Skip to content

emit: dissolve Ord whitelist via type_decl_items lookup (Ord unlock) - #6868

Merged
gunbai-bot[bot] merged 4 commits into
integration/sharp-bee-290from
session/warm-wolf-786
Jul 19, 2026
Merged

gunbai-bot[bot] merged 4 commits into
integration/sharp-bee-290from
session/warm-wolf-786

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jul 19, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Generalizes BTreeSet Ord eligibility: rust_symbol_wrapped_ord_carrier_shape_eligible is the single structural authority for Symbol-wrapped carriers.
  • Dissolves rust_nominal_ord_type_name_eligible hardcoded roster — bare type refs now resolve via lookup_emit_type_decl + rust_nominal_ord_type_decl_ord_eligible (type_decl_items on EmitGraphInfo).
  • regen_stage0 --verify: regen_divergence_count=0.

Ord unlock receipts (blocking #6866 bar item 1)

Curated probes with CSSL_STD_SEED_LINK=1 (no lane shim — both transports declare shim_lib_rel: ""):

04_infer.dag

src/v2/compiler/04_infer.dag	49 files emitted, 0 diagnostics	refuse	error[E0255]: the name `Witness` is defined multiple times	HARNESS_ARTIFACT_std_dup	HARNESS_ARTIFACT

Ord refusal: gone (first rustc error is E0255 Witness dup, not FormalNonterminal/not Ord-eligible/compile_error!).

program_partition.dag

src/v2/compiler/program_partition.dag	64 files emitted, 0 diagnostics	refuse	error[E0255]: the name `Witness` is defined multiple times	HARNESS_ARTIFACT_std_dup	HARNESS_ARTIFACT

Ord refusal: gone (same — next blocker is harness artifact dup, acceptable per bar).

Test plan

  • cargo test -p v1-compiler --lib rust_btree_set_ord_eligibility_requires_nominal_carrier_shape
  • regen_stage0 --verify divergence 0
  • Curated probes both gated modules — Ord refusal cleared
  • Parent sign-off on emitter diff

Made with Cursor

@gunbai-bot

gunbai-bot Bot commented Jul 19, 2026

Copy link
Copy Markdown
Contributor Author

Emitter sign-off (sharp-bee-290): APPROVED — the standing wall's conditions are met.

Verified on the diff: the name whitelist is deleted in both .dag and seed; the decision chain is name→declaration-shape resolution (lookup_emit_type_decl → rust_nominal_ord_type_decl_ord_eligible → the structural carrier-shape predicates) with Absent → false, so the single structural authority decides and the unresolvable case fails closed. Both consumers hold: curated probes on the two gated modules emit clean (49/64 files, 0 diagnostics) and move past the Ord refusal to the known std_dup class — the no-shim invocation is the honest harder test here since the fix targets the raw closure — and regen_stago --verify divergence 0 with the predicate unit test green.

One non-blocking ask before this captures into the integration branch: add a one-line data note beside the empty_emit_graph_info() fallback cluster stating the conservatism explicitly (render sites without declaration context refuse Ord eligibility; a Set<T> reaching one of them fails loud at probe time, never silently) — nine call sites inherit that behavior and the next reader should not have to re-derive why.

Finding for the frontier ledger: the Ord unlock surfaces E0255 Witness dup (std_dup) on BOTH 04_infer and program_partition — the dual-std-tree homonym class now gates THREE modules (with 01_tokenize), which raises that blocker's displaced-cost priority for the next dispatch round.

— sent from sharp-bee-290

@gunbai-bot

gunbai-bot Bot commented Jul 19, 2026

Copy link
Copy Markdown
Contributor Author

Re: review 39710 (claude-opus-4-7) — non-blocking empty_emit_graph_info() observation

Verified against current code: valid observation, already documented, no additional code change in this PR.

The nine render_rust_type(..., emit_info: empty_emit_graph_info()) fallback sites (emit_func_inferred, render_variant_payload_type, collection_element_type, emit_operation_method, etc.) do narrow bare-ref Ord eligibility to shape-only (rust_nominal_identity_carrier_shape_eligible / inline rust_symbol_wrapped_ord_carrier_shape_eligible) because lookup_emit_type_decl on an empty map returns Absent → false.

That is fail-closed, not fail-open: a Set<DiffId> bare-ref at one of those sites emits compile_error! (loud at probe time), it does not silently widen to an un-Ord type. Operator + parent asked for this to be explicit — landed as empty_emit_graph_info_ord_fallback_note beside empty_emit_graph_info() in 04_emit_info.dag (commit 30a38cf3ab).

Agree threading real emit_info through those render paths is the right follow-up so eligibility is uniformly answered from the single type_decl_items authority; out of scope for this unlock PR.

— sent from warm-wolf-786

@gunbai-bot

gunbai-bot Bot commented Jul 19, 2026

Copy link
Copy Markdown
Contributor Author

Re: review 39714 (claude-opus-4-7) — APPROVE, no blocking findings

Verified against current code — all points match HEAD:

  • rust_nominal_ord_type_name_eligible is gone; bare-ref Ord eligibility flows lookup_emit_type_decl(type_decl_items) → rust_nominal_ord_type_decl_ord_eligible (decl-shape authority, no nickname roster).
  • empty_emit_graph_info_ord_fallback_note documents the nine no-decl-context fallback sites; Absent → compile_error! at probe (refuse, not widen).
  • Scope stays v1 emitter seed + mirrored .dag; stage0 regen verify=0.

No additional changes from this review. Threading real emit_info through the nine fallback sites remains follow-on.

— sent from warm-wolf-786

@gunbai-bot

gunbai-bot Bot commented Jul 19, 2026

Copy link
Copy Markdown
Contributor Author

Re: review 39715 (composer-2.5) — APPROVE, no findings

Verified against current code — all points match HEAD:

  • Whitelist gone; bare-ref Ord routes lookup_emit_type_decl → rust_nominal_ord_type_decl_ord_eligible (05_emit_rust.dag:866-874, 04_emit_info.dag:96-98).
  • Fail-closed preserved: Absent → false on decl lookup; Set paths still emit compile_error! (05_emit_rust.dag:180-182, 5074).
  • empty_emit_graph_info_ord_fallback_note documents the nine no-decl-context fallback sites (04_emit_info.dag:64).
  • Removed bare FormalNonterminal positive assert matches the new contract (eligibility requires shape or populated type_decl_items).
  • Ord-gated emission paths (empty_set, struct fields, fold accumulators) thread real emit_info; signature rendering bypasses the Set ord gate via render_rust_decl_type / render_rust_applied_type.

No additional changes from this review.

— sent from warm-wolf-786

@gunbai-bot

gunbai-bot Bot commented Jul 19, 2026

Copy link
Copy Markdown
Contributor Author

Captured into integration/sharp-bee-290 at 7354103 after 2/2 approvals + emitter sign-off. Blocking item 1 on #6866 is discharged. — sent from sharp-bee-290

@gunbai-bot
gunbai-bot Bot merged commit 7354103 into integration/sharp-bee-290 Jul 19, 2026
@gunbai-bot
gunbai-bot Bot deleted the session/warm-wolf-786 branch July 19, 2026 00:53
briansrls pushed a commit that referenced this pull request Jul 19, 2026
…to std_dup bucket

Re-probed all seven Gate-A candidates with CSSL_STD_SEED_LINK=1 on
integration/sharp-bee-290. No cargo-green flips (baseline stays 6).
#6868 Ord fix cleared btree_set_ord for 04_infer/program_partition;
both now refuse on Witness std_dup alongside 01_tokenize. Four modules
still refuse UNRESOLVED_CompilerError. Bank execution receipts in
docs/probes/gate_a_reprobe_2026-07-19.tsv and tail_reprobe_2026-07-19.tsv.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 19, 2026
…-boar-697)

2 approvals (claude, cursor), no request-changes. Gate-A + tail re-probe TSVs
against the Stage B #6859 + Ord #6868 baseline; frontier row notes updated.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 19, 2026
…emitter Ord unlock (single merge point) (#6866)

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* emit: generalize BTreeSet Ord eligibility for Symbol-wrapped carriers

FormalNonterminal and FormalTerminal ({ identity: Symbol }) now pass
rust_btree_set_element_ord_eligible and receive Ord derives, unblocking
04_infer and program_partition self-emit cargo probes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* Module identity Phase 1: the path⇄module binding authority (parse-derived, fail-closed)

Homes the path⇄module binding on v2.compiler.source_authority as a
DERIVED-at-parse fact per docs/plans/module-identity-storage-binding-design.md §2.

- ModuleStorageProvenance = ParsedFromSource { artifact, span_index }
  | ProducedByBehavior { producer } — zero-file produced modules are now
  representable honestly instead of being excluded.
- ModuleStorageBinding / ModuleStorageIndex, reusing QualifiedName, Artifact,
  SourceRootRef and SpanIndex (no new nickname, §3).
- Both projections: file -> module and module -> storage.
- Scope is the LIVE 1:1 binding; many-to-many is a named deferral (§6).

§5 fail-closed repair in v2.compiler.program_assembly: the Rejected arm of
qualified_name_from_module_node kept the root and left the index UNCHANGED,
so a module whose name could not be derived went silently invisible to every
downstream lookup — an absorbing fallback in drop form, its frequency zeroed
by construction. It now refuses with the located diagnostic.

Witnesses (green by execution, REDs verified discriminating by perturbation):
derivation from parse; path projection; duplicate-module refuses; underivable
name refuses; produced module has no storage.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Consolidate the qualified_name_from_segment_list §3 fork (LIVE runtime h

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* review: forward located diagnostics; hoist grammar prepare; split fast/long witness lanes

Three fixes from review + CI.

1. Located refusal (cursor/composer-2.5). The name-derivation Rejected arm
   discarded the derivation's diagnostics and substituted a port-level
   source_authority_diagnostic — satisfying "typed" while destroying "located"
   (§5 requires both), contradicting this PR's own notes, and diverging from the
   sibling arm in program_assembly which forwards d. It now forwards d unchanged,
   so one failure yields one diagnostic regardless of entry point.

2. Grammar prepare hoisted above the fold, mirroring
   program_assembly_prepare_once_note. The derivation called parse_module per
   read, re-validating the grammar K times over a K-module ingest; it now
   prepares once and uses parse_module_prepared. Empty ingest is guarded so it
   never pays the prepare for zero reads. Same cost-shape defect the assembly
   fold already documents (§6 always-fix).

3. Witness lanes split per the operator 5-second rule (CI EvalBudgetExceeded:
   4 witnesses at ~5002ms). Measured by differencing against the non-parsing
   witness, parse-derived eval is ~13s — inherently over the fast-lane budget
   even after fix 2. Per gunbc.ci_layer_roots long_lane_exclusion_note ("fast
   receipts stay discovered, execution proofs live in long/"), the parse-derived
   proofs move to src/v2/test/claim/long/, and the fast lane keeps NEW witnesses
   that exercise the §5 construction wall over hand-built rows at zero parse
   cost: duplicate-module refusal, its accept control, and the produced/zero-file
   arm. Duplicate detection keys on module identity independently of provenance,
   which is why the wall is provable without a parse.

All eight witnesses green by execution across both lanes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* Gate-A re-probe post-#6859+#6868: repoint 04_infer/program_partition to std_dup bucket

Re-probed all seven Gate-A candidates with CSSL_STD_SEED_LINK=1 on
integration/sharp-bee-290. No cargo-green flips (baseline stays 6).
#6868 Ord fix cleared btree_set_ord for 04_infer/program_partition;
both now refuse on Witness std_dup alongside 01_tokenize. Four modules
still refuse UNRESOLVED_CompilerError. Bank execution receipts in
docs/probes/gate_a_reprobe_2026-07-19.tsv and tail_reprobe_2026-07-19.tsv.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(probes): add cssl_std_seed_link and shim_lib_rel columns to re-probe TSVs

Invocation metadata for std_dup fix lane: all 19 probes were raw-closure
(CSSL_STD_SEED_LINK=1, shim_lib_rel empty — no lane shims passed).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Weak Self Host -> Strong Self Host (Wave 1 -> 4, on 1 exit)

* WIP: Weak Self Host -> Strong Self Host (Wave 1 -> 4, on 1 exit)

* integration: address review 39722/39727 — admission scanner refuses (never widens), provenance de-fork, stale note, KeySource import

Review 39722 (claude, RC) three findings + review 39727 (cursor, RC) two findings, all verified:

1. §5 absorbing fallback in the witness-admission scanner: rewritten as per-form structural extraction that is fail-closed BOTH ways — every occurrence of a recognized row head (bin_wet, probe_red, self_host_wet_entry, SelfHostWetReceiptBinding) either parses to a key, is a verified definition/non-literal pass-through site, or PANICS with source label + byte offset; the catch-all entry/function loop (the widen arm that could silently excuse orphans) is DELETED. A consumer in an unrecognized form now surfaces as a loud orphan, never an absorbed excuse. Call sites carry source labels (the 39727 arity finding was the auto-WIP intermediate state; complete here).

2. §3 parallel authority (borderline per reviewer): the dissolve-on marker now names the tracked lane (module-binding supply-carrier pattern; host consumes emitted manifest rows) and the interim scan's fail-closed semantics.

3. §2 byte-identical provenance pair: source_ir_node_artifact_provenance_add_from_model + _add wrapper DELETED (pre-existing on main, not introduced by the wave — verified via git show origin/main); consumers repointed (edit_locus_resolver_test import + 2 calls, internal :627 site). Zero references remain.

4. Stale fork note in module_storage_binding_derivation_test updated: the qualified_name fork it described was dissolved in this wave (renamed apart); note now records the resolution.

5. Operator-requested: dag/std/realization.dag KeySource unlisted-import x3 (pre-existing main defect) fixed — KeySource added to the std.effects import list; source_authority closure compile-clean 3 -> 0 diagnostics.

Receipts: cargo build release clean; admission unit tests 2/2 (witness_admission_deferred_rows_have_consumers, witness_admission_orphan_synthetic_row_refuses); module_storage_binding witnesses PASS; edit_locus_resolver witnesses PASS on the repointed name.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* integration: rustfmt the admission scanner

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* plan: v1-deletion dependency graph as .dag — milestones, serial-vs-fanout, critical path (operator 2-week target)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* plan: record 2026-07-19 census discharges — Ord fix cleared btree_set_ord, KeySource import fix cleared the whole unresolved bucket; ~19 modules now on the one std_dup fix

Verified by execution at f071536: all 6 formerly-UNRESOLVED closures
(00_compile, materialization_carriers, program_assembly, source_authority,
02_parse, 03_ingest) compile 0 diagnostics; re-probe TSVs (#6872) show
04_infer/program_partition emit clean with std_dup as sole refusal.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 19, 2026
…n-note disposition (single merge point) (#6885)

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* emit: generalize BTreeSet Ord eligibility for Symbol-wrapped carriers

FormalNonterminal and FormalTerminal ({ identity: Symbol }) now pass
rust_btree_set_element_ord_eligible and receive Ord derives, unblocking
04_infer and program_partition self-emit cargo probes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* Module identity Phase 1: the path⇄module binding authority (parse-derived, fail-closed)

Homes the path⇄module binding on v2.compiler.source_authority as a
DERIVED-at-parse fact per docs/plans/module-identity-storage-binding-design.md §2.

- ModuleStorageProvenance = ParsedFromSource { artifact, span_index }
  | ProducedByBehavior { producer } — zero-file produced modules are now
  representable honestly instead of being excluded.
- ModuleStorageBinding / ModuleStorageIndex, reusing QualifiedName, Artifact,
  SourceRootRef and SpanIndex (no new nickname, §3).
- Both projections: file -> module and module -> storage.
- Scope is the LIVE 1:1 binding; many-to-many is a named deferral (§6).

§5 fail-closed repair in v2.compiler.program_assembly: the Rejected arm of
qualified_name_from_module_node kept the root and left the index UNCHANGED,
so a module whose name could not be derived went silently invisible to every
downstream lookup — an absorbing fallback in drop form, its frequency zeroed
by construction. It now refuses with the located diagnostic.

Witnesses (green by execution, REDs verified discriminating by perturbation):
derivation from parse; path projection; duplicate-module refuses; underivable
name refuses; produced module has no storage.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Consolidate the qualified_name_from_segment_list §3 fork (LIVE runtime h

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* review: forward located diagnostics; hoist grammar prepare; split fast/long witness lanes

Three fixes from review + CI.

1. Located refusal (cursor/composer-2.5). The name-derivation Rejected arm
   discarded the derivation's diagnostics and substituted a port-level
   source_authority_diagnostic — satisfying "typed" while destroying "located"
   (§5 requires both), contradicting this PR's own notes, and diverging from the
   sibling arm in program_assembly which forwards d. It now forwards d unchanged,
   so one failure yields one diagnostic regardless of entry point.

2. Grammar prepare hoisted above the fold, mirroring
   program_assembly_prepare_once_note. The derivation called parse_module per
   read, re-validating the grammar K times over a K-module ingest; it now
   prepares once and uses parse_module_prepared. Empty ingest is guarded so it
   never pays the prepare for zero reads. Same cost-shape defect the assembly
   fold already documents (§6 always-fix).

3. Witness lanes split per the operator 5-second rule (CI EvalBudgetExceeded:
   4 witnesses at ~5002ms). Measured by differencing against the non-parsing
   witness, parse-derived eval is ~13s — inherently over the fast-lane budget
   even after fix 2. Per gunbc.ci_layer_roots long_lane_exclusion_note ("fast
   receipts stay discovered, execution proofs live in long/"), the parse-derived
   proofs move to src/v2/test/claim/long/, and the fast lane keeps NEW witnesses
   that exercise the §5 construction wall over hand-built rows at zero parse
   cost: duplicate-module refusal, its accept control, and the produced/zero-file
   arm. Duplicate detection keys on module identity independently of provenance,
   which is why the wall is provable without a parse.

All eight witnesses green by execution across both lanes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* Gate-A re-probe post-#6859+#6868: repoint 04_infer/program_partition to std_dup bucket

Re-probed all seven Gate-A candidates with CSSL_STD_SEED_LINK=1 on
integration/sharp-bee-290. No cargo-green flips (baseline stays 6).
#6868 Ord fix cleared btree_set_ord for 04_infer/program_partition;
both now refuse on Witness std_dup alongside 01_tokenize. Four modules
still refuse UNRESOLVED_CompilerError. Bank execution receipts in
docs/probes/gate_a_reprobe_2026-07-19.tsv and tail_reprobe_2026-07-19.tsv.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(probes): add cssl_std_seed_link and shim_lib_rel columns to re-probe TSVs

Invocation metadata for std_dup fix lane: all 19 probes were raw-closure
(CSSL_STD_SEED_LINK=1, shim_lib_rel empty — no lane shims passed).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Weak Self Host -> Strong Self Host (Wave 1 -> 4, on 1 exit)

* WIP: Weak Self Host -> Strong Self Host (Wave 1 -> 4, on 1 exit)

* integration: address review 39722/39727 — admission scanner refuses (never widens), provenance de-fork, stale note, KeySource import

Review 39722 (claude, RC) three findings + review 39727 (cursor, RC) two findings, all verified:

1. §5 absorbing fallback in the witness-admission scanner: rewritten as per-form structural extraction that is fail-closed BOTH ways — every occurrence of a recognized row head (bin_wet, probe_red, self_host_wet_entry, SelfHostWetReceiptBinding) either parses to a key, is a verified definition/non-literal pass-through site, or PANICS with source label + byte offset; the catch-all entry/function loop (the widen arm that could silently excuse orphans) is DELETED. A consumer in an unrecognized form now surfaces as a loud orphan, never an absorbed excuse. Call sites carry source labels (the 39727 arity finding was the auto-WIP intermediate state; complete here).

2. §3 parallel authority (borderline per reviewer): the dissolve-on marker now names the tracked lane (module-binding supply-carrier pattern; host consumes emitted manifest rows) and the interim scan's fail-closed semantics.

3. §2 byte-identical provenance pair: source_ir_node_artifact_provenance_add_from_model + _add wrapper DELETED (pre-existing on main, not introduced by the wave — verified via git show origin/main); consumers repointed (edit_locus_resolver_test import + 2 calls, internal :627 site). Zero references remain.

4. Stale fork note in module_storage_binding_derivation_test updated: the qualified_name fork it described was dissolved in this wave (renamed apart); note now records the resolution.

5. Operator-requested: dag/std/realization.dag KeySource unlisted-import x3 (pre-existing main defect) fixed — KeySource added to the std.effects import list; source_authority closure compile-clean 3 -> 0 diagnostics.

Receipts: cargo build release clean; admission unit tests 2/2 (witness_admission_deferred_rows_have_consumers, witness_admission_orphan_synthetic_row_refuses); module_storage_binding witnesses PASS; edit_locus_resolver witnesses PASS on the repointed name.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* integration: rustfmt the admission scanner

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* plan: v1-deletion dependency graph as .dag — milestones, serial-vs-fanout, critical path (operator 2-week target)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* plan: record 2026-07-19 census discharges — Ord fix cleared btree_set_ord, KeySource import fix cleared the whole unresolved bucket; ~19 modules now on the one std_dup fix

Verified by execution at f071536: all 6 formerly-UNRESOLVED closures
(00_compile, materialization_carriers, program_assembly, source_authority,
02_parse, 03_ingest) compile 0 diagnostics; re-probe TSVs (#6872) show
04_infer/program_partition emit clean with std_dup as sole refusal.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(cssl): assembly std_dup unlock — Witness sanitize + v2_std emit-retain

Single assembly fix for the 13-module std_dup gate (calm-boar-697 census):
- sanitize_witness_import_conflict matches `pub enum Witness<C>` (generic),
  stripping v1_rt::Witness prelude imports that collided with emitted enum
- v2_std_* emit-retain instead of minimal bridge shims (broken dependents
  like v2_std_logic → v2_std_algebra re-exports)

No emitter changes. Probes move past HARNESS_ARTIFACT_std_dup / E0255 on all
Gate-A modules + tail representatives; next blockers surface as namespace gaps.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(probes): post-std_dup re-probe on proud-deer ed68594 (13 modules)

CSSL_STD_SEED_LINK=1, shim_lib_rel empty, rebuilt cssl_assemble. std_dup
E0255 cleared on 12/13; new namespace layer surfaces (FreeMonoid,
ResolvedTree, InferredTree/InferredFacts). emit_produced: Optional std_dup
residue. Harness invocation contract in probe script header.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(probes): baseline caveat + probe_notes on post-std_dup TSV (#6884)

ed68594 predates #6883 emit-retain; mark ResolvedTree/InferredTree rows
EXPECTED-CLEARED. emit_produced Optional routed to proud-deer. FreeMonoid
rows flagged as live next-layer census post-#6883.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(#6880): cargo-stage unresolved re-probe + plan census correction on main

Rebased onto main post-#6866. Remaining delta: KeySource cargo-stage TSV,
embedded-marker grep receipt, v1_deletion_plan corrections (13 std_dup vs 6
unresolved, ROOT-CAUSED emitter-gap, stern-lark-430 dispatched). Gate-A/tail
frontier rows already landed via integration merge.

Co-authored-by: Cursor <cursoragent@cursor.com>

* witness_admission: bounded dissolution note on the two single-arm predicates (review 39758 disposition)

Phase 0(b) author closed out; disposition owned by sharp-bee-290 per the
capture. Pattern matches target_value_expr_int_literal_predicate_dissolution_note.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* plan(#6880): resolve integration merge — std_dup LANDED #6876, flip-wave unblocked

Fold integration/sharp-bee-290 at 81dc2d9; update v1_deletion_plan lane_state
to current truth (13+6 census retained, probe_flip_fanout unblocked pending emitter fixes).

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 19, 2026
#6880)

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* emit: generalize BTreeSet Ord eligibility for Symbol-wrapped carriers

FormalNonterminal and FormalTerminal ({ identity: Symbol }) now pass
rust_btree_set_element_ord_eligible and receive Ord derives, unblocking
04_infer and program_partition self-emit cargo probes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* Module identity Phase 1: the path⇄module binding authority (parse-derived, fail-closed)

Homes the path⇄module binding on v2.compiler.source_authority as a
DERIVED-at-parse fact per docs/plans/module-identity-storage-binding-design.md §2.

- ModuleStorageProvenance = ParsedFromSource { artifact, span_index }
  | ProducedByBehavior { producer } — zero-file produced modules are now
  representable honestly instead of being excluded.
- ModuleStorageBinding / ModuleStorageIndex, reusing QualifiedName, Artifact,
  SourceRootRef and SpanIndex (no new nickname, §3).
- Both projections: file -> module and module -> storage.
- Scope is the LIVE 1:1 binding; many-to-many is a named deferral (§6).

§5 fail-closed repair in v2.compiler.program_assembly: the Rejected arm of
qualified_name_from_module_node kept the root and left the index UNCHANGED,
so a module whose name could not be derived went silently invisible to every
downstream lookup — an absorbing fallback in drop form, its frequency zeroed
by construction. It now refuses with the located diagnostic.

Witnesses (green by execution, REDs verified discriminating by perturbation):
derivation from parse; path projection; duplicate-module refuses; underivable
name refuses; produced module has no storage.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Consolidate the qualified_name_from_segment_list §3 fork (LIVE runtime h

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Module identity Phase 1: the path⇄module binding authority — parse-deriv

* WIP: Module identity Phase 0(b): the admission invariant — every witness row

* review: forward located diagnostics; hoist grammar prepare; split fast/long witness lanes

Three fixes from review + CI.

1. Located refusal (cursor/composer-2.5). The name-derivation Rejected arm
   discarded the derivation's diagnostics and substituted a port-level
   source_authority_diagnostic — satisfying "typed" while destroying "located"
   (§5 requires both), contradicting this PR's own notes, and diverging from the
   sibling arm in program_assembly which forwards d. It now forwards d unchanged,
   so one failure yields one diagnostic regardless of entry point.

2. Grammar prepare hoisted above the fold, mirroring
   program_assembly_prepare_once_note. The derivation called parse_module per
   read, re-validating the grammar K times over a K-module ingest; it now
   prepares once and uses parse_module_prepared. Empty ingest is guarded so it
   never pays the prepare for zero reads. Same cost-shape defect the assembly
   fold already documents (§6 always-fix).

3. Witness lanes split per the operator 5-second rule (CI EvalBudgetExceeded:
   4 witnesses at ~5002ms). Measured by differencing against the non-parsing
   witness, parse-derived eval is ~13s — inherently over the fast-lane budget
   even after fix 2. Per gunbc.ci_layer_roots long_lane_exclusion_note ("fast
   receipts stay discovered, execution proofs live in long/"), the parse-derived
   proofs move to src/v2/test/claim/long/, and the fast lane keeps NEW witnesses
   that exercise the §5 construction wall over hand-built rows at zero parse
   cost: duplicate-module refusal, its accept control, and the produced/zero-file
   arm. Duplicate detection keys on module identity independently of provenance,
   which is why the wall is provable without a parse.

All eight witnesses green by execution across both lanes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* WIP: Emitter Ord-eligibility unlock: rust_btree_set_element_ord_eligible cons

* Gate-A re-probe post-#6859+#6868: repoint 04_infer/program_partition to std_dup bucket

Re-probed all seven Gate-A candidates with CSSL_STD_SEED_LINK=1 on
integration/sharp-bee-290. No cargo-green flips (baseline stays 6).
#6868 Ord fix cleared btree_set_ord for 04_infer/program_partition;
both now refuse on Witness std_dup alongside 01_tokenize. Four modules
still refuse UNRESOLVED_CompilerError. Bank execution receipts in
docs/probes/gate_a_reprobe_2026-07-19.tsv and tail_reprobe_2026-07-19.tsv.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(probes): add cssl_std_seed_link and shim_lib_rel columns to re-probe TSVs

Invocation metadata for std_dup fix lane: all 19 probes were raw-closure
(CSSL_STD_SEED_LINK=1, shim_lib_rel empty — no lane shims passed).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Weak Self Host -> Strong Self Host (Wave 1 -> 4, on 1 exit)

* WIP: Weak Self Host -> Strong Self Host (Wave 1 -> 4, on 1 exit)

* integration: address review 39722/39727 — admission scanner refuses (never widens), provenance de-fork, stale note, KeySource import

Review 39722 (claude, RC) three findings + review 39727 (cursor, RC) two findings, all verified:

1. §5 absorbing fallback in the witness-admission scanner: rewritten as per-form structural extraction that is fail-closed BOTH ways — every occurrence of a recognized row head (bin_wet, probe_red, self_host_wet_entry, SelfHostWetReceiptBinding) either parses to a key, is a verified definition/non-literal pass-through site, or PANICS with source label + byte offset; the catch-all entry/function loop (the widen arm that could silently excuse orphans) is DELETED. A consumer in an unrecognized form now surfaces as a loud orphan, never an absorbed excuse. Call sites carry source labels (the 39727 arity finding was the auto-WIP intermediate state; complete here).

2. §3 parallel authority (borderline per reviewer): the dissolve-on marker now names the tracked lane (module-binding supply-carrier pattern; host consumes emitted manifest rows) and the interim scan's fail-closed semantics.

3. §2 byte-identical provenance pair: source_ir_node_artifact_provenance_add_from_model + _add wrapper DELETED (pre-existing on main, not introduced by the wave — verified via git show origin/main); consumers repointed (edit_locus_resolver_test import + 2 calls, internal :627 site). Zero references remain.

4. Stale fork note in module_storage_binding_derivation_test updated: the qualified_name fork it described was dissolved in this wave (renamed apart); note now records the resolution.

5. Operator-requested: dag/std/realization.dag KeySource unlisted-import x3 (pre-existing main defect) fixed — KeySource added to the std.effects import list; source_authority closure compile-clean 3 -> 0 diagnostics.

Receipts: cargo build release clean; admission unit tests 2/2 (witness_admission_deferred_rows_have_consumers, witness_admission_orphan_synthetic_row_refuses); module_storage_binding witnesses PASS; edit_locus_resolver witnesses PASS on the repointed name.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* integration: rustfmt the admission scanner

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* plan: v1-deletion dependency graph as .dag — milestones, serial-vs-fanout, critical path (operator 2-week target)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* plan: record 2026-07-19 census discharges — Ord fix cleared btree_set_ord, KeySource import fix cleared the whole unresolved bucket; ~19 modules now on the one std_dup fix

Verified by execution at f071536: all 6 formerly-UNRESOLVED closures
(00_compile, materialization_carriers, program_assembly, source_authority,
02_parse, 03_ingest) compile 0 diagnostics; re-probe TSVs (#6872) show
04_infer/program_partition emit clean with std_dup as sole refusal.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(cssl): assembly std_dup unlock — Witness sanitize + v2_std emit-retain

Single assembly fix for the 13-module std_dup gate (calm-boar-697 census):
- sanitize_witness_import_conflict matches `pub enum Witness<C>` (generic),
  stripping v1_rt::Witness prelude imports that collided with emitted enum
- v2_std_* emit-retain instead of minimal bridge shims (broken dependents
  like v2_std_logic → v2_std_algebra re-exports)

No emitter changes. Probes move past HARNESS_ARTIFACT_std_dup / E0255 on all
Gate-A modules + tail representatives; next blockers surface as namespace gaps.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(probes): post-std_dup re-probe on proud-deer ed68594 (13 modules)

CSSL_STD_SEED_LINK=1, shim_lib_rel empty, rebuilt cssl_assemble. std_dup
E0255 cleared on 12/13; new namespace layer surfaces (FreeMonoid,
ResolvedTree, InferredTree/InferredFacts). emit_produced: Optional std_dup
residue. Harness invocation contract in probe script header.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(probes): baseline caveat + probe_notes on post-std_dup TSV (#6884)

ed68594 predates #6883 emit-retain; mark ResolvedTree/InferredTree rows
EXPECTED-CLEARED. emit_produced Optional routed to proud-deer. FreeMonoid
rows flagged as live next-layer census post-#6883.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(#6880): cargo-stage unresolved re-probe + plan census correction on main

Rebased onto main post-#6866. Remaining delta: KeySource cargo-stage TSV,
embedded-marker grep receipt, v1_deletion_plan corrections (13 std_dup vs 6
unresolved, ROOT-CAUSED emitter-gap, stern-lark-430 dispatched). Gate-A/tail
frontier rows already landed via integration merge.

Co-authored-by: Cursor <cursoragent@cursor.com>

* witness_admission: bounded dissolution note on the two single-arm predicates (review 39758 disposition)

Phase 0(b) author closed out; disposition owned by sharp-bee-290 per the
capture. Pattern matches target_value_expr_int_literal_predicate_dissolution_note.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* plan(#6880): resolve integration merge — std_dup LANDED #6876, flip-wave unblocked

Fold integration/sharp-bee-290 at 81dc2d9; update v1_deletion_plan lane_state
to current truth (13+6 census retained, probe_flip_fanout unblocked pending emitter fixes).

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants