

Verified by execution at f071536: all 6 formerly-UNRESOLVED closures
(00_compile, materialization_carriers, program_assembly, source_authority,
02_parse, 03_ingest) compile 0 diagnostics; re-probe TSVs (#6872) show
04_infer/program_partition emit clean with std_dup as sole refusal.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(cssl): assembly std_dup unlock — Witness sanitize + v2_std emit-retain

Single assembly fix for the 13-module std_dup gate (calm-boar-697 census):
- sanitize_witness_import_conflict matches `pub enum Witness<C>` (generic),
  stripping v1_rt::Witness prelude imports that collided with emitted enum
- v2_std_* emit-retain instead of minimal bridge shims (broken dependents
  like v2_std_logic → v2_std_algebra re-exports)

No emitter changes. Probes move past HARNESS_ARTIFACT_std_dup / E0255 on all
Gate-A modules + tail representatives; next blockers surface as namespace gaps.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(probes): post-std_dup re-probe on proud-deer ed68594 (13 modules)

CSSL_STD_SEED_LINK=1, shim_lib_rel empty, rebuilt cssl_assemble. std_dup
E0255 cleared on 12/13; new namespace layer surfaces (FreeMonoid,
ResolvedTree, InferredTree/InferredFacts). emit_produced: Optional std_dup
residue. Harness invocation contract in probe script header.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(probes): baseline caveat + probe_notes on post-std_dup TSV (#6884)

ed68594 predates #6883 emit-retain; mark ResolvedTree/InferredTree rows
EXPECTED-CLEARED. emit_produced Optional routed to proud-deer. FreeMonoid
rows flagged as live next-layer census post-#6883.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(#6880): cargo-stage unresolved re-probe + plan census correction on main

Rebased onto main post-#6866. Remaining delta: KeySource cargo-stage TSV,
embedded-marker grep receipt, v1_deletion_plan corrections (13 std_dup vs 6
unresolved, ROOT-CAUSED emitter-gap, stern-lark-430 dispatched). Gate-A/tail
frontier rows already landed via integration merge.

Co-authored-by: Cursor <cursoragent@cursor.com>

* witness_admission: bounded dissolution note on the two single-arm predicates (review 39758 disposition)

Phase 0(b) author closed out; disposition owned by sharp-bee-290 per the
capture. Pattern matches target_value_expr_int_literal_predicate_dissolution_note.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* plan(#6880): resolve integration merge — std_dup LANDED #6876, flip-wave unblocked

Fold integration/sharp-bee-290 at 81dc2d9; update v1_deletion_plan lane_state
to current truth (13+6 census retained, probe_flip_fanout unblocked pending emitter fixes).

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 19, 2026
#6880)

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* emit: generalize BTreeSet Ord eligibility for Symbol-wrapped carriers

FormalNonterminal and FormalTerminal ({ identity: Symbol }) now pass
rust_btree_set_element_ord_eligible and receive Ord derives, unblocking
04_infer and program_partition self-emit cargo probes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* Module identity Phase 1: the path⇄module binding authority (parse-derived, fail-closed)

Homes the path⇄module binding on v2.compiler.source_authority as a
DERIVED-at-parse fact per docs/plans/module-identity-storage-binding-design.md §2.

- ModuleStorageProvenance = ParsedFromSource { artifact, span_index }
  | ProducedByBehavior { producer } — zero-file produced modules are now
  representable honestly instead of being excluded.
- ModuleStorageBinding / ModuleStorageIndex, reusing QualifiedName, Artifact,
  SourceRootRef and SpanIndex (no new nickname, §3).
- Both projections: file -> module and module -> storage.
- Scope is the LIVE 1:1 binding; many-to-many is a named deferral (§6).

§5 fail-closed repair in v2.compiler.program_assembly: the Rejected arm of
qualified_name_from_module_node kept the root and left the index UNCHANGED,
so a module whose name could not be derived went silently invisible to every
downstream lookup — an absorbing fallback in drop form, its frequency zeroed
by construction. It now refuses with the located diagnostic.

Witnesses (green by execution, REDs verified discriminating by perturbation):
derivation from parse; path projection; duplicate-module refuses; underivable
name refuses; produced module has no storage.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Consolidate the qualified_name_from_segment_list §3 fork (LIVE runtime h

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* review: forward located diagnostics; hoist grammar prepare; split fast/long witness lanes

Three fixes from review + CI.

1. Located refusal (cursor/composer-2.5). The name-derivation Rejected arm
   discarded the derivation's diagnostics and substituted a port-level
   source_authority_diagnostic — satisfying "typed" while destroying "located"
   (§5 requires both), contradicting this PR's own notes, and diverging from the
   sibling arm in program_assembly which forwards d. It now forwards d unchanged,
   so one failure yields one diagnostic regardless of entry point.

2. Grammar prepare hoisted above the fold, mirroring
   program_assembly_prepare_once_note. The derivation called parse_module per
   read, re-validating the grammar K times over a K-module ingest; it now
   prepares once and uses parse_module_prepared. Empty ingest is guarded so it
   never pays the prepare for zero reads. Same cost-shape defect the assembly
   fold already documents (§6 always-fix).

3. Witness lanes split per the operator 5-second rule (CI EvalBudgetExceeded:
   4 witnesses at ~5002ms). Measured by differencing against the non-parsing
   witness, parse-derived eval is ~13s — inherently over the fast-lane budget
   even after fix 2. Per gunbc.ci_layer_roots long_lane_exclusion_note ("fast
   receipts stay discovered, execution proofs live in long/"), the parse-derived
   proofs move to src/v2/test/claim/long/, and the fast lane keeps NEW witnesses
   that exercise the §5 construction wall over hand-built rows at zero parse
   cost: duplicate-module refusal, its accept control, and the produced/zero-file
   arm. Duplicate detection keys on module identity independently of provenance,
   which is why the wall is provable without a parse.

All eight witnesses green by execution across both lanes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* Gate-A re-probe post-#6859+#6868: repoint 04_infer/program_partition to std_dup bucket

Re-probed all seven Gate-A candidates with CSSL_STD_SEED_LINK=1 on
integration/sharp-bee-290. No cargo-green flips (baseline stays 6).
#6868 Ord fix cleared btree_set_ord for 04_infer/program_partition;
both now refuse on Witness std_dup alongside 01_tokenize. Four modules
still refuse UNRESOLVED_CompilerError. Bank execution receipts in
docs/probes/gate_a_reprobe_2026-07-19.tsv and tail_reprobe_2026-07-19.tsv.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(probes): add cssl_std_seed_link and shim_lib_rel columns to re-probe TSVs

Invocation metadata for std_dup fix lane: all 19 probes were raw-closure
(CSSL_STD_SEED_LINK=1, shim_lib_rel empty — no lane shims passed).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Weak Self Host -> Strong Self Host (Wave 1 -> 4, on 1 exit)

* WIP: Weak Self Host -> Strong Self Host (Wave 1 -> 4, on 1 exit)

* integration: address review 39722/39727 — admission scanner refuses (never widens), provenance de-fork, stale note, KeySource import

Review 39722 (claude, RC) three findings + review 39727 (cursor, RC) two findings, all verified:

1. §5 absorbing fallback in the witness-admission scanner: rewritten as per-form structural extraction that is fail-closed BOTH ways — every occurrence of a recognized row head (bin_wet, probe_red, self_host_wet_entry, SelfHostWetReceiptBinding) either parses to a key, is a verified definition/non-literal pass-through site, or PANICS with source label + byte offset; the catch-all entry/function loop (the widen arm that could silently excuse orphans) is DELETED. A consumer in an unrecognized form now surfaces as a loud orphan, never an absorbed excuse. Call sites carry source labels (the 39727 arity finding was the auto-WIP intermediate state; complete here).

2. §3 parallel authority (borderline per reviewer): the dissolve-on marker now names the tracked lane (module-binding supply-carrier pattern; host consumes emitted manifest rows) and the interim scan's fail-closed semantics.

3. §2 byte-identical provenance pair: source_ir_node_artifact_provenance_add_from_model + _add wrapper DELETED (pre-existing on main, not introduced by the wave — verified via git show origin/main); consumers repointed (edit_locus_resolver_test import + 2 calls, internal :627 site). Zero references remain.

4. Stale fork note in module_storage_binding_derivation_test updated: the qualified_name fork it described was dissolved in this wave (renamed apart); note now records the resolution.

5. Operator-requested: dag/std/realization.dag KeySource unlisted-import x3 (pre-existing main defect) fixed — KeySource added to the std.effects import list; source_authority closure compile-clean 3 -> 0 diagnostics.

Receipts: cargo build release clean; admission unit tests 2/2 (witness_admission_deferred_rows_have_consumers, witness_admission_orphan_synthetic_row_refuses); module_storage_binding witnesses PASS; edit_locus_resolver witnesses PASS on the repointed name.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* integration: rustfmt the admission scanner

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* plan: v1-deletion dependency graph as .dag — milestones, serial-vs-fanout, critical path (operator 2-week target)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* plan: record 2026-07-19 census discharges — Ord fix cleared btree_set_ord, KeySource import fix cleared the whole unresolved bucket; ~19 modules now on the one std_dup fix

Verified by execution at f071536: all 6 formerly-UNRESOLVED closures
(00_compile, materialization_carriers, program_assembly, source_authority,
02_parse, 03_ingest) compile 0 diagnostics; re-probe TSVs (#6872) show
04_infer/program_partition emit clean with std_dup as sole refusal.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(cssl): assembly std_dup unlock — Witness sanitize + v2_std emit-retain

Single assembly fix for the 13-module std_dup gate (calm-boar-697 census):
- sanitize_witness_import_conflict matches `pub enum Witness<C>` (generic),
  stripping v1_rt::Witness prelude imports that collided with emitted enum
- v2_std_* emit-retain instead of minimal bridge shims (broken dependents
  like v2_std_logic → v2_std_algebra re-exports)

No emitter changes. Probes move past HARNESS_ARTIFACT_std_dup / E0255 on all
Gate-A modules + tail representatives; next blockers surface as namespace gaps.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(probes): post-std_dup re-probe on proud-deer ed68594 (13 modules)

CSSL_STD_SEED_LINK=1, shim_lib_rel empty, rebuilt cssl_assemble. std_dup
E0255 cleared on 12/13; new namespace layer surfaces (FreeMonoid,
ResolvedTree, InferredTree/InferredFacts). emit_produced: Optional std_dup
residue. Harness invocation contract in probe script header.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(probes): baseline caveat + probe_notes on post-std_dup TSV (#6884)

ed68594 predates #6883 emit-retain; mark ResolvedTree/InferredTree rows
EXPECTED-CLEARED. emit_produced Optional routed to proud-deer. FreeMonoid
rows flagged as live next-layer census post-#6883.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(#6880): cargo-stage unresolved re-probe + plan census correction on main

Rebased onto main post-#6866. Remaining delta: KeySource cargo-stage TSV,
embedded-marker grep receipt, v1_deletion_plan corrections (13 std_dup vs 6
unresolved, ROOT-CAUSED emitter-gap, stern-lark-430 dispatched). Gate-A/tail
frontier rows already landed via integration merge.

Co-authored-by: Cursor <cursoragent@cursor.com>

* witness_admission: bounded dissolution note on the two single-arm predicates (review 39758 disposition)

Phase 0(b) author closed out; disposition owned by sharp-bee-290 per the
capture. Pattern matches target_value_expr_int_literal_predicate_dissolution_note.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* plan(#6880): resolve integration merge — std_dup LANDED #6876, flip-wave unblocked

Fold integration/sharp-bee-290 at 81dc2d9; update v1_deletion_plan lane_state
to current truth (13+6 census retained, probe_flip_fanout unblocked pending emitter fixes).

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant