Repository navigation
sub charclass - #693
sub charclass#693
Conversation
|
Review note: This looks like real progress, but it reads as a partial closure rather than full What the diff clearly does:
What still appears missing relative to the lane brief / roadmap framing:
So I’d suggest either:
Without that clarification, the risk is that we mark |
|
Review metadata
Verdict: APPROVE — the diff is small and narrowly scoped: it lifts ASCII lexical classification from hidden host predicates ( Exploratory observations (non-blocking):
|
Clarify bounded closure: std.unicode authority + Rust mirror + gate; syntax.dag retagging and structural CharClass data in tokenize.dag remain follow-ups (M1(2.8) class-5 gap #3). PR body updated on GitHub. Made-with: Cursor
|
Review metadata
Findings
Verdict |
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
0ff74578· Trigger:schedule - Thinking:
319s wall
BLOCKING (2)
Root Cause
dsl/std/unicode.dagNew lexical class authority lands as a raw sum without recording whether the variants are terminal or a bounded scaffold → add the classification receipt and named trigger next to the declaration, or dissolve it into structural rows now.dsl/std/unicode.dagThe Digit predicate is being reused by calling the whole classifier recursively → extract a non-recursive codepoint predicate or duplicate the bounded range check inIdentContinue.
Non-blocking — Strengths
src/v3/compiler/src/tokenize_char_class.rsThe Rust mirror is documented, scoped to ASCII tokenizer semantics, and names the M1(2.8) class-5 trigger for deletion.
ROADMAP — Verified
- sub_charclass_in_std_unicode tokenizer half: This PR adds
std.unicode::CharClass/char_in_classand routes generated tokenizer predicates through the mirrored class API.
ROADMAP — Incomplete
- sub_charclass_in_std_unicode full lane:
syntax.dagretagging and structuralCharClassrows intokenize.dagremain deferred, as the PR body states.
| // tokenizer authority, revisit whether this sum moves to a lexical sibling | ||
| // (e.g. std-facing tokenize) vs staying co-located with scalar `Char` helpers. | ||
|
|
||
| type CharClass = Whitespace | Digit | IdentStart | IdentContinue |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
| Whitespace => cp == 9 || cp == 10 || cp == 12 || cp == 13 || cp == 32 | ||
| Digit => cp >= 48 && cp <= 57 | ||
| IdentStart => (cp >= 65 && cp <= 90) || (cp >= 97 && cp <= 122) || cp == 95 | ||
| IdentContinue => char_in_class(c: c, class: Digit) |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
|
Review metadata
Verdict: APPROVE — small, narrowly scoped interim bridge that's properly documented as tracked debt. The diff introduces
All three tracked-debt properties present, so the parallel-representation concern is acceptable per the layered model rules. Exploratory observations (optional):
|
|
Review metadata
Findings
Verdict: APPROVE_WITH_COMMENTS. The actual tokenizer behavior change looks narrow, documented, and ratcheted; my only concern is the public export of the temporary mirror rather than the mirror logic itself. |
… unit tests API review on #693: avoid publishing the interim tokenizer CharClass bridge as v3_compiler public API. Fold sub_charclass_in_std_unicode checks into #[cfg(test)] on tokenize_char_class; drop the integration module. Make TokenizerCharClass/byte_matches pub(crate). Refresh parse_corpus_manifest for tokenize.dag comment churn. Made-with: Cursor
…iple 4) Inline 🟢 TERMINAL ledger for the four-pattern check per modeling-discipline.md; addresses blocking review on PR #693 (substrate coproduct without receipt). Made-with: Cursor
Clarify bounded closure: std.unicode authority + Rust mirror + gate; syntax.dag retagging and structural CharClass data in tokenize.dag remain follow-ups (M1(2.8) class-5 gap #3). PR body updated on GitHub. Made-with: Cursor
… unit tests API review on #693: avoid publishing the interim tokenizer CharClass bridge as v3_compiler public API. Fold sub_charclass_in_std_unicode checks into TokenizerCharClass/byte_matches pub(crate). Refresh parse_corpus_manifest for tokenize.dag comment churn. Made-with: Cursor
…iple 4) Inline 🟢 TERMINAL ledger for the four-pattern check per modeling-discipline.md; addresses blocking review on PR #693 (substrate coproduct without receipt). Made-with: Cursor
3c56d49 to
32db8e1
Compare
|
Review metadata
Verdict: APPROVE Small, well-scoped change. Adds Findings: none worth blocking on. Exploratory observations (non-blocking):
|
Clarify bounded closure: std.unicode authority + Rust mirror + gate; syntax.dag retagging and structural CharClass data in tokenize.dag remain follow-ups (M1(2.8) class-5 gap #3). PR body updated on GitHub. Made-with: Cursor
… unit tests API review on #693: avoid publishing the interim tokenizer CharClass bridge as v3_compiler public API. Fold sub_charclass_in_std_unicode checks into TokenizerCharClass/byte_matches pub(crate). Refresh parse_corpus_manifest for tokenize.dag comment churn. Made-with: Cursor
…iple 4) Inline 🟢 TERMINAL ledger for the four-pattern check per modeling-discipline.md; addresses blocking review on PR #693 (substrate coproduct without receipt). Made-with: Cursor
32db8e1 to
db03c85
Compare
|
Review metadata
Verdict: APPROVE. No findings. I don’t see a concrete violation of |
… row - Inline digit + letter ranges in byte_matches::IdentContinue to match unicode.dag (same CX rationale as .dag authority). - Add ROADMAP ledger row for interpreter-backed char_in_class vs byte_matches parity on 0..=127 (PR #693 bridge finish). Made-with: Cursor
|
Review metadata
Findings: none blocking.
Two SHARED-READS, not parallel-representation: Verdict: APPROVE — narrow, well-framed bridge step with proper dissolution receipt, tracked debt entry, and tests that lock the mirror against drift. Nothing in this diff violates the rubric. |
|
Review metadata
Findings
Verdict |
|
Review metadata
Verdict: APPROVE The diff routes the tokenizer's four Exploratory (non-asks):
|
Clarify bounded closure: std.unicode authority + Rust mirror + gate; syntax.dag retagging and structural CharClass data in tokenize.dag remain follow-ups (M1(2.8) class-5 gap #3). PR body updated on GitHub. Made-with: Cursor
… unit tests API review on #693: avoid publishing the interim tokenizer CharClass bridge as v3_compiler public API. Fold sub_charclass_in_std_unicode checks into TokenizerCharClass/byte_matches pub(crate). Refresh parse_corpus_manifest for tokenize.dag comment churn. Made-with: Cursor
9eb98ff to
1d30377
Compare
…iple 4) Inline 🟢 TERMINAL ledger for the four-pattern check per modeling-discipline.md; addresses blocking review on PR #693 (substrate coproduct without receipt). Made-with: Cursor
… row - Inline digit + letter ranges in byte_matches::IdentContinue to match unicode.dag (same CX rationale as .dag authority). - Add ROADMAP ledger row for interpreter-backed char_in_class vs byte_matches parity on 0..=127 (PR #693 bridge finish). Made-with: Cursor
|
Review metadata
Verdict: APPROVE. Diff is narrowly scoped, the new |
|
Review metadata
This is a narrowly scoped tokenizer-half bridge: adds Tracked-bridge check on
The PR is also self-aware about the test side being weaker than ideal: the anchors are substring-based and the behavioral lock is Consistency spot-checks pass: Exploratory observation (non-blocking): the PR's own doc flags concept placement — Verdict: APPROVE — narrow, well-documented tokenizer-half bridge with a concrete dissolution trigger. No invariant/principle violations grounded in the diff. |
…edger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
Minor citation-fix ask from the director-side ROADMAP amendment (PR #706): Your PR body cites
Please update the PR body's citation to (Governance note: the director-side amendment at #706 retracts the 2026-04-23 "no substrate capability gap" claim this PR's execution surfaced. Phase-1 scope here is fully endorsed — this is a citation-sync ask only.) |
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
556d3584· Trigger:schedule - Thinking:
271s wall
Non-blocking — Strengths
src/v3/compiler/src/tokenize_char_class.rsThe interim mirror now has unit coverage for generated-tokenizer wiring and 0..=127 ASCII behavior until interpreter-backed parity lands.
ROADMAP — Verified
- char_in_class interpreter parity: The new row explicitly tracks replacing the host-stdlib ratchet with evaluated
char_in_classparity and deleting the mirror under the structural scanner-row gate.
✅ No blocking concerns remain in the current diff.
…director, post-#693 escalation) (#706) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…post-2026-04-24 merge wave (#738) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…f-hosting design proposal (supersedes ≤5-floor framing) (#762) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…el-program manager for 0-floor self-hosting per #762) (#766) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…ic across 5 authority docs) (#782) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c3 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c3: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b03 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b03 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e691.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c3 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c3: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b03 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b03 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e691.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 second-wave worker-escalation fixes Four substantive worker STOP-AND-ESCALATEs from briefs landed in PR #797. All four worker recommendations correct; each needs a Director call + brief update. ## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate Worker correctly identified that brief req 2 (declared-effect carrier as part of fn type signature, per feedback_no_annotations) requires net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots. Without parser surface, every user function would have declared_effects = [] while inference returns non-empty — lens fires EffectLeakageError everywhere on enable. Worker rejected power-through and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map parser split). Director picked split: - NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface syntax + lookahead + body parser + lowerer extension + exhaustive-match audit + coproduct dissolution receipt. - MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to post-parser-extension scope. Pre-flight check NOT a parser-extension step; STOP if parser sub-lane PR not merged. ## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping Worker found load-bearing evidence at infer.rs:3693-3703: DB-11 deliberately strips refinements at operator dispatch as a designed-in fix for symmetric-operators failure mode. Brief's "attach where b != 0 as a proof for a / b" directly contradicts this design choice. STOP-3 (where-clause conflict with DB-11) is real; STOP-1 (substrate scope) needs net-new substrate (per-operator partiality fact + predicate- entailment check + asymmetric per-operand refinement-honoring) — M+ minimum. ownership_lens precedent in original brief is post-hoc observability, not proof carrier. Worker recommended redirect to design/scoping per nested-optional precedent. Director picked redirect. Brief fully rewritten as design/scoping with four-question structure: (1) DB-11 interaction analysis; (2) substrate proposal for proof-or- totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes with acceptance-theatre risk on user-defined-total-wrapper-only); (4) Director-actionable recommendation. Output is doc PR. ## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C) Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int) with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136 closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b) i128 implementation requires either path 1 (hierarchy refactor — contradicts non-goal) or path 2 (regen lie between substrate and emit — violates discipline). Worker leaned option (C) re-scope: land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke) to a sibling sub-lane that does proper Int128/Word128 substrate work. Director picked option (C). Brief req 1 re-scoped to drop canonical- carrier-widening; lane value comes from range facts + reconciliation narrowing + out-of-range diagnostic against existing i64. Req 4 explicitly deferred with sibling-sub-lane reference. Sibling sub-lane NOT to be authored or implied in this PR; tracked separately. ## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change) Worker correctly STOP'd per the brief's own pre-flight check: parser sub-lane has not landed; SurfaceExpr::Map not on main. Director authorized cross-lane reassignment: wise-boar-480 takes the parser sub-lane (t-substrate-valuebody-map-parser-worker.md) since they already have full investigation context. No brief changes needed; the routing decision is in the dispatch. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope Resolves codex P2 inline at sha e35103f on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still required widening LiteralBits::Int(i64) to an unbounded carrier and passing the i64::MIN smoke. Internally unsatisfiable. Fix: - Slice section retitled "range facts + reconciliation narrowing (against existing i64 carrier)" with explicit note about the re-scope. - Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly forbids touching LiteralBits::Int shape, dag_scalar_generated.rs regen for that variant, or tokenize i64 parse path. - Slice steps 2-5 reframed: range facts use i64-representable magnitudes; reconciliation narrowing uses existing i64 carrier; diagnostic only for i64-representable out-of-range; smoke tests for req 5 only (req 4 i64::MIN deferred). - Acceptance checklist updated: - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as re-scoped/deferred. - LiteralBits::Int(i64) carrier untouched (no widening; no parallel; no shape change). - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference. - STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the carrier" — explicit STOP if execution surfaces range-fact narrowing requiring carrier-widening; that's the boundary the re-scope drew; belongs in sibling Int128/Word128 sub-lane. Brief now consistently treats carrier-widening as out-of-scope across all sections. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty Resolves codex BLOCKING #1 at sha e35103f on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier but req 2 required range facts using "the SAME magnitude carrier as req 1" — meaning i64-typed range bounds. u64's max (2^64-1) doesn't fit in i64; range fact for u64 would have to truncate, omit, or mirror in Rust (representation drift). All three options violate fail-closed declared-facts discipline (P1 / P3). Fix: - Req 2 rewritten to specify String-decimal representation: range_min_inclusive: String + range_max_inclusive: String fields on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127" for i8; "0"/"18446744073709551615" for u64). - Explicit reasoning why String-decimal: u64's max doesn't fit in i64; binding range bounds to literal carrier forces truncation/ omission/mirror-drift; all violate fail-closed declared-facts discipline. - Bridge framing: String-decimal is pending the sibling Int128/ Word128 sub-lane; both range bounds and literal payload migrate to typed carrier when that lands. - Req 3 updated for String-decimal comparison semantics: reconciliation parses both bounds and literal magnitude into a common comparison space (i128 host comparison primitive — host narrowing, NOT carrier widening). Bounded by what the i64-typed literal can express; any i64-representable literal compares against any width's String-decimal bound. Carrier discipline preserved. Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral) is sha-stale — already resolved at 3e142d1. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c3 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c3: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b03 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b03 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e691.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 second-wave worker-escalation fixes Four substantive worker STOP-AND-ESCALATEs from briefs landed in PR #797. All four worker recommendations correct; each needs a Director call + brief update. ## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate Worker correctly identified that brief req 2 (declared-effect carrier as part of fn type signature, per feedback_no_annotations) requires net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots. Without parser surface, every user function would have declared_effects = [] while inference returns non-empty — lens fires EffectLeakageError everywhere on enable. Worker rejected power-through and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map parser split). Director picked split: - NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface syntax + lookahead + body parser + lowerer extension + exhaustive-match audit + coproduct dissolution receipt. - MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to post-parser-extension scope. Pre-flight check NOT a parser-extension step; STOP if parser sub-lane PR not merged. ## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping Worker found load-bearing evidence at infer.rs:3693-3703: DB-11 deliberately strips refinements at operator dispatch as a designed-in fix for symmetric-operators failure mode. Brief's "attach where b != 0 as a proof for a / b" directly contradicts this design choice. STOP-3 (where-clause conflict with DB-11) is real; STOP-1 (substrate scope) needs net-new substrate (per-operator partiality fact + predicate- entailment check + asymmetric per-operand refinement-honoring) — M+ minimum. ownership_lens precedent in original brief is post-hoc observability, not proof carrier. Worker recommended redirect to design/scoping per nested-optional precedent. Director picked redirect. Brief fully rewritten as design/scoping with four-question structure: (1) DB-11 interaction analysis; (2) substrate proposal for proof-or- totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes with acceptance-theatre risk on user-defined-total-wrapper-only); (4) Director-actionable recommendation. Output is doc PR. ## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C) Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int) with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136 closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b) i128 implementation requires either path 1 (hierarchy refactor — contradicts non-goal) or path 2 (regen lie between substrate and emit — violates discipline). Worker leaned option (C) re-scope: land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke) to a sibling sub-lane that does proper Int128/Word128 substrate work. Director picked option (C). Brief req 1 re-scoped to drop canonical- carrier-widening; lane value comes from range facts + reconciliation narrowing + out-of-range diagnostic against existing i64. Req 4 explicitly deferred with sibling-sub-lane reference. Sibling sub-lane NOT to be authored or implied in this PR; tracked separately. ## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change) Worker correctly STOP'd per the brief's own pre-flight check: parser sub-lane has not landed; SurfaceExpr::Map not on main. Director authorized cross-lane reassignment: wise-boar-480 takes the parser sub-lane (t-substrate-valuebody-map-parser-worker.md) since they already have full investigation context. No brief changes needed; the routing decision is in the dispatch. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope Resolves codex P2 inline at sha e35103f on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still required widening LiteralBits::Int(i64) to an unbounded carrier and passing the i64::MIN smoke. Internally unsatisfiable. Fix: - Slice section retitled "range facts + reconciliation narrowing (against existing i64 carrier)" with explicit note about the re-scope. - Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly forbids touching LiteralBits::Int shape, dag_scalar_generated.rs regen for that variant, or tokenize i64 parse path. - Slice steps 2-5 reframed: range facts use i64-representable magnitudes; reconciliation narrowing uses existing i64 carrier; diagnostic only for i64-representable out-of-range; smoke tests for req 5 only (req 4 i64::MIN deferred). - Acceptance checklist updated: - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as re-scoped/deferred. - LiteralBits::Int(i64) carrier untouched (no widening; no parallel; no shape change). - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference. - STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the carrier" — explicit STOP if execution surfaces range-fact narrowing requiring carrier-widening; that's the boundary the re-scope drew; belongs in sibling Int128/Word128 sub-lane. Brief now consistently treats carrier-widening as out-of-scope across all sections. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty Resolves codex BLOCKING #1 at sha e35103f on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier but req 2 required range facts using "the SAME magnitude carrier as req 1" — meaning i64-typed range bounds. u64's max (2^64-1) doesn't fit in i64; range fact for u64 would have to truncate, omit, or mirror in Rust (representation drift). All three options violate fail-closed declared-facts discipline (P1 / P3). Fix: - Req 2 rewritten to specify String-decimal representation: range_min_inclusive: String + range_max_inclusive: String fields on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127" for i8; "0"/"18446744073709551615" for u64). - Explicit reasoning why String-decimal: u64's max doesn't fit in i64; binding range bounds to literal carrier forces truncation/ omission/mirror-drift; all violate fail-closed declared-facts discipline. - Bridge framing: String-decimal is pending the sibling Int128/ Word128 sub-lane; both range bounds and literal payload migrate to typed carrier when that lands. - Req 3 updated for String-decimal comparison semantics: reconciliation parses both bounds and literal magnitude into a common comparison space (i128 host comparison primitive — host narrowing, NOT carrier widening). Bounded by what the i64-typed literal can express; any i64-representable literal compares against any width's String-decimal bound. Carrier discipline preserved. Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral) is sha-stale — already resolved at 3e142d1. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed Resolves codex BLOCKING at sha 0815189 (post-#799-merge feedback). Real residual: req 2 specifies String-decimal range bounds (to cover u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" / "i64-representable magnitudes" for the range facts. Two incompatible authorities for the same range-fact shape — would let a worker satisfy the slice while truncating/omitting u64 bounds (P3 fail-closed violation). Fix: - Line 31 (req 1 re-scope clarification): updated to explicitly state "range facts (req 2) use String-decimal representation (width- independent; covers u64::MAX which doesn't fit in i64)". Distinguished literal *payload* (stays i64) from range-bound *representation* (String) — both serve req 1's "no carrier widening" boundary. - Line 44 (slice step 2): updated from "Range bounds use i64- representable magnitudes" to "Range bounds use String-decimal representation per req 2" with concrete example (u64 bounds). - Acceptance bullet: updated from "Range facts on integer algebras (substrate-declared, not Rust-mirrored)" to add "using String-decimal representation ... width-independent; u64 bounds expressible without truncation." The brief now consistently treats range bounds as String-decimal across req 2, req 3, slice, acceptance, and the req 1 clarification — no remaining authorities saying i64-typed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c3 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c3: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b03 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b03 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e691.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 second-wave worker-escalation fixes Four substantive worker STOP-AND-ESCALATEs from briefs landed in PR #797. All four worker recommendations correct; each needs a Director call + brief update. ## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate Worker correctly identified that brief req 2 (declared-effect carrier as part of fn type signature, per feedback_no_annotations) requires net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots. Without parser surface, every user function would have declared_effects = [] while inference returns non-empty — lens fires EffectLeakageError everywhere on enable. Worker rejected power-through and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map parser split). Director picked split: - NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface syntax + lookahead + body parser + lowerer extension + exhaustive-match audit + coproduct dissolution receipt. - MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to post-parser-extension scope. Pre-flight check NOT a parser-extension step; STOP if parser sub-lane PR not merged. ## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping Worker found load-bearing evidence at infer.rs:3693-3703: DB-11 deliberately strips refinements at operator dispatch as a designed-in fix for symmetric-operators failure mode. Brief's "attach where b != 0 as a proof for a / b" directly contradicts this design choice. STOP-3 (where-clause conflict with DB-11) is real; STOP-1 (substrate scope) needs net-new substrate (per-operator partiality fact + predicate- entailment check + asymmetric per-operand refinement-honoring) — M+ minimum. ownership_lens precedent in original brief is post-hoc observability, not proof carrier. Worker recommended redirect to design/scoping per nested-optional precedent. Director picked redirect. Brief fully rewritten as design/scoping with four-question structure: (1) DB-11 interaction analysis; (2) substrate proposal for proof-or- totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes with acceptance-theatre risk on user-defined-total-wrapper-only); (4) Director-actionable recommendation. Output is doc PR. ## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C) Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int) with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136 closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b) i128 implementation requires either path 1 (hierarchy refactor — contradicts non-goal) or path 2 (regen lie between substrate and emit — violates discipline). Worker leaned option (C) re-scope: land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke) to a sibling sub-lane that does proper Int128/Word128 substrate work. Director picked option (C). Brief req 1 re-scoped to drop canonical- carrier-widening; lane value comes from range facts + reconciliation narrowing + out-of-range diagnostic against existing i64. Req 4 explicitly deferred with sibling-sub-lane reference. Sibling sub-lane NOT to be authored or implied in this PR; tracked separately. ## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change) Worker correctly STOP'd per the brief's own pre-flight check: parser sub-lane has not landed; SurfaceExpr::Map not on main. Director authorized cross-lane reassignment: wise-boar-480 takes the parser sub-lane (t-substrate-valuebody-map-parser-worker.md) since they already have full investigation context. No brief changes needed; the routing decision is in the dispatch. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope Resolves codex P2 inline at sha e35103f on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still required widening LiteralBits::Int(i64) to an unbounded carrier and passing the i64::MIN smoke. Internally unsatisfiable. Fix: - Slice section retitled "range facts + reconciliation narrowing (against existing i64 carrier)" with explicit note about the re-scope. - Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly forbids touching LiteralBits::Int shape, dag_scalar_generated.rs regen for that variant, or tokenize i64 parse path. - Slice steps 2-5 reframed: range facts use i64-representable magnitudes; reconciliation narrowing uses existing i64 carrier; diagnostic only for i64-representable out-of-range; smoke tests for req 5 only (req 4 i64::MIN deferred). - Acceptance checklist updated: - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as re-scoped/deferred. - LiteralBits::Int(i64) carrier untouched (no widening; no parallel; no shape change). - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference. - STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the carrier" — explicit STOP if execution surfaces range-fact narrowing requiring carrier-widening; that's the boundary the re-scope drew; belongs in sibling Int128/Word128 sub-lane. Brief now consistently treats carrier-widening as out-of-scope across all sections. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty Resolves codex BLOCKING #1 at sha e35103f on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier but req 2 required range facts using "the SAME magnitude carrier as req 1" — meaning i64-typed range bounds. u64's max (2^64-1) doesn't fit in i64; range fact for u64 would have to truncate, omit, or mirror in Rust (representation drift). All three options violate fail-closed declared-facts discipline (P1 / P3). Fix: - Req 2 rewritten to specify String-decimal representation: range_min_inclusive: String + range_max_inclusive: String fields on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127" for i8; "0"/"18446744073709551615" for u64). - Explicit reasoning why String-decimal: u64's max doesn't fit in i64; binding range bounds to literal carrier forces truncation/ omission/mirror-drift; all violate fail-closed declared-facts discipline. - Bridge framing: String-decimal is pending the sibling Int128/ Word128 sub-lane; both range bounds and literal payload migrate to typed carrier when that lands. - Req 3 updated for String-decimal comparison semantics: reconciliation parses both bounds and literal magnitude into a common comparison space (i128 host comparison primitive — host narrowing, NOT carrier widening). Bounded by what the i64-typed literal can express; any i64-representable literal compares against any width's String-decimal bound. Carrier discipline preserved. Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral) is sha-stale — already resolved at 3e142d1. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed Resolves codex BLOCKING at sha 0815189 (post-#799-merge feedback). Real residual: req 2 specifies String-decimal range bounds (to cover u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" / "i64-representable magnitudes" for the range facts. Two incompatible authorities for the same range-fact shape — would let a worker satisfy the slice while truncating/omitting u64 bounds (P3 fail-closed violation). Fix: - Line 31 (req 1 re-scope clarification): updated to explicitly state "range facts (req 2) use String-decimal representation (width- independent; covers u64::MAX which doesn't fit in i64)". Distinguished literal *payload* (stays i64) from range-bound *representation* (String) — both serve req 1's "no carrier widening" boundary. - Line 44 (slice step 2): updated from "Range bounds use i64- representable magnitudes" to "Range bounds use String-decimal representation per req 2" with concrete example (u64 bounds). - Acceptance bullet: updated from "Range facts on integer algebras (substrate-declared, not Rust-mirrored)" to add "using String-decimal representation ... width-independent; u64 bounds expressible without truncation." The brief now consistently treats range bounds as String-decimal across req 2, req 3, slice, acceptance, and the req 1 clarification — no remaining authorities saying i64-typed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing User + PM exchange 2026-04-25 surfaced that the in-flight effects chain was importing wrong assumptions from external languages (declared-effects-as-annotation + lens-vs-declaration check). Right framing under gunbc's closed-system discipline is parallel to complexity: every effect derives structurally from the composition of typed primitive operations; nothing can hide because there's no escape hatch; nothing needs annotation because the structure IS the registry. Four doc-only actions: 1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md. Frames the closed-system answer with PM's 5-behavior synergy table (Value/Transform/Branch/Loop/Bind as universal compositional-fold pattern). Four worked examples; aggressive reading on redundancy (compile-error-by-construction via referential-transparency proof; reread() primitive for legitimate cases); implementation-brief shape in §Q6. 2. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md. 3. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md. Notes Fn→Arrow refactor brief stays dispatchable as independent value. 4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by- construction framing replaces lens-detection framing. Memory file feedback_closed_system_effects.md saved separately; cross-link added to feedback_construction_over_ratchets.md. Net cost: doc-level cleanup. Zero substrate code rework. Foundation (OperationEffect + service-call infrastructure + 5-behavior substrate) already exists. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect Per PM convergence review on #808 + user's deeper 2026-04-25 framing: the closed-system framing landed in #808 retired the user-facing annotation but kept OperationEffect taxonomy as substrate-level tagging. User's deeper framing: the taxonomy ITSELF is parallel-representation — operations are intrinsically read-shaped or write-shaped via their TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns- derived-value-only → read). Tagging operations with Read | Upsert | Create | Append | Delete names what the structure already says. Three changes: 1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as normalized view, or retire as parallel-representation?" - Two paths: (i) tags derived from signature shape (acceptable normalized view) vs (ii) tags declared per-primitive (parallel- representation; retire). - Audit-as-existence-check (Q4 req 2 reframed): all effectful primitives derive cleanly from signature shape → path (i); any primitive needs hand-declared tag → path (ii) by existence proof. - Director default: path (ii). Logging primitives that return Unit are likely the audit's existence-proof. - Two design-question resolutions: (a) external effects not in return type → resource-threading discipline (typed param returned modified, IO-monad-without-the-monad pattern); (b) transactional grouping → derived structural fact from Bind composition + typed transaction primitives. 2. Q4 reqs revised: req 2 from "tag every primitive with explicit OperationEffect signature" to "audit-as-existence-check that every primitive's type signature derives the right effect classification"; req 3 added (resource-threading discipline); req 6 added (transactional-pattern lens). Req 1 (effects lens) anchors on operation type-signature shape, not on hand-declared tags. 3. THESIS:345-347 amendment strengthened — "operations are intrinsically read-shaped or write-shaped via their type-signature shape; consumers walk the signatures directly; there is no parallel taxonomy or annotation layer to declare or maintain. Tracking effects as a separate enumerated concept IS the bug pattern, dissolved by construction." Plus references to resource-threading discipline + transactional grouping as derived structural fact. Memory file feedback_closed_system_effects.md updated to reflect the deeper framing (type-signature-shape, not taxonomy-tagging) + resource-threading discipline section + transactional-patterns section. Net cost: doc-only delta on top of #808. Substrate retirement (OperationEffect enum + derive_op_effect + idempotency.dag re-anchor) deferred to the audit-as-existence-check phase of the implementation brief; surfaced as Q5.5 OPEN CALL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage Resolves codex BLOCKING at sha d49ce79 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real: the prior text claimed service primitives "already carry typed effect signatures" presenting future audit-state as current substrate fact (P1 violation). My Q5.5 amendment at 2dc656b partially fixed the OperationEffect line but left a parallel over-claim on the new "signature-shape coverage" framing. Fix: Q4 substrate-state listing rewritten to honestly distinguish: - Live: Behavior enum + substrate foundation (the principle that operations should carry signature shape). - Incomplete: signature-shape coverage across actual primitives. HTTP-derived primitives carry implicit shape via derive_op_effect's method-table; logging/mutation primitives that return Unit or don't thread their target resource do NOT carry the structural shape that would express read-vs-write. Achieving full coverage is required work under reqs 2 + 3, not a current fact. - Pending audit-as-existence-check: OperationEffect + derive_op_effect (path (i) vs (ii) per Q5.5). Honest live-state callout added explicitly: "the closed-system FOUNDATION (5 behaviors + DAG substrate + the principle that operations should carry signature-shape) is live. The IMPLEMENTATION COVERAGE across all effectful primitives is partial. Req 2 + req 3 are the work that closes the gap." Brief now distinguishes principle-is-live (foundation) from coverage-is-partial (audit work) without conflating them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim Per PM follow-up review on #808 + user's stronger discipline framing ("substrate must make bypass structurally impossible at every layer of the transport stack"): the closed-system claim is honest only when typed primitives ARE the path. Today two structural holes exist where bypasses sidestep the typed-primitive substrate. Both surfaced explicitly as Q4.5 pre-conditions — load-bearing for the lens's coverage claim. Three changes: 1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed- system claim)" inserted between Q4 and Q5: P1 — Extdeps typed-primitive consumption structurally enforced. Substrate must make `messages: Json` impossible to declare in service definitions; typed `LlmMessage` / `ContentBlock` / `GitHubAuthToken`-with-full-scopes are the only path. Tracked debt at ROADMAP.md:153-154 (LLM provider flattening) + `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded). Required prereq for full lens coverage; lens can land first + surface structural-coverage-gap diagnostics on bypass surfaces so the gap becomes visible rather than silent. P2 — `ExecuteCommand` fully materialized as typed runner primitive. TESTING.md (post-#782) committed to 0-residual but ExecuteCommand isn't fully materialized; deleting Rust boundary tests creates verification gap. Already named under PB-Runtime in Zero-Floor; signal pending. Pre-requisite for ANY Rust boundary-test deletion. 2. Old leftover duplicate Q5 section deleted (artifact from prior Q5/Q5.5 reshape; second copy of asymmetric-tightening text was in the file alongside the earlier Q5 instance). 3. Worker-discretion-vs-Director-call section in Q4.5: lens implementation worker dispatchable now (reports gaps as findings); P1 closure is substantive substrate work touching extdeps (dedicated lane); P2 closure is PB-Runtime (signal pending). Net: design doc now honestly distinguishes principle-is-live (Q4 rewrite at 191be31) from coverage-is-partial (Q4.5 prereqs named explicitly). The closed-system claim has explicit pre- conditions documented; implementation brief discovers them as known dependencies, not as STOP-AND-ESCALATEs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default Resolves claude APPROVE_WITH_COMMENTS at sha 191be31 on #808. Two real residuals after the Q5.5 reframe: 1. Q6's reqs/STOPs/acceptance still framed under path (i) — said "audit + tag std/ primitives — every effectful primitive carries an explicit OperationEffect signature." Directly contradicted Q4 (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment ("there is no parallel taxonomy to declare or maintain"). Worker reading Q6 in isolation would author the retracted shape. 2. Capacity / sequencing table line about "audit lane (tag std/ primitives with effect signatures)" carried the same stale framing. 3. Q6 STOP "primitive performing side effects without an OperationEffect tag" assumed tag-as-authority; under path (ii) the STOP shape is "primitive whose signature doesn't structurally reveal its effect." Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale (already fixed at f073aa9 Q4.5 commit). ## Q6 fixes - Reqs renumbered + reframed: - Req 1 anchors on operation type-signature shape (not hand-declared OperationEffect tags); composition reads from signature shape per Q2 table. - Req 2 changed from "audit + tag every primitive" to "audit-as-existence-check" — verify signature-shape coverage; ANY primitive needing a hand-declared tag IS the existence-proof for path (ii) retirement. - Req 3 added: resource-threading discipline applied to existing primitives (logging that returns Unit gets reshaped per audit). - Req 6 added: transactional-pattern lens (Bind composition + Transaction → Transaction'). - Req 7 added: asymmetric-tightening worked example in PR body (per claude review observation; the one place declaration-shaped surface re-enters). - Req 8 (was 5): tests now reference signature-shape derivation explicitly, not tag lookup. - STOPs reframed: - "OperationEffect retirement decision" — audit produces path (i) vs (ii) verdict; substrate retirement is its own dedicated sub-lane; this lane does NOT absorb it. - Pure/impure carrier STOP notes that "pure" should also derive from signature shape (pure functions don't return modified resources) — so the STOP itself may dissolve under further design. - Q4.5 P1 explicitly NOT a STOP — lens reporting structural- coverage-gap on extdeps bypass surfaces is the lens delivering its foundation-gap-visibility value. - Q4.5 P2 explicitly independent — lens doesn't depend on ExecuteCommand materialization. - Acceptance extended: lens reports gap diagnostics on P1 bypass surfaces; audit produces existence-proof verdict for Director re-decision; asymmetric-tightening worked example in PR body. ## Capacity / sequencing table Replaced "1 audit lane (tag std/ primitives with effect signatures)" with "1 audit-as-existence-check lane (verify primitives' signature- shape coverage; NOT 'tag every primitive') — produces the path (i) vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2 prereq lanes to the net summary. Closing line: "The taxonomy- retirement scope (substrate-side) is not in this lane — it's surfaced by audit and routed to dedicated retirement lane if path (ii) wins." Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity table. Worker reading Q6 in isolation now sees path-(ii)-default framing matching Q4 + Q5.5 + THESIS amendment. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792 Resolves codex inline BLOCKING at sha 191be31 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150. Real: my Q4.5 P2 framing described ExecuteCommand as still NotYetImplemented (M1.5 allowlist + Rust TestRunner returning NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand extension before this PR's authoring. TESTING.md:195 capability-state callout confirms: - Rust TestRunner + M1.5 testgen harness share one std::process path for arbitrary command + args + expect_exit_code. - M1.5 allowlist + fail-closed panic retired. - Distinguishable ClaimResult::Fail messages for spawn / timeout / policy / exit-mismatch. - Linux unshare(1) namespace isolation on host-allowing systems. - T-PB-B-1 boundary migration example landed. Fix: P2 section rewritten: - Header retitled "ExecuteCommand runner primitive: LANDED (PR #792); residual is bulk-migration." - Status update naming PR #792 + the post-#792 capability state (allowlist retired, etc.). - Honest acknowledgement: "My earlier P2 framing was stale." - Residual narrowed to bulk-migration of existing Rust Command::new boundary tests (tracked as ROADMAP residual, not lens prereq). - Sequencing reframed: P2 was always orthogonal to the effects lens itself; bulk migration proceeds at its own pace; lens not blocked. Q4.5 footer updated: - "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via #792; only consumer-side bulk migration remains)" - Worker-discretion-vs-Director-call P2 line updated: "runner primitive landed; only consumer-side bulk migration remains; tracked as ROADMAP residual, independent of the lens." Q6 STOP for P2 updated: - "the lens itself doesn't depend on P2; only TESTING.md's 0-residual claim does" → "runner primitive landed via PR #792 (post-Q4.5- authoring update). The lens itself never depended on P2; bulk consumer migration is residual ROADMAP work and remains independent of this lane." Brief now reflects live state. The closed-system claim's prereq landscape is honest: - P1 (extdeps typed-primitive consumption): real prereq, tracked debt at ROADMAP:153-154. - P2 (ExecuteCommand runner): satisfied via #792; bulk migration is consumer-side residual, not foundation work. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale Resolves codex non-blocking finding at sha bcac41b on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real residual: capacity-table line still listed P2 as "`ExecuteCommand` materialization" prereq + framed both P1 and P2 as "pre-existing tracked-debt" — but my prior 57a9b13 fix established that PR #792 already landed the runner primitive, so P2 is no longer a materialization prereq. Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq) from P2 (residual, not prereq): - P1: extdeps typed-primitive consumption — pre-existing tracked debt at ROADMAP:153-154; load-bearing for the lens's full-coverage claim. - P2: ExecuteCommand runner primitive landed via PR #792; only consumer-side bulk migration of existing Rust Command::new boundary tests remains (tracked as ROADMAP residual, independent of the lens; not a materialization prereq). Brief now consistently treats P2 as bulk-migration-residual across: - §Q4.5 P2 section header (LANDED via PR #792; residual is bulk-migration). - §Q4.5 footer (P2: runner primitive landed; only consumer-side bulk migration remains). - Q6 STOP for P2 (runner primitive landed; bulk migration is residual ROADMAP work). - §Capacity / sequencing impact (P2 as residual, not prereq). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349 Codex finding on PR #808 sha ece964e: lines 153-154 are unrelated target-grounding prose; the matching extdeps typed-primitive bypass entries (LLM service flattening, GitHub auth model bypass) live at ROADMAP.md:348-349. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix third stale ROADMAP citation at line 271 Codex follow-up on sha 2552ca3: prior fix missed a third occurrence at line 271 in the §Q4.5 capacity table. Now consistent with lines 139 and 173 (ROADMAP.md:348-349). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity Codex flagged 'Effect-signature tagging on std/ primitives' as potentially contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240) already explicitly say 'NOT tag every primitive' — but the cross-manager line used sloppy wording. Reworded to make explicit that the audit walks signature shape; no parallel tag added. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…strate Pass program (#814) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c3 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c3: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b03 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b03 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e691.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 second-wave worker-escalation fixes Four substantive worker STOP-AND-ESCALATEs from briefs landed in PR #797. All four worker recommendations correct; each needs a Director call + brief update. ## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate Worker correctly identified that brief req 2 (declared-effect carrier as part of fn type signature, per feedback_no_annotations) requires net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots. Without parser surface, every user function would have declared_effects = [] while inference returns non-empty — lens fires EffectLeakageError everywhere on enable. Worker rejected power-through and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map parser split). Director picked split: - NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface syntax + lookahead + body parser + lowerer extension + exhaustive-match audit + coproduct dissolution receipt. - MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to post-parser-extension scope. Pre-flight check NOT a parser-extension step; STOP if parser sub-lane PR not merged. ## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping Worker found load-bearing evidence at infer.rs:3693-3703: DB-11 deliberately strips refinements at operator dispatch as a designed-in fix for symmetric-operators failure mode. Brief's "attach where b != 0 as a proof for a / b" directly contradicts this design choice. STOP-3 (where-clause conflict with DB-11) is real; STOP-1 (substrate scope) needs net-new substrate (per-operator partiality fact + predicate- entailment check + asymmetric per-operand refinement-honoring) — M+ minimum. ownership_lens precedent in original brief is post-hoc observability, not proof carrier. Worker recommended redirect to design/scoping per nested-optional precedent. Director picked redirect. Brief fully rewritten as design/scoping with four-question structure: (1) DB-11 interaction analysis; (2) substrate proposal for proof-or- totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes with acceptance-theatre risk on user-defined-total-wrapper-only); (4) Director-actionable recommendation. Output is doc PR. ## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C) Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int) with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136 closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b) i128 implementation requires either path 1 (hierarchy refactor — contradicts non-goal) or path 2 (regen lie between substrate and emit — violates discipline). Worker leaned option (C) re-scope: land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke) to a sibling sub-lane that does proper Int128/Word128 substrate work. Director picked option (C). Brief req 1 re-scoped to drop canonical- carrier-widening; lane value comes from range facts + reconciliation narrowing + out-of-range diagnostic against existing i64. Req 4 explicitly deferred with sibling-sub-lane reference. Sibling sub-lane NOT to be authored or implied in this PR; tracked separately. ## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change) Worker correctly STOP'd per the brief's own pre-flight check: parser sub-lane has not landed; SurfaceExpr::Map not on main. Director authorized cross-lane reassignment: wise-boar-480 takes the parser sub-lane (t-substrate-valuebody-map-parser-worker.md) since they already have full investigation context. No brief changes needed; the routing decision is in the dispatch. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope Resolves codex P2 inline at sha e35103f on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still required widening LiteralBits::Int(i64) to an unbounded carrier and passing the i64::MIN smoke. Internally unsatisfiable. Fix: - Slice section retitled "range facts + reconciliation narrowing (against existing i64 carrier)" with explicit note about the re-scope. - Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly forbids touching LiteralBits::Int shape, dag_scalar_generated.rs regen for that variant, or tokenize i64 parse path. - Slice steps 2-5 reframed: range facts use i64-representable magnitudes; reconciliation narrowing uses existing i64 carrier; diagnostic only for i64-representable out-of-range; smoke tests for req 5 only (req 4 i64::MIN deferred). - Acceptance checklist updated: - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as re-scoped/deferred. - LiteralBits::Int(i64) carrier untouched (no widening; no parallel; no shape change). - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference. - STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the carrier" — explicit STOP if execution surfaces range-fact narrowing requiring carrier-widening; that's the boundary the re-scope drew; belongs in sibling Int128/Word128 sub-lane. Brief now consistently treats carrier-widening as out-of-scope across all sections. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty Resolves codex BLOCKING #1 at sha e35103f on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier but req 2 required range facts using "the SAME magnitude carrier as req 1" — meaning i64-typed range bounds. u64's max (2^64-1) doesn't fit in i64; range fact for u64 would have to truncate, omit, or mirror in Rust (representation drift). All three options violate fail-closed declared-facts discipline (P1 / P3). Fix: - Req 2 rewritten to specify String-decimal representation: range_min_inclusive: String + range_max_inclusive: String fields on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127" for i8; "0"/"18446744073709551615" for u64). - Explicit reasoning why String-decimal: u64's max doesn't fit in i64; binding range bounds to literal carrier forces truncation/ omission/mirror-drift; all violate fail-closed declared-facts discipline. - Bridge framing: String-decimal is pending the sibling Int128/ Word128 sub-lane; both range bounds and literal payload migrate to typed carrier when that lands. - Req 3 updated for String-decimal comparison semantics: reconciliation parses both bounds and literal magnitude into a common comparison space (i128 host comparison primitive — host narrowing, NOT carrier widening). Bounded by what the i64-typed literal can express; any i64-representable literal compares against any width's String-decimal bound. Carrier discipline preserved. Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral) is sha-stale — already resolved at 3e142d1. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed Resolves codex BLOCKING at sha 0815189 (post-#799-merge feedback). Real residual: req 2 specifies String-decimal range bounds (to cover u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" / "i64-representable magnitudes" for the range facts. Two incompatible authorities for the same range-fact shape — would let a worker satisfy the slice while truncating/omitting u64 bounds (P3 fail-closed violation). Fix: - Line 31 (req 1 re-scope clarification): updated to explicitly state "range facts (req 2) use String-decimal representation (width- independent; covers u64::MAX which doesn't fit in i64)". Distinguished literal *payload* (stays i64) from range-bound *representation* (String) — both serve req 1's "no carrier widening" boundary. - Line 44 (slice step 2): updated from "Range bounds use i64- representable magnitudes" to "Range bounds use String-decimal representation per req 2" with concrete example (u64 bounds). - Acceptance bullet: updated from "Range facts on integer algebras (substrate-declared, not Rust-mirrored)" to add "using String-decimal representation ... width-independent; u64 bounds expressible without truncation." The brief now consistently treats range bounds as String-decimal across req 2, req 3, slice, acceptance, and the req 1 clarification — no remaining authorities saying i64-typed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing User + PM exchange 2026-04-25 surfaced that the in-flight effects chain was importing wrong assumptions from external languages (declared-effects-as-annotation + lens-vs-declaration check). Right framing under gunbc's closed-system discipline is parallel to complexity: every effect derives structurally from the composition of typed primitive operations; nothing can hide because there's no escape hatch; nothing needs annotation because the structure IS the registry. Four doc-only actions: 1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md. Frames the closed-system answer with PM's 5-behavior synergy table (Value/Transform/Branch/Loop/Bind as universal compositional-fold pattern). Four worked examples; aggressive reading on redundancy (compile-error-by-construction via referential-transparency proof; reread() primitive for legitimate cases); implementation-brief shape in §Q6. 2. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md. 3. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md. Notes Fn→Arrow refactor brief stays dispatchable as independent value. 4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by- construction framing replaces lens-detection framing. Memory file feedback_closed_system_effects.md saved separately; cross-link added to feedback_construction_over_ratchets.md. Net cost: doc-level cleanup. Zero substrate code rework. Foundation (OperationEffect + service-call infrastructure + 5-behavior substrate) already exists. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect Per PM convergence review on #808 + user's deeper 2026-04-25 framing: the closed-system framing landed in #808 retired the user-facing annotation but kept OperationEffect taxonomy as substrate-level tagging. User's deeper framing: the taxonomy ITSELF is parallel-representation — operations are intrinsically read-shaped or write-shaped via their TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns- derived-value-only → read). Tagging operations with Read | Upsert | Create | Append | Delete names what the structure already says. Three changes: 1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as normalized view, or retire as parallel-representation?" - Two paths: (i) tags derived from signature shape (acceptable normalized view) vs (ii) tags declared per-primitive (parallel- representation; retire). - Audit-as-existence-check (Q4 req 2 reframed): all effectful primitives derive cleanly from signature shape → path (i); any primitive needs hand-declared tag → path (ii) by existence proof. - Director default: path (ii). Logging primitives that return Unit are likely the audit's existence-proof. - Two design-question resolutions: (a) external effects not in return type → resource-threading discipline (typed param returned modified, IO-monad-without-the-monad pattern); (b) transactional grouping → derived structural fact from Bind composition + typed transaction primitives. 2. Q4 reqs revised: req 2 from "tag every primitive with explicit OperationEffect signature" to "audit-as-existence-check that every primitive's type signature derives the right effect classification"; req 3 added (resource-threading discipline); req 6 added (transactional-pattern lens). Req 1 (effects lens) anchors on operation type-signature shape, not on hand-declared tags. 3. THESIS:345-347 amendment strengthened — "operations are intrinsically read-shaped or write-shaped via their type-signature shape; consumers walk the signatures directly; there is no parallel taxonomy or annotation layer to declare or maintain. Tracking effects as a separate enumerated concept IS the bug pattern, dissolved by construction." Plus references to resource-threading discipline + transactional grouping as derived structural fact. Memory file feedback_closed_system_effects.md updated to reflect the deeper framing (type-signature-shape, not taxonomy-tagging) + resource-threading discipline section + transactional-patterns section. Net cost: doc-only delta on top of #808. Substrate retirement (OperationEffect enum + derive_op_effect + idempotency.dag re-anchor) deferred to the audit-as-existence-check phase of the implementation brief; surfaced as Q5.5 OPEN CALL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage Resolves codex BLOCKING at sha d49ce79 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real: the prior text claimed service primitives "already carry typed effect signatures" presenting future audit-state as current substrate fact (P1 violation). My Q5.5 amendment at 2dc656b partially fixed the OperationEffect line but left a parallel over-claim on the new "signature-shape coverage" framing. Fix: Q4 substrate-state listing rewritten to honestly distinguish: - Live: Behavior enum + substrate foundation (the principle that operations should carry signature shape). - Incomplete: signature-shape coverage across actual primitives. HTTP-derived primitives carry implicit shape via derive_op_effect's method-table; logging/mutation primitives that return Unit or don't thread their target resource do NOT carry the structural shape that would express read-vs-write. Achieving full coverage is required work under reqs 2 + 3, not a current fact. - Pending audit-as-existence-check: OperationEffect + derive_op_effect (path (i) vs (ii) per Q5.5). Honest live-state callout added explicitly: "the closed-system FOUNDATION (5 behaviors + DAG substrate + the principle that operations should carry signature-shape) is live. The IMPLEMENTATION COVERAGE across all effectful primitives is partial. Req 2 + req 3 are the work that closes the gap." Brief now distinguishes principle-is-live (foundation) from coverage-is-partial (audit work) without conflating them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim Per PM follow-up review on #808 + user's stronger discipline framing ("substrate must make bypass structurally impossible at every layer of the transport stack"): the closed-system claim is honest only when typed primitives ARE the path. Today two structural holes exist where bypasses sidestep the typed-primitive substrate. Both surfaced explicitly as Q4.5 pre-conditions — load-bearing for the lens's coverage claim. Three changes: 1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed- system claim)" inserted between Q4 and Q5: P1 — Extdeps typed-primitive consumption structurally enforced. Substrate must make `messages: Json` impossible to declare in service definitions; typed `LlmMessage` / `ContentBlock` / `GitHubAuthToken`-with-full-scopes are the only path. Tracked debt at ROADMAP.md:153-154 (LLM provider flattening) + `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded). Required prereq for full lens coverage; lens can land first + surface structural-coverage-gap diagnostics on bypass surfaces so the gap becomes visible rather than silent. P2 — `ExecuteCommand` fully materialized as typed runner primitive. TESTING.md (post-#782) committed to 0-residual but ExecuteCommand isn't fully materialized; deleting Rust boundary tests creates verification gap. Already named under PB-Runtime in Zero-Floor; signal pending. Pre-requisite for ANY Rust boundary-test deletion. 2. Old leftover duplicate Q5 section deleted (artifact from prior Q5/Q5.5 reshape; second copy of asymmetric-tightening text was in the file alongside the earlier Q5 instance). 3. Worker-discretion-vs-Director-call section in Q4.5: lens implementation worker dispatchable now (reports gaps as findings); P1 closure is substantive substrate work touching extdeps (dedicated lane); P2 closure is PB-Runtime (signal pending). Net: design doc now honestly distinguishes principle-is-live (Q4 rewrite at 191be31) from coverage-is-partial (Q4.5 prereqs named explicitly). The closed-system claim has explicit pre- conditions documented; implementation brief discovers them as known dependencies, not as STOP-AND-ESCALATEs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default Resolves claude APPROVE_WITH_COMMENTS at sha 191be31 on #808. Two real residuals after the Q5.5 reframe: 1. Q6's reqs/STOPs/acceptance still framed under path (i) — said "audit + tag std/ primitives — every effectful primitive carries an explicit OperationEffect signature." Directly contradicted Q4 (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment ("there is no parallel taxonomy to declare or maintain"). Worker reading Q6 in isolation would author the retracted shape. 2. Capacity / sequencing table line about "audit lane (tag std/ primitives with effect signatures)" carried the same stale framing. 3. Q6 STOP "primitive performing side effects without an OperationEffect tag" assumed tag-as-authority; under path (ii) the STOP shape is "primitive whose signature doesn't structurally reveal its effect." Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale (already fixed at f073aa9 Q4.5 commit). ## Q6 fixes - Reqs renumbered + reframed: - Req 1 anchors on operation type-signature shape (not hand-declared OperationEffect tags); composition reads from signature shape per Q2 table. - Req 2 changed from "audit + tag every primitive" to "audit-as-existence-check" — verify signature-shape coverage; ANY primitive needing a hand-declared tag IS the existence-proof for path (ii) retirement. - Req 3 added: resource-threading discipline applied to existing primitives (logging that returns Unit gets reshaped per audit). - Req 6 added: transactional-pattern lens (Bind composition + Transaction → Transaction'). - Req 7 added: asymmetric-tightening worked example in PR body (per claude review observation; the one place declaration-shaped surface re-enters). - Req 8 (was 5): tests now reference signature-shape derivation explicitly, not tag lookup. - STOPs reframed: - "OperationEffect retirement decision" — audit produces path (i) vs (ii) verdict; substrate retirement is its own dedicated sub-lane; this lane does NOT absorb it. - Pure/impure carrier STOP notes that "pure" should also derive from signature shape (pure functions don't return modified resources) — so the STOP itself may dissolve under further design. - Q4.5 P1 explicitly NOT a STOP — lens reporting structural- coverage-gap on extdeps bypass surfaces is the lens delivering its foundation-gap-visibility value. - Q4.5 P2 explicitly independent — lens doesn't depend on ExecuteCommand materialization. - Acceptance extended: lens reports gap diagnostics on P1 bypass surfaces; audit produces existence-proof verdict for Director re-decision; asymmetric-tightening worked example in PR body. ## Capacity / sequencing table Replaced "1 audit lane (tag std/ primitives with effect signatures)" with "1 audit-as-existence-check lane (verify primitives' signature- shape coverage; NOT 'tag every primitive') — produces the path (i) vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2 prereq lanes to the net summary. Closing line: "The taxonomy- retirement scope (substrate-side) is not in this lane — it's surfaced by audit and routed to dedicated retirement lane if path (ii) wins." Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity table. Worker reading Q6 in isolation now sees path-(ii)-default framing matching Q4 + Q5.5 + THESIS amendment. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792 Resolves codex inline BLOCKING at sha 191be31 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150. Real: my Q4.5 P2 framing described ExecuteCommand as still NotYetImplemented (M1.5 allowlist + Rust TestRunner returning NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand extension before this PR's authoring. TESTING.md:195 capability-state callout confirms: - Rust TestRunner + M1.5 testgen harness share one std::process path for arbitrary command + args + expect_exit_code. - M1.5 allowlist + fail-closed panic retired. - Distinguishable ClaimResult::Fail messages for spawn / timeout / policy / exit-mismatch. - Linux unshare(1) namespace isolation on host-allowing systems. - T-PB-B-1 boundary migration example landed. Fix: P2 section rewritten: - Header retitled "ExecuteCommand runner primitive: LANDED (PR #792); residual is bulk-migration." - Status update naming PR #792 + the post-#792 capability state (allowlist retired, etc.). - Honest acknowledgement: "My earlier P2 framing was stale." - Residual narrowed to bulk-migration of existing Rust Command::new boundary tests (tracked as ROADMAP residual, not lens prereq). - Sequencing reframed: P2 was always orthogonal to the effects lens itself; bulk migration proceeds at its own pace; lens not blocked. Q4.5 footer updated: - "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via #792; only consumer-side bulk migration remains)" - Worker-discretion-vs-Director-call P2 line updated: "runner primitive landed; only consumer-side bulk migration remains; tracked as ROADMAP residual, independent of the lens." Q6 STOP for P2 updated: - "the lens itself doesn't depend on P2; only TESTING.md's 0-residual claim does" → "runner primitive landed via PR #792 (post-Q4.5- authoring update). The lens itself never depended on P2; bulk consumer migration is residual ROADMAP work and remains independent of this lane." Brief now reflects live state. The closed-system claim's prereq landscape is honest: - P1 (extdeps typed-primitive consumption): real prereq, tracked debt at ROADMAP:153-154. - P2 (ExecuteCommand runner): satisfied via #792; bulk migration is consumer-side residual, not foundation work. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale Resolves codex non-blocking finding at sha bcac41b on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real residual: capacity-table line still listed P2 as "`ExecuteCommand` materialization" prereq + framed both P1 and P2 as "pre-existing tracked-debt" — but my prior 57a9b13 fix established that PR #792 already landed the runner primitive, so P2 is no longer a materialization prereq. Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq) from P2 (residual, not prereq): - P1: extdeps typed-primitive consumption — pre-existing tracked debt at ROADMAP:153-154; load-bearing for the lens's full-coverage claim. - P2: ExecuteCommand runner primitive landed via PR #792; only consumer-side bulk migration of existing Rust Command::new boundary tests remains (tracked as ROADMAP residual, independent of the lens; not a materialization prereq). Brief now consistently treats P2 as bulk-migration-residual across: - §Q4.5 P2 section header (LANDED via PR #792; residual is bulk-migration). - §Q4.5 footer (P2: runner primitive landed; only consumer-side bulk migration remains). - Q6 STOP for P2 (runner primitive landed; bulk migration is residual ROADMAP work). - §Capacity / sequencing impact (P2 as residual, not prereq). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349 Codex finding on PR #808 sha ece964e: lines 153-154 are unrelated target-grounding prose; the matching extdeps typed-primitive bypass entries (LLM service flattening, GitHub auth model bypass) live at ROADMAP.md:348-349. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix third stale ROADMAP citation at line 271 Codex follow-up on sha 2552ca3: prior fix missed a third occurrence at line 271 in the §Q4.5 capacity table. Now consistent with lines 139 and 173 (ROADMAP.md:348-349). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity Codex flagged 'Effect-signature tagging on std/ primitives' as potentially contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240) already explicitly say 'NOT tag every primitive' — but the cross-manager line used sloppy wording. Reworded to make explicit that the audit walks signature shape; no parallel tag added. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5 - B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound - B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause - B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge - B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation) B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25): language vocabulary is primitives + namespacing only; no escape syntax; the §0 sentinels are the compiler itself failing to use primitives + namespacing internally. Eight surface sites dissolve via four substrate carriers (DeclarationRef, structural fold-shape carrier, structural emit-helper carrier, structural extdeps-fixture-set carrier). B1-B3 are independent; dispatch in parallel. B4 is sequential program work; sub-brief dispatch (B4.1-B4.12) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — drop incoherent inner-fallback non-goal Codex P2: the non-goal line excluding the inner declaration().name unwrap_or_else fallback contradicted Slice step 2, which replaces the whole chain with let-Some-else-return. Both fallbacks are in scope by construction; remove the contradictory non-goal. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives PM REQUEST_CHANGES: §Frame listed '4 type connectives (Conjunction | Disjunction | Cardinality | Bit)' which contradicted the canonical thesis source. Replaced with the canonical 6 (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary closes here'. Also removed 'typed substrate carriers' from the vocabulary list — substrate carriers are defined using the vocabulary, not part of it. Added a clarifying note that B4's carriers (DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are typed declarations composed from the vocabulary, not vocabulary extensions. Per feedback_verify_thesis_claims: brief framings citing thesis structure must ground in the canonical source. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…la tighten (post-#814 carry-forward) (#815) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c3 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c3: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b03 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b03 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e691.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 second-wave worker-escalation fixes Four substantive worker STOP-AND-ESCALATEs from briefs landed in PR #797. All four worker recommendations correct; each needs a Director call + brief update. ## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate Worker correctly identified that brief req 2 (declared-effect carrier as part of fn type signature, per feedback_no_annotations) requires net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots. Without parser surface, every user function would have declared_effects = [] while inference returns non-empty — lens fires EffectLeakageError everywhere on enable. Worker rejected power-through and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map parser split). Director picked split: - NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface syntax + lookahead + body parser + lowerer extension + exhaustive-match audit + coproduct dissolution receipt. - MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to post-parser-extension scope. Pre-flight check NOT a parser-extension step; STOP if parser sub-lane PR not merged. ## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping Worker found load-bearing evidence at infer.rs:3693-3703: DB-11 deliberately strips refinements at operator dispatch as a designed-in fix for symmetric-operators failure mode. Brief's "attach where b != 0 as a proof for a / b" directly contradicts this design choice. STOP-3 (where-clause conflict with DB-11) is real; STOP-1 (substrate scope) needs net-new substrate (per-operator partiality fact + predicate- entailment check + asymmetric per-operand refinement-honoring) — M+ minimum. ownership_lens precedent in original brief is post-hoc observability, not proof carrier. Worker recommended redirect to design/scoping per nested-optional precedent. Director picked redirect. Brief fully rewritten as design/scoping with four-question structure: (1) DB-11 interaction analysis; (2) substrate proposal for proof-or- totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes with acceptance-theatre risk on user-defined-total-wrapper-only); (4) Director-actionable recommendation. Output is doc PR. ## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C) Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int) with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136 closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b) i128 implementation requires either path 1 (hierarchy refactor — contradicts non-goal) or path 2 (regen lie between substrate and emit — violates discipline). Worker leaned option (C) re-scope: land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke) to a sibling sub-lane that does proper Int128/Word128 substrate work. Director picked option (C). Brief req 1 re-scoped to drop canonical- carrier-widening; lane value comes from range facts + reconciliation narrowing + out-of-range diagnostic against existing i64. Req 4 explicitly deferred with sibling-sub-lane reference. Sibling sub-lane NOT to be authored or implied in this PR; tracked separately. ## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change) Worker correctly STOP'd per the brief's own pre-flight check: parser sub-lane has not landed; SurfaceExpr::Map not on main. Director authorized cross-lane reassignment: wise-boar-480 takes the parser sub-lane (t-substrate-valuebody-map-parser-worker.md) since they already have full investigation context. No brief changes needed; the routing decision is in the dispatch. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope Resolves codex P2 inline at sha e35103f on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still required widening LiteralBits::Int(i64) to an unbounded carrier and passing the i64::MIN smoke. Internally unsatisfiable. Fix: - Slice section retitled "range facts + reconciliation narrowing (against existing i64 carrier)" with explicit note about the re-scope. - Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly forbids touching LiteralBits::Int shape, dag_scalar_generated.rs regen for that variant, or tokenize i64 parse path. - Slice steps 2-5 reframed: range facts use i64-representable magnitudes; reconciliation narrowing uses existing i64 carrier; diagnostic only for i64-representable out-of-range; smoke tests for req 5 only (req 4 i64::MIN deferred). - Acceptance checklist updated: - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as re-scoped/deferred. - LiteralBits::Int(i64) carrier untouched (no widening; no parallel; no shape change). - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference. - STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the carrier" — explicit STOP if execution surfaces range-fact narrowing requiring carrier-widening; that's the boundary the re-scope drew; belongs in sibling Int128/Word128 sub-lane. Brief now consistently treats carrier-widening as out-of-scope across all sections. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty Resolves codex BLOCKING #1 at sha e35103f on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier but req 2 required range facts using "the SAME magnitude carrier as req 1" — meaning i64-typed range bounds. u64's max (2^64-1) doesn't fit in i64; range fact for u64 would have to truncate, omit, or mirror in Rust (representation drift). All three options violate fail-closed declared-facts discipline (P1 / P3). Fix: - Req 2 rewritten to specify String-decimal representation: range_min_inclusive: String + range_max_inclusive: String fields on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127" for i8; "0"/"18446744073709551615" for u64). - Explicit reasoning why String-decimal: u64's max doesn't fit in i64; binding range bounds to literal carrier forces truncation/ omission/mirror-drift; all violate fail-closed declared-facts discipline. - Bridge framing: String-decimal is pending the sibling Int128/ Word128 sub-lane; both range bounds and literal payload migrate to typed carrier when that lands. - Req 3 updated for String-decimal comparison semantics: reconciliation parses both bounds and literal magnitude into a common comparison space (i128 host comparison primitive — host narrowing, NOT carrier widening). Bounded by what the i64-typed literal can express; any i64-representable literal compares against any width's String-decimal bound. Carrier discipline preserved. Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral) is sha-stale — already resolved at 3e142d1. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed Resolves codex BLOCKING at sha 0815189 (post-#799-merge feedback). Real residual: req 2 specifies String-decimal range bounds (to cover u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" / "i64-representable magnitudes" for the range facts. Two incompatible authorities for the same range-fact shape — would let a worker satisfy the slice while truncating/omitting u64 bounds (P3 fail-closed violation). Fix: - Line 31 (req 1 re-scope clarification): updated to explicitly state "range facts (req 2) use String-decimal representation (width- independent; covers u64::MAX which doesn't fit in i64)". Distinguished literal *payload* (stays i64) from range-bound *representation* (String) — both serve req 1's "no carrier widening" boundary. - Line 44 (slice step 2): updated from "Range bounds use i64- representable magnitudes" to "Range bounds use String-decimal representation per req 2" with concrete example (u64 bounds). - Acceptance bullet: updated from "Range facts on integer algebras (substrate-declared, not Rust-mirrored)" to add "using String-decimal representation ... width-independent; u64 bounds expressible without truncation." The brief now consistently treats range bounds as String-decimal across req 2, req 3, slice, acceptance, and the req 1 clarification — no remaining authorities saying i64-typed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing User + PM exchange 2026-04-25 surfaced that the in-flight effects chain was importing wrong assumptions from external languages (declared-effects-as-annotation + lens-vs-declaration check). Right framing under gunbc's closed-system discipline is parallel to complexity: every effect derives structurally from the composition of typed primitive operations; nothing can hide because there's no escape hatch; nothing needs annotation because the structure IS the registry. Four doc-only actions: 1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md. Frames the closed-system answer with PM's 5-behavior synergy table (Value/Transform/Branch/Loop/Bind as universal compositional-fold pattern). Four worked examples; aggressive reading on redundancy (compile-error-by-construction via referential-transparency proof; reread() primitive for legitimate cases); implementation-brief shape in §Q6. 2. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md. 3. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md. Notes Fn→Arrow refactor brief stays dispatchable as independent value. 4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by- construction framing replaces lens-detection framing. Memory file feedback_closed_system_effects.md saved separately; cross-link added to feedback_construction_over_ratchets.md. Net cost: doc-level cleanup. Zero substrate code rework. Foundation (OperationEffect + service-call infrastructure + 5-behavior substrate) already exists. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect Per PM convergence review on #808 + user's deeper 2026-04-25 framing: the closed-system framing landed in #808 retired the user-facing annotation but kept OperationEffect taxonomy as substrate-level tagging. User's deeper framing: the taxonomy ITSELF is parallel-representation — operations are intrinsically read-shaped or write-shaped via their TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns- derived-value-only → read). Tagging operations with Read | Upsert | Create | Append | Delete names what the structure already says. Three changes: 1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as normalized view, or retire as parallel-representation?" - Two paths: (i) tags derived from signature shape (acceptable normalized view) vs (ii) tags declared per-primitive (parallel- representation; retire). - Audit-as-existence-check (Q4 req 2 reframed): all effectful primitives derive cleanly from signature shape → path (i); any primitive needs hand-declared tag → path (ii) by existence proof. - Director default: path (ii). Logging primitives that return Unit are likely the audit's existence-proof. - Two design-question resolutions: (a) external effects not in return type → resource-threading discipline (typed param returned modified, IO-monad-without-the-monad pattern); (b) transactional grouping → derived structural fact from Bind composition + typed transaction primitives. 2. Q4 reqs revised: req 2 from "tag every primitive with explicit OperationEffect signature" to "audit-as-existence-check that every primitive's type signature derives the right effect classification"; req 3 added (resource-threading discipline); req 6 added (transactional-pattern lens). Req 1 (effects lens) anchors on operation type-signature shape, not on hand-declared tags. 3. THESIS:345-347 amendment strengthened — "operations are intrinsically read-shaped or write-shaped via their type-signature shape; consumers walk the signatures directly; there is no parallel taxonomy or annotation layer to declare or maintain. Tracking effects as a separate enumerated concept IS the bug pattern, dissolved by construction." Plus references to resource-threading discipline + transactional grouping as derived structural fact. Memory file feedback_closed_system_effects.md updated to reflect the deeper framing (type-signature-shape, not taxonomy-tagging) + resource-threading discipline section + transactional-patterns section. Net cost: doc-only delta on top of #808. Substrate retirement (OperationEffect enum + derive_op_effect + idempotency.dag re-anchor) deferred to the audit-as-existence-check phase of the implementation brief; surfaced as Q5.5 OPEN CALL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage Resolves codex BLOCKING at sha d49ce79 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real: the prior text claimed service primitives "already carry typed effect signatures" presenting future audit-state as current substrate fact (P1 violation). My Q5.5 amendment at 2dc656b partially fixed the OperationEffect line but left a parallel over-claim on the new "signature-shape coverage" framing. Fix: Q4 substrate-state listing rewritten to honestly distinguish: - Live: Behavior enum + substrate foundation (the principle that operations should carry signature shape). - Incomplete: signature-shape coverage across actual primitives. HTTP-derived primitives carry implicit shape via derive_op_effect's method-table; logging/mutation primitives that return Unit or don't thread their target resource do NOT carry the structural shape that would express read-vs-write. Achieving full coverage is required work under reqs 2 + 3, not a current fact. - Pending audit-as-existence-check: OperationEffect + derive_op_effect (path (i) vs (ii) per Q5.5). Honest live-state callout added explicitly: "the closed-system FOUNDATION (5 behaviors + DAG substrate + the principle that operations should carry signature-shape) is live. The IMPLEMENTATION COVERAGE across all effectful primitives is partial. Req 2 + req 3 are the work that closes the gap." Brief now distinguishes principle-is-live (foundation) from coverage-is-partial (audit work) without conflating them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim Per PM follow-up review on #808 + user's stronger discipline framing ("substrate must make bypass structurally impossible at every layer of the transport stack"): the closed-system claim is honest only when typed primitives ARE the path. Today two structural holes exist where bypasses sidestep the typed-primitive substrate. Both surfaced explicitly as Q4.5 pre-conditions — load-bearing for the lens's coverage claim. Three changes: 1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed- system claim)" inserted between Q4 and Q5: P1 — Extdeps typed-primitive consumption structurally enforced. Substrate must make `messages: Json` impossible to declare in service definitions; typed `LlmMessage` / `ContentBlock` / `GitHubAuthToken`-with-full-scopes are the only path. Tracked debt at ROADMAP.md:153-154 (LLM provider flattening) + `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded). Required prereq for full lens coverage; lens can land first + surface structural-coverage-gap diagnostics on bypass surfaces so the gap becomes visible rather than silent. P2 — `ExecuteCommand` fully materialized as typed runner primitive. TESTING.md (post-#782) committed to 0-residual but ExecuteCommand isn't fully materialized; deleting Rust boundary tests creates verification gap. Already named under PB-Runtime in Zero-Floor; signal pending. Pre-requisite for ANY Rust boundary-test deletion. 2. Old leftover duplicate Q5 section deleted (artifact from prior Q5/Q5.5 reshape; second copy of asymmetric-tightening text was in the file alongside the earlier Q5 instance). 3. Worker-discretion-vs-Director-call section in Q4.5: lens implementation worker dispatchable now (reports gaps as findings); P1 closure is substantive substrate work touching extdeps (dedicated lane); P2 closure is PB-Runtime (signal pending). Net: design doc now honestly distinguishes principle-is-live (Q4 rewrite at 191be31) from coverage-is-partial (Q4.5 prereqs named explicitly). The closed-system claim has explicit pre- conditions documented; implementation brief discovers them as known dependencies, not as STOP-AND-ESCALATEs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default Resolves claude APPROVE_WITH_COMMENTS at sha 191be31 on #808. Two real residuals after the Q5.5 reframe: 1. Q6's reqs/STOPs/acceptance still framed under path (i) — said "audit + tag std/ primitives — every effectful primitive carries an explicit OperationEffect signature." Directly contradicted Q4 (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment ("there is no parallel taxonomy to declare or maintain"). Worker reading Q6 in isolation would author the retracted shape. 2. Capacity / sequencing table line about "audit lane (tag std/ primitives with effect signatures)" carried the same stale framing. 3. Q6 STOP "primitive performing side effects without an OperationEffect tag" assumed tag-as-authority; under path (ii) the STOP shape is "primitive whose signature doesn't structurally reveal its effect." Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale (already fixed at f073aa9 Q4.5 commit). ## Q6 fixes - Reqs renumbered + reframed: - Req 1 anchors on operation type-signature shape (not hand-declared OperationEffect tags); composition reads from signature shape per Q2 table. - Req 2 changed from "audit + tag every primitive" to "audit-as-existence-check" — verify signature-shape coverage; ANY primitive needing a hand-declared tag IS the existence-proof for path (ii) retirement. - Req 3 added: resource-threading discipline applied to existing primitives (logging that returns Unit gets reshaped per audit). - Req 6 added: transactional-pattern lens (Bind composition + Transaction → Transaction'). - Req 7 added: asymmetric-tightening worked example in PR body (per claude review observation; the one place declaration-shaped surface re-enters). - Req 8 (was 5): tests now reference signature-shape derivation explicitly, not tag lookup. - STOPs reframed: - "OperationEffect retirement decision" — audit produces path (i) vs (ii) verdict; substrate retirement is its own dedicated sub-lane; this lane does NOT absorb it. - Pure/impure carrier STOP notes that "pure" should also derive from signature shape (pure functions don't return modified resources) — so the STOP itself may dissolve under further design. - Q4.5 P1 explicitly NOT a STOP — lens reporting structural- coverage-gap on extdeps bypass surfaces is the lens delivering its foundation-gap-visibility value. - Q4.5 P2 explicitly independent — lens doesn't depend on ExecuteCommand materialization. - Acceptance extended: lens reports gap diagnostics on P1 bypass surfaces; audit produces existence-proof verdict for Director re-decision; asymmetric-tightening worked example in PR body. ## Capacity / sequencing table Replaced "1 audit lane (tag std/ primitives with effect signatures)" with "1 audit-as-existence-check lane (verify primitives' signature- shape coverage; NOT 'tag every primitive') — produces the path (i) vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2 prereq lanes to the net summary. Closing line: "The taxonomy- retirement scope (substrate-side) is not in this lane — it's surfaced by audit and routed to dedicated retirement lane if path (ii) wins." Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity table. Worker reading Q6 in isolation now sees path-(ii)-default framing matching Q4 + Q5.5 + THESIS amendment. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792 Resolves codex inline BLOCKING at sha 191be31 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150. Real: my Q4.5 P2 framing described ExecuteCommand as still NotYetImplemented (M1.5 allowlist + Rust TestRunner returning NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand extension before this PR's authoring. TESTING.md:195 capability-state callout confirms: - Rust TestRunner + M1.5 testgen harness share one std::process path for arbitrary command + args + expect_exit_code. - M1.5 allowlist + fail-closed panic retired. - Distinguishable ClaimResult::Fail messages for spawn / timeout / policy / exit-mismatch. - Linux unshare(1) namespace isolation on host-allowing systems. - T-PB-B-1 boundary migration example landed. Fix: P2 section rewritten: - Header retitled "ExecuteCommand runner primitive: LANDED (PR #792); residual is bulk-migration." - Status update naming PR #792 + the post-#792 capability state (allowlist retired, etc.). - Honest acknowledgement: "My earlier P2 framing was stale." - Residual narrowed to bulk-migration of existing Rust Command::new boundary tests (tracked as ROADMAP residual, not lens prereq). - Sequencing reframed: P2 was always orthogonal to the effects lens itself; bulk migration proceeds at its own pace; lens not blocked. Q4.5 footer updated: - "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via #792; only consumer-side bulk migration remains)" - Worker-discretion-vs-Director-call P2 line updated: "runner primitive landed; only consumer-side bulk migration remains; tracked as ROADMAP residual, independent of the lens." Q6 STOP for P2 updated: - "the lens itself doesn't depend on P2; only TESTING.md's 0-residual claim does" → "runner primitive landed via PR #792 (post-Q4.5- authoring update). The lens itself never depended on P2; bulk consumer migration is residual ROADMAP work and remains independent of this lane." Brief now reflects live state. The closed-system claim's prereq landscape is honest: - P1 (extdeps typed-primitive consumption): real prereq, tracked debt at ROADMAP:153-154. - P2 (ExecuteCommand runner): satisfied via #792; bulk migration is consumer-side residual, not foundation work. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale Resolves codex non-blocking finding at sha bcac41b on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real residual: capacity-table line still listed P2 as "`ExecuteCommand` materialization" prereq + framed both P1 and P2 as "pre-existing tracked-debt" — but my prior 57a9b13 fix established that PR #792 already landed the runner primitive, so P2 is no longer a materialization prereq. Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq) from P2 (residual, not prereq): - P1: extdeps typed-primitive consumption — pre-existing tracked debt at ROADMAP:153-154; load-bearing for the lens's full-coverage claim. - P2: ExecuteCommand runner primitive landed via PR #792; only consumer-side bulk migration of existing Rust Command::new boundary tests remains (tracked as ROADMAP residual, independent of the lens; not a materialization prereq). Brief now consistently treats P2 as bulk-migration-residual across: - §Q4.5 P2 section header (LANDED via PR #792; residual is bulk-migration). - §Q4.5 footer (P2: runner primitive landed; only consumer-side bulk migration remains). - Q6 STOP for P2 (runner primitive landed; bulk migration is residual ROADMAP work). - §Capacity / sequencing impact (P2 as residual, not prereq). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349 Codex finding on PR #808 sha ece964e: lines 153-154 are unrelated target-grounding prose; the matching extdeps typed-primitive bypass entries (LLM service flattening, GitHub auth model bypass) live at ROADMAP.md:348-349. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix third stale ROADMAP citation at line 271 Codex follow-up on sha 2552ca3: prior fix missed a third occurrence at line 271 in the §Q4.5 capacity table. Now consistent with lines 139 and 173 (ROADMAP.md:348-349). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity Codex flagged 'Effect-signature tagging on std/ primitives' as potentially contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240) already explicitly say 'NOT tag every primitive' — but the cross-manager line used sloppy wording. Reworded to make explicit that the audit walks signature shape; no parallel tag added. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5 - B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound - B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause - B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge - B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation) B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25): language vocabulary is primitives + namespacing only; no escape syntax; the §0 sentinels are the compiler itself failing to use primitives + namespacing internally. Eight surface sites dissolve via four substrate carriers (DeclarationRef, structural fold-shape carrier, structural emit-helper carrier, structural extdeps-fixture-set carrier). B1-B3 are independent; dispatch in parallel. B4 is sequential program work; sub-brief dispatch (B4.1-B4.12) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — drop incoherent inner-fallback non-goal Codex P2: the non-goal line excluding the inner declaration().name unwrap_or_else fallback contradicted Slice step 2, which replaces the whole chain with let-Some-else-return. Both fallbacks are in scope by construction; remove the contradictory non-goal. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives PM REQUEST_CHANGES: §Frame listed '4 type connectives (Conjunction | Disjunction | Cardinality | Bit)' which contradicted the canonical thesis source. Replaced with the canonical 6 (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary closes here'. Also removed 'typed substrate carriers' from the vocabulary list — substrate carriers are defined using the vocabulary, not part of it. Added a clarifying note that B4's carriers (DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are typed declarations composed from the vocabulary, not vocabulary extensions. Per feedback_verify_thesis_claims: brief framings citing thesis structure must ground in the canonical source. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of naming the live substrate authority. Two coordinated fixes: 1. §Read first cites src/v3/std/substrate.dag (live .dag substrate authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel meta-type — already exists with consumers in verification.dag, emit_model.dag, python.dag). 2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing DeclarationRef'. The work is consumer migration + any role-extension layer the audit reveals, NOT designing or landing the carrier. Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers) keep their 'new' framing but explicitly require sub-briefs to grep src/v3/std/ + src/v3/spec/ for existing authority before authoring 'design and land' framing — per feedback_verify_thesis_claims + feedback_emitter_workaround_is_gap_symptom. Acceptance + sub-brief dispatch order updated to reflect B4.1's consumer-migration shape. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — tighten Phase 1 umbrella sentence The umbrella 'Land the typed carriers into src/v3/std/' framing was stale after f52e2ce's reframe of #1 to consumer-migration. Replaced with audit-first wording that covers both the consume-existing case (#1) and the design-and-land case (#2-#4 if their audits show real gaps). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…ost-#815 follow-up) (#816) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c3 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c3: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b03 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b03 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e691.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 second-wave worker-escalation fixes Four substantive worker STOP-AND-ESCALATEs from briefs landed in PR #797. All four worker recommendations correct; each needs a Director call + brief update. ## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate Worker correctly identified that brief req 2 (declared-effect carrier as part of fn type signature, per feedback_no_annotations) requires net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots. Without parser surface, every user function would have declared_effects = [] while inference returns non-empty — lens fires EffectLeakageError everywhere on enable. Worker rejected power-through and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map parser split). Director picked split: - NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface syntax + lookahead + body parser + lowerer extension + exhaustive-match audit + coproduct dissolution receipt. - MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to post-parser-extension scope. Pre-flight check NOT a parser-extension step; STOP if parser sub-lane PR not merged. ## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping Worker found load-bearing evidence at infer.rs:3693-3703: DB-11 deliberately strips refinements at operator dispatch as a designed-in fix for symmetric-operators failure mode. Brief's "attach where b != 0 as a proof for a / b" directly contradicts this design choice. STOP-3 (where-clause conflict with DB-11) is real; STOP-1 (substrate scope) needs net-new substrate (per-operator partiality fact + predicate- entailment check + asymmetric per-operand refinement-honoring) — M+ minimum. ownership_lens precedent in original brief is post-hoc observability, not proof carrier. Worker recommended redirect to design/scoping per nested-optional precedent. Director picked redirect. Brief fully rewritten as design/scoping with four-question structure: (1) DB-11 interaction analysis; (2) substrate proposal for proof-or- totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes with acceptance-theatre risk on user-defined-total-wrapper-only); (4) Director-actionable recommendation. Output is doc PR. ## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C) Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int) with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136 closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b) i128 implementation requires either path 1 (hierarchy refactor — contradicts non-goal) or path 2 (regen lie between substrate and emit — violates discipline). Worker leaned option (C) re-scope: land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke) to a sibling sub-lane that does proper Int128/Word128 substrate work. Director picked option (C). Brief req 1 re-scoped to drop canonical- carrier-widening; lane value comes from range facts + reconciliation narrowing + out-of-range diagnostic against existing i64. Req 4 explicitly deferred with sibling-sub-lane reference. Sibling sub-lane NOT to be authored or implied in this PR; tracked separately. ## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change) Worker correctly STOP'd per the brief's own pre-flight check: parser sub-lane has not landed; SurfaceExpr::Map not on main. Director authorized cross-lane reassignment: wise-boar-480 takes the parser sub-lane (t-substrate-valuebody-map-parser-worker.md) since they already have full investigation context. No brief changes needed; the routing decision is in the dispatch. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope Resolves codex P2 inline at sha e35103f on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still required widening LiteralBits::Int(i64) to an unbounded carrier and passing the i64::MIN smoke. Internally unsatisfiable. Fix: - Slice section retitled "range facts + reconciliation narrowing (against existing i64 carrier)" with explicit note about the re-scope. - Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly forbids touching LiteralBits::Int shape, dag_scalar_generated.rs regen for that variant, or tokenize i64 parse path. - Slice steps 2-5 reframed: range facts use i64-representable magnitudes; reconciliation narrowing uses existing i64 carrier; diagnostic only for i64-representable out-of-range; smoke tests for req 5 only (req 4 i64::MIN deferred). - Acceptance checklist updated: - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as re-scoped/deferred. - LiteralBits::Int(i64) carrier untouched (no widening; no parallel; no shape change). - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference. - STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the carrier" — explicit STOP if execution surfaces range-fact narrowing requiring carrier-widening; that's the boundary the re-scope drew; belongs in sibling Int128/Word128 sub-lane. Brief now consistently treats carrier-widening as out-of-scope across all sections. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty Resolves codex BLOCKING #1 at sha e35103f on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier but req 2 required range facts using "the SAME magnitude carrier as req 1" — meaning i64-typed range bounds. u64's max (2^64-1) doesn't fit in i64; range fact for u64 would have to truncate, omit, or mirror in Rust (representation drift). All three options violate fail-closed declared-facts discipline (P1 / P3). Fix: - Req 2 rewritten to specify String-decimal representation: range_min_inclusive: String + range_max_inclusive: String fields on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127" for i8; "0"/"18446744073709551615" for u64). - Explicit reasoning why String-decimal: u64's max doesn't fit in i64; binding range bounds to literal carrier forces truncation/ omission/mirror-drift; all violate fail-closed declared-facts discipline. - Bridge framing: String-decimal is pending the sibling Int128/ Word128 sub-lane; both range bounds and literal payload migrate to typed carrier when that lands. - Req 3 updated for String-decimal comparison semantics: reconciliation parses both bounds and literal magnitude into a common comparison space (i128 host comparison primitive — host narrowing, NOT carrier widening). Bounded by what the i64-typed literal can express; any i64-representable literal compares against any width's String-decimal bound. Carrier discipline preserved. Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral) is sha-stale — already resolved at 3e142d1. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed Resolves codex BLOCKING at sha 0815189 (post-#799-merge feedback). Real residual: req 2 specifies String-decimal range bounds (to cover u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" / "i64-representable magnitudes" for the range facts. Two incompatible authorities for the same range-fact shape — would let a worker satisfy the slice while truncating/omitting u64 bounds (P3 fail-closed violation). Fix: - Line 31 (req 1 re-scope clarification): updated to explicitly state "range facts (req 2) use String-decimal representation (width- independent; covers u64::MAX which doesn't fit in i64)". Distinguished literal *payload* (stays i64) from range-bound *representation* (String) — both serve req 1's "no carrier widening" boundary. - Line 44 (slice step 2): updated from "Range bounds use i64- representable magnitudes" to "Range bounds use String-decimal representation per req 2" with concrete example (u64 bounds). - Acceptance bullet: updated from "Range facts on integer algebras (substrate-declared, not Rust-mirrored)" to add "using String-decimal representation ... width-independent; u64 bounds expressible without truncation." The brief now consistently treats range bounds as String-decimal across req 2, req 3, slice, acceptance, and the req 1 clarification — no remaining authorities saying i64-typed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing User + PM exchange 2026-04-25 surfaced that the in-flight effects chain was importing wrong assumptions from external languages (declared-effects-as-annotation + lens-vs-declaration check). Right framing under gunbc's closed-system discipline is parallel to complexity: every effect derives structurally from the composition of typed primitive operations; nothing can hide because there's no escape hatch; nothing needs annotation because the structure IS the registry. Four doc-only actions: 1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md. Frames the closed-system answer with PM's 5-behavior synergy table (Value/Transform/Branch/Loop/Bind as universal compositional-fold pattern). Four worked examples; aggressive reading on redundancy (compile-error-by-construction via referential-transparency proof; reread() primitive for legitimate cases); implementation-brief shape in §Q6. 2. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md. 3. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md. Notes Fn→Arrow refactor brief stays dispatchable as independent value. 4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by- construction framing replaces lens-detection framing. Memory file feedback_closed_system_effects.md saved separately; cross-link added to feedback_construction_over_ratchets.md. Net cost: doc-level cleanup. Zero substrate code rework. Foundation (OperationEffect + service-call infrastructure + 5-behavior substrate) already exists. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect Per PM convergence review on #808 + user's deeper 2026-04-25 framing: the closed-system framing landed in #808 retired the user-facing annotation but kept OperationEffect taxonomy as substrate-level tagging. User's deeper framing: the taxonomy ITSELF is parallel-representation — operations are intrinsically read-shaped or write-shaped via their TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns- derived-value-only → read). Tagging operations with Read | Upsert | Create | Append | Delete names what the structure already says. Three changes: 1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as normalized view, or retire as parallel-representation?" - Two paths: (i) tags derived from signature shape (acceptable normalized view) vs (ii) tags declared per-primitive (parallel- representation; retire). - Audit-as-existence-check (Q4 req 2 reframed): all effectful primitives derive cleanly from signature shape → path (i); any primitive needs hand-declared tag → path (ii) by existence proof. - Director default: path (ii). Logging primitives that return Unit are likely the audit's existence-proof. - Two design-question resolutions: (a) external effects not in return type → resource-threading discipline (typed param returned modified, IO-monad-without-the-monad pattern); (b) transactional grouping → derived structural fact from Bind composition + typed transaction primitives. 2. Q4 reqs revised: req 2 from "tag every primitive with explicit OperationEffect signature" to "audit-as-existence-check that every primitive's type signature derives the right effect classification"; req 3 added (resource-threading discipline); req 6 added (transactional-pattern lens). Req 1 (effects lens) anchors on operation type-signature shape, not on hand-declared tags. 3. THESIS:345-347 amendment strengthened — "operations are intrinsically read-shaped or write-shaped via their type-signature shape; consumers walk the signatures directly; there is no parallel taxonomy or annotation layer to declare or maintain. Tracking effects as a separate enumerated concept IS the bug pattern, dissolved by construction." Plus references to resource-threading discipline + transactional grouping as derived structural fact. Memory file feedback_closed_system_effects.md updated to reflect the deeper framing (type-signature-shape, not taxonomy-tagging) + resource-threading discipline section + transactional-patterns section. Net cost: doc-only delta on top of #808. Substrate retirement (OperationEffect enum + derive_op_effect + idempotency.dag re-anchor) deferred to the audit-as-existence-check phase of the implementation brief; surfaced as Q5.5 OPEN CALL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage Resolves codex BLOCKING at sha d49ce79 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real: the prior text claimed service primitives "already carry typed effect signatures" presenting future audit-state as current substrate fact (P1 violation). My Q5.5 amendment at 2dc656b partially fixed the OperationEffect line but left a parallel over-claim on the new "signature-shape coverage" framing. Fix: Q4 substrate-state listing rewritten to honestly distinguish: - Live: Behavior enum + substrate foundation (the principle that operations should carry signature shape). - Incomplete: signature-shape coverage across actual primitives. HTTP-derived primitives carry implicit shape via derive_op_effect's method-table; logging/mutation primitives that return Unit or don't thread their target resource do NOT carry the structural shape that would express read-vs-write. Achieving full coverage is required work under reqs 2 + 3, not a current fact. - Pending audit-as-existence-check: OperationEffect + derive_op_effect (path (i) vs (ii) per Q5.5). Honest live-state callout added explicitly: "the closed-system FOUNDATION (5 behaviors + DAG substrate + the principle that operations should carry signature-shape) is live. The IMPLEMENTATION COVERAGE across all effectful primitives is partial. Req 2 + req 3 are the work that closes the gap." Brief now distinguishes principle-is-live (foundation) from coverage-is-partial (audit work) without conflating them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim Per PM follow-up review on #808 + user's stronger discipline framing ("substrate must make bypass structurally impossible at every layer of the transport stack"): the closed-system claim is honest only when typed primitives ARE the path. Today two structural holes exist where bypasses sidestep the typed-primitive substrate. Both surfaced explicitly as Q4.5 pre-conditions — load-bearing for the lens's coverage claim. Three changes: 1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed- system claim)" inserted between Q4 and Q5: P1 — Extdeps typed-primitive consumption structurally enforced. Substrate must make `messages: Json` impossible to declare in service definitions; typed `LlmMessage` / `ContentBlock` / `GitHubAuthToken`-with-full-scopes are the only path. Tracked debt at ROADMAP.md:153-154 (LLM provider flattening) + `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded). Required prereq for full lens coverage; lens can land first + surface structural-coverage-gap diagnostics on bypass surfaces so the gap becomes visible rather than silent. P2 — `ExecuteCommand` fully materialized as typed runner primitive. TESTING.md (post-#782) committed to 0-residual but ExecuteCommand isn't fully materialized; deleting Rust boundary tests creates verification gap. Already named under PB-Runtime in Zero-Floor; signal pending. Pre-requisite for ANY Rust boundary-test deletion. 2. Old leftover duplicate Q5 section deleted (artifact from prior Q5/Q5.5 reshape; second copy of asymmetric-tightening text was in the file alongside the earlier Q5 instance). 3. Worker-discretion-vs-Director-call section in Q4.5: lens implementation worker dispatchable now (reports gaps as findings); P1 closure is substantive substrate work touching extdeps (dedicated lane); P2 closure is PB-Runtime (signal pending). Net: design doc now honestly distinguishes principle-is-live (Q4 rewrite at 191be31) from coverage-is-partial (Q4.5 prereqs named explicitly). The closed-system claim has explicit pre- conditions documented; implementation brief discovers them as known dependencies, not as STOP-AND-ESCALATEs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default Resolves claude APPROVE_WITH_COMMENTS at sha 191be31 on #808. Two real residuals after the Q5.5 reframe: 1. Q6's reqs/STOPs/acceptance still framed under path (i) — said "audit + tag std/ primitives — every effectful primitive carries an explicit OperationEffect signature." Directly contradicted Q4 (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment ("there is no parallel taxonomy to declare or maintain"). Worker reading Q6 in isolation would author the retracted shape. 2. Capacity / sequencing table line about "audit lane (tag std/ primitives with effect signatures)" carried the same stale framing. 3. Q6 STOP "primitive performing side effects without an OperationEffect tag" assumed tag-as-authority; under path (ii) the STOP shape is "primitive whose signature doesn't structurally reveal its effect." Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale (already fixed at f073aa9 Q4.5 commit). ## Q6 fixes - Reqs renumbered + reframed: - Req 1 anchors on operation type-signature shape (not hand-declared OperationEffect tags); composition reads from signature shape per Q2 table. - Req 2 changed from "audit + tag every primitive" to "audit-as-existence-check" — verify signature-shape coverage; ANY primitive needing a hand-declared tag IS the existence-proof for path (ii) retirement. - Req 3 added: resource-threading discipline applied to existing primitives (logging that returns Unit gets reshaped per audit). - Req 6 added: transactional-pattern lens (Bind composition + Transaction → Transaction'). - Req 7 added: asymmetric-tightening worked example in PR body (per claude review observation; the one place declaration-shaped surface re-enters). - Req 8 (was 5): tests now reference signature-shape derivation explicitly, not tag lookup. - STOPs reframed: - "OperationEffect retirement decision" — audit produces path (i) vs (ii) verdict; substrate retirement is its own dedicated sub-lane; this lane does NOT absorb it. - Pure/impure carrier STOP notes that "pure" should also derive from signature shape (pure functions don't return modified resources) — so the STOP itself may dissolve under further design. - Q4.5 P1 explicitly NOT a STOP — lens reporting structural- coverage-gap on extdeps bypass surfaces is the lens delivering its foundation-gap-visibility value. - Q4.5 P2 explicitly independent — lens doesn't depend on ExecuteCommand materialization. - Acceptance extended: lens reports gap diagnostics on P1 bypass surfaces; audit produces existence-proof verdict for Director re-decision; asymmetric-tightening worked example in PR body. ## Capacity / sequencing table Replaced "1 audit lane (tag std/ primitives with effect signatures)" with "1 audit-as-existence-check lane (verify primitives' signature- shape coverage; NOT 'tag every primitive') — produces the path (i) vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2 prereq lanes to the net summary. Closing line: "The taxonomy- retirement scope (substrate-side) is not in this lane — it's surfaced by audit and routed to dedicated retirement lane if path (ii) wins." Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity table. Worker reading Q6 in isolation now sees path-(ii)-default framing matching Q4 + Q5.5 + THESIS amendment. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792 Resolves codex inline BLOCKING at sha 191be31 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150. Real: my Q4.5 P2 framing described ExecuteCommand as still NotYetImplemented (M1.5 allowlist + Rust TestRunner returning NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand extension before this PR's authoring. TESTING.md:195 capability-state callout confirms: - Rust TestRunner + M1.5 testgen harness share one std::process path for arbitrary command + args + expect_exit_code. - M1.5 allowlist + fail-closed panic retired. - Distinguishable ClaimResult::Fail messages for spawn / timeout / policy / exit-mismatch. - Linux unshare(1) namespace isolation on host-allowing systems. - T-PB-B-1 boundary migration example landed. Fix: P2 section rewritten: - Header retitled "ExecuteCommand runner primitive: LANDED (PR #792); residual is bulk-migration." - Status update naming PR #792 + the post-#792 capability state (allowlist retired, etc.). - Honest acknowledgement: "My earlier P2 framing was stale." - Residual narrowed to bulk-migration of existing Rust Command::new boundary tests (tracked as ROADMAP residual, not lens prereq). - Sequencing reframed: P2 was always orthogonal to the effects lens itself; bulk migration proceeds at its own pace; lens not blocked. Q4.5 footer updated: - "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via #792; only consumer-side bulk migration remains)" - Worker-discretion-vs-Director-call P2 line updated: "runner primitive landed; only consumer-side bulk migration remains; tracked as ROADMAP residual, independent of the lens." Q6 STOP for P2 updated: - "the lens itself doesn't depend on P2; only TESTING.md's 0-residual claim does" → "runner primitive landed via PR #792 (post-Q4.5- authoring update). The lens itself never depended on P2; bulk consumer migration is residual ROADMAP work and remains independent of this lane." Brief now reflects live state. The closed-system claim's prereq landscape is honest: - P1 (extdeps typed-primitive consumption): real prereq, tracked debt at ROADMAP:153-154. - P2 (ExecuteCommand runner): satisfied via #792; bulk migration is consumer-side residual, not foundation work. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale Resolves codex non-blocking finding at sha bcac41b on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real residual: capacity-table line still listed P2 as "`ExecuteCommand` materialization" prereq + framed both P1 and P2 as "pre-existing tracked-debt" — but my prior 57a9b13 fix established that PR #792 already landed the runner primitive, so P2 is no longer a materialization prereq. Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq) from P2 (residual, not prereq): - P1: extdeps typed-primitive consumption — pre-existing tracked debt at ROADMAP:153-154; load-bearing for the lens's full-coverage claim. - P2: ExecuteCommand runner primitive landed via PR #792; only consumer-side bulk migration of existing Rust Command::new boundary tests remains (tracked as ROADMAP residual, independent of the lens; not a materialization prereq). Brief now consistently treats P2 as bulk-migration-residual across: - §Q4.5 P2 section header (LANDED via PR #792; residual is bulk-migration). - §Q4.5 footer (P2: runner primitive landed; only consumer-side bulk migration remains). - Q6 STOP for P2 (runner primitive landed; bulk migration is residual ROADMAP work). - §Capacity / sequencing impact (P2 as residual, not prereq). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349 Codex finding on PR #808 sha ece964e: lines 153-154 are unrelated target-grounding prose; the matching extdeps typed-primitive bypass entries (LLM service flattening, GitHub auth model bypass) live at ROADMAP.md:348-349. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix third stale ROADMAP citation at line 271 Codex follow-up on sha 2552ca3: prior fix missed a third occurrence at line 271 in the §Q4.5 capacity table. Now consistent with lines 139 and 173 (ROADMAP.md:348-349). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity Codex flagged 'Effect-signature tagging on std/ primitives' as potentially contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240) already explicitly say 'NOT tag every primitive' — but the cross-manager line used sloppy wording. Reworded to make explicit that the audit walks signature shape; no parallel tag added. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5 - B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound - B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause - B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge - B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation) B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25): language vocabulary is primitives + namespacing only; no escape syntax; the §0 sentinels are the compiler itself failing to use primitives + namespacing internally. Eight surface sites dissolve via four substrate carriers (DeclarationRef, structural fold-shape carrier, structural emit-helper carrier, structural extdeps-fixture-set carrier). B1-B3 are independent; dispatch in parallel. B4 is sequential program work; sub-brief dispatch (B4.1-B4.12) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — drop incoherent inner-fallback non-goal Codex P2: the non-goal line excluding the inner declaration().name unwrap_or_else fallback contradicted Slice step 2, which replaces the whole chain with let-Some-else-return. Both fallbacks are in scope by construction; remove the contradictory non-goal. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives PM REQUEST_CHANGES: §Frame listed '4 type connectives (Conjunction | Disjunction | Cardinality | Bit)' which contradicted the canonical thesis source. Replaced with the canonical 6 (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary closes here'. Also removed 'typed substrate carriers' from the vocabulary list — substrate carriers are defined using the vocabulary, not part of it. Added a clarifying note that B4's carriers (DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are typed declarations composed from the vocabulary, not vocabulary extensions. Per feedback_verify_thesis_claims: brief framings citing thesis structure must ground in the canonical source. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of naming the live substrate authority. Two coordinated fixes: 1. §Read first cites src/v3/std/substrate.dag (live .dag substrate authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel meta-type — already exists with consumers in verification.dag, emit_model.dag, python.dag). 2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing DeclarationRef'. The work is consumer migration + any role-extension layer the audit reveals, NOT designing or landing the carrier. Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers) keep their 'new' framing but explicitly require sub-briefs to grep src/v3/std/ + src/v3/spec/ for existing authority before authoring 'design and land' framing — per feedback_verify_thesis_claims + feedback_emitter_workaround_is_gap_symptom. Acceptance + sub-brief dispatch order updated to reflect B4.1's consumer-migration shape. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — tighten Phase 1 umbrella sentence The umbrella 'Land the typed carriers into src/v3/std/' framing was stale after f52e2ce's reframe of #1 to consumer-migration. Replaced with audit-first wording that covers both the consume-existing case (#1) and the design-and-land case (#2-#4 if their audits show real gaps). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands' which conflicted with the post-reframe reality that B4.1 consumes the existing DeclarationRef. Updated to 'consumes or lands' with explicit existing-authority citation and audit-pending caveat for B4.2-B4.4. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…4 precedent (rev. softening) (#818) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c3 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c3: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b03 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b03 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e691.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 second-wave worker-escalation fixes Four substantive worker STOP-AND-ESCALATEs from briefs landed in PR #797. All four worker recommendations correct; each needs a Director call + brief update. ## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate Worker correctly identified that brief req 2 (declared-effect carrier as part of fn type signature, per feedback_no_annotations) requires net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots. Without parser surface, every user function would have declared_effects = [] while inference returns non-empty — lens fires EffectLeakageError everywhere on enable. Worker rejected power-through and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map parser split). Director picked split: - NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface syntax + lookahead + body parser + lowerer extension + exhaustive-match audit + coproduct dissolution receipt. - MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to post-parser-extension scope. Pre-flight check NOT a parser-extension step; STOP if parser sub-lane PR not merged. ## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping Worker found load-bearing evidence at infer.rs:3693-3703: DB-11 deliberately strips refinements at operator dispatch as a designed-in fix for symmetric-operators failure mode. Brief's "attach where b != 0 as a proof for a / b" directly contradicts this design choice. STOP-3 (where-clause conflict with DB-11) is real; STOP-1 (substrate scope) needs net-new substrate (per-operator partiality fact + predicate- entailment check + asymmetric per-operand refinement-honoring) — M+ minimum. ownership_lens precedent in original brief is post-hoc observability, not proof carrier. Worker recommended redirect to design/scoping per nested-optional precedent. Director picked redirect. Brief fully rewritten as design/scoping with four-question structure: (1) DB-11 interaction analysis; (2) substrate proposal for proof-or- totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes with acceptance-theatre risk on user-defined-total-wrapper-only); (4) Director-actionable recommendation. Output is doc PR. ## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C) Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int) with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136 closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b) i128 implementation requires either path 1 (hierarchy refactor — contradicts non-goal) or path 2 (regen lie between substrate and emit — violates discipline). Worker leaned option (C) re-scope: land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke) to a sibling sub-lane that does proper Int128/Word128 substrate work. Director picked option (C). Brief req 1 re-scoped to drop canonical- carrier-widening; lane value comes from range facts + reconciliation narrowing + out-of-range diagnostic against existing i64. Req 4 explicitly deferred with sibling-sub-lane reference. Sibling sub-lane NOT to be authored or implied in this PR; tracked separately. ## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change) Worker correctly STOP'd per the brief's own pre-flight check: parser sub-lane has not landed; SurfaceExpr::Map not on main. Director authorized cross-lane reassignment: wise-boar-480 takes the parser sub-lane (t-substrate-valuebody-map-parser-worker.md) since they already have full investigation context. No brief changes needed; the routing decision is in the dispatch. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope Resolves codex P2 inline at sha e35103f on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still required widening LiteralBits::Int(i64) to an unbounded carrier and passing the i64::MIN smoke. Internally unsatisfiable. Fix: - Slice section retitled "range facts + reconciliation narrowing (against existing i64 carrier)" with explicit note about the re-scope. - Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly forbids touching LiteralBits::Int shape, dag_scalar_generated.rs regen for that variant, or tokenize i64 parse path. - Slice steps 2-5 reframed: range facts use i64-representable magnitudes; reconciliation narrowing uses existing i64 carrier; diagnostic only for i64-representable out-of-range; smoke tests for req 5 only (req 4 i64::MIN deferred). - Acceptance checklist updated: - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as re-scoped/deferred. - LiteralBits::Int(i64) carrier untouched (no widening; no parallel; no shape change). - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference. - STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the carrier" — explicit STOP if execution surfaces range-fact narrowing requiring carrier-widening; that's the boundary the re-scope drew; belongs in sibling Int128/Word128 sub-lane. Brief now consistently treats carrier-widening as out-of-scope across all sections. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty Resolves codex BLOCKING #1 at sha e35103f on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier but req 2 required range facts using "the SAME magnitude carrier as req 1" — meaning i64-typed range bounds. u64's max (2^64-1) doesn't fit in i64; range fact for u64 would have to truncate, omit, or mirror in Rust (representation drift). All three options violate fail-closed declared-facts discipline (P1 / P3). Fix: - Req 2 rewritten to specify String-decimal representation: range_min_inclusive: String + range_max_inclusive: String fields on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127" for i8; "0"/"18446744073709551615" for u64). - Explicit reasoning why String-decimal: u64's max doesn't fit in i64; binding range bounds to literal carrier forces truncation/ omission/mirror-drift; all violate fail-closed declared-facts discipline. - Bridge framing: String-decimal is pending the sibling Int128/ Word128 sub-lane; both range bounds and literal payload migrate to typed carrier when that lands. - Req 3 updated for String-decimal comparison semantics: reconciliation parses both bounds and literal magnitude into a common comparison space (i128 host comparison primitive — host narrowing, NOT carrier widening). Bounded by what the i64-typed literal can express; any i64-representable literal compares against any width's String-decimal bound. Carrier discipline preserved. Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral) is sha-stale — already resolved at 3e142d1. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed Resolves codex BLOCKING at sha 0815189 (post-#799-merge feedback). Real residual: req 2 specifies String-decimal range bounds (to cover u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" / "i64-representable magnitudes" for the range facts. Two incompatible authorities for the same range-fact shape — would let a worker satisfy the slice while truncating/omitting u64 bounds (P3 fail-closed violation). Fix: - Line 31 (req 1 re-scope clarification): updated to explicitly state "range facts (req 2) use String-decimal representation (width- independent; covers u64::MAX which doesn't fit in i64)". Distinguished literal *payload* (stays i64) from range-bound *representation* (String) — both serve req 1's "no carrier widening" boundary. - Line 44 (slice step 2): updated from "Range bounds use i64- representable magnitudes" to "Range bounds use String-decimal representation per req 2" with concrete example (u64 bounds). - Acceptance bullet: updated from "Range facts on integer algebras (substrate-declared, not Rust-mirrored)" to add "using String-decimal representation ... width-independent; u64 bounds expressible without truncation." The brief now consistently treats range bounds as String-decimal across req 2, req 3, slice, acceptance, and the req 1 clarification — no remaining authorities saying i64-typed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing User + PM exchange 2026-04-25 surfaced that the in-flight effects chain was importing wrong assumptions from external languages (declared-effects-as-annotation + lens-vs-declaration check). Right framing under gunbc's closed-system discipline is parallel to complexity: every effect derives structurally from the composition of typed primitive operations; nothing can hide because there's no escape hatch; nothing needs annotation because the structure IS the registry. Four doc-only actions: 1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md. Frames the closed-system answer with PM's 5-behavior synergy table (Value/Transform/Branch/Loop/Bind as universal compositional-fold pattern). Four worked examples; aggressive reading on redundancy (compile-error-by-construction via referential-transparency proof; reread() primitive for legitimate cases); implementation-brief shape in §Q6. 2. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md. 3. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md. Notes Fn→Arrow refactor brief stays dispatchable as independent value. 4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by- construction framing replaces lens-detection framing. Memory file feedback_closed_system_effects.md saved separately; cross-link added to feedback_construction_over_ratchets.md. Net cost: doc-level cleanup. Zero substrate code rework. Foundation (OperationEffect + service-call infrastructure + 5-behavior substrate) already exists. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect Per PM convergence review on #808 + user's deeper 2026-04-25 framing: the closed-system framing landed in #808 retired the user-facing annotation but kept OperationEffect taxonomy as substrate-level tagging. User's deeper framing: the taxonomy ITSELF is parallel-representation — operations are intrinsically read-shaped or write-shaped via their TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns- derived-value-only → read). Tagging operations with Read | Upsert | Create | Append | Delete names what the structure already says. Three changes: 1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as normalized view, or retire as parallel-representation?" - Two paths: (i) tags derived from signature shape (acceptable normalized view) vs (ii) tags declared per-primitive (parallel- representation; retire). - Audit-as-existence-check (Q4 req 2 reframed): all effectful primitives derive cleanly from signature shape → path (i); any primitive needs hand-declared tag → path (ii) by existence proof. - Director default: path (ii). Logging primitives that return Unit are likely the audit's existence-proof. - Two design-question resolutions: (a) external effects not in return type → resource-threading discipline (typed param returned modified, IO-monad-without-the-monad pattern); (b) transactional grouping → derived structural fact from Bind composition + typed transaction primitives. 2. Q4 reqs revised: req 2 from "tag every primitive with explicit OperationEffect signature" to "audit-as-existence-check that every primitive's type signature derives the right effect classification"; req 3 added (resource-threading discipline); req 6 added (transactional-pattern lens). Req 1 (effects lens) anchors on operation type-signature shape, not on hand-declared tags. 3. THESIS:345-347 amendment strengthened — "operations are intrinsically read-shaped or write-shaped via their type-signature shape; consumers walk the signatures directly; there is no parallel taxonomy or annotation layer to declare or maintain. Tracking effects as a separate enumerated concept IS the bug pattern, dissolved by construction." Plus references to resource-threading discipline + transactional grouping as derived structural fact. Memory file feedback_closed_system_effects.md updated to reflect the deeper framing (type-signature-shape, not taxonomy-tagging) + resource-threading discipline section + transactional-patterns section. Net cost: doc-only delta on top of #808. Substrate retirement (OperationEffect enum + derive_op_effect + idempotency.dag re-anchor) deferred to the audit-as-existence-check phase of the implementation brief; surfaced as Q5.5 OPEN CALL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage Resolves codex BLOCKING at sha d49ce79 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real: the prior text claimed service primitives "already carry typed effect signatures" presenting future audit-state as current substrate fact (P1 violation). My Q5.5 amendment at 2dc656b partially fixed the OperationEffect line but left a parallel over-claim on the new "signature-shape coverage" framing. Fix: Q4 substrate-state listing rewritten to honestly distinguish: - Live: Behavior enum + substrate foundation (the principle that operations should carry signature shape). - Incomplete: signature-shape coverage across actual primitives. HTTP-derived primitives carry implicit shape via derive_op_effect's method-table; logging/mutation primitives that return Unit or don't thread their target resource do NOT carry the structural shape that would express read-vs-write. Achieving full coverage is required work under reqs 2 + 3, not a current fact. - Pending audit-as-existence-check: OperationEffect + derive_op_effect (path (i) vs (ii) per Q5.5). Honest live-state callout added explicitly: "the closed-system FOUNDATION (5 behaviors + DAG substrate + the principle that operations should carry signature-shape) is live. The IMPLEMENTATION COVERAGE across all effectful primitives is partial. Req 2 + req 3 are the work that closes the gap." Brief now distinguishes principle-is-live (foundation) from coverage-is-partial (audit work) without conflating them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim Per PM follow-up review on #808 + user's stronger discipline framing ("substrate must make bypass structurally impossible at every layer of the transport stack"): the closed-system claim is honest only when typed primitives ARE the path. Today two structural holes exist where bypasses sidestep the typed-primitive substrate. Both surfaced explicitly as Q4.5 pre-conditions — load-bearing for the lens's coverage claim. Three changes: 1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed- system claim)" inserted between Q4 and Q5: P1 — Extdeps typed-primitive consumption structurally enforced. Substrate must make `messages: Json` impossible to declare in service definitions; typed `LlmMessage` / `ContentBlock` / `GitHubAuthToken`-with-full-scopes are the only path. Tracked debt at ROADMAP.md:153-154 (LLM provider flattening) + `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded). Required prereq for full lens coverage; lens can land first + surface structural-coverage-gap diagnostics on bypass surfaces so the gap becomes visible rather than silent. P2 — `ExecuteCommand` fully materialized as typed runner primitive. TESTING.md (post-#782) committed to 0-residual but ExecuteCommand isn't fully materialized; deleting Rust boundary tests creates verification gap. Already named under PB-Runtime in Zero-Floor; signal pending. Pre-requisite for ANY Rust boundary-test deletion. 2. Old leftover duplicate Q5 section deleted (artifact from prior Q5/Q5.5 reshape; second copy of asymmetric-tightening text was in the file alongside the earlier Q5 instance). 3. Worker-discretion-vs-Director-call section in Q4.5: lens implementation worker dispatchable now (reports gaps as findings); P1 closure is substantive substrate work touching extdeps (dedicated lane); P2 closure is PB-Runtime (signal pending). Net: design doc now honestly distinguishes principle-is-live (Q4 rewrite at 191be31) from coverage-is-partial (Q4.5 prereqs named explicitly). The closed-system claim has explicit pre- conditions documented; implementation brief discovers them as known dependencies, not as STOP-AND-ESCALATEs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default Resolves claude APPROVE_WITH_COMMENTS at sha 191be31 on #808. Two real residuals after the Q5.5 reframe: 1. Q6's reqs/STOPs/acceptance still framed under path (i) — said "audit + tag std/ primitives — every effectful primitive carries an explicit OperationEffect signature." Directly contradicted Q4 (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment ("there is no parallel taxonomy to declare or maintain"). Worker reading Q6 in isolation would author the retracted shape. 2. Capacity / sequencing table line about "audit lane (tag std/ primitives with effect signatures)" carried the same stale framing. 3. Q6 STOP "primitive performing side effects without an OperationEffect tag" assumed tag-as-authority; under path (ii) the STOP shape is "primitive whose signature doesn't structurally reveal its effect." Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale (already fixed at f073aa9 Q4.5 commit). ## Q6 fixes - Reqs renumbered + reframed: - Req 1 anchors on operation type-signature shape (not hand-declared OperationEffect tags); composition reads from signature shape per Q2 table. - Req 2 changed from "audit + tag every primitive" to "audit-as-existence-check" — verify signature-shape coverage; ANY primitive needing a hand-declared tag IS the existence-proof for path (ii) retirement. - Req 3 added: resource-threading discipline applied to existing primitives (logging that returns Unit gets reshaped per audit). - Req 6 added: transactional-pattern lens (Bind composition + Transaction → Transaction'). - Req 7 added: asymmetric-tightening worked example in PR body (per claude review observation; the one place declaration-shaped surface re-enters). - Req 8 (was 5): tests now reference signature-shape derivation explicitly, not tag lookup. - STOPs reframed: - "OperationEffect retirement decision" — audit produces path (i) vs (ii) verdict; substrate retirement is its own dedicated sub-lane; this lane does NOT absorb it. - Pure/impure carrier STOP notes that "pure" should also derive from signature shape (pure functions don't return modified resources) — so the STOP itself may dissolve under further design. - Q4.5 P1 explicitly NOT a STOP — lens reporting structural- coverage-gap on extdeps bypass surfaces is the lens delivering its foundation-gap-visibility value. - Q4.5 P2 explicitly independent — lens doesn't depend on ExecuteCommand materialization. - Acceptance extended: lens reports gap diagnostics on P1 bypass surfaces; audit produces existence-proof verdict for Director re-decision; asymmetric-tightening worked example in PR body. ## Capacity / sequencing table Replaced "1 audit lane (tag std/ primitives with effect signatures)" with "1 audit-as-existence-check lane (verify primitives' signature- shape coverage; NOT 'tag every primitive') — produces the path (i) vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2 prereq lanes to the net summary. Closing line: "The taxonomy- retirement scope (substrate-side) is not in this lane — it's surfaced by audit and routed to dedicated retirement lane if path (ii) wins." Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity table. Worker reading Q6 in isolation now sees path-(ii)-default framing matching Q4 + Q5.5 + THESIS amendment. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792 Resolves codex inline BLOCKING at sha 191be31 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150. Real: my Q4.5 P2 framing described ExecuteCommand as still NotYetImplemented (M1.5 allowlist + Rust TestRunner returning NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand extension before this PR's authoring. TESTING.md:195 capability-state callout confirms: - Rust TestRunner + M1.5 testgen harness share one std::process path for arbitrary command + args + expect_exit_code. - M1.5 allowlist + fail-closed panic retired. - Distinguishable ClaimResult::Fail messages for spawn / timeout / policy / exit-mismatch. - Linux unshare(1) namespace isolation on host-allowing systems. - T-PB-B-1 boundary migration example landed. Fix: P2 section rewritten: - Header retitled "ExecuteCommand runner primitive: LANDED (PR #792); residual is bulk-migration." - Status update naming PR #792 + the post-#792 capability state (allowlist retired, etc.). - Honest acknowledgement: "My earlier P2 framing was stale." - Residual narrowed to bulk-migration of existing Rust Command::new boundary tests (tracked as ROADMAP residual, not lens prereq). - Sequencing reframed: P2 was always orthogonal to the effects lens itself; bulk migration proceeds at its own pace; lens not blocked. Q4.5 footer updated: - "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via #792; only consumer-side bulk migration remains)" - Worker-discretion-vs-Director-call P2 line updated: "runner primitive landed; only consumer-side bulk migration remains; tracked as ROADMAP residual, independent of the lens." Q6 STOP for P2 updated: - "the lens itself doesn't depend on P2; only TESTING.md's 0-residual claim does" → "runner primitive landed via PR #792 (post-Q4.5- authoring update). The lens itself never depended on P2; bulk consumer migration is residual ROADMAP work and remains independent of this lane." Brief now reflects live state. The closed-system claim's prereq landscape is honest: - P1 (extdeps typed-primitive consumption): real prereq, tracked debt at ROADMAP:153-154. - P2 (ExecuteCommand runner): satisfied via #792; bulk migration is consumer-side residual, not foundation work. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale Resolves codex non-blocking finding at sha bcac41b on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real residual: capacity-table line still listed P2 as "`ExecuteCommand` materialization" prereq + framed both P1 and P2 as "pre-existing tracked-debt" — but my prior 57a9b13 fix established that PR #792 already landed the runner primitive, so P2 is no longer a materialization prereq. Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq) from P2 (residual, not prereq): - P1: extdeps typed-primitive consumption — pre-existing tracked debt at ROADMAP:153-154; load-bearing for the lens's full-coverage claim. - P2: ExecuteCommand runner primitive landed via PR #792; only consumer-side bulk migration of existing Rust Command::new boundary tests remains (tracked as ROADMAP residual, independent of the lens; not a materialization prereq). Brief now consistently treats P2 as bulk-migration-residual across: - §Q4.5 P2 section header (LANDED via PR #792; residual is bulk-migration). - §Q4.5 footer (P2: runner primitive landed; only consumer-side bulk migration remains). - Q6 STOP for P2 (runner primitive landed; bulk migration is residual ROADMAP work). - §Capacity / sequencing impact (P2 as residual, not prereq). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349 Codex finding on PR #808 sha ece964e: lines 153-154 are unrelated target-grounding prose; the matching extdeps typed-primitive bypass entries (LLM service flattening, GitHub auth model bypass) live at ROADMAP.md:348-349. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix third stale ROADMAP citation at line 271 Codex follow-up on sha 2552ca3: prior fix missed a third occurrence at line 271 in the §Q4.5 capacity table. Now consistent with lines 139 and 173 (ROADMAP.md:348-349). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity Codex flagged 'Effect-signature tagging on std/ primitives' as potentially contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240) already explicitly say 'NOT tag every primitive' — but the cross-manager line used sloppy wording. Reworded to make explicit that the audit walks signature shape; no parallel tag added. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5 - B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound - B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause - B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge - B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation) B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25): language vocabulary is primitives + namespacing only; no escape syntax; the §0 sentinels are the compiler itself failing to use primitives + namespacing internally. Eight surface sites dissolve via four substrate carriers (DeclarationRef, structural fold-shape carrier, structural emit-helper carrier, structural extdeps-fixture-set carrier). B1-B3 are independent; dispatch in parallel. B4 is sequential program work; sub-brief dispatch (B4.1-B4.12) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — drop incoherent inner-fallback non-goal Codex P2: the non-goal line excluding the inner declaration().name unwrap_or_else fallback contradicted Slice step 2, which replaces the whole chain with let-Some-else-return. Both fallbacks are in scope by construction; remove the contradictory non-goal. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives PM REQUEST_CHANGES: §Frame listed '4 type connectives (Conjunction | Disjunction | Cardinality | Bit)' which contradicted the canonical thesis source. Replaced with the canonical 6 (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary closes here'. Also removed 'typed substrate carriers' from the vocabulary list — substrate carriers are defined using the vocabulary, not part of it. Added a clarifying note that B4's carriers (DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are typed declarations composed from the vocabulary, not vocabulary extensions. Per feedback_verify_thesis_claims: brief framings citing thesis structure must ground in the canonical source. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of naming the live substrate authority. Two coordinated fixes: 1. §Read first cites src/v3/std/substrate.dag (live .dag substrate authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel meta-type — already exists with consumers in verification.dag, emit_model.dag, python.dag). 2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing DeclarationRef'. The work is consumer migration + any role-extension layer the audit reveals, NOT designing or landing the carrier. Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers) keep their 'new' framing but explicitly require sub-briefs to grep src/v3/std/ + src/v3/spec/ for existing authority before authoring 'design and land' framing — per feedback_verify_thesis_claims + feedback_emitter_workaround_is_gap_symptom. Acceptance + sub-brief dispatch order updated to reflect B4.1's consumer-migration shape. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — tighten Phase 1 umbrella sentence The umbrella 'Land the typed carriers into src/v3/std/' framing was stale after f52e2ce's reframe of #1 to consumer-migration. Replaced with audit-first wording that covers both the consume-existing case (#1) and the design-and-land case (#2-#4 if their audits show real gaps). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands' which conflicted with the post-reframe reality that B4.1 consumes the existing DeclarationRef. Updated to 'consumes or lands' with explicit existing-authority citation and audit-pending caveat for B4.2-B4.4. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — soften regression-test requirement (3 worker bounces) Three consecutive B1 worker dispatches (zesty-crane-890 cursor → valiant-boar-498 codex → cool-lynx-395 cursor) archived without opening a PR. Likely friction point: brief Slice step 4 asks for a unit test that constructs a Dag with an orphan variant declaration, but emit.rs has zero existing #[test] precedent — emit testing happens via integration fixtures. Workers see 'build novel test harness' inside what's billed as an S-scope fix and bounce. Per feedback_construction_over_ratchets: when a brief has friction, fix the brief, don't ratchet the worker. Softened step 4 + acceptance: regression test stays optional. If test setup requires novel scaffolding, route the gap to follow-up. The structural fail-closed at step 2 is the load-bearing change. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description' is too weak; PR descriptions don't survive squash-merge cleanly. Two coordinated edits: 1. Slice step 4 — explicit substrate-signal framing: skipped test means emit-side hermetic-unit-test infrastructure is the missing substrate (feedback_emitter_workaround_is_gap_symptom). 2. Acceptance — require ROADMAP debt row (new or existing) with named dissolution trigger, referenced in PR body. Converts the skip from PR-local note (transient) into tracked debt (durable, dispatchable). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124 Codex BLOCKING: my earlier softening claimed emit.rs had no #[test] precedent — wrong. The module has #[cfg(test)] mod tests at line 3124 with 12+ tests using compile_to_dag(source, filename) as harness (e.g., go_struct_fields_render_with_separators :3143, shared_walk_to_disj_finds_match_scrutinee_sum_type :3195). This is a feedback_verify_thesis_claims violation on Director-side brief authoring — claim made without grep verification. Fix: restore step 4 as required, with explicit precedent citation. Worker constructs the failure case via the existing harness (direct Dag, fixture string, or BranchPattern exercise; worker's call on cleanest path). STOP-AND-ESCALATE only if construction proves materially harder than precedent suggests, in which case that escalation surfaces a real substrate gap and warrants ROADMAP debt — but the default is 'add the test.' Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites) Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded to 'several using compile_to_dag'. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
#836) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c33: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 second-wave worker-escalation fixes Four substantive worker STOP-AND-ESCALATEs from briefs landed in PR #797. All four worker recommendations correct; each needs a Director call + brief update. ## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate Worker correctly identified that brief req 2 (declared-effect carrier as part of fn type signature, per feedback_no_annotations) requires net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots. Without parser surface, every user function would have declared_effects = [] while inference returns non-empty — lens fires EffectLeakageError everywhere on enable. Worker rejected power-through and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map parser split). Director picked split: - NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface syntax + lookahead + body parser + lowerer extension + exhaustive-match audit + coproduct dissolution receipt. - MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to post-parser-extension scope. Pre-flight check NOT a parser-extension step; STOP if parser sub-lane PR not merged. ## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping Worker found load-bearing evidence at infer.rs:3693-3703: DB-11 deliberately strips refinements at operator dispatch as a designed-in fix for symmetric-operators failure mode. Brief's "attach where b != 0 as a proof for a / b" directly contradicts this design choice. STOP-3 (where-clause conflict with DB-11) is real; STOP-1 (substrate scope) needs net-new substrate (per-operator partiality fact + predicate- entailment check + asymmetric per-operand refinement-honoring) — M+ minimum. ownership_lens precedent in original brief is post-hoc observability, not proof carrier. Worker recommended redirect to design/scoping per nested-optional precedent. Director picked redirect. Brief fully rewritten as design/scoping with four-question structure: (1) DB-11 interaction analysis; (2) substrate proposal for proof-or- totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes with acceptance-theatre risk on user-defined-total-wrapper-only); (4) Director-actionable recommendation. Output is doc PR. ## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C) Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int) with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136 closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b) i128 implementation requires either path 1 (hierarchy refactor — contradicts non-goal) or path 2 (regen lie between substrate and emit — violates discipline). Worker leaned option (C) re-scope: land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke) to a sibling sub-lane that does proper Int128/Word128 substrate work. Director picked option (C). Brief req 1 re-scoped to drop canonical- carrier-widening; lane value comes from range facts + reconciliation narrowing + out-of-range diagnostic against existing i64. Req 4 explicitly deferred with sibling-sub-lane reference. Sibling sub-lane NOT to be authored or implied in this PR; tracked separately. ## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change) Worker correctly STOP'd per the brief's own pre-flight check: parser sub-lane has not landed; SurfaceExpr::Map not on main. Director authorized cross-lane reassignment: wise-boar-480 takes the parser sub-lane (t-substrate-valuebody-map-parser-worker.md) since they already have full investigation context. No brief changes needed; the routing decision is in the dispatch. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope Resolves codex P2 inline at sha e35103fad on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still required widening LiteralBits::Int(i64) to an unbounded carrier and passing the i64::MIN smoke. Internally unsatisfiable. Fix: - Slice section retitled "range facts + reconciliation narrowing (against existing i64 carrier)" with explicit note about the re-scope. - Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly forbids touching LiteralBits::Int shape, dag_scalar_generated.rs regen for that variant, or tokenize i64 parse path. - Slice steps 2-5 reframed: range facts use i64-representable magnitudes; reconciliation narrowing uses existing i64 carrier; diagnostic only for i64-representable out-of-range; smoke tests for req 5 only (req 4 i64::MIN deferred). - Acceptance checklist updated: - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as re-scoped/deferred. - LiteralBits::Int(i64) carrier untouched (no widening; no parallel; no shape change). - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference. - STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the carrier" — explicit STOP if execution surfaces range-fact narrowing requiring carrier-widening; that's the boundary the re-scope drew; belongs in sibling Int128/Word128 sub-lane. Brief now consistently treats carrier-widening as out-of-scope across all sections. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty Resolves codex BLOCKING #1 at sha e35103fa on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier but req 2 required range facts using "the SAME magnitude carrier as req 1" — meaning i64-typed range bounds. u64's max (2^64-1) doesn't fit in i64; range fact for u64 would have to truncate, omit, or mirror in Rust (representation drift). All three options violate fail-closed declared-facts discipline (P1 / P3). Fix: - Req 2 rewritten to specify String-decimal representation: range_min_inclusive: String + range_max_inclusive: String fields on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127" for i8; "0"/"18446744073709551615" for u64). - Explicit reasoning why String-decimal: u64's max doesn't fit in i64; binding range bounds to literal carrier forces truncation/ omission/mirror-drift; all violate fail-closed declared-facts discipline. - Bridge framing: String-decimal is pending the sibling Int128/ Word128 sub-lane; both range bounds and literal payload migrate to typed carrier when that lands. - Req 3 updated for String-decimal comparison semantics: reconciliation parses both bounds and literal magnitude into a common comparison space (i128 host comparison primitive — host narrowing, NOT carrier widening). Bounded by what the i64-typed literal can express; any i64-representable literal compares against any width's String-decimal bound. Carrier discipline preserved. Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral) is sha-stale — already resolved at 3e142d169. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback). Real residual: req 2 specifies String-decimal range bounds (to cover u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" / "i64-representable magnitudes" for the range facts. Two incompatible authorities for the same range-fact shape — would let a worker satisfy the slice while truncating/omitting u64 bounds (P3 fail-closed violation). Fix: - Line 31 (req 1 re-scope clarification): updated to explicitly state "range facts (req 2) use String-decimal representation (width- independent; covers u64::MAX which doesn't fit in i64)". Distinguished literal *payload* (stays i64) from range-bound *representation* (String) — both serve req 1's "no carrier widening" boundary. - Line 44 (slice step 2): updated from "Range bounds use i64- representable magnitudes" to "Range bounds use String-decimal representation per req 2" with concrete example (u64 bounds). - Acceptance bullet: updated from "Range facts on integer algebras (substrate-declared, not Rust-mirrored)" to add "using String-decimal representation ... width-independent; u64 bounds expressible without truncation." The brief now consistently treats range bounds as String-decimal across req 2, req 3, slice, acceptance, and the req 1 clarification — no remaining authorities saying i64-typed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing User + PM exchange 2026-04-25 surfaced that the in-flight effects chain was importing wrong assumptions from external languages (declared-effects-as-annotation + lens-vs-declaration check). Right framing under gunbc's closed-system discipline is parallel to complexity: every effect derives structurally from the composition of typed primitive operations; nothing can hide because there's no escape hatch; nothing needs annotation because the structure IS the registry. Four doc-only actions: 1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md. Frames the closed-system answer with PM's 5-behavior synergy table (Value/Transform/Branch/Loop/Bind as universal compositional-fold pattern). Four worked examples; aggressive reading on redundancy (compile-error-by-construction via referential-transparency proof; reread() primitive for legitimate cases); implementation-brief shape in §Q6. 2. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md. 3. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md. Notes Fn→Arrow refactor brief stays dispatchable as independent value. 4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by- construction framing replaces lens-detection framing. Memory file feedback_closed_system_effects.md saved separately; cross-link added to feedback_construction_over_ratchets.md. Net cost: doc-level cleanup. Zero substrate code rework. Foundation (OperationEffect + service-call infrastructure + 5-behavior substrate) already exists. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect Per PM convergence review on #808 + user's deeper 2026-04-25 framing: the closed-system framing landed in #808 retired the user-facing annotation but kept OperationEffect taxonomy as substrate-level tagging. User's deeper framing: the taxonomy ITSELF is parallel-representation — operations are intrinsically read-shaped or write-shaped via their TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns- derived-value-only → read). Tagging operations with Read | Upsert | Create | Append | Delete names what the structure already says. Three changes: 1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as normalized view, or retire as parallel-representation?" - Two paths: (i) tags derived from signature shape (acceptable normalized view) vs (ii) tags declared per-primitive (parallel- representation; retire). - Audit-as-existence-check (Q4 req 2 reframed): all effectful primitives derive cleanly from signature shape → path (i); any primitive needs hand-declared tag → path (ii) by existence proof. - Director default: path (ii). Logging primitives that return Unit are likely the audit's existence-proof. - Two design-question resolutions: (a) external effects not in return type → resource-threading discipline (typed param returned modified, IO-monad-without-the-monad pattern); (b) transactional grouping → derived structural fact from Bind composition + typed transaction primitives. 2. Q4 reqs revised: req 2 from "tag every primitive with explicit OperationEffect signature" to "audit-as-existence-check that every primitive's type signature derives the right effect classification"; req 3 added (resource-threading discipline); req 6 added (transactional-pattern lens). Req 1 (effects lens) anchors on operation type-signature shape, not on hand-declared tags. 3. THESIS:345-347 amendment strengthened — "operations are intrinsically read-shaped or write-shaped via their type-signature shape; consumers walk the signatures directly; there is no parallel taxonomy or annotation layer to declare or maintain. Tracking effects as a separate enumerated concept IS the bug pattern, dissolved by construction." Plus references to resource-threading discipline + transactional grouping as derived structural fact. Memory file feedback_closed_system_effects.md updated to reflect the deeper framing (type-signature-shape, not taxonomy-tagging) + resource-threading discipline section + transactional-patterns section. Net cost: doc-only delta on top of #808. Substrate retirement (OperationEffect enum + derive_op_effect + idempotency.dag re-anchor) deferred to the audit-as-existence-check phase of the implementation brief; surfaced as Q5.5 OPEN CALL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage Resolves codex BLOCKING at sha d49ce79a on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real: the prior text claimed service primitives "already carry typed effect signatures" presenting future audit-state as current substrate fact (P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the OperationEffect line but left a parallel over-claim on the new "signature-shape coverage" framing. Fix: Q4 substrate-state listing rewritten to honestly distinguish: - Live: Behavior enum + substrate foundation (the principle that operations should carry signature shape). - Incomplete: signature-shape coverage across actual primitives. HTTP-derived primitives carry implicit shape via derive_op_effect's method-table; logging/mutation primitives that return Unit or don't thread their target resource do NOT carry the structural shape that would express read-vs-write. Achieving full coverage is required work under reqs 2 + 3, not a current fact. - Pending audit-as-existence-check: OperationEffect + derive_op_effect (path (i) vs (ii) per Q5.5). Honest live-state callout added explicitly: "the closed-system FOUNDATION (5 behaviors + DAG substrate + the principle that operations should carry signature-shape) is live. The IMPLEMENTATION COVERAGE across all effectful primitives is partial. Req 2 + req 3 are the work that closes the gap." Brief now distinguishes principle-is-live (foundation) from coverage-is-partial (audit work) without conflating them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim Per PM follow-up review on #808 + user's stronger discipline framing ("substrate must make bypass structurally impossible at every layer of the transport stack"): the closed-system claim is honest only when typed primitives ARE the path. Today two structural holes exist where bypasses sidestep the typed-primitive substrate. Both surfaced explicitly as Q4.5 pre-conditions — load-bearing for the lens's coverage claim. Three changes: 1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed- system claim)" inserted between Q4 and Q5: P1 — Extdeps typed-primitive consumption structurally enforced. Substrate must make `messages: Json` impossible to declare in service definitions; typed `LlmMessage` / `ContentBlock` / `GitHubAuthToken`-with-full-scopes are the only path. Tracked debt at ROADMAP.md:153-154 (LLM provider flattening) + `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded). Required prereq for full lens coverage; lens can land first + surface structural-coverage-gap diagnostics on bypass surfaces so the gap becomes visible rather than silent. P2 — `ExecuteCommand` fully materialized as typed runner primitive. TESTING.md (post-#782) committed to 0-residual but ExecuteCommand isn't fully materialized; deleting Rust boundary tests creates verification gap. Already named under PB-Runtime in Zero-Floor; signal pending. Pre-requisite for ANY Rust boundary-test deletion. 2. Old leftover duplicate Q5 section deleted (artifact from prior Q5/Q5.5 reshape; second copy of asymmetric-tightening text was in the file alongside the earlier Q5 instance). 3. Worker-discretion-vs-Director-call section in Q4.5: lens implementation worker dispatchable now (reports gaps as findings); P1 closure is substantive substrate work touching extdeps (dedicated lane); P2 closure is PB-Runtime (signal pending). Net: design doc now honestly distinguishes principle-is-live (Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs named explicitly). The closed-system claim has explicit pre- conditions documented; implementation brief discovers them as known dependencies, not as STOP-AND-ESCALATEs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two real residuals after the Q5.5 reframe: 1. Q6's reqs/STOPs/acceptance still framed under path (i) — said "audit + tag std/ primitives — every effectful primitive carries an explicit OperationEffect signature." Directly contradicted Q4 (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment ("there is no parallel taxonomy to declare or maintain"). Worker reading Q6 in isolation would author the retracted shape. 2. Capacity / sequencing table line about "audit lane (tag std/ primitives with effect signatures)" carried the same stale framing. 3. Q6 STOP "primitive performing side effects without an OperationEffect tag" assumed tag-as-authority; under path (ii) the STOP shape is "primitive whose signature doesn't structurally reveal its effect." Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale (already fixed at f073aa95e Q4.5 commit). ## Q6 fixes - Reqs renumbered + reframed: - Req 1 anchors on operation type-signature shape (not hand-declared OperationEffect tags); composition reads from signature shape per Q2 table. - Req 2 changed from "audit + tag every primitive" to "audit-as-existence-check" — verify signature-shape coverage; ANY primitive needing a hand-declared tag IS the existence-proof for path (ii) retirement. - Req 3 added: resource-threading discipline applied to existing primitives (logging that returns Unit gets reshaped per audit). - Req 6 added: transactional-pattern lens (Bind composition + Transaction → Transaction'). - Req 7 added: asymmetric-tightening worked example in PR body (per claude review observation; the one place declaration-shaped surface re-enters). - Req 8 (was 5): tests now reference signature-shape derivation explicitly, not tag lookup. - STOPs reframed: - "OperationEffect retirement decision" — audit produces path (i) vs (ii) verdict; substrate retirement is its own dedicated sub-lane; this lane does NOT absorb it. - Pure/impure carrier STOP notes that "pure" should also derive from signature shape (pure functions don't return modified resources) — so the STOP itself may dissolve under further design. - Q4.5 P1 explicitly NOT a STOP — lens reporting structural- coverage-gap on extdeps bypass surfaces is the lens delivering its foundation-gap-visibility value. - Q4.5 P2 explicitly independent — lens doesn't depend on ExecuteCommand materialization. - Acceptance extended: lens reports gap diagnostics on P1 bypass surfaces; audit produces existence-proof verdict for Director re-decision; asymmetric-tightening worked example in PR body. ## Capacity / sequencing table Replaced "1 audit lane (tag std/ primitives with effect signatures)" with "1 audit-as-existence-check lane (verify primitives' signature- shape coverage; NOT 'tag every primitive') — produces the path (i) vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2 prereq lanes to the net summary. Closing line: "The taxonomy- retirement scope (substrate-side) is not in this lane — it's surfaced by audit and routed to dedicated retirement lane if path (ii) wins." Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity table. Worker reading Q6 in isolation now sees path-(ii)-default framing matching Q4 + Q5.5 + THESIS amendment. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792 Resolves codex inline BLOCKING at sha 191be310 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150. Real: my Q4.5 P2 framing described ExecuteCommand as still NotYetImplemented (M1.5 allowlist + Rust TestRunner returning NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand extension before this PR's authoring. TESTING.md:195 capability-state callout confirms: - Rust TestRunner + M1.5 testgen harness share one std::process path for arbitrary command + args + expect_exit_code. - M1.5 allowlist + fail-closed panic retired. - Distinguishable ClaimResult::Fail messages for spawn / timeout / policy / exit-mismatch. - Linux unshare(1) namespace isolation on host-allowing systems. - T-PB-B-1 boundary migration example landed. Fix: P2 section rewritten: - Header retitled "ExecuteCommand runner primitive: LANDED (PR #792); residual is bulk-migration." - Status update naming PR #792 + the post-#792 capability state (allowlist retired, etc.). - Honest acknowledgement: "My earlier P2 framing was stale." - Residual narrowed to bulk-migration of existing Rust Command::new boundary tests (tracked as ROADMAP residual, not lens prereq). - Sequencing reframed: P2 was always orthogonal to the effects lens itself; bulk migration proceeds at its own pace; lens not blocked. Q4.5 footer updated: - "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via #792; only consumer-side bulk migration remains)" - Worker-discretion-vs-Director-call P2 line updated: "runner primitive landed; only consumer-side bulk migration remains; tracked as ROADMAP residual, independent of the lens." Q6 STOP for P2 updated: - "the lens itself doesn't depend on P2; only TESTING.md's 0-residual claim does" → "runner primitive landed via PR #792 (post-Q4.5- authoring update). The lens itself never depended on P2; bulk consumer migration is residual ROADMAP work and remains independent of this lane." Brief now reflects live state. The closed-system claim's prereq landscape is honest: - P1 (extdeps typed-primitive consumption): real prereq, tracked debt at ROADMAP:153-154. - P2 (ExecuteCommand runner): satisfied via #792; bulk migration is consumer-side residual, not foundation work. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale Resolves codex non-blocking finding at sha bcac41bb on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real residual: capacity-table line still listed P2 as "`ExecuteCommand` materialization" prereq + framed both P1 and P2 as "pre-existing tracked-debt" — but my prior 57a9b1318 fix established that PR #792 already landed the runner primitive, so P2 is no longer a materialization prereq. Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq) from P2 (residual, not prereq): - P1: extdeps typed-primitive consumption — pre-existing tracked debt at ROADMAP:153-154; load-bearing for the lens's full-coverage claim. - P2: ExecuteCommand runner primitive landed via PR #792; only consumer-side bulk migration of existing Rust Command::new boundary tests remains (tracked as ROADMAP residual, independent of the lens; not a materialization prereq). Brief now consistently treats P2 as bulk-migration-residual across: - §Q4.5 P2 section header (LANDED via PR #792; residual is bulk-migration). - §Q4.5 footer (P2: runner primitive landed; only consumer-side bulk migration remains). - Q6 STOP for P2 (runner primitive landed; bulk migration is residual ROADMAP work). - §Capacity / sequencing impact (P2 as residual, not prereq). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349 Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated target-grounding prose; the matching extdeps typed-primitive bypass entries (LLM service flattening, GitHub auth model bypass) live at ROADMAP.md:348-349. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix third stale ROADMAP citation at line 271 Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence at line 271 in the §Q4.5 capacity table. Now consistent with lines 139 and 173 (ROADMAP.md:348-349). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity Codex flagged 'Effect-signature tagging on std/ primitives' as potentially contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240) already explicitly say 'NOT tag every primitive' — but the cross-manager line used sloppy wording. Reworded to make explicit that the audit walks signature shape; no parallel tag added. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5 - B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound - B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause - B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge - B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation) B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25): language vocabulary is primitives + namespacing only; no escape syntax; the §0 sentinels are the compiler itself failing to use primitives + namespacing internally. Eight surface sites dissolve via four substrate carriers (DeclarationRef, structural fold-shape carrier, structural emit-helper carrier, structural extdeps-fixture-set carrier). B1-B3 are independent; dispatch in parallel. B4 is sequential program work; sub-brief dispatch (B4.1-B4.12) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — drop incoherent inner-fallback non-goal Codex P2: the non-goal line excluding the inner declaration().name unwrap_or_else fallback contradicted Slice step 2, which replaces the whole chain with let-Some-else-return. Both fallbacks are in scope by construction; remove the contradictory non-goal. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives PM REQUEST_CHANGES: §Frame listed '4 type connectives (Conjunction | Disjunction | Cardinality | Bit)' which contradicted the canonical thesis source. Replaced with the canonical 6 (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary closes here'. Also removed 'typed substrate carriers' from the vocabulary list — substrate carriers are defined using the vocabulary, not part of it. Added a clarifying note that B4's carriers (DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are typed declarations composed from the vocabulary, not vocabulary extensions. Per feedback_verify_thesis_claims: brief framings citing thesis structure must ground in the canonical source. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of naming the live substrate authority. Two coordinated fixes: 1. §Read first cites src/v3/std/substrate.dag (live .dag substrate authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel meta-type — already exists with consumers in verification.dag, emit_model.dag, python.dag). 2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing DeclarationRef'. The work is consumer migration + any role-extension layer the audit reveals, NOT designing or landing the carrier. Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers) keep their 'new' framing but explicitly require sub-briefs to grep src/v3/std/ + src/v3/spec/ for existing authority before authoring 'design and land' framing — per feedback_verify_thesis_claims + feedback_emitter_workaround_is_gap_symptom. Acceptance + sub-brief dispatch order updated to reflect B4.1's consumer-migration shape. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — tighten Phase 1 umbrella sentence The umbrella 'Land the typed carriers into src/v3/std/' framing was stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced with audit-first wording that covers both the consume-existing case (#1) and the design-and-land case (#2-#4 if their audits show real gaps). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands' which conflicted with the post-reframe reality that B4.1 consumes the existing DeclarationRef. Updated to 'consumes or lands' with explicit existing-authority citation and audit-pending caveat for B4.2-B4.4. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — soften regression-test requirement (3 worker bounces) Three consecutive B1 worker dispatches (zesty-crane-890 cursor → valiant-boar-498 codex → cool-lynx-395 cursor) archived without opening a PR. Likely friction point: brief Slice step 4 asks for a unit test that constructs a Dag with an orphan variant declaration, but emit.rs has zero existing #[test] precedent — emit testing happens via integration fixtures. Workers see 'build novel test harness' inside what's billed as an S-scope fix and bounce. Per feedback_construction_over_ratchets: when a brief has friction, fix the brief, don't ratchet the worker. Softened step 4 + acceptance: regression test stays optional. If test setup requires novel scaffolding, route the gap to follow-up. The structural fail-closed at step 2 is the load-bearing change. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description' is too weak; PR descriptions don't survive squash-merge cleanly. Two coordinated edits: 1. Slice step 4 — explicit substrate-signal framing: skipped test means emit-side hermetic-unit-test infrastructure is the missing substrate (feedback_emitter_workaround_is_gap_symptom). 2. Acceptance — require ROADMAP debt row (new or existing) with named dissolution trigger, referenced in PR body. Converts the skip from PR-local note (transient) into tracked debt (durable, dispatchable). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124 Codex BLOCKING: my earlier softening claimed emit.rs had no #[test] precedent — wrong. The module has #[cfg(test)] mod tests at line 3124 with 12+ tests using compile_to_dag(source, filename) as harness (e.g., go_struct_fields_render_with_separators :3143, shared_walk_to_disj_finds_match_scrutinee_sum_type :3195). This is a feedback_verify_thesis_claims violation on Director-side brief authoring — claim made without grep verification. Fix: restore step 4 as required, with explicit precedent citation. Worker constructs the failure case via the existing harness (direct Dag, fixture string, or BranchPattern exercise; worker's call on cleanest path). STOP-AND-ESCALATE only if construction proves materially harder than precedent suggests, in which case that escalation surfaces a real substrate gap and warrants ROADMAP debt — but the default is 'add the test.' Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites) Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded to 'several using compile_to_dag'. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this is Wave 1 of Director's 14-brief authoring queue, covering B4 program internals. Authored: - b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) — replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag") fold-skip with structural template-formal carrier; mandatory authority audit per feedback_audit_adjacent_authority_first. - b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) — replaces §0.6 emit.rs bind/branch.span.file equality with typed BindEmitParticipation/BranchEmitParticipation roles populated at lowering; aligned with #824 worker's in-flight implementation shape. - b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4 of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with typed substrate authority; explicit pre-promotion-constraint disposition (single-authority vs authority+tracked-debt) addresses parallel-representation risk surfaced on #825. - b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) — names B4.5-B4.12 Phase 2 sites with carrier dependencies, cross-program coordination notes, and skeleton-brief template; full per-site briefs author at dispatch time per #827's Substrate Manager ownership. Cross-cutting discipline applied per inbox #828 reply: - feedback_audit_adjacent_authority_first (mandatory grep before design) - feedback_no_textual_enforcement_bridges (no replacement sentinels) - feedback_parallel_representation_debt (explicit if shape (b)) - feedback_construction_over_ratchets (no parity-by-runtime as primary) - feedback_coproduct_dissolution (receipts for new variants) Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3) Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue. Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by Modeling Manager's Wave 3 worker briefs (gated on these landing). Authored: - r2-substrate-cardinality-for-int-lit-subset.md (M) — produces magnitude carrier consumed by T-Modeling int-lit. Coordinates with PR #806's prior cardinality work; mandatory authority audit guards against #796's rejected IntLiteralMagnitude shape resurfacing. Open design questions: magnitude representation, reconciliation narrowing point, i64::MIN representability. - r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces nominal-opacity carrier consumed by T-Modeling Secret<T>. Open design questions: carrier shape (flag/connective/sealed-accessor), generic-walk discipline, accessor gating. - r2-substrate-parametric-algebra-for-dimensions-subset.md (M) — produces phantom-parameter carrier consumed by T-Modeling Dimension<Carrier>. Open design questions: carrier shape, type-equivalence rule, algebra-method dispatch, lifting/coercion. All three: - Scoped narrowly to their paired R2 consumer; not full substrate-capability lanes. - Mandatory pre-author authority audit per feedback_audit_adjacent_authority_first. - Cross-program readiness signal pattern from #827's manager rework. - Coproduct dissolution receipts required for any new variants. - Open design questions surfaced explicitly so Substrate Manager (or Director pre-spin-up) can resolve at dispatch time. Wave 3 (T-Modeling worker briefs × 4) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4) Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue. Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each gated on a Substrate Manager readiness signal (Wave 2 producers). Authored: - r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2 cardinality-for-int-lit; moves narrowing from tokenizer to reconciliation; MagnitudeOutOfRange diagnostic per C-8. - r2-modeling-secret-graduation-worker.md — gated on Wave 2 nominal-opaque-for-Secret; authors Secret<T> + gated accessors (redact, compare_in_constant_time); C-8 diagnostic on non-gated access; signals Impossible-Bugs Manager on close (thesis claim covered). - r2-modeling-dimensions-phantom-worker.md — gated on Wave 2 parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier> + core SI base units + algebra-method dispatch; cross-dimension arithmetic produces typed diagnostic; signals Impossible-Bugs Manager (thesis claim). - r2-modeling-tokenizer-charclass-phase2-worker.md — gated on T-Substrate ValueBody-list/sum (#790); migrates tokenizer consumers to Char/List<Char>/CharClass canonical types; sibling consumer to Grounding Manager's Engine sharpened-(b). All four: - Explicit gating: 'do not dispatch until producer signal posts.' - Producer/consumer signal pattern from #827. - Cross-program signals to R2 Release Manager (Goal 2 closure) and Impossible-Bugs Manager (thesis-claim coverage). - Spoofing regression tests: discipline anchor against feedback_no_textual_enforcement_bridges. Wave 4 (T-ImpossibleBugs worker briefs × 3) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3) Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue. Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes, consuming the existing design/scoping briefs as authority. Authored: - r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on cardinality refinement substrate (T-Substrate territory adjacent to int-lit / DB-11 alias-where). Implementation: structural normalize of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T?? worker decision (reject vs normalize). Cites t-impossiblebugs-nested-optional-flatten-design.md as authority. - r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated on Tier 2 substrate (predicate-entailment infrastructure; distinct from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes predicate entailment, (b) feedback_totality_by_omission dissolves partial primitives, (c) park. Worker decides at audit time. Cites t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority. - r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate prerequisite per closed-system framing in design doc (#808). Audit- as-existence-check + lens implementation as compositional fold over 5 behaviors; redundancy detection compile-error via referential transparency + reread() escape hatch; path (i/ii) decision on OperationEffect taxonomy retain-vs-retire (default retire). Cites design doc #808 as authority. Cross-cutting: - Each cites prior design/scoping brief as authority (the existing *-design.md / *-worker.md REFRAMED files). - Explicit gating per #827 producer/consumer signal pattern; two briefs gated on substrate, one NOT gated (closed-system). - STOP-AND-ESCALATE includes 'design brief assumptions don't hold' surfacing per feedback_thesis_gate_state_drift. Wave 4 complete. Director's 14-brief queue done; awaiting PM portion (6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4.4 — tighten Slice §3 per PM review on #836 PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b) (authority + tracked debt parallel-rep) as autonomously acceptable contradicts feedback_construction_over_ratchets + feedback_parallel_representation_debt. Tightened: - Shape (a) is the only autonomous worker path. - Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a regen-host-loader sub-lane decision; not authorable without explicit Substrate Manager approval citation in the PR body. - Acceptance bullet requires the approval citation when shape (b) lands. - STOP-AND-ESCALATE rephrased to make this explicit; permanent parallel-representation re-escalates even with manager approval. This preserves shape (a) as autonomous; shape (b) becomes a cross-manager design escalation, not a B4.4 implementation call. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief Cursor review on #836 flagged the Read-first reference to .claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md as machine-specific (outside the repo, not resolvable from a normal clone). Replaced with in-repo prose pointing at the design doc's §Q1-Q3 as canonical authority — the discipline lives there in-repo. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs) Codex flagged: src/v3/std/types.dag does not exist; the canonical authority is at dsl/std/types.dag. Affected briefs (all from R2 spin-up Wave 2 + Wave 3): - r2-substrate-cardinality-for-int-lit-subset.md - r2-substrate-nominal-opaque-for-secret-subset.md - r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs) - r2-modeling-dimensions-phantom-worker.md - r2-modeling-secret-graduation-worker.md feedback_verify_thesis_claims violation on Director-side brief authoring — assumed path without grep. Same family of error as the earlier emit.rs precedent claim. Mass-replaced via perl; verified no remaining stale refs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant Codex BLOCKING on #836: my R2 worker brief gated nested-optional on cardinality refinement substrate, but the design doc verifies v3 is ALREADY past the cardinality bridge — TypeConnective::Cardinality is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is the carrier for Option. The dissolution is an UNGATED implementation via substrate-constructor invariant. feedback_verify_thesis_claims violation again — should have read the design doc fully before assuming the substrate gate. Rewrote brief to match design doc canonical sketch: - Single predicate (cardinality_idempotent_target) owns the rule - Single allocator (alloc_cardinality_decl) is THE substrate-constructor - API closure on TypeConnective::Cardinality payload (modeling-discipline practice 6) — variant cannot be struct-init'd outside the allocator - 3 hand-Rust + ~22 codegen call sites enumerated per design audit - infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as the killer case for generic-instantiation paths - Surface-syntax T?? decision left to worker (Director-lean: silent normalize) Brief now dispatchable immediately, no producer signal needed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment substrate path, but the design doc §4 explicitly recommends totality-by- omission as the Director-actionable path. Predicate-entailment is M+ scope that reopens DB-11's explicitly-closed asymmetric-strip design — design doc explicitly discards it. feedback_verify_thesis_claims violation again — same family as nested- optional reframe. Should have read design doc §4 in full before assuming the path ordering. Rewrote brief to match design doc §4 follow-on shape: - Primary path: per-class totality-by-omission (algebra retype + per- target realization migration). For Int/Int: OrderedRing.div retype at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 / python:486 + python_target.rs:680 helper). - NOT predicate-entailment (out of scope; M+ + DB-11 reopen). - NOT NonZero-typed-input (deferred to separate per-operand-variance substrate brief; STOP-AND-ESCALATE if chosen). - Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i] indexing, quotient, remainder) queue separately per design doc audit. - feedback_totality_by_omission discipline anchor explicit. Brief now matches feedback_totality_by_omission discipline + design doc recommendation. No substrate prerequisite; dispatchable immediately. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a pattern: I authored R2 worker briefs without fully reading each design doc's Director-actionable recommendation. Pre-emptively re-verified unenumerated-effects against design doc §Q6 to catch the same family of error before reviewers do. Findings: brief was substantively close but missing 3 of 8 design-doc reqs: - Req 3: Resource-threading discipline applied to existing primitives - Req 5: reread(key) primitive in std/ as explicit Slice item (was only mentioned in tests) - Req 7: Asymmetric-tightening worked example in PR body Plus: Slice didn't cite the canonical lens path src/v3/lenses/effect_enumeration.dag from design doc. Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6 specifies 4 specific STOPs (path-decision-escalation, pure: Bool carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP) that I had elided. Reframed Slice as 8 numbered reqs matching design doc verbatim; STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs; Acceptance enumerated per req. This is the third reframe in the unhandled-bugs series — same feedback_verify_thesis_claims violation each time. The pattern suggests Director-side R2 brief authoring should ALWAYS read each design doc's §Director-actionable / §Q-recommendation in full first, not assume. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)" listed as a worker-pick option violates THESIS.md substrate-shape lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) are canonical (per #811 thesis additions and #827 PM review); a 7th is a C1 stop signal requiring failed-dissolution evidence + Director substrate-design call, not autonomous worker pick. Removed the "new TypeConnective variant" option; replaced with `inhabits`-edge-shape carrier as third option (audit-time check). The explicit STOP-AND-ESCALATE clause now states: 7th connective is the precondition for failed-dissolution-evidence + Director substrate-design call, not a worker path. feedback_verify_thesis_claims still in play — should have grounded substrate-shape options against the THESIS lock before listing Opaque(T) as worker-autonomous. Pattern continues; reading source-of-truth before authoring options is the discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place) Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter already exist at dag.rs:186, :217 — explicitly authored for the R2 Dimensions consumer per the doc comment at dag.rs:148-160. phantom_unit_mismatch already wired at infer.rs:1057, :1132. The substrate is fully landed; my brief framing it as 'producer sub-lane to land carrier' is wrong on the same feedback_audit_adjacent_authority_first violation that hit nested-optional / unhandled-diagnostic / unenumerated- effects. Reframed the substrate-side brief as no-op / closed-by-audit: - Documents the audit receipt (5 sites confirming substrate exists) - States the lane is closed - Routes T-Modeling Dimensions consumer to dispatch immediately against the existing carrier - Records the lesson: 'always grep substrate before authoring producer briefs' — discipline doesn't end at brief boundaries. Updated r2-modeling-dimensions-phantom-worker.md correspondingly: - Changed gating from 'do not dispatch until producer signal' to 'NOT GATED — dispatch immediately' - Read-first updated with concrete dag.rs/infer.rs cites - Slice §1 changed from 'confirm producer signal' to 'verify substrate at HEAD' - STOP reframed: existing carrier extension would need Substrate Manager call, not autonomous worker pick Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit both verified — no existing substrate (no is_nominal_opaque / MagnitudeBound patterns in dag.rs); both still legitimately producer-side work. Pattern is now four reframes deep on the R2 spin-up wave. The lesson saved is structural: read source-of-truth before authoring options. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority Codex BLOCKING on #836: my new R2 spin-up brief duplicates the existing t-substrate-cardinality-int-lit-worker.md, which carries the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64) stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane). Single-authority violation per INVARIANTS P2. Same feedback_audit_adjacent_authority_first failure as parametric- algebra-for-Dimensions reframe (4 hours ago): assumed substrate authority didn't exist; should have grepped docs/briefs/ before authoring. This is the SECOND R2 spin-up substrate brief closed as redundant — the discipline lesson is structural. Reframed brief as no-op routing doc (documents the audit receipt; routes consumers to the existing authority); updated r2-modeling-int-lit-magnitude-worker.md to cite t-substrate-cardinality-int-lit-worker.md instead. Pattern across the R2 spin-up wave reframes (5 now): 1. nested-optional gating-on-substrate (substrate already past cardinality bridge) 2. unhandled-diagnostic predicate-entailment default (design doc recommends totality-by-omission) 3. unenumerated-effects 8-req design-doc elision 4. parametric-algebra Producer (Declaration.phantom_params already authored explicitly for this consumer) 5. cardinality-for-int-lit Producer (existing brief is authority) All five are 'as…
* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation)
Director-authored amendment following the 2026-04-24 escalation from PR
#693 (sub-child sharp-bear-829 under Surface Manager).
Two edits:
1. New "Class 5 Gap 3 — port-carried field values in data bodies"
row in the 2026-04-21 post-merge-debt section. The substrate gap was
documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP
ledger row for cross-lane visibility. PR #693's execution surfaced it
as the blocker on sub_charclass_in_std_unicode phase-2.
2. Retract the "ready-to-dispatch (no substrate capability gap)" claim
on the Character-level row, annotate phase-1 landed via PR #693
(CharClass vocabulary + Rust-mirror structural scanner path), and
point phase-2 at the new Class 5 Gap 3 row.
Codifies the audit pattern: "this consumption gap has no substrate
capability gap" claims must be verified by attempting the retype before
the claim lands.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main
* docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review)
* docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review)
Row title still said 'consumption gap, not substrate gap' while the
body block retracted that claim and cited Class 5 Gap 3 as a substrate
dependency for phase-2. Title now matches body: mixed classification,
consumption for steps 1+3, substrate for step 2.
* docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit)
gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining
gap" description was wrong: field-level shapes (nested records, list
literals, declaration refs, Var refs, sum-variant literals) are
supported today via FieldValue variants + lower_structural_field_value
(dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the
top-level ValueBody boundary (non-scalar, non-record top-level bodies).
The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself
stale: it describes the pre-PR-B-unwind shape where FieldValue was
LiteralBits-only. PR-B's unwind extended FieldValue to carry
Reference / Record / List / Variant, moving the gap to ValueBody.
Two fixes:
1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody
boundary, point at code paths (dag.rs, lower.rs) as live authority,
flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass
blocker classification to "provisional pending reproduction."
2. Update the Character-level row's phase-2 block to name that the
specific shape of the CharClass failure needs concrete reproduction
from the escalating sub-child before the blocker is finalized.
Recursive audit-pattern instance: the row I wrote to codify "verify
live state before claiming substrate gap" itself failed to verify live
state. Both incidents (2026-04-23 original row + 2026-04-24 my
retraction row) are now cited in the audit-pattern sub-note as
examples of the same discipline.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33
Three substantive fixes addressing internal-consistency gaps in the cascade
promotion PR caught by codex review at sha 0d6e7c33:
1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane
acceptance bullets and Hand-Rust census paragraph in line with the
updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero
(LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is
retracted under 0-floor with explicit migration to ExecuteCommand-based
.dag TestClaim declarations.
2. docs/design-pure-bootstrap-zero.md promotion section — converted from
future-tense ("This doc is PROPOSAL until promoted… promotion is a
single Director-authored cascade PR…") to historical past-tense
promotion-receipt framing ("This doc was PROPOSAL until promoted;
promotion was a single Director-authored cascade PR that did all of the
following atomically…"); blocking-clause struck through and resolved
inline. Banner cites PR #782 explicitly.
3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_
profile excluded (Map<String, AlgebraProfile> body, not list-of-sum;
needs distinct ValueBody::Map substrate work, tracked separately as a
future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass
phase-2 + Engine sharpened-(b) pilot enumeration), both sharing
list-of-sum substrate work. Lane table, dependency DAG, and capacity
summary updated for consistency (slot count 9-13, was 10-14).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities
Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade
self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22
explicitly names THESIS.md and "any other authority docs" as required
retraction targets; the prior diff updated ROADMAP + r2-structure + design
docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting-
manager.md pointing at the now-SUPERSEDED ≤5-floor framing.
Files:
- THESIS.md (5 prose blocks updated):
- :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests
migrate to ExecuteCommand-based .dag TestClaim declarations.
- :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag.
- :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor
target citing design-pure-bootstrap-zero.md as live authority;
hand_maintained_src list shrinks to empty set.
- :301-318 — Tests-are-structural-data block: residual carve-out retracted;
predicate name pb_rust_tests_outside_residual_zero retained as
housekeeping (semantically the residual is empty under cascade).
- docs/thesis/compiler-std-consolidation.md (5 references):
- Header link to design-pure-bootstrap-zero.md (LIVE) supersedes
design-pure-bootstrap.md (SUPERSEDED).
- :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process
lane named as the dissolution trigger for bootstrap.rs itself.
- :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md.
- :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority
re-cited.
- :185 Related docs link.
- docs/briefs/r1-selfhosting-manager.md (active dispatch brief):
- SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5);
T-PB-B residual carve-out retracted; predicate names retained for
housekeeping; cascade-promoted authorities are source of truth.
- Slice descriptions for T-PB-A / T-PB-B updated inline.
- Framing-question + ask updated to 0-floor / no-residual framing.
- Day-1 + up-to-director hand-off bullets updated.
- Working-state checklist :111 ≤5 → 0 with cite.
- Decisions log :164 ≤5 → 0-floor target updated.
- docs/r2-structure.md §2 design call (RETRACTED block):
- "Pre-promotion ≤5 irreducible-shim gate-name review" struck through
in entirety (both Option A sharpen-and-keep and Option B rename are
moot under 0-floor). Section preserved as audit-trail historical
context.
- Background-doc index: self-hosting anchor updated to
design-pure-bootstrap-zero.md as live authority.
- docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per
non-blocking suggestion):
- Banner cites cascade promotion PR #782 explicitly.
- New paragraph: "Treat all numeric floors below as retracted" with
explicit lines named that quote in isolation (table row, body prose
references). Prevents re-quoting from this doc as live authority.
Cascade is now atomically consistent across:
THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔
docs/thesis/compiler-std-consolidation.md ↔
docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔
docs/design-pure-bootstrap-zero.md (LIVE) ↔
docs/design-pure-bootstrap.md (SUPERSEDED).
The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds
genuinely.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(cascade-promotion): correct ExecuteCommand runner-capability claim
Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation):
TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138
overstated live runner capability — claimed runner support landed in
PR #688/#741 with "emit Rust, invoke rustc on output, check exit code"
as a structurally-equivalent migration path. Verified against live
sources:
- src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema
exists (declared via PR #678).
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5
testgen harness allowlists ONLY `command == "true" && args.is_empty()
&& expect_exit == 0`.
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 —
panics fail-closed on any other shape with explicit "ExecuteCommand
shell shape is not supported here (runner-owned — do not treat as
ordinary false)".
- src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no
match arm for ExecuteCommand; falls through to ClaimResult::
NotYetImplemented.
Reality: a TestClaim declaring rustc/python/go invocation is
structurally expressible as data today, but executing it is blocked.
Full arbitrary-command runner support is the PB-Runtime lane's
deliverable.
Files updated:
- TESTING.md:195 — capability state callout with file:line citations;
"Full runner support — arbitrary command + args (rustc/python/go) with
exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor
program)." Bullet about migration shape preserved as the cascade-named
successor pattern, not as a live capability.
- TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane
lands the ExecuteCommand runner extension" as an explicit precondition.
- docs/design-pure-bootstrap-zero.md:138 — same correction for the
matching prose, with PB-Runtime named as the runner-extension
dependency for boundary-test migration.
- ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner
foundation in #688/#741 with `true`-no-args allowlist only — full
arbitrary-command runner support deferred to PB-Runtime lane,
blocking the actual boundary-test migration." Dependencies column
extended to "DB-15 + T-TestGen + PB-Runtime".
The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still
holds for atomic-cascade-across-authority-docs; this commit closes the
remaining capability/claim mismatch flagged by codex.
(Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still
SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.)
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief
Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation).
The prior banner contained:
> "Operationally R1 closure may still ship before the 0-floor is reached
> — the ratchet ensures the trajectory; the gate's acceptance number is
> what shifts."
This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0.
Two competing gate semantics in the cascade is exactly what the
atomic-cascade clause forbids.
Replaced with single-authority-honest framing:
> "R1 closure now requires the 0-floor target by gate semantics: T-PB-A
> and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade
> promotion changed their acceptance numbers to 0; R1 cannot close
> while the SG-0 census carries non-zero hand-Rust."
Plus minor sharpening:
- "T-PB-A's non-test target is 0" → "non-test acceptance target is 0
per ROADMAP.md:67" (cite the authority).
- T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep
the capability-state honesty consistent with the recent fix wave.
- Predicate-rename housekeeping line moved into banner ("post-cascade
housekeeping, not a pre-promotion blocker") — was implicit before.
The brief now genuinely inherits the cascade-promoted gate; no
competing release authority.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): R2 second-wave worker-escalation fixes
Four substantive worker STOP-AND-ESCALATEs from briefs landed in
PR #797. All four worker recommendations correct; each needs a
Director call + brief update.
## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate
Worker correctly identified that brief req 2 (declared-effect carrier
as part of fn type signature, per feedback_no_annotations) requires
net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at
src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots.
Without parser surface, every user function would have
declared_effects = [] while inference returns non-empty — lens fires
EffectLeakageError everywhere on enable. Worker rejected power-through
and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map
parser split).
Director picked split:
- NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md
Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface
syntax + lookahead + body parser + lowerer extension + exhaustive-match
audit + coproduct dissolution receipt.
- MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to
post-parser-extension scope. Pre-flight check NOT a parser-extension
step; STOP if parser sub-lane PR not merged.
## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping
Worker found load-bearing evidence at infer.rs:3693-3703: DB-11
deliberately strips refinements at operator dispatch as a designed-in
fix for symmetric-operators failure mode. Brief's "attach where b != 0
as a proof for a / b" directly contradicts this design choice. STOP-3
(where-clause conflict with DB-11) is real; STOP-1 (substrate scope)
needs net-new substrate (per-operator partiality fact + predicate-
entailment check + asymmetric per-operand refinement-honoring) — M+
minimum. ownership_lens precedent in original brief is post-hoc
observability, not proof carrier.
Worker recommended redirect to design/scoping per nested-optional
precedent. Director picked redirect.
Brief fully rewritten as design/scoping with four-question structure:
(1) DB-11 interaction analysis; (2) substrate proposal for proof-or-
totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes
with acceptance-theatre risk on user-defined-total-wrapper-only);
(4) Director-actionable recommendation. Output is doc PR.
## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C)
Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int)
with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136
closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b)
i128 implementation requires either path 1 (hierarchy refactor —
contradicts non-goal) or path 2 (regen lie between substrate and
emit — violates discipline). Worker leaned option (C) re-scope:
land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke)
to a sibling sub-lane that does proper Int128/Word128 substrate work.
Director picked option (C). Brief req 1 re-scoped to drop canonical-
carrier-widening; lane value comes from range facts + reconciliation
narrowing + out-of-range diagnostic against existing i64. Req 4
explicitly deferred with sibling-sub-lane reference. Sibling sub-lane
NOT to be authored or implied in this PR; tracked separately.
## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change)
Worker correctly STOP'd per the brief's own pre-flight check: parser
sub-lane has not landed; SurfaceExpr::Map not on main. Director
authorized cross-lane reassignment: wise-boar-480 takes the parser
sub-lane (t-substrate-valuebody-map-parser-worker.md) since they
already have full investigation context. No brief changes needed; the
routing decision is in the dispatch.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope
Resolves codex P2 inline at sha e35103fad on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer
carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still
required widening LiteralBits::Int(i64) to an unbounded carrier and
passing the i64::MIN smoke. Internally unsatisfiable.
Fix:
- Slice section retitled "range facts + reconciliation narrowing
(against existing i64 carrier)" with explicit note about the
re-scope.
- Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly
forbids touching LiteralBits::Int shape, dag_scalar_generated.rs
regen for that variant, or tokenize i64 parse path.
- Slice steps 2-5 reframed: range facts use i64-representable
magnitudes; reconciliation narrowing uses existing i64 carrier;
diagnostic only for i64-representable out-of-range; smoke tests
for req 5 only (req 4 i64::MIN deferred).
- Acceptance checklist updated:
- Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as
re-scoped/deferred.
- LiteralBits::Int(i64) carrier untouched (no widening; no
parallel; no shape change).
- i64::MIN smoke marked DEFERRED with sibling-sub-lane reference.
- STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the
carrier" — explicit STOP if execution surfaces range-fact narrowing
requiring carrier-widening; that's the boundary the re-scope drew;
belongs in sibling Int128/Word128 sub-lane.
Brief now consistently treats carrier-widening as out-of-scope across
all sections.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty
Resolves codex BLOCKING #1 at sha e35103fa on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier
but req 2 required range facts using "the SAME magnitude carrier
as req 1" — meaning i64-typed range bounds. u64's max (2^64-1)
doesn't fit in i64; range fact for u64 would have to truncate,
omit, or mirror in Rust (representation drift). All three options
violate fail-closed declared-facts discipline (P1 / P3).
Fix:
- Req 2 rewritten to specify String-decimal representation:
range_min_inclusive: String + range_max_inclusive: String fields
on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127"
for i8; "0"/"18446744073709551615" for u64).
- Explicit reasoning why String-decimal: u64's max doesn't fit in
i64; binding range bounds to literal carrier forces truncation/
omission/mirror-drift; all violate fail-closed declared-facts
discipline.
- Bridge framing: String-decimal is pending the sibling Int128/
Word128 sub-lane; both range bounds and literal payload migrate
to typed carrier when that lands.
- Req 3 updated for String-decimal comparison semantics:
reconciliation parses both bounds and literal magnitude into a
common comparison space (i128 host comparison primitive — host
narrowing, NOT carrier widening). Bounded by what the i64-typed
literal can express; any i64-representable literal compares
against any width's String-decimal bound. Carrier discipline
preserved.
Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral)
is sha-stale — already resolved at 3e142d169.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed
Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback).
Real residual: req 2 specifies String-decimal range bounds (to cover
u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance
bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" /
"i64-representable magnitudes" for the range facts. Two incompatible
authorities for the same range-fact shape — would let a worker satisfy
the slice while truncating/omitting u64 bounds (P3 fail-closed
violation).
Fix:
- Line 31 (req 1 re-scope clarification): updated to explicitly state
"range facts (req 2) use String-decimal representation (width-
independent; covers u64::MAX which doesn't fit in i64)". Distinguished
literal *payload* (stays i64) from range-bound *representation*
(String) — both serve req 1's "no carrier widening" boundary.
- Line 44 (slice step 2): updated from "Range bounds use i64-
representable magnitudes" to "Range bounds use String-decimal
representation per req 2" with concrete example (u64 bounds).
- Acceptance bullet: updated from "Range facts on integer algebras
(substrate-declared, not Rust-mirrored)" to add "using String-decimal
representation ... width-independent; u64 bounds expressible without
truncation."
The brief now consistently treats range bounds as String-decimal
across req 2, req 3, slice, acceptance, and the req 1 clarification —
no remaining authorities saying i64-typed.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing
User + PM exchange 2026-04-25 surfaced that the in-flight effects
chain was importing wrong assumptions from external languages
(declared-effects-as-annotation + lens-vs-declaration check). Right
framing under gunbc's closed-system discipline is parallel to
complexity: every effect derives structurally from the composition
of typed primitive operations; nothing can hide because there's no
escape hatch; nothing needs annotation because the structure IS the
registry.
Four doc-only actions:
1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md.
Frames the closed-system answer with PM's 5-behavior synergy
table (Value/Transform/Branch/Loop/Bind as universal
compositional-fold pattern). Four worked examples; aggressive
reading on redundancy (compile-error-by-construction via
referential-transparency proof; reread() primitive for legitimate
cases); implementation-brief shape in §Q6.
2. SUPERSEDED banner on
docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md.
3. SUPERSEDED banner on
docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md.
Notes Fn→Arrow refactor brief stays dispatchable as independent
value.
4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by-
construction framing replaces lens-detection framing.
Memory file feedback_closed_system_effects.md saved separately;
cross-link added to feedback_construction_over_ratchets.md.
Net cost: doc-level cleanup. Zero substrate code rework. Foundation
(OperationEffect + service-call infrastructure + 5-behavior
substrate) already exists.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect
Per PM convergence review on #808 + user's deeper 2026-04-25 framing:
the closed-system framing landed in #808 retired the user-facing
annotation but kept OperationEffect taxonomy as substrate-level tagging.
User's deeper framing: the taxonomy ITSELF is parallel-representation —
operations are intrinsically read-shaped or write-shaped via their
TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns-
derived-value-only → read). Tagging operations with Read | Upsert |
Create | Append | Delete names what the structure already says.
Three changes:
1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as
normalized view, or retire as parallel-representation?"
- Two paths: (i) tags derived from signature shape (acceptable
normalized view) vs (ii) tags declared per-primitive (parallel-
representation; retire).
- Audit-as-existence-check (Q4 req 2 reframed): all effectful
primitives derive cleanly from signature shape → path (i); any
primitive needs hand-declared tag → path (ii) by existence proof.
- Director default: path (ii). Logging primitives that return Unit
are likely the audit's existence-proof.
- Two design-question resolutions: (a) external effects not in
return type → resource-threading discipline (typed param returned
modified, IO-monad-without-the-monad pattern); (b) transactional
grouping → derived structural fact from Bind composition + typed
transaction primitives.
2. Q4 reqs revised: req 2 from "tag every primitive with explicit
OperationEffect signature" to "audit-as-existence-check that every
primitive's type signature derives the right effect classification";
req 3 added (resource-threading discipline); req 6 added
(transactional-pattern lens). Req 1 (effects lens) anchors on
operation type-signature shape, not on hand-declared tags.
3. THESIS:345-347 amendment strengthened — "operations are
intrinsically read-shaped or write-shaped via their type-signature
shape; consumers walk the signatures directly; there is no parallel
taxonomy or annotation layer to declare or maintain. Tracking
effects as a separate enumerated concept IS the bug pattern,
dissolved by construction." Plus references to resource-threading
discipline + transactional grouping as derived structural fact.
Memory file feedback_closed_system_effects.md updated to reflect the
deeper framing (type-signature-shape, not taxonomy-tagging) +
resource-threading discipline section + transactional-patterns
section.
Net cost: doc-only delta on top of #808. Substrate retirement
(OperationEffect enum + derive_op_effect + idempotency.dag re-anchor)
deferred to the audit-as-existence-check phase of the implementation
brief; surfaced as Q5.5 OPEN CALL.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage
Resolves codex BLOCKING at sha d49ce79a on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real:
the prior text claimed service primitives "already carry typed effect
signatures" presenting future audit-state as current substrate fact
(P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the
OperationEffect line but left a parallel over-claim on the new
"signature-shape coverage" framing.
Fix: Q4 substrate-state listing rewritten to honestly distinguish:
- Live: Behavior enum + substrate foundation (the principle that
operations should carry signature shape).
- Incomplete: signature-shape coverage across actual primitives.
HTTP-derived primitives carry implicit shape via derive_op_effect's
method-table; logging/mutation primitives that return Unit or don't
thread their target resource do NOT carry the structural shape that
would express read-vs-write. Achieving full coverage is required
work under reqs 2 + 3, not a current fact.
- Pending audit-as-existence-check: OperationEffect + derive_op_effect
(path (i) vs (ii) per Q5.5).
Honest live-state callout added explicitly: "the closed-system
FOUNDATION (5 behaviors + DAG substrate + the principle that
operations should carry signature-shape) is live. The IMPLEMENTATION
COVERAGE across all effectful primitives is partial. Req 2 + req 3
are the work that closes the gap."
Brief now distinguishes principle-is-live (foundation) from
coverage-is-partial (audit work) without conflating them.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* WIP: gunbc Director
* docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim
Per PM follow-up review on #808 + user's stronger discipline framing
("substrate must make bypass structurally impossible at every layer
of the transport stack"): the closed-system claim is honest only when
typed primitives ARE the path. Today two structural holes exist where
bypasses sidestep the typed-primitive substrate. Both surfaced
explicitly as Q4.5 pre-conditions — load-bearing for the lens's
coverage claim.
Three changes:
1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed-
system claim)" inserted between Q4 and Q5:
P1 — Extdeps typed-primitive consumption structurally enforced.
Substrate must make `messages: Json` impossible to declare in
service definitions; typed `LlmMessage` / `ContentBlock` /
`GitHubAuthToken`-with-full-scopes are the only path. Tracked
debt at ROADMAP.md:153-154 (LLM provider flattening) +
`dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded).
Required prereq for full lens coverage; lens can land first +
surface structural-coverage-gap diagnostics on bypass surfaces
so the gap becomes visible rather than silent.
P2 — `ExecuteCommand` fully materialized as typed runner
primitive. TESTING.md (post-#782) committed to 0-residual but
ExecuteCommand isn't fully materialized; deleting Rust boundary
tests creates verification gap. Already named under PB-Runtime
in Zero-Floor; signal pending. Pre-requisite for ANY Rust
boundary-test deletion.
2. Old leftover duplicate Q5 section deleted (artifact from prior
Q5/Q5.5 reshape; second copy of asymmetric-tightening text was
in the file alongside the earlier Q5 instance).
3. Worker-discretion-vs-Director-call section in Q4.5: lens
implementation worker dispatchable now (reports gaps as
findings); P1 closure is substantive substrate work touching
extdeps (dedicated lane); P2 closure is PB-Runtime (signal
pending).
Net: design doc now honestly distinguishes principle-is-live
(Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs
named explicitly). The closed-system claim has explicit pre-
conditions documented; implementation brief discovers them as
known dependencies, not as STOP-AND-ESCALATEs.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default
Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two
real residuals after the Q5.5 reframe:
1. Q6's reqs/STOPs/acceptance still framed under path (i) — said
"audit + tag std/ primitives — every effectful primitive carries
an explicit OperationEffect signature." Directly contradicted Q4
(post-191be310b) + Q5.5's path (ii) default + the THESIS amendment
("there is no parallel taxonomy to declare or maintain"). Worker
reading Q6 in isolation would author the retracted shape.
2. Capacity / sequencing table line about "audit lane (tag std/
primitives with effect signatures)" carried the same stale
framing.
3. Q6 STOP "primitive performing side effects without an
OperationEffect tag" assumed tag-as-authority; under path (ii)
the STOP shape is "primitive whose signature doesn't structurally
reveal its effect."
Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale
(already fixed at f073aa95e Q4.5 commit).
## Q6 fixes
- Reqs renumbered + reframed:
- Req 1 anchors on operation type-signature shape (not hand-declared
OperationEffect tags); composition reads from signature shape per
Q2 table.
- Req 2 changed from "audit + tag every primitive" to
"audit-as-existence-check" — verify signature-shape coverage; ANY
primitive needing a hand-declared tag IS the existence-proof for
path (ii) retirement.
- Req 3 added: resource-threading discipline applied to existing
primitives (logging that returns Unit gets reshaped per audit).
- Req 6 added: transactional-pattern lens (Bind composition +
Transaction → Transaction').
- Req 7 added: asymmetric-tightening worked example in PR body
(per claude review observation; the one place declaration-shaped
surface re-enters).
- Req 8 (was 5): tests now reference signature-shape derivation
explicitly, not tag lookup.
- STOPs reframed:
- "OperationEffect retirement decision" — audit produces path (i)
vs (ii) verdict; substrate retirement is its own dedicated
sub-lane; this lane does NOT absorb it.
- Pure/impure carrier STOP notes that "pure" should also derive
from signature shape (pure functions don't return modified
resources) — so the STOP itself may dissolve under further design.
- Q4.5 P1 explicitly NOT a STOP — lens reporting structural-
coverage-gap on extdeps bypass surfaces is the lens delivering
its foundation-gap-visibility value.
- Q4.5 P2 explicitly independent — lens doesn't depend on
ExecuteCommand materialization.
- Acceptance extended: lens reports gap diagnostics on P1 bypass
surfaces; audit produces existence-proof verdict for Director
re-decision; asymmetric-tightening worked example in PR body.
## Capacity / sequencing table
Replaced "1 audit lane (tag std/ primitives with effect signatures)"
with "1 audit-as-existence-check lane (verify primitives' signature-
shape coverage; NOT 'tag every primitive') — produces the path (i)
vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2
prereq lanes to the net summary. Closing line: "The taxonomy-
retirement scope (substrate-side) is not in this lane — it's
surfaced by audit and routed to dedicated retirement lane if path
(ii) wins."
Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity
table. Worker reading Q6 in isolation now sees path-(ii)-default
framing matching Q4 + Q5.5 + THESIS amendment.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792
Resolves codex inline BLOCKING at sha 191be310 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150.
Real: my Q4.5 P2 framing described ExecuteCommand as still
NotYetImplemented (M1.5 allowlist + Rust TestRunner returning
NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand
extension before this PR's authoring. TESTING.md:195 capability-state
callout confirms:
- Rust TestRunner + M1.5 testgen harness share one std::process path
for arbitrary command + args + expect_exit_code.
- M1.5 allowlist + fail-closed panic retired.
- Distinguishable ClaimResult::Fail messages for spawn / timeout /
policy / exit-mismatch.
- Linux unshare(1) namespace isolation on host-allowing systems.
- T-PB-B-1 boundary migration example landed.
Fix:
P2 section rewritten:
- Header retitled "ExecuteCommand runner primitive: LANDED (PR #792);
residual is bulk-migration."
- Status update naming PR #792 + the post-#792 capability state
(allowlist retired, etc.).
- Honest acknowledgement: "My earlier P2 framing was stale."
- Residual narrowed to bulk-migration of existing Rust Command::new
boundary tests (tracked as ROADMAP residual, not lens prereq).
- Sequencing reframed: P2 was always orthogonal to the effects lens
itself; bulk migration proceeds at its own pace; lens not blocked.
Q4.5 footer updated:
- "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via
#792; only consumer-side bulk migration remains)"
- Worker-discretion-vs-Director-call P2 line updated: "runner
primitive landed; only consumer-side bulk migration remains;
tracked as ROADMAP residual, independent of the lens."
Q6 STOP for P2 updated:
- "the lens itself doesn't depend on P2; only TESTING.md's 0-residual
claim does" → "runner primitive landed via PR #792 (post-Q4.5-
authoring update). The lens itself never depended on P2; bulk
consumer migration is residual ROADMAP work and remains independent
of this lane."
Brief now reflects live state. The closed-system claim's prereq
landscape is honest:
- P1 (extdeps typed-primitive consumption): real prereq, tracked
debt at ROADMAP:153-154.
- P2 (ExecuteCommand runner): satisfied via #792; bulk migration is
consumer-side residual, not foundation work.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale
Resolves codex non-blocking finding at sha bcac41bb on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real
residual: capacity-table line still listed P2 as "`ExecuteCommand`
materialization" prereq + framed both P1 and P2 as "pre-existing
tracked-debt" — but my prior 57a9b1318 fix established that PR #792
already landed the runner primitive, so P2 is no longer a
materialization prereq.
Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq)
from P2 (residual, not prereq):
- P1: extdeps typed-primitive consumption — pre-existing tracked
debt at ROADMAP:153-154; load-bearing for the lens's full-coverage
claim.
- P2: ExecuteCommand runner primitive landed via PR #792; only
consumer-side bulk migration of existing Rust Command::new
boundary tests remains (tracked as ROADMAP residual, independent
of the lens; not a materialization prereq).
Brief now consistently treats P2 as bulk-migration-residual across:
- §Q4.5 P2 section header (LANDED via PR #792; residual is
bulk-migration).
- §Q4.5 footer (P2: runner primitive landed; only consumer-side
bulk migration remains).
- Q6 STOP for P2 (runner primitive landed; bulk migration is
residual ROADMAP work).
- §Capacity / sequencing impact (P2 as residual, not prereq).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349
Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated
target-grounding prose; the matching extdeps typed-primitive bypass
entries (LLM service flattening, GitHub auth model bypass) live at
ROADMAP.md:348-349.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(effects-design): fix third stale ROADMAP citation at line 271
Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence
at line 271 in the §Q4.5 capacity table. Now consistent with lines
139 and 173 (ROADMAP.md:348-349).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity
Codex flagged 'Effect-signature tagging on std/ primitives' as potentially
contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240)
already explicitly say 'NOT tag every primitive' — but the cross-manager
line used sloppy wording. Reworded to make explicit that the audit walks
signature shape; no parallel tag added.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5
- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)
B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).
B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B1 — drop incoherent inner-fallback non-goal
Codex P2: the non-goal line excluding the inner declaration().name
unwrap_or_else fallback contradicted Slice step 2, which replaces the
whole chain with let-Some-else-return. Both fallbacks are in scope by
construction; remove the contradictory non-goal.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives
PM REQUEST_CHANGES: §Frame listed '4 type connectives
(Conjunction | Disjunction | Cardinality | Bit)' which contradicted
the canonical thesis source. Replaced with the canonical 6
(Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per
docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary
closes here'. Also removed 'typed substrate carriers' from the
vocabulary list — substrate carriers are defined using the vocabulary,
not part of it. Added a clarifying note that B4's carriers
(DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are
typed declarations composed from the vocabulary, not vocabulary
extensions.
Per feedback_verify_thesis_claims: brief framings citing thesis
structure must ground in the canonical source.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority
Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of
naming the live substrate authority. Two coordinated fixes:
1. §Read first cites src/v3/std/substrate.dag (live .dag substrate
authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel
meta-type — already exists with consumers in verification.dag,
emit_model.dag, python.dag).
2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing
DeclarationRef'. The work is consumer migration + any role-extension
layer the audit reveals, NOT designing or landing the carrier.
Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers)
keep their 'new' framing but explicitly require sub-briefs to grep
src/v3/std/ + src/v3/spec/ for existing authority before authoring
'design and land' framing — per feedback_verify_thesis_claims +
feedback_emitter_workaround_is_gap_symptom.
Acceptance + sub-brief dispatch order updated to reflect B4.1's
consumer-migration shape.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B4 — tighten Phase 1 umbrella sentence
The umbrella 'Land the typed carriers into src/v3/std/' framing was
stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced
with audit-first wording that covers both the consume-existing case (#1)
and the design-and-land case (#2-#4 if their audits show real gaps).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording
Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands'
which conflicted with the post-reframe reality that B4.1 consumes the
existing DeclarationRef. Updated to 'consumes or lands' with explicit
existing-authority citation and audit-pending caveat for B4.2-B4.4.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B1 — soften regression-test requirement (3 worker bounces)
Three consecutive B1 worker dispatches (zesty-crane-890 cursor →
valiant-boar-498 codex → cool-lynx-395 cursor) archived without
opening a PR. Likely friction point: brief Slice step 4 asks for a
unit test that constructs a Dag with an orphan variant declaration,
but emit.rs has zero existing #[test] precedent — emit testing
happens via integration fixtures. Workers see 'build novel test
harness' inside what's billed as an S-scope fix and bounce.
Per feedback_construction_over_ratchets: when a brief has friction,
fix the brief, don't ratchet the worker.
Softened step 4 + acceptance: regression test stays optional. If
test setup requires novel scaffolding, route the gap to follow-up.
The structural fail-closed at step 2 is the load-bearing change.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt
PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description'
is too weak; PR descriptions don't survive squash-merge cleanly.
Two coordinated edits:
1. Slice step 4 — explicit substrate-signal framing: skipped test
means emit-side hermetic-unit-test infrastructure is the missing
substrate (feedback_emitter_workaround_is_gap_symptom).
2. Acceptance — require ROADMAP debt row (new or existing) with
named dissolution trigger, referenced in PR body. Converts the
skip from PR-local note (transient) into tracked debt (durable,
dispatchable).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124
Codex BLOCKING: my earlier softening claimed emit.rs had no #[test]
precedent — wrong. The module has #[cfg(test)] mod tests at line 3124
with 12+ tests using compile_to_dag(source, filename) as harness
(e.g., go_struct_fields_render_with_separators :3143,
shared_walk_to_disj_finds_match_scrutinee_sum_type :3195).
This is a feedback_verify_thesis_claims violation on Director-side
brief authoring — claim made without grep verification.
Fix: restore step 4 as required, with explicit precedent citation.
Worker constructs the failure case via the existing harness
(direct Dag, fixture string, or BranchPattern exercise; worker's
call on cleanest path). STOP-AND-ESCALATE only if construction
proves materially harder than precedent suggests, in which case
that escalation surfaces a real substrate gap and warrants ROADMAP
debt — but the default is 'add the test.'
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites)
Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but
emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded
to 'several using compile_to_dag'.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue
Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this
is Wave 1 of Director's 14-brief authoring queue, covering B4 program
internals.
Authored:
- b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) —
replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag")
fold-skip with structural template-formal carrier; mandatory
authority audit per feedback_audit_adjacent_authority_first.
- b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) —
replaces §0.6 emit.rs bind/branch.span.file equality with typed
BindEmitParticipation/BranchEmitParticipation roles populated at
lowering; aligned with #824 worker's in-flight implementation shape.
- b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4
of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with
typed substrate authority; explicit pre-promotion-constraint
disposition (single-authority vs authority+tracked-debt) addresses
parallel-representation risk surfaced on #825.
- b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) —
names B4.5-B4.12 Phase 2 sites with carrier dependencies,
cross-program coordination notes, and skeleton-brief template;
full per-site briefs author at dispatch time per #827's
Substrate Manager ownership.
Cross-cutting discipline applied per inbox #828 reply:
- feedback_audit_adjacent_authority_first (mandatory grep before design)
- feedback_no_textual_enforcement_bridges (no replacement sentinels)
- feedback_parallel_representation_debt (explicit if shape (b))
- feedback_construction_over_ratchets (no parity-by-runtime as primary)
- feedback_coproduct_dissolution (receipts for new variants)
Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling
worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* WIP: gunbc Director
* docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3)
Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue.
Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by
Modeling Manager's Wave 3 worker briefs (gated on these landing).
Authored:
- r2-substrate-cardinality-for-int-lit-subset.md (M) — produces
magnitude carrier consumed by T-Modeling int-lit. Coordinates with
PR #806's prior cardinality work; mandatory authority audit guards
against #796's rejected IntLiteralMagnitude shape resurfacing.
Open design questions: magnitude representation, reconciliation
narrowing point, i64::MIN representability.
- r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces
nominal-opacity carrier consumed by T-Modeling Secret<T>. Open
design questions: carrier shape (flag/connective/sealed-accessor),
generic-walk discipline, accessor gating.
- r2-substrate-parametric-algebra-for-dimensions-subset.md (M) —
produces phantom-parameter carrier consumed by T-Modeling
Dimension<Carrier>. Open design questions: carrier shape,
type-equivalence rule, algebra-method dispatch, lifting/coercion.
All three:
- Scoped narrowly to their paired R2 consumer; not full
substrate-capability lanes.
- Mandatory pre-author authority audit per
feedback_audit_adjacent_authority_first.
- Cross-program readiness signal pattern from #827's manager rework.
- Coproduct dissolution receipts required for any new variants.
- Open design questions surfaced explicitly so Substrate Manager
(or Director pre-spin-up) can resolve at dispatch time.
Wave 3 (T-Modeling worker briefs × 4) follows.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4)
Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue.
Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each
gated on a Substrate Manager readiness signal (Wave 2 producers).
Authored:
- r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2
cardinality-for-int-lit; moves narrowing from tokenizer to
reconciliation; MagnitudeOutOfRange diagnostic per C-8.
- r2-modeling-secret-graduation-worker.md — gated on Wave 2
nominal-opaque-for-Secret; authors Secret<T> + gated accessors
(redact, compare_in_constant_time); C-8 diagnostic on non-gated
access; signals Impossible-Bugs Manager on close (thesis claim
covered).
- r2-modeling-dimensions-phantom-worker.md — gated on Wave 2
parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier>
+ core SI base units + algebra-method dispatch; cross-dimension
arithmetic produces typed diagnostic; signals Impossible-Bugs
Manager (thesis claim).
- r2-modeling-tokenizer-charclass-phase2-worker.md — gated on
T-Substrate ValueBody-list/sum (#790); migrates tokenizer
consumers to Char/List<Char>/CharClass canonical types; sibling
consumer to Grounding Manager's Engine sharpened-(b).
All four:
- Explicit gating: 'do not dispatch until producer signal posts.'
- Producer/consumer signal pattern from #827.
- Cross-program signals to R2 Release Manager (Goal 2 closure)
and Impossible-Bugs Manager (thesis-claim coverage).
- Spoofing regression tests: discipline anchor against
feedback_no_textual_enforcement_bridges.
Wave 4 (T-ImpossibleBugs worker briefs × 3) follows.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3)
Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue.
Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes,
consuming the existing design/scoping briefs as authority.
Authored:
- r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on
cardinality refinement substrate (T-Substrate territory adjacent
to int-lit / DB-11 alias-where). Implementation: structural normalize
of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T??
worker decision (reject vs normalize). Cites
t-impossiblebugs-nested-optional-flatten-design.md as authority.
- r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated
on Tier 2 substrate (predicate-entailment infrastructure; distinct
from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes
predicate entailment, (b) feedback_totality_by_omission dissolves
partial primitives, (c) park. Worker decides at audit time. Cites
t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority.
- r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate
prerequisite per closed-system framing in design doc (#808). Audit-
as-existence-check + lens implementation as compositional fold over
5 behaviors; redundancy detection compile-error via referential
transparency + reread() escape hatch; path (i/ii) decision on
OperationEffect taxonomy retain-vs-retire (default retire). Cites
design doc #808 as authority.
Cross-cutting:
- Each cites prior design/scoping brief as authority (the existing
*-design.md / *-worker.md REFRAMED files).
- Explicit gating per #827 producer/consumer signal pattern; two
briefs gated on substrate, one NOT gated (closed-system).
- STOP-AND-ESCALATE includes 'design brief assumptions don't hold'
surfacing per feedback_thesis_gate_state_drift.
Wave 4 complete. Director's 14-brief queue done; awaiting PM portion
(6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B4.4 — tighten Slice §3 per PM review on #836
PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b)
(authority + tracked debt parallel-rep) as autonomously acceptable
contradicts feedback_construction_over_ratchets +
feedback_parallel_representation_debt.
Tightened:
- Shape (a) is the only autonomous worker path.
- Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a
regen-host-loader sub-lane decision; not authorable without explicit
Substrate Manager approval citation in the PR body.
- Acceptance bullet requires the approval citation when shape (b)
lands.
- STOP-AND-ESCALATE rephrased to make this explicit; permanent
parallel-representation re-escalates even with manager approval.
This preserves shape (a) as autonomous; shape (b) becomes a
cross-manager design escalation, not a B4.4 implementation call.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief
Cursor review on #836 flagged the Read-first reference to
.claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md
as machine-specific (outside the repo, not resolvable from a normal
clone). Replaced with in-repo prose pointing at the design doc's
§Q1-Q3 as canonical authority — the discipline lives there in-repo.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs)
Codex flagged: src/v3/std/types.dag does not exist; the canonical
authority is at dsl/std/types.dag. Affected briefs (all from R2
spin-up Wave 2 + Wave 3):
- r2-substrate-cardinality-for-int-lit-subset.md
- r2-substrate-nominal-opaque-for-secret-subset.md
- r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs)
- r2-modeling-dimensions-phantom-worker.md
- r2-modeling-secret-graduation-worker.md
feedback_verify_thesis_claims violation on Director-side brief
authoring — assumed path without grep. Same family of error as
the earlier emit.rs precedent claim. Mass-replaced via perl;
verified no remaining stale refs.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant
Codex BLOCKING on #836: my R2 worker brief gated nested-optional on
cardinality refinement substrate, but the design doc verifies v3 is
ALREADY past the cardinality bridge — TypeConnective::Cardinality
is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is
the carrier for Option. The dissolution is an UNGATED implementation
via substrate-constructor invariant.
feedback_verify_thesis_claims violation again — should have read the
design doc fully before assuming the substrate gate.
Rewrote brief to match design doc canonical sketch:
- Single predicate (cardinality_idempotent_target) owns the rule
- Single allocator (alloc_cardinality_decl) is THE substrate-constructor
- API closure on TypeConnective::Cardinality payload (modeling-discipline
practice 6) — variant cannot be struct-init'd outside the allocator
- 3 hand-Rust + ~22 codegen call sites enumerated per design audit
- infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as
the killer case for generic-instantiation paths
- Surface-syntax T?? decision left to worker (Director-lean: silent
normalize)
Brief now dispatchable immediately, no producer signal needed.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation
Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment
substrate path, but the design doc §4 explicitly recommends totality-by-
omission as the Director-actionable path. Predicate-entailment is M+ scope
that reopens DB-11's explicitly-closed asymmetric-strip design — design
doc explicitly discards it.
feedback_verify_thesis_claims violation again — same family as nested-
optional reframe. Should have read design doc §4 in full before assuming
the path ordering.
Rewrote brief to match design doc §4 follow-on shape:
- Primary path: per-class totality-by-omission (algebra retype + per-
target realization migration). For Int/Int: OrderedRing.div retype
at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 /
python:486 + python_target.rs:680 helper).
- NOT predicate-entailment (out of scope; M+ + DB-11 reopen).
- NOT NonZero-typed-input (deferred to separate per-operand-variance
substrate brief; STOP-AND-ESCALATE if chosen).
- Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i]
indexing, quotient, remainder) queue separately per design doc audit.
- feedback_totality_by_omission discipline anchor explicit.
Brief now matches feedback_totality_by_omission discipline + design doc
recommendation. No substrate prerequisite; dispatchable immediately.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure
Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a
pattern: I authored R2 worker briefs without fully reading each design
doc's Director-actionable recommendation. Pre-emptively re-verified
unenumerated-effects against design doc §Q6 to catch the same family
of error before reviewers do.
Findings: brief was substantively close but missing 3 of 8 design-doc
reqs:
- Req 3: Resource-threading discipline applied to existing primitives
- Req 5: reread(key) primitive in std/ as explicit Slice item (was
only mentioned in tests)
- Req 7: Asymmetric-tightening worked example in PR body
Plus: Slice didn't cite the canonical lens path
src/v3/lenses/effect_enumeration.dag from design doc.
Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6
specifies 4 specific STOPs (path-decision-escalation, pure: Bool
carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP)
that I had elided.
Reframed Slice as 8 numbered reqs matching design doc verbatim;
STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs;
Acceptance enumerated per req.
This is the third reframe in the unhandled-bugs series — same
feedback_verify_thesis_claims violation each time. The pattern
suggests Director-side R2 brief authoring should ALWAYS read each
design doc's §Director-actionable / §Q-recommendation in full first,
not assume.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options
Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)"
listed as a worker-pick option violates THESIS.md substrate-shape
lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality |
Instantiation) are canonical (per #811 thesis additions and #827 PM
review); a 7th is a C1 stop signal requiring failed-dissolution
evidence + Director substrate-design call, not autonomous worker pick.
Removed the "new TypeConnective variant" option; replaced with
`inhabits`-edge-shape carrier as third option (audit-time check). The
explicit STOP-AND-ESCALATE clause now states: 7th connective is the
precondition for failed-dissolution-evidence + Director substrate-design
call, not a worker path.
feedback_verify_thesis_claims still in play — should have grounded
substrate-shape options against the THESIS lock before listing Opaque(T)
as worker-autonomous. Pattern continues; reading source-of-truth before
authoring options is the discipline.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place)
Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter
already exist at dag.rs:186, :217 — explicitly authored for the
R2 Dimensions consumer per the doc comment at dag.rs:148-160.
phantom_unit_mismatch already wired at infer.rs:1057, :1132. The
substrate is fully landed; my brief framing it as 'producer sub-lane
to land carrier' is wrong on the same feedback_audit_adjacent_authority_first
violation that hit nested-optional / unhandled-diagnostic / unenumerated-
effects.
Reframed the substrate-side brief as no-op / closed-by-audit:
- Documents the audit receipt (5 sites confirming substrate exists)
- States the lane is closed
- Routes T-Modeling Dimensions consumer to dispatch immediately
against the existing carrier
- Records the lesson: 'always grep substrate before authoring
producer briefs' — discipline doesn't end at brief boundaries.
Updated r2-modeling-dimensions-phantom-worker.md correspondingly:
- Changed gating from 'do not dispatch until producer signal' to
'NOT GATED — dispatch immediately'
- Read-first updated with concrete dag.rs/infer.rs cites
- Slice §1 changed from 'confirm producer signal' to 'verify
substrate at HEAD'
- STOP reframed: existing carrier extension would need Substrate
Manager call, not autonomous worker pick
Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit
both verified — no existing substrate (no is_nominal_opaque /
MagnitudeBound patterns in dag.rs); both still legitimately
producer-side work.
Pattern is now four reframes deep on the R2 spin-up wave. The lesson
saved is structural: read source-of-truth before authoring options.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority
Codex BLOCKING on #836: my new R2 spin-up brief duplicates the
existing t-substrate-cardinality-int-lit-worker.md, which carries
the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64)
stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane).
Single-authority violation per INVARIANTS P2.
Same feedback_audit_adjacent_authority_first failure as parametric-
algebra-for-Dimensions reframe (4 hours ago): assumed substrate
authority didn't exist; should have grepped docs/briefs/ before
authoring. This is the SECOND R2 spin-up substrate brief closed
as redundant — the discipline lesson is structural.
Reframed brief as no-op routing doc (documents the audit receipt;
routes consumers to the existing authority); updated
r2-modeling-int-lit-magnitude-worker.md to cite
t-substrate-cardinality-int-lit-worker.md instead.
Pattern across the R2 spin-up wave reframes (5 now):
1. nested-optional gating-on-substrate (substrate already past
cardinality bridge)
2. unhandled-diagnostic predicate-entailment default (design doc
recommends totality-by-omission)
3. unenumerated-effects 8-req design-doc elision
4. parametric-algebra Producer (Declaration.phantom_params already
authored explicitly for this consumer)
5. cardinality-for-int-lit Producer (existing brief is authority)
All five are 'assumed state without grep before authoring'. Future
R2 subs…
…+ reflection completeness + Q6.5 two-layer diagnostic-kind) (#1129) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c33: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 second-wave worker-escalation fixes Four substantive worker STOP-AND-ESCALATEs from briefs landed in PR #797. All four worker recommendations correct; each needs a Director call + brief update. ## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate Worker correctly identified that brief req 2 (declared-effect carrier as part of fn type signature, per feedback_no_annotations) requires net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots. Without parser surface, every user function would have declared_effects = [] while inference returns non-empty — lens fires EffectLeakageError everywhere on enable. Worker rejected power-through and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map parser split). Director picked split: - NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface syntax + lookahead + body parser + lowerer extension + exhaustive-match audit + coproduct dissolution receipt. - MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to post-parser-extension scope. Pre-flight check NOT a parser-extension step; STOP if parser sub-lane PR not merged. ## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping Worker found load-bearing evidence at infer.rs:3693-3703: DB-11 deliberately strips refinements at operator dispatch as a designed-in fix for symmetric-operators failure mode. Brief's "attach where b != 0 as a proof for a / b" directly contradicts this design choice. STOP-3 (where-clause conflict with DB-11) is real; STOP-1 (substrate scope) needs net-new substrate (per-operator partiality fact + predicate- entailment check + asymmetric per-operand refinement-honoring) — M+ minimum. ownership_lens precedent in original brief is post-hoc observability, not proof carrier. Worker recommended redirect to design/scoping per nested-optional precedent. Director picked redirect. Brief fully rewritten as design/scoping with four-question structure: (1) DB-11 interaction analysis; (2) substrate proposal for proof-or- totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes with acceptance-theatre risk on user-defined-total-wrapper-only); (4) Director-actionable recommendation. Output is doc PR. ## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C) Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int) with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136 closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b) i128 implementation requires either path 1 (hierarchy refactor — contradicts non-goal) or path 2 (regen lie between substrate and emit — violates discipline). Worker leaned option (C) re-scope: land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke) to a sibling sub-lane that does proper Int128/Word128 substrate work. Director picked option (C). Brief req 1 re-scoped to drop canonical- carrier-widening; lane value comes from range facts + reconciliation narrowing + out-of-range diagnostic against existing i64. Req 4 explicitly deferred with sibling-sub-lane reference. Sibling sub-lane NOT to be authored or implied in this PR; tracked separately. ## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change) Worker correctly STOP'd per the brief's own pre-flight check: parser sub-lane has not landed; SurfaceExpr::Map not on main. Director authorized cross-lane reassignment: wise-boar-480 takes the parser sub-lane (t-substrate-valuebody-map-parser-worker.md) since they already have full investigation context. No brief changes needed; the routing decision is in the dispatch. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope Resolves codex P2 inline at sha e35103fad on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still required widening LiteralBits::Int(i64) to an unbounded carrier and passing the i64::MIN smoke. Internally unsatisfiable. Fix: - Slice section retitled "range facts + reconciliation narrowing (against existing i64 carrier)" with explicit note about the re-scope. - Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly forbids touching LiteralBits::Int shape, dag_scalar_generated.rs regen for that variant, or tokenize i64 parse path. - Slice steps 2-5 reframed: range facts use i64-representable magnitudes; reconciliation narrowing uses existing i64 carrier; diagnostic only for i64-representable out-of-range; smoke tests for req 5 only (req 4 i64::MIN deferred). - Acceptance checklist updated: - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as re-scoped/deferred. - LiteralBits::Int(i64) carrier untouched (no widening; no parallel; no shape change). - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference. - STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the carrier" — explicit STOP if execution surfaces range-fact narrowing requiring carrier-widening; that's the boundary the re-scope drew; belongs in sibling Int128/Word128 sub-lane. Brief now consistently treats carrier-widening as out-of-scope across all sections. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty Resolves codex BLOCKING #1 at sha e35103fa on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier but req 2 required range facts using "the SAME magnitude carrier as req 1" — meaning i64-typed range bounds. u64's max (2^64-1) doesn't fit in i64; range fact for u64 would have to truncate, omit, or mirror in Rust (representation drift). All three options violate fail-closed declared-facts discipline (P1 / P3). Fix: - Req 2 rewritten to specify String-decimal representation: range_min_inclusive: String + range_max_inclusive: String fields on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127" for i8; "0"/"18446744073709551615" for u64). - Explicit reasoning why String-decimal: u64's max doesn't fit in i64; binding range bounds to literal carrier forces truncation/ omission/mirror-drift; all violate fail-closed declared-facts discipline. - Bridge framing: String-decimal is pending the sibling Int128/ Word128 sub-lane; both range bounds and literal payload migrate to typed carrier when that lands. - Req 3 updated for String-decimal comparison semantics: reconciliation parses both bounds and literal magnitude into a common comparison space (i128 host comparison primitive — host narrowing, NOT carrier widening). Bounded by what the i64-typed literal can express; any i64-representable literal compares against any width's String-decimal bound. Carrier discipline preserved. Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral) is sha-stale — already resolved at 3e142d169. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback). Real residual: req 2 specifies String-decimal range bounds (to cover u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" / "i64-representable magnitudes" for the range facts. Two incompatible authorities for the same range-fact shape — would let a worker satisfy the slice while truncating/omitting u64 bounds (P3 fail-closed violation). Fix: - Line 31 (req 1 re-scope clarification): updated to explicitly state "range facts (req 2) use String-decimal representation (width- independent; covers u64::MAX which doesn't fit in i64)". Distinguished literal *payload* (stays i64) from range-bound *representation* (String) — both serve req 1's "no carrier widening" boundary. - Line 44 (slice step 2): updated from "Range bounds use i64- representable magnitudes" to "Range bounds use String-decimal representation per req 2" with concrete example (u64 bounds). - Acceptance bullet: updated from "Range facts on integer algebras (substrate-declared, not Rust-mirrored)" to add "using String-decimal representation ... width-independent; u64 bounds expressible without truncation." The brief now consistently treats range bounds as String-decimal across req 2, req 3, slice, acceptance, and the req 1 clarification — no remaining authorities saying i64-typed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing User + PM exchange 2026-04-25 surfaced that the in-flight effects chain was importing wrong assumptions from external languages (declared-effects-as-annotation + lens-vs-declaration check). Right framing under gunbc's closed-system discipline is parallel to complexity: every effect derives structurally from the composition of typed primitive operations; nothing can hide because there's no escape hatch; nothing needs annotation because the structure IS the registry. Four doc-only actions: 1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md. Frames the closed-system answer with PM's 5-behavior synergy table (Value/Transform/Branch/Loop/Bind as universal compositional-fold pattern). Four worked examples; aggressive reading on redundancy (compile-error-by-construction via referential-transparency proof; reread() primitive for legitimate cases); implementation-brief shape in §Q6. 2. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md. 3. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md. Notes Fn→Arrow refactor brief stays dispatchable as independent value. 4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by- construction framing replaces lens-detection framing. Memory file feedback_closed_system_effects.md saved separately; cross-link added to feedback_construction_over_ratchets.md. Net cost: doc-level cleanup. Zero substrate code rework. Foundation (OperationEffect + service-call infrastructure + 5-behavior substrate) already exists. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect Per PM convergence review on #808 + user's deeper 2026-04-25 framing: the closed-system framing landed in #808 retired the user-facing annotation but kept OperationEffect taxonomy as substrate-level tagging. User's deeper framing: the taxonomy ITSELF is parallel-representation — operations are intrinsically read-shaped or write-shaped via their TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns- derived-value-only → read). Tagging operations with Read | Upsert | Create | Append | Delete names what the structure already says. Three changes: 1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as normalized view, or retire as parallel-representation?" - Two paths: (i) tags derived from signature shape (acceptable normalized view) vs (ii) tags declared per-primitive (parallel- representation; retire). - Audit-as-existence-check (Q4 req 2 reframed): all effectful primitives derive cleanly from signature shape → path (i); any primitive needs hand-declared tag → path (ii) by existence proof. - Director default: path (ii). Logging primitives that return Unit are likely the audit's existence-proof. - Two design-question resolutions: (a) external effects not in return type → resource-threading discipline (typed param returned modified, IO-monad-without-the-monad pattern); (b) transactional grouping → derived structural fact from Bind composition + typed transaction primitives. 2. Q4 reqs revised: req 2 from "tag every primitive with explicit OperationEffect signature" to "audit-as-existence-check that every primitive's type signature derives the right effect classification"; req 3 added (resource-threading discipline); req 6 added (transactional-pattern lens). Req 1 (effects lens) anchors on operation type-signature shape, not on hand-declared tags. 3. THESIS:345-347 amendment strengthened — "operations are intrinsically read-shaped or write-shaped via their type-signature shape; consumers walk the signatures directly; there is no parallel taxonomy or annotation layer to declare or maintain. Tracking effects as a separate enumerated concept IS the bug pattern, dissolved by construction." Plus references to resource-threading discipline + transactional grouping as derived structural fact. Memory file feedback_closed_system_effects.md updated to reflect the deeper framing (type-signature-shape, not taxonomy-tagging) + resource-threading discipline section + transactional-patterns section. Net cost: doc-only delta on top of #808. Substrate retirement (OperationEffect enum + derive_op_effect + idempotency.dag re-anchor) deferred to the audit-as-existence-check phase of the implementation brief; surfaced as Q5.5 OPEN CALL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage Resolves codex BLOCKING at sha d49ce79a on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real: the prior text claimed service primitives "already carry typed effect signatures" presenting future audit-state as current substrate fact (P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the OperationEffect line but left a parallel over-claim on the new "signature-shape coverage" framing. Fix: Q4 substrate-state listing rewritten to honestly distinguish: - Live: Behavior enum + substrate foundation (the principle that operations should carry signature shape). - Incomplete: signature-shape coverage across actual primitives. HTTP-derived primitives carry implicit shape via derive_op_effect's method-table; logging/mutation primitives that return Unit or don't thread their target resource do NOT carry the structural shape that would express read-vs-write. Achieving full coverage is required work under reqs 2 + 3, not a current fact. - Pending audit-as-existence-check: OperationEffect + derive_op_effect (path (i) vs (ii) per Q5.5). Honest live-state callout added explicitly: "the closed-system FOUNDATION (5 behaviors + DAG substrate + the principle that operations should carry signature-shape) is live. The IMPLEMENTATION COVERAGE across all effectful primitives is partial. Req 2 + req 3 are the work that closes the gap." Brief now distinguishes principle-is-live (foundation) from coverage-is-partial (audit work) without conflating them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim Per PM follow-up review on #808 + user's stronger discipline framing ("substrate must make bypass structurally impossible at every layer of the transport stack"): the closed-system claim is honest only when typed primitives ARE the path. Today two structural holes exist where bypasses sidestep the typed-primitive substrate. Both surfaced explicitly as Q4.5 pre-conditions — load-bearing for the lens's coverage claim. Three changes: 1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed- system claim)" inserted between Q4 and Q5: P1 — Extdeps typed-primitive consumption structurally enforced. Substrate must make `messages: Json` impossible to declare in service definitions; typed `LlmMessage` / `ContentBlock` / `GitHubAuthToken`-with-full-scopes are the only path. Tracked debt at ROADMAP.md:153-154 (LLM provider flattening) + `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded). Required prereq for full lens coverage; lens can land first + surface structural-coverage-gap diagnostics on bypass surfaces so the gap becomes visible rather than silent. P2 — `ExecuteCommand` fully materialized as typed runner primitive. TESTING.md (post-#782) committed to 0-residual but ExecuteCommand isn't fully materialized; deleting Rust boundary tests creates verification gap. Already named under PB-Runtime in Zero-Floor; signal pending. Pre-requisite for ANY Rust boundary-test deletion. 2. Old leftover duplicate Q5 section deleted (artifact from prior Q5/Q5.5 reshape; second copy of asymmetric-tightening text was in the file alongside the earlier Q5 instance). 3. Worker-discretion-vs-Director-call section in Q4.5: lens implementation worker dispatchable now (reports gaps as findings); P1 closure is substantive substrate work touching extdeps (dedicated lane); P2 closure is PB-Runtime (signal pending). Net: design doc now honestly distinguishes principle-is-live (Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs named explicitly). The closed-system claim has explicit pre- conditions documented; implementation brief discovers them as known dependencies, not as STOP-AND-ESCALATEs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two real residuals after the Q5.5 reframe: 1. Q6's reqs/STOPs/acceptance still framed under path (i) — said "audit + tag std/ primitives — every effectful primitive carries an explicit OperationEffect signature." Directly contradicted Q4 (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment ("there is no parallel taxonomy to declare or maintain"). Worker reading Q6 in isolation would author the retracted shape. 2. Capacity / sequencing table line about "audit lane (tag std/ primitives with effect signatures)" carried the same stale framing. 3. Q6 STOP "primitive performing side effects without an OperationEffect tag" assumed tag-as-authority; under path (ii) the STOP shape is "primitive whose signature doesn't structurally reveal its effect." Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale (already fixed at f073aa95e Q4.5 commit). ## Q6 fixes - Reqs renumbered + reframed: - Req 1 anchors on operation type-signature shape (not hand-declared OperationEffect tags); composition reads from signature shape per Q2 table. - Req 2 changed from "audit + tag every primitive" to "audit-as-existence-check" — verify signature-shape coverage; ANY primitive needing a hand-declared tag IS the existence-proof for path (ii) retirement. - Req 3 added: resource-threading discipline applied to existing primitives (logging that returns Unit gets reshaped per audit). - Req 6 added: transactional-pattern lens (Bind composition + Transaction → Transaction'). - Req 7 added: asymmetric-tightening worked example in PR body (per claude review observation; the one place declaration-shaped surface re-enters). - Req 8 (was 5): tests now reference signature-shape derivation explicitly, not tag lookup. - STOPs reframed: - "OperationEffect retirement decision" — audit produces path (i) vs (ii) verdict; substrate retirement is its own dedicated sub-lane; this lane does NOT absorb it. - Pure/impure carrier STOP notes that "pure" should also derive from signature shape (pure functions don't return modified resources) — so the STOP itself may dissolve under further design. - Q4.5 P1 explicitly NOT a STOP — lens reporting structural- coverage-gap on extdeps bypass surfaces is the lens delivering its foundation-gap-visibility value. - Q4.5 P2 explicitly independent — lens doesn't depend on ExecuteCommand materialization. - Acceptance extended: lens reports gap diagnostics on P1 bypass surfaces; audit produces existence-proof verdict for Director re-decision; asymmetric-tightening worked example in PR body. ## Capacity / sequencing table Replaced "1 audit lane (tag std/ primitives with effect signatures)" with "1 audit-as-existence-check lane (verify primitives' signature- shape coverage; NOT 'tag every primitive') — produces the path (i) vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2 prereq lanes to the net summary. Closing line: "The taxonomy- retirement scope (substrate-side) is not in this lane — it's surfaced by audit and routed to dedicated retirement lane if path (ii) wins." Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity table. Worker reading Q6 in isolation now sees path-(ii)-default framing matching Q4 + Q5.5 + THESIS amendment. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792 Resolves codex inline BLOCKING at sha 191be310 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150. Real: my Q4.5 P2 framing described ExecuteCommand as still NotYetImplemented (M1.5 allowlist + Rust TestRunner returning NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand extension before this PR's authoring. TESTING.md:195 capability-state callout confirms: - Rust TestRunner + M1.5 testgen harness share one std::process path for arbitrary command + args + expect_exit_code. - M1.5 allowlist + fail-closed panic retired. - Distinguishable ClaimResult::Fail messages for spawn / timeout / policy / exit-mismatch. - Linux unshare(1) namespace isolation on host-allowing systems. - T-PB-B-1 boundary migration example landed. Fix: P2 section rewritten: - Header retitled "ExecuteCommand runner primitive: LANDED (PR #792); residual is bulk-migration." - Status update naming PR #792 + the post-#792 capability state (allowlist retired, etc.). - Honest acknowledgement: "My earlier P2 framing was stale." - Residual narrowed to bulk-migration of existing Rust Command::new boundary tests (tracked as ROADMAP residual, not lens prereq). - Sequencing reframed: P2 was always orthogonal to the effects lens itself; bulk migration proceeds at its own pace; lens not blocked. Q4.5 footer updated: - "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via #792; only consumer-side bulk migration remains)" - Worker-discretion-vs-Director-call P2 line updated: "runner primitive landed; only consumer-side bulk migration remains; tracked as ROADMAP residual, independent of the lens." Q6 STOP for P2 updated: - "the lens itself doesn't depend on P2; only TESTING.md's 0-residual claim does" → "runner primitive landed via PR #792 (post-Q4.5- authoring update). The lens itself never depended on P2; bulk consumer migration is residual ROADMAP work and remains independent of this lane." Brief now reflects live state. The closed-system claim's prereq landscape is honest: - P1 (extdeps typed-primitive consumption): real prereq, tracked debt at ROADMAP:153-154. - P2 (ExecuteCommand runner): satisfied via #792; bulk migration is consumer-side residual, not foundation work. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale Resolves codex non-blocking finding at sha bcac41bb on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real residual: capacity-table line still listed P2 as "`ExecuteCommand` materialization" prereq + framed both P1 and P2 as "pre-existing tracked-debt" — but my prior 57a9b1318 fix established that PR #792 already landed the runner primitive, so P2 is no longer a materialization prereq. Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq) from P2 (residual, not prereq): - P1: extdeps typed-primitive consumption — pre-existing tracked debt at ROADMAP:153-154; load-bearing for the lens's full-coverage claim. - P2: ExecuteCommand runner primitive landed via PR #792; only consumer-side bulk migration of existing Rust Command::new boundary tests remains (tracked as ROADMAP residual, independent of the lens; not a materialization prereq). Brief now consistently treats P2 as bulk-migration-residual across: - §Q4.5 P2 section header (LANDED via PR #792; residual is bulk-migration). - §Q4.5 footer (P2: runner primitive landed; only consumer-side bulk migration remains). - Q6 STOP for P2 (runner primitive landed; bulk migration is residual ROADMAP work). - §Capacity / sequencing impact (P2 as residual, not prereq). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349 Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated target-grounding prose; the matching extdeps typed-primitive bypass entries (LLM service flattening, GitHub auth model bypass) live at ROADMAP.md:348-349. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix third stale ROADMAP citation at line 271 Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence at line 271 in the §Q4.5 capacity table. Now consistent with lines 139 and 173 (ROADMAP.md:348-349). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity Codex flagged 'Effect-signature tagging on std/ primitives' as potentially contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240) already explicitly say 'NOT tag every primitive' — but the cross-manager line used sloppy wording. Reworded to make explicit that the audit walks signature shape; no parallel tag added. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5 - B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound - B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause - B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge - B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation) B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25): language vocabulary is primitives + namespacing only; no escape syntax; the §0 sentinels are the compiler itself failing to use primitives + namespacing internally. Eight surface sites dissolve via four substrate carriers (DeclarationRef, structural fold-shape carrier, structural emit-helper carrier, structural extdeps-fixture-set carrier). B1-B3 are independent; dispatch in parallel. B4 is sequential program work; sub-brief dispatch (B4.1-B4.12) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — drop incoherent inner-fallback non-goal Codex P2: the non-goal line excluding the inner declaration().name unwrap_or_else fallback contradicted Slice step 2, which replaces the whole chain with let-Some-else-return. Both fallbacks are in scope by construction; remove the contradictory non-goal. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives PM REQUEST_CHANGES: §Frame listed '4 type connectives (Conjunction | Disjunction | Cardinality | Bit)' which contradicted the canonical thesis source. Replaced with the canonical 6 (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary closes here'. Also removed 'typed substrate carriers' from the vocabulary list — substrate carriers are defined using the vocabulary, not part of it. Added a clarifying note that B4's carriers (DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are typed declarations composed from the vocabulary, not vocabulary extensions. Per feedback_verify_thesis_claims: brief framings citing thesis structure must ground in the canonical source. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of naming the live substrate authority. Two coordinated fixes: 1. §Read first cites src/v3/std/substrate.dag (live .dag substrate authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel meta-type — already exists with consumers in verification.dag, emit_model.dag, python.dag). 2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing DeclarationRef'. The work is consumer migration + any role-extension layer the audit reveals, NOT designing or landing the carrier. Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers) keep their 'new' framing but explicitly require sub-briefs to grep src/v3/std/ + src/v3/spec/ for existing authority before authoring 'design and land' framing — per feedback_verify_thesis_claims + feedback_emitter_workaround_is_gap_symptom. Acceptance + sub-brief dispatch order updated to reflect B4.1's consumer-migration shape. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — tighten Phase 1 umbrella sentence The umbrella 'Land the typed carriers into src/v3/std/' framing was stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced with audit-first wording that covers both the consume-existing case (#1) and the design-and-land case (#2-#4 if their audits show real gaps). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands' which conflicted with the post-reframe reality that B4.1 consumes the existing DeclarationRef. Updated to 'consumes or lands' with explicit existing-authority citation and audit-pending caveat for B4.2-B4.4. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — soften regression-test requirement (3 worker bounces) Three consecutive B1 worker dispatches (zesty-crane-890 cursor → valiant-boar-498 codex → cool-lynx-395 cursor) archived without opening a PR. Likely friction point: brief Slice step 4 asks for a unit test that constructs a Dag with an orphan variant declaration, but emit.rs has zero existing #[test] precedent — emit testing happens via integration fixtures. Workers see 'build novel test harness' inside what's billed as an S-scope fix and bounce. Per feedback_construction_over_ratchets: when a brief has friction, fix the brief, don't ratchet the worker. Softened step 4 + acceptance: regression test stays optional. If test setup requires novel scaffolding, route the gap to follow-up. The structural fail-closed at step 2 is the load-bearing change. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description' is too weak; PR descriptions don't survive squash-merge cleanly. Two coordinated edits: 1. Slice step 4 — explicit substrate-signal framing: skipped test means emit-side hermetic-unit-test infrastructure is the missing substrate (feedback_emitter_workaround_is_gap_symptom). 2. Acceptance — require ROADMAP debt row (new or existing) with named dissolution trigger, referenced in PR body. Converts the skip from PR-local note (transient) into tracked debt (durable, dispatchable). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124 Codex BLOCKING: my earlier softening claimed emit.rs had no #[test] precedent — wrong. The module has #[cfg(test)] mod tests at line 3124 with 12+ tests using compile_to_dag(source, filename) as harness (e.g., go_struct_fields_render_with_separators :3143, shared_walk_to_disj_finds_match_scrutinee_sum_type :3195). This is a feedback_verify_thesis_claims violation on Director-side brief authoring — claim made without grep verification. Fix: restore step 4 as required, with explicit precedent citation. Worker constructs the failure case via the existing harness (direct Dag, fixture string, or BranchPattern exercise; worker's call on cleanest path). STOP-AND-ESCALATE only if construction proves materially harder than precedent suggests, in which case that escalation surfaces a real substrate gap and warrants ROADMAP debt — but the default is 'add the test.' Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites) Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded to 'several using compile_to_dag'. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this is Wave 1 of Director's 14-brief authoring queue, covering B4 program internals. Authored: - b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) — replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag") fold-skip with structural template-formal carrier; mandatory authority audit per feedback_audit_adjacent_authority_first. - b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) — replaces §0.6 emit.rs bind/branch.span.file equality with typed BindEmitParticipation/BranchEmitParticipation roles populated at lowering; aligned with #824 worker's in-flight implementation shape. - b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4 of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with typed substrate authority; explicit pre-promotion-constraint disposition (single-authority vs authority+tracked-debt) addresses parallel-representation risk surfaced on #825. - b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) — names B4.5-B4.12 Phase 2 sites with carrier dependencies, cross-program coordination notes, and skeleton-brief template; full per-site briefs author at dispatch time per #827's Substrate Manager ownership. Cross-cutting discipline applied per inbox #828 reply: - feedback_audit_adjacent_authority_first (mandatory grep before design) - feedback_no_textual_enforcement_bridges (no replacement sentinels) - feedback_parallel_representation_debt (explicit if shape (b)) - feedback_construction_over_ratchets (no parity-by-runtime as primary) - feedback_coproduct_dissolution (receipts for new variants) Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3) Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue. Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by Modeling Manager's Wave 3 worker briefs (gated on these landing). Authored: - r2-substrate-cardinality-for-int-lit-subset.md (M) — produces magnitude carrier consumed by T-Modeling int-lit. Coordinates with PR #806's prior cardinality work; mandatory authority audit guards against #796's rejected IntLiteralMagnitude shape resurfacing. Open design questions: magnitude representation, reconciliation narrowing point, i64::MIN representability. - r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces nominal-opacity carrier consumed by T-Modeling Secret<T>. Open design questions: carrier shape (flag/connective/sealed-accessor), generic-walk discipline, accessor gating. - r2-substrate-parametric-algebra-for-dimensions-subset.md (M) — produces phantom-parameter carrier consumed by T-Modeling Dimension<Carrier>. Open design questions: carrier shape, type-equivalence rule, algebra-method dispatch, lifting/coercion. All three: - Scoped narrowly to their paired R2 consumer; not full substrate-capability lanes. - Mandatory pre-author authority audit per feedback_audit_adjacent_authority_first. - Cross-program readiness signal pattern from #827's manager rework. - Coproduct dissolution receipts required for any new variants. - Open design questions surfaced explicitly so Substrate Manager (or Director pre-spin-up) can resolve at dispatch time. Wave 3 (T-Modeling worker briefs × 4) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4) Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue. Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each gated on a Substrate Manager readiness signal (Wave 2 producers). Authored: - r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2 cardinality-for-int-lit; moves narrowing from tokenizer to reconciliation; MagnitudeOutOfRange diagnostic per C-8. - r2-modeling-secret-graduation-worker.md — gated on Wave 2 nominal-opaque-for-Secret; authors Secret<T> + gated accessors (redact, compare_in_constant_time); C-8 diagnostic on non-gated access; signals Impossible-Bugs Manager on close (thesis claim covered). - r2-modeling-dimensions-phantom-worker.md — gated on Wave 2 parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier> + core SI base units + algebra-method dispatch; cross-dimension arithmetic produces typed diagnostic; signals Impossible-Bugs Manager (thesis claim). - r2-modeling-tokenizer-charclass-phase2-worker.md — gated on T-Substrate ValueBody-list/sum (#790); migrates tokenizer consumers to Char/List<Char>/CharClass canonical types; sibling consumer to Grounding Manager's Engine sharpened-(b). All four: - Explicit gating: 'do not dispatch until producer signal posts.' - Producer/consumer signal pattern from #827. - Cross-program signals to R2 Release Manager (Goal 2 closure) and Impossible-Bugs Manager (thesis-claim coverage). - Spoofing regression tests: discipline anchor against feedback_no_textual_enforcement_bridges. Wave 4 (T-ImpossibleBugs worker briefs × 3) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3) Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue. Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes, consuming the existing design/scoping briefs as authority. Authored: - r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on cardinality refinement substrate (T-Substrate territory adjacent to int-lit / DB-11 alias-where). Implementation: structural normalize of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T?? worker decision (reject vs normalize). Cites t-impossiblebugs-nested-optional-flatten-design.md as authority. - r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated on Tier 2 substrate (predicate-entailment infrastructure; distinct from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes predicate entailment, (b) feedback_totality_by_omission dissolves partial primitives, (c) park. Worker decides at audit time. Cites t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority. - r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate prerequisite per closed-system framing in design doc (#808). Audit- as-existence-check + lens implementation as compositional fold over 5 behaviors; redundancy detection compile-error via referential transparency + reread() escape hatch; path (i/ii) decision on OperationEffect taxonomy retain-vs-retire (default retire). Cites design doc #808 as authority. Cross-cutting: - Each cites prior design/scoping brief as authority (the existing *-design.md / *-worker.md REFRAMED files). - Explicit gating per #827 producer/consumer signal pattern; two briefs gated on substrate, one NOT gated (closed-system). - STOP-AND-ESCALATE includes 'design brief assumptions don't hold' surfacing per feedback_thesis_gate_state_drift. Wave 4 complete. Director's 14-brief queue done; awaiting PM portion (6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4.4 — tighten Slice §3 per PM review on #836 PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b) (authority + tracked debt parallel-rep) as autonomously acceptable contradicts feedback_construction_over_ratchets + feedback_parallel_representation_debt. Tightened: - Shape (a) is the only autonomous worker path. - Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a regen-host-loader sub-lane decision; not authorable without explicit Substrate Manager approval citation in the PR body. - Acceptance bullet requires the approval citation when shape (b) lands. - STOP-AND-ESCALATE rephrased to make this explicit; permanent parallel-representation re-escalates even with manager approval. This preserves shape (a) as autonomous; shape (b) becomes a cross-manager design escalation, not a B4.4 implementation call. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief Cursor review on #836 flagged the Read-first reference to .claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md as machine-specific (outside the repo, not resolvable from a normal clone). Replaced with in-repo prose pointing at the design doc's §Q1-Q3 as canonical authority — the discipline lives there in-repo. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs) Codex flagged: src/v3/std/types.dag does not exist; the canonical authority is at dsl/std/types.dag. Affected briefs (all from R2 spin-up Wave 2 + Wave 3): - r2-substrate-cardinality-for-int-lit-subset.md - r2-substrate-nominal-opaque-for-secret-subset.md - r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs) - r2-modeling-dimensions-phantom-worker.md - r2-modeling-secret-graduation-worker.md feedback_verify_thesis_claims violation on Director-side brief authoring — assumed path without grep. Same family of error as the earlier emit.rs precedent claim. Mass-replaced via perl; verified no remaining stale refs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant Codex BLOCKING on #836: my R2 worker brief gated nested-optional on cardinality refinement substrate, but the design doc verifies v3 is ALREADY past the cardinality bridge — TypeConnective::Cardinality is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is the carrier for Option. The dissolution is an UNGATED implementation via substrate-constructor invariant. feedback_verify_thesis_claims violation again — should have read the design doc fully before assuming the substrate gate. Rewrote brief to match design doc canonical sketch: - Single predicate (cardinality_idempotent_target) owns the rule - Single allocator (alloc_cardinality_decl) is THE substrate-constructor - API closure on TypeConnective::Cardinality payload (modeling-discipline practice 6) — variant cannot be struct-init'd outside the allocator - 3 hand-Rust + ~22 codegen call sites enumerated per design audit - infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as the killer case for generic-instantiation paths - Surface-syntax T?? decision left to worker (Director-lean: silent normalize) Brief now dispatchable immediately, no producer signal needed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment substrate path, but the design doc §4 explicitly recommends totality-by- omission as the Director-actionable path. Predicate-entailment is M+ scope that reopens DB-11's explicitly-closed asymmetric-strip design — design doc explicitly discards it. feedback_verify_thesis_claims violation again — same family as nested- optional reframe. Should have read design doc §4 in full before assuming the path ordering. Rewrote brief to match design doc §4 follow-on shape: - Primary path: per-class totality-by-omission (algebra retype + per- target realization migration). For Int/Int: OrderedRing.div retype at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 / python:486 + python_target.rs:680 helper). - NOT predicate-entailment (out of scope; M+ + DB-11 reopen). - NOT NonZero-typed-input (deferred to separate per-operand-variance substrate brief; STOP-AND-ESCALATE if chosen). - Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i] indexing, quotient, remainder) queue separately per design doc audit. - feedback_totality_by_omission discipline anchor explicit. Brief now matches feedback_totality_by_omission discipline + design doc recommendation. No substrate prerequisite; dispatchable immediately. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a pattern: I authored R2 worker briefs without fully reading each design doc's Director-actionable recommendation. Pre-emptively re-verified unenumerated-effects against design doc §Q6 to catch the same family of error before reviewers do. Findings: brief was substantively close but missing 3 of 8 design-doc reqs: - Req 3: Resource-threading discipline applied to existing primitives - Req 5: reread(key) primitive in std/ as explicit Slice item (was only mentioned in tests) - Req 7: Asymmetric-tightening worked example in PR body Plus: Slice didn't cite the canonical lens path src/v3/lenses/effect_enumeration.dag from design doc. Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6 specifies 4 specific STOPs (path-decision-escalation, pure: Bool carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP) that I had elided. Reframed Slice as 8 numbered reqs matching design doc verbatim; STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs; Acceptance enumerated per req. This is the third reframe in the unhandled-bugs series — same feedback_verify_thesis_claims violation each time. The pattern suggests Director-side R2 brief authoring should ALWAYS read each design doc's §Director-actionable / §Q-recommendation in full first, not assume. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)" listed as a worker-pick option violates THESIS.md substrate-shape lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) are canonical (per #811 thesis additions and #827 PM review); a 7th is a C1 stop signal requiring failed-dissolution evidence + Director substrate-design call, not autonomous worker pick. Removed the "new TypeConnective variant" option; replaced with `inhabits`-edge-shape carrier as third option (audit-time check). The explicit STOP-AND-ESCALATE clause now states: 7th connective is the precondition for failed-dissolution-evidence + Director substrate-design call, not a worker path. feedback_verify_thesis_claims still in play — should have grounded substrate-shape options against the THESIS lock before listing Opaque(T) as worker-autonomous. Pattern continues; reading source-of-truth before authoring options is the discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place) Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter already exist at dag.rs:186, :217 — explicitly authored for the R2 Dimensions consumer per the doc comment at dag.rs:148-160. phantom_unit_mismatch already wired at infer.rs:1057, :1132. The substrate is fully landed; my brief framing it as 'producer sub-lane to land carrier' is wrong on the same feedback_audit_adjacent_authority_first violation that hit nested-optional / unhandled-diagnostic / unenumerated- effects. Reframed the substrate-side brief as no-op / closed-by-audit: - Documents the audit receipt (5 sites confirming substrate exists) - States the lane is closed - Routes T-Modeling Dimensions consumer to dispatch immediately against the existing carrier - Records the lesson: 'always grep substrate before authoring producer briefs' — discipline doesn't end at brief boundaries. Updated r2-modeling-dimensions-phantom-worker.md correspondingly: - Changed gating from 'do not dispatch until producer signal' to 'NOT GATED — dispatch immediately' - Read-first updated with concrete dag.rs/infer.rs cites - Slice §1 changed from 'confirm producer signal' to 'verify substrate at HEAD' - STOP reframed: existing carrier extension would need Substrate Manager call, not autonomous worker pick Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit both verified — no existing substrate (no is_nominal_opaque / MagnitudeBound patterns in dag.rs); both still legitimately producer-side work. Pattern is now four reframes deep on the R2 spin-up wave. The lesson saved is structural: read source-of-truth before authoring options. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority Codex BLOCKING on #836: my new R2 spin-up brief duplicates the existing t-substrate-cardinality-int-lit-worker.md, which carries the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64) stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane). Single-authority violation per INVARIANTS P2. Same feedback_audit_adjacent_authority_first failure as parametric- algebra-for-Dimensions reframe (4 hours ago): assumed substrate authority didn't exist; should have grepped docs/briefs/ before authoring. This is the SECOND R2 spin-up substrate brief closed as redundant — the discipline lesson is structural. Reframed brief as no-op routing doc (documents the audit receipt; routes consumers to the existing authority); updated r2-modeling-int-lit-magnitude-worker.md to cite t-substrate-cardinality-int-lit-worker.md instead. Pattern across the R2 spin-up wave reframes (5 now): 1. nested-optional gating-on-substrate (substrate already past cardinality bridge) 2. unhandled-diagnostic predicate-entailment default (design doc recommends totality-by-omission) 3. unenumerated-effects 8-req design-doc elision 4. parametric-algebra Producer (Declaration.phantom_params already authored explicitly for this consumer) 5. cardinality-for-int-lit…
…gpt-5-5-pro post-merge follow-up) (#1162) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c33: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 second-wave worker-escalation fixes Four substantive worker STOP-AND-ESCALATEs from briefs landed in PR #797. All four worker recommendations correct; each needs a Director call + brief update. ## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate Worker correctly identified that brief req 2 (declared-effect carrier as part of fn type signature, per feedback_no_annotations) requires net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots. Without parser surface, every user function would have declared_effects = [] while inference returns non-empty — lens fires EffectLeakageError everywhere on enable. Worker rejected power-through and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map parser split). Director picked split: - NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface syntax + lookahead + body parser + lowerer extension + exhaustive-match audit + coproduct dissolution receipt. - MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to post-parser-extension scope. Pre-flight check NOT a parser-extension step; STOP if parser sub-lane PR not merged. ## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping Worker found load-bearing evidence at infer.rs:3693-3703: DB-11 deliberately strips refinements at operator dispatch as a designed-in fix for symmetric-operators failure mode. Brief's "attach where b != 0 as a proof for a / b" directly contradicts this design choice. STOP-3 (where-clause conflict with DB-11) is real; STOP-1 (substrate scope) needs net-new substrate (per-operator partiality fact + predicate- entailment check + asymmetric per-operand refinement-honoring) — M+ minimum. ownership_lens precedent in original brief is post-hoc observability, not proof carrier. Worker recommended redirect to design/scoping per nested-optional precedent. Director picked redirect. Brief fully rewritten as design/scoping with four-question structure: (1) DB-11 interaction analysis; (2) substrate proposal for proof-or- totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes with acceptance-theatre risk on user-defined-total-wrapper-only); (4) Director-actionable recommendation. Output is doc PR. ## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C) Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int) with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136 closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b) i128 implementation requires either path 1 (hierarchy refactor — contradicts non-goal) or path 2 (regen lie between substrate and emit — violates discipline). Worker leaned option (C) re-scope: land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke) to a sibling sub-lane that does proper Int128/Word128 substrate work. Director picked option (C). Brief req 1 re-scoped to drop canonical- carrier-widening; lane value comes from range facts + reconciliation narrowing + out-of-range diagnostic against existing i64. Req 4 explicitly deferred with sibling-sub-lane reference. Sibling sub-lane NOT to be authored or implied in this PR; tracked separately. ## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change) Worker correctly STOP'd per the brief's own pre-flight check: parser sub-lane has not landed; SurfaceExpr::Map not on main. Director authorized cross-lane reassignment: wise-boar-480 takes the parser sub-lane (t-substrate-valuebody-map-parser-worker.md) since they already have full investigation context. No brief changes needed; the routing decision is in the dispatch. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope Resolves codex P2 inline at sha e35103fad on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still required widening LiteralBits::Int(i64) to an unbounded carrier and passing the i64::MIN smoke. Internally unsatisfiable. Fix: - Slice section retitled "range facts + reconciliation narrowing (against existing i64 carrier)" with explicit note about the re-scope. - Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly forbids touching LiteralBits::Int shape, dag_scalar_generated.rs regen for that variant, or tokenize i64 parse path. - Slice steps 2-5 reframed: range facts use i64-representable magnitudes; reconciliation narrowing uses existing i64 carrier; diagnostic only for i64-representable out-of-range; smoke tests for req 5 only (req 4 i64::MIN deferred). - Acceptance checklist updated: - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as re-scoped/deferred. - LiteralBits::Int(i64) carrier untouched (no widening; no parallel; no shape change). - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference. - STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the carrier" — explicit STOP if execution surfaces range-fact narrowing requiring carrier-widening; that's the boundary the re-scope drew; belongs in sibling Int128/Word128 sub-lane. Brief now consistently treats carrier-widening as out-of-scope across all sections. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty Resolves codex BLOCKING #1 at sha e35103fa on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier but req 2 required range facts using "the SAME magnitude carrier as req 1" — meaning i64-typed range bounds. u64's max (2^64-1) doesn't fit in i64; range fact for u64 would have to truncate, omit, or mirror in Rust (representation drift). All three options violate fail-closed declared-facts discipline (P1 / P3). Fix: - Req 2 rewritten to specify String-decimal representation: range_min_inclusive: String + range_max_inclusive: String fields on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127" for i8; "0"/"18446744073709551615" for u64). - Explicit reasoning why String-decimal: u64's max doesn't fit in i64; binding range bounds to literal carrier forces truncation/ omission/mirror-drift; all violate fail-closed declared-facts discipline. - Bridge framing: String-decimal is pending the sibling Int128/ Word128 sub-lane; both range bounds and literal payload migrate to typed carrier when that lands. - Req 3 updated for String-decimal comparison semantics: reconciliation parses both bounds and literal magnitude into a common comparison space (i128 host comparison primitive — host narrowing, NOT carrier widening). Bounded by what the i64-typed literal can express; any i64-representable literal compares against any width's String-decimal bound. Carrier discipline preserved. Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral) is sha-stale — already resolved at 3e142d169. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback). Real residual: req 2 specifies String-decimal range bounds (to cover u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" / "i64-representable magnitudes" for the range facts. Two incompatible authorities for the same range-fact shape — would let a worker satisfy the slice while truncating/omitting u64 bounds (P3 fail-closed violation). Fix: - Line 31 (req 1 re-scope clarification): updated to explicitly state "range facts (req 2) use String-decimal representation (width- independent; covers u64::MAX which doesn't fit in i64)". Distinguished literal *payload* (stays i64) from range-bound *representation* (String) — both serve req 1's "no carrier widening" boundary. - Line 44 (slice step 2): updated from "Range bounds use i64- representable magnitudes" to "Range bounds use String-decimal representation per req 2" with concrete example (u64 bounds). - Acceptance bullet: updated from "Range facts on integer algebras (substrate-declared, not Rust-mirrored)" to add "using String-decimal representation ... width-independent; u64 bounds expressible without truncation." The brief now consistently treats range bounds as String-decimal across req 2, req 3, slice, acceptance, and the req 1 clarification — no remaining authorities saying i64-typed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing User + PM exchange 2026-04-25 surfaced that the in-flight effects chain was importing wrong assumptions from external languages (declared-effects-as-annotation + lens-vs-declaration check). Right framing under gunbc's closed-system discipline is parallel to complexity: every effect derives structurally from the composition of typed primitive operations; nothing can hide because there's no escape hatch; nothing needs annotation because the structure IS the registry. Four doc-only actions: 1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md. Frames the closed-system answer with PM's 5-behavior synergy table (Value/Transform/Branch/Loop/Bind as universal compositional-fold pattern). Four worked examples; aggressive reading on redundancy (compile-error-by-construction via referential-transparency proof; reread() primitive for legitimate cases); implementation-brief shape in §Q6. 2. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md. 3. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md. Notes Fn→Arrow refactor brief stays dispatchable as independent value. 4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by- construction framing replaces lens-detection framing. Memory file feedback_closed_system_effects.md saved separately; cross-link added to feedback_construction_over_ratchets.md. Net cost: doc-level cleanup. Zero substrate code rework. Foundation (OperationEffect + service-call infrastructure + 5-behavior substrate) already exists. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect Per PM convergence review on #808 + user's deeper 2026-04-25 framing: the closed-system framing landed in #808 retired the user-facing annotation but kept OperationEffect taxonomy as substrate-level tagging. User's deeper framing: the taxonomy ITSELF is parallel-representation — operations are intrinsically read-shaped or write-shaped via their TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns- derived-value-only → read). Tagging operations with Read | Upsert | Create | Append | Delete names what the structure already says. Three changes: 1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as normalized view, or retire as parallel-representation?" - Two paths: (i) tags derived from signature shape (acceptable normalized view) vs (ii) tags declared per-primitive (parallel- representation; retire). - Audit-as-existence-check (Q4 req 2 reframed): all effectful primitives derive cleanly from signature shape → path (i); any primitive needs hand-declared tag → path (ii) by existence proof. - Director default: path (ii). Logging primitives that return Unit are likely the audit's existence-proof. - Two design-question resolutions: (a) external effects not in return type → resource-threading discipline (typed param returned modified, IO-monad-without-the-monad pattern); (b) transactional grouping → derived structural fact from Bind composition + typed transaction primitives. 2. Q4 reqs revised: req 2 from "tag every primitive with explicit OperationEffect signature" to "audit-as-existence-check that every primitive's type signature derives the right effect classification"; req 3 added (resource-threading discipline); req 6 added (transactional-pattern lens). Req 1 (effects lens) anchors on operation type-signature shape, not on hand-declared tags. 3. THESIS:345-347 amendment strengthened — "operations are intrinsically read-shaped or write-shaped via their type-signature shape; consumers walk the signatures directly; there is no parallel taxonomy or annotation layer to declare or maintain. Tracking effects as a separate enumerated concept IS the bug pattern, dissolved by construction." Plus references to resource-threading discipline + transactional grouping as derived structural fact. Memory file feedback_closed_system_effects.md updated to reflect the deeper framing (type-signature-shape, not taxonomy-tagging) + resource-threading discipline section + transactional-patterns section. Net cost: doc-only delta on top of #808. Substrate retirement (OperationEffect enum + derive_op_effect + idempotency.dag re-anchor) deferred to the audit-as-existence-check phase of the implementation brief; surfaced as Q5.5 OPEN CALL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage Resolves codex BLOCKING at sha d49ce79a on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real: the prior text claimed service primitives "already carry typed effect signatures" presenting future audit-state as current substrate fact (P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the OperationEffect line but left a parallel over-claim on the new "signature-shape coverage" framing. Fix: Q4 substrate-state listing rewritten to honestly distinguish: - Live: Behavior enum + substrate foundation (the principle that operations should carry signature shape). - Incomplete: signature-shape coverage across actual primitives. HTTP-derived primitives carry implicit shape via derive_op_effect's method-table; logging/mutation primitives that return Unit or don't thread their target resource do NOT carry the structural shape that would express read-vs-write. Achieving full coverage is required work under reqs 2 + 3, not a current fact. - Pending audit-as-existence-check: OperationEffect + derive_op_effect (path (i) vs (ii) per Q5.5). Honest live-state callout added explicitly: "the closed-system FOUNDATION (5 behaviors + DAG substrate + the principle that operations should carry signature-shape) is live. The IMPLEMENTATION COVERAGE across all effectful primitives is partial. Req 2 + req 3 are the work that closes the gap." Brief now distinguishes principle-is-live (foundation) from coverage-is-partial (audit work) without conflating them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim Per PM follow-up review on #808 + user's stronger discipline framing ("substrate must make bypass structurally impossible at every layer of the transport stack"): the closed-system claim is honest only when typed primitives ARE the path. Today two structural holes exist where bypasses sidestep the typed-primitive substrate. Both surfaced explicitly as Q4.5 pre-conditions — load-bearing for the lens's coverage claim. Three changes: 1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed- system claim)" inserted between Q4 and Q5: P1 — Extdeps typed-primitive consumption structurally enforced. Substrate must make `messages: Json` impossible to declare in service definitions; typed `LlmMessage` / `ContentBlock` / `GitHubAuthToken`-with-full-scopes are the only path. Tracked debt at ROADMAP.md:153-154 (LLM provider flattening) + `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded). Required prereq for full lens coverage; lens can land first + surface structural-coverage-gap diagnostics on bypass surfaces so the gap becomes visible rather than silent. P2 — `ExecuteCommand` fully materialized as typed runner primitive. TESTING.md (post-#782) committed to 0-residual but ExecuteCommand isn't fully materialized; deleting Rust boundary tests creates verification gap. Already named under PB-Runtime in Zero-Floor; signal pending. Pre-requisite for ANY Rust boundary-test deletion. 2. Old leftover duplicate Q5 section deleted (artifact from prior Q5/Q5.5 reshape; second copy of asymmetric-tightening text was in the file alongside the earlier Q5 instance). 3. Worker-discretion-vs-Director-call section in Q4.5: lens implementation worker dispatchable now (reports gaps as findings); P1 closure is substantive substrate work touching extdeps (dedicated lane); P2 closure is PB-Runtime (signal pending). Net: design doc now honestly distinguishes principle-is-live (Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs named explicitly). The closed-system claim has explicit pre- conditions documented; implementation brief discovers them as known dependencies, not as STOP-AND-ESCALATEs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two real residuals after the Q5.5 reframe: 1. Q6's reqs/STOPs/acceptance still framed under path (i) — said "audit + tag std/ primitives — every effectful primitive carries an explicit OperationEffect signature." Directly contradicted Q4 (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment ("there is no parallel taxonomy to declare or maintain"). Worker reading Q6 in isolation would author the retracted shape. 2. Capacity / sequencing table line about "audit lane (tag std/ primitives with effect signatures)" carried the same stale framing. 3. Q6 STOP "primitive performing side effects without an OperationEffect tag" assumed tag-as-authority; under path (ii) the STOP shape is "primitive whose signature doesn't structurally reveal its effect." Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale (already fixed at f073aa95e Q4.5 commit). ## Q6 fixes - Reqs renumbered + reframed: - Req 1 anchors on operation type-signature shape (not hand-declared OperationEffect tags); composition reads from signature shape per Q2 table. - Req 2 changed from "audit + tag every primitive" to "audit-as-existence-check" — verify signature-shape coverage; ANY primitive needing a hand-declared tag IS the existence-proof for path (ii) retirement. - Req 3 added: resource-threading discipline applied to existing primitives (logging that returns Unit gets reshaped per audit). - Req 6 added: transactional-pattern lens (Bind composition + Transaction → Transaction'). - Req 7 added: asymmetric-tightening worked example in PR body (per claude review observation; the one place declaration-shaped surface re-enters). - Req 8 (was 5): tests now reference signature-shape derivation explicitly, not tag lookup. - STOPs reframed: - "OperationEffect retirement decision" — audit produces path (i) vs (ii) verdict; substrate retirement is its own dedicated sub-lane; this lane does NOT absorb it. - Pure/impure carrier STOP notes that "pure" should also derive from signature shape (pure functions don't return modified resources) — so the STOP itself may dissolve under further design. - Q4.5 P1 explicitly NOT a STOP — lens reporting structural- coverage-gap on extdeps bypass surfaces is the lens delivering its foundation-gap-visibility value. - Q4.5 P2 explicitly independent — lens doesn't depend on ExecuteCommand materialization. - Acceptance extended: lens reports gap diagnostics on P1 bypass surfaces; audit produces existence-proof verdict for Director re-decision; asymmetric-tightening worked example in PR body. ## Capacity / sequencing table Replaced "1 audit lane (tag std/ primitives with effect signatures)" with "1 audit-as-existence-check lane (verify primitives' signature- shape coverage; NOT 'tag every primitive') — produces the path (i) vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2 prereq lanes to the net summary. Closing line: "The taxonomy- retirement scope (substrate-side) is not in this lane — it's surfaced by audit and routed to dedicated retirement lane if path (ii) wins." Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity table. Worker reading Q6 in isolation now sees path-(ii)-default framing matching Q4 + Q5.5 + THESIS amendment. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792 Resolves codex inline BLOCKING at sha 191be310 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150. Real: my Q4.5 P2 framing described ExecuteCommand as still NotYetImplemented (M1.5 allowlist + Rust TestRunner returning NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand extension before this PR's authoring. TESTING.md:195 capability-state callout confirms: - Rust TestRunner + M1.5 testgen harness share one std::process path for arbitrary command + args + expect_exit_code. - M1.5 allowlist + fail-closed panic retired. - Distinguishable ClaimResult::Fail messages for spawn / timeout / policy / exit-mismatch. - Linux unshare(1) namespace isolation on host-allowing systems. - T-PB-B-1 boundary migration example landed. Fix: P2 section rewritten: - Header retitled "ExecuteCommand runner primitive: LANDED (PR #792); residual is bulk-migration." - Status update naming PR #792 + the post-#792 capability state (allowlist retired, etc.). - Honest acknowledgement: "My earlier P2 framing was stale." - Residual narrowed to bulk-migration of existing Rust Command::new boundary tests (tracked as ROADMAP residual, not lens prereq). - Sequencing reframed: P2 was always orthogonal to the effects lens itself; bulk migration proceeds at its own pace; lens not blocked. Q4.5 footer updated: - "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via #792; only consumer-side bulk migration remains)" - Worker-discretion-vs-Director-call P2 line updated: "runner primitive landed; only consumer-side bulk migration remains; tracked as ROADMAP residual, independent of the lens." Q6 STOP for P2 updated: - "the lens itself doesn't depend on P2; only TESTING.md's 0-residual claim does" → "runner primitive landed via PR #792 (post-Q4.5- authoring update). The lens itself never depended on P2; bulk consumer migration is residual ROADMAP work and remains independent of this lane." Brief now reflects live state. The closed-system claim's prereq landscape is honest: - P1 (extdeps typed-primitive consumption): real prereq, tracked debt at ROADMAP:153-154. - P2 (ExecuteCommand runner): satisfied via #792; bulk migration is consumer-side residual, not foundation work. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale Resolves codex non-blocking finding at sha bcac41bb on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real residual: capacity-table line still listed P2 as "`ExecuteCommand` materialization" prereq + framed both P1 and P2 as "pre-existing tracked-debt" — but my prior 57a9b1318 fix established that PR #792 already landed the runner primitive, so P2 is no longer a materialization prereq. Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq) from P2 (residual, not prereq): - P1: extdeps typed-primitive consumption — pre-existing tracked debt at ROADMAP:153-154; load-bearing for the lens's full-coverage claim. - P2: ExecuteCommand runner primitive landed via PR #792; only consumer-side bulk migration of existing Rust Command::new boundary tests remains (tracked as ROADMAP residual, independent of the lens; not a materialization prereq). Brief now consistently treats P2 as bulk-migration-residual across: - §Q4.5 P2 section header (LANDED via PR #792; residual is bulk-migration). - §Q4.5 footer (P2: runner primitive landed; only consumer-side bulk migration remains). - Q6 STOP for P2 (runner primitive landed; bulk migration is residual ROADMAP work). - §Capacity / sequencing impact (P2 as residual, not prereq). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349 Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated target-grounding prose; the matching extdeps typed-primitive bypass entries (LLM service flattening, GitHub auth model bypass) live at ROADMAP.md:348-349. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix third stale ROADMAP citation at line 271 Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence at line 271 in the §Q4.5 capacity table. Now consistent with lines 139 and 173 (ROADMAP.md:348-349). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity Codex flagged 'Effect-signature tagging on std/ primitives' as potentially contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240) already explicitly say 'NOT tag every primitive' — but the cross-manager line used sloppy wording. Reworded to make explicit that the audit walks signature shape; no parallel tag added. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5 - B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound - B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause - B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge - B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation) B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25): language vocabulary is primitives + namespacing only; no escape syntax; the §0 sentinels are the compiler itself failing to use primitives + namespacing internally. Eight surface sites dissolve via four substrate carriers (DeclarationRef, structural fold-shape carrier, structural emit-helper carrier, structural extdeps-fixture-set carrier). B1-B3 are independent; dispatch in parallel. B4 is sequential program work; sub-brief dispatch (B4.1-B4.12) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — drop incoherent inner-fallback non-goal Codex P2: the non-goal line excluding the inner declaration().name unwrap_or_else fallback contradicted Slice step 2, which replaces the whole chain with let-Some-else-return. Both fallbacks are in scope by construction; remove the contradictory non-goal. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives PM REQUEST_CHANGES: §Frame listed '4 type connectives (Conjunction | Disjunction | Cardinality | Bit)' which contradicted the canonical thesis source. Replaced with the canonical 6 (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary closes here'. Also removed 'typed substrate carriers' from the vocabulary list — substrate carriers are defined using the vocabulary, not part of it. Added a clarifying note that B4's carriers (DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are typed declarations composed from the vocabulary, not vocabulary extensions. Per feedback_verify_thesis_claims: brief framings citing thesis structure must ground in the canonical source. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of naming the live substrate authority. Two coordinated fixes: 1. §Read first cites src/v3/std/substrate.dag (live .dag substrate authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel meta-type — already exists with consumers in verification.dag, emit_model.dag, python.dag). 2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing DeclarationRef'. The work is consumer migration + any role-extension layer the audit reveals, NOT designing or landing the carrier. Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers) keep their 'new' framing but explicitly require sub-briefs to grep src/v3/std/ + src/v3/spec/ for existing authority before authoring 'design and land' framing — per feedback_verify_thesis_claims + feedback_emitter_workaround_is_gap_symptom. Acceptance + sub-brief dispatch order updated to reflect B4.1's consumer-migration shape. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — tighten Phase 1 umbrella sentence The umbrella 'Land the typed carriers into src/v3/std/' framing was stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced with audit-first wording that covers both the consume-existing case (#1) and the design-and-land case (#2-#4 if their audits show real gaps). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands' which conflicted with the post-reframe reality that B4.1 consumes the existing DeclarationRef. Updated to 'consumes or lands' with explicit existing-authority citation and audit-pending caveat for B4.2-B4.4. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — soften regression-test requirement (3 worker bounces) Three consecutive B1 worker dispatches (zesty-crane-890 cursor → valiant-boar-498 codex → cool-lynx-395 cursor) archived without opening a PR. Likely friction point: brief Slice step 4 asks for a unit test that constructs a Dag with an orphan variant declaration, but emit.rs has zero existing #[test] precedent — emit testing happens via integration fixtures. Workers see 'build novel test harness' inside what's billed as an S-scope fix and bounce. Per feedback_construction_over_ratchets: when a brief has friction, fix the brief, don't ratchet the worker. Softened step 4 + acceptance: regression test stays optional. If test setup requires novel scaffolding, route the gap to follow-up. The structural fail-closed at step 2 is the load-bearing change. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description' is too weak; PR descriptions don't survive squash-merge cleanly. Two coordinated edits: 1. Slice step 4 — explicit substrate-signal framing: skipped test means emit-side hermetic-unit-test infrastructure is the missing substrate (feedback_emitter_workaround_is_gap_symptom). 2. Acceptance — require ROADMAP debt row (new or existing) with named dissolution trigger, referenced in PR body. Converts the skip from PR-local note (transient) into tracked debt (durable, dispatchable). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124 Codex BLOCKING: my earlier softening claimed emit.rs had no #[test] precedent — wrong. The module has #[cfg(test)] mod tests at line 3124 with 12+ tests using compile_to_dag(source, filename) as harness (e.g., go_struct_fields_render_with_separators :3143, shared_walk_to_disj_finds_match_scrutinee_sum_type :3195). This is a feedback_verify_thesis_claims violation on Director-side brief authoring — claim made without grep verification. Fix: restore step 4 as required, with explicit precedent citation. Worker constructs the failure case via the existing harness (direct Dag, fixture string, or BranchPattern exercise; worker's call on cleanest path). STOP-AND-ESCALATE only if construction proves materially harder than precedent suggests, in which case that escalation surfaces a real substrate gap and warrants ROADMAP debt — but the default is 'add the test.' Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites) Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded to 'several using compile_to_dag'. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this is Wave 1 of Director's 14-brief authoring queue, covering B4 program internals. Authored: - b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) — replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag") fold-skip with structural template-formal carrier; mandatory authority audit per feedback_audit_adjacent_authority_first. - b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) — replaces §0.6 emit.rs bind/branch.span.file equality with typed BindEmitParticipation/BranchEmitParticipation roles populated at lowering; aligned with #824 worker's in-flight implementation shape. - b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4 of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with typed substrate authority; explicit pre-promotion-constraint disposition (single-authority vs authority+tracked-debt) addresses parallel-representation risk surfaced on #825. - b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) — names B4.5-B4.12 Phase 2 sites with carrier dependencies, cross-program coordination notes, and skeleton-brief template; full per-site briefs author at dispatch time per #827's Substrate Manager ownership. Cross-cutting discipline applied per inbox #828 reply: - feedback_audit_adjacent_authority_first (mandatory grep before design) - feedback_no_textual_enforcement_bridges (no replacement sentinels) - feedback_parallel_representation_debt (explicit if shape (b)) - feedback_construction_over_ratchets (no parity-by-runtime as primary) - feedback_coproduct_dissolution (receipts for new variants) Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3) Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue. Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by Modeling Manager's Wave 3 worker briefs (gated on these landing). Authored: - r2-substrate-cardinality-for-int-lit-subset.md (M) — produces magnitude carrier consumed by T-Modeling int-lit. Coordinates with PR #806's prior cardinality work; mandatory authority audit guards against #796's rejected IntLiteralMagnitude shape resurfacing. Open design questions: magnitude representation, reconciliation narrowing point, i64::MIN representability. - r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces nominal-opacity carrier consumed by T-Modeling Secret<T>. Open design questions: carrier shape (flag/connective/sealed-accessor), generic-walk discipline, accessor gating. - r2-substrate-parametric-algebra-for-dimensions-subset.md (M) — produces phantom-parameter carrier consumed by T-Modeling Dimension<Carrier>. Open design questions: carrier shape, type-equivalence rule, algebra-method dispatch, lifting/coercion. All three: - Scoped narrowly to their paired R2 consumer; not full substrate-capability lanes. - Mandatory pre-author authority audit per feedback_audit_adjacent_authority_first. - Cross-program readiness signal pattern from #827's manager rework. - Coproduct dissolution receipts required for any new variants. - Open design questions surfaced explicitly so Substrate Manager (or Director pre-spin-up) can resolve at dispatch time. Wave 3 (T-Modeling worker briefs × 4) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4) Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue. Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each gated on a Substrate Manager readiness signal (Wave 2 producers). Authored: - r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2 cardinality-for-int-lit; moves narrowing from tokenizer to reconciliation; MagnitudeOutOfRange diagnostic per C-8. - r2-modeling-secret-graduation-worker.md — gated on Wave 2 nominal-opaque-for-Secret; authors Secret<T> + gated accessors (redact, compare_in_constant_time); C-8 diagnostic on non-gated access; signals Impossible-Bugs Manager on close (thesis claim covered). - r2-modeling-dimensions-phantom-worker.md — gated on Wave 2 parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier> + core SI base units + algebra-method dispatch; cross-dimension arithmetic produces typed diagnostic; signals Impossible-Bugs Manager (thesis claim). - r2-modeling-tokenizer-charclass-phase2-worker.md — gated on T-Substrate ValueBody-list/sum (#790); migrates tokenizer consumers to Char/List<Char>/CharClass canonical types; sibling consumer to Grounding Manager's Engine sharpened-(b). All four: - Explicit gating: 'do not dispatch until producer signal posts.' - Producer/consumer signal pattern from #827. - Cross-program signals to R2 Release Manager (Goal 2 closure) and Impossible-Bugs Manager (thesis-claim coverage). - Spoofing regression tests: discipline anchor against feedback_no_textual_enforcement_bridges. Wave 4 (T-ImpossibleBugs worker briefs × 3) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3) Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue. Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes, consuming the existing design/scoping briefs as authority. Authored: - r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on cardinality refinement substrate (T-Substrate territory adjacent to int-lit / DB-11 alias-where). Implementation: structural normalize of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T?? worker decision (reject vs normalize). Cites t-impossiblebugs-nested-optional-flatten-design.md as authority. - r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated on Tier 2 substrate (predicate-entailment infrastructure; distinct from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes predicate entailment, (b) feedback_totality_by_omission dissolves partial primitives, (c) park. Worker decides at audit time. Cites t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority. - r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate prerequisite per closed-system framing in design doc (#808). Audit- as-existence-check + lens implementation as compositional fold over 5 behaviors; redundancy detection compile-error via referential transparency + reread() escape hatch; path (i/ii) decision on OperationEffect taxonomy retain-vs-retire (default retire). Cites design doc #808 as authority. Cross-cutting: - Each cites prior design/scoping brief as authority (the existing *-design.md / *-worker.md REFRAMED files). - Explicit gating per #827 producer/consumer signal pattern; two briefs gated on substrate, one NOT gated (closed-system). - STOP-AND-ESCALATE includes 'design brief assumptions don't hold' surfacing per feedback_thesis_gate_state_drift. Wave 4 complete. Director's 14-brief queue done; awaiting PM portion (6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4.4 — tighten Slice §3 per PM review on #836 PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b) (authority + tracked debt parallel-rep) as autonomously acceptable contradicts feedback_construction_over_ratchets + feedback_parallel_representation_debt. Tightened: - Shape (a) is the only autonomous worker path. - Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a regen-host-loader sub-lane decision; not authorable without explicit Substrate Manager approval citation in the PR body. - Acceptance bullet requires the approval citation when shape (b) lands. - STOP-AND-ESCALATE rephrased to make this explicit; permanent parallel-representation re-escalates even with manager approval. This preserves shape (a) as autonomous; shape (b) becomes a cross-manager design escalation, not a B4.4 implementation call. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief Cursor review on #836 flagged the Read-first reference to .claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md as machine-specific (outside the repo, not resolvable from a normal clone). Replaced with in-repo prose pointing at the design doc's §Q1-Q3 as canonical authority — the discipline lives there in-repo. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs) Codex flagged: src/v3/std/types.dag does not exist; the canonical authority is at dsl/std/types.dag. Affected briefs (all from R2 spin-up Wave 2 + Wave 3): - r2-substrate-cardinality-for-int-lit-subset.md - r2-substrate-nominal-opaque-for-secret-subset.md - r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs) - r2-modeling-dimensions-phantom-worker.md - r2-modeling-secret-graduation-worker.md feedback_verify_thesis_claims violation on Director-side brief authoring — assumed path without grep. Same family of error as the earlier emit.rs precedent claim. Mass-replaced via perl; verified no remaining stale refs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant Codex BLOCKING on #836: my R2 worker brief gated nested-optional on cardinality refinement substrate, but the design doc verifies v3 is ALREADY past the cardinality bridge — TypeConnective::Cardinality is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is the carrier for Option. The dissolution is an UNGATED implementation via substrate-constructor invariant. feedback_verify_thesis_claims violation again — should have read the design doc fully before assuming the substrate gate. Rewrote brief to match design doc canonical sketch: - Single predicate (cardinality_idempotent_target) owns the rule - Single allocator (alloc_cardinality_decl) is THE substrate-constructor - API closure on TypeConnective::Cardinality payload (modeling-discipline practice 6) — variant cannot be struct-init'd outside the allocator - 3 hand-Rust + ~22 codegen call sites enumerated per design audit - infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as the killer case for generic-instantiation paths - Surface-syntax T?? decision left to worker (Director-lean: silent normalize) Brief now dispatchable immediately, no producer signal needed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment substrate path, but the design doc §4 explicitly recommends totality-by- omission as the Director-actionable path. Predicate-entailment is M+ scope that reopens DB-11's explicitly-closed asymmetric-strip design — design doc explicitly discards it. feedback_verify_thesis_claims violation again — same family as nested- optional reframe. Should have read design doc §4 in full before assuming the path ordering. Rewrote brief to match design doc §4 follow-on shape: - Primary path: per-class totality-by-omission (algebra retype + per- target realization migration). For Int/Int: OrderedRing.div retype at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 / python:486 + python_target.rs:680 helper). - NOT predicate-entailment (out of scope; M+ + DB-11 reopen). - NOT NonZero-typed-input (deferred to separate per-operand-variance substrate brief; STOP-AND-ESCALATE if chosen). - Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i] indexing, quotient, remainder) queue separately per design doc audit. - feedback_totality_by_omission discipline anchor explicit. Brief now matches feedback_totality_by_omission discipline + design doc recommendation. No substrate prerequisite; dispatchable immediately. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a pattern: I authored R2 worker briefs without fully reading each design doc's Director-actionable recommendation. Pre-emptively re-verified unenumerated-effects against design doc §Q6 to catch the same family of error before reviewers do. Findings: brief was substantively close but missing 3 of 8 design-doc reqs: - Req 3: Resource-threading discipline applied to existing primitives - Req 5: reread(key) primitive in std/ as explicit Slice item (was only mentioned in tests) - Req 7: Asymmetric-tightening worked example in PR body Plus: Slice didn't cite the canonical lens path src/v3/lenses/effect_enumeration.dag from design doc. Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6 specifies 4 specific STOPs (path-decision-escalation, pure: Bool carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP) that I had elided. Reframed Slice as 8 numbered reqs matching design doc verbatim; STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs; Acceptance enumerated per req. This is the third reframe in the unhandled-bugs series — same feedback_verify_thesis_claims violation each time. The pattern suggests Director-side R2 brief authoring should ALWAYS read each design doc's §Director-actionable / §Q-recommendation in full first, not assume. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)" listed as a worker-pick option violates THESIS.md substrate-shape lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) are canonical (per #811 thesis additions and #827 PM review); a 7th is a C1 stop signal requiring failed-dissolution evidence + Director substrate-design call, not autonomous worker pick. Removed the "new TypeConnective variant" option; replaced with `inhabits`-edge-shape carrier as third option (audit-time check). The explicit STOP-AND-ESCALATE clause now states: 7th connective is the precondition for failed-dissolution-evidence + Director substrate-design call, not a worker path. feedback_verify_thesis_claims still in play — should have grounded substrate-shape options against the THESIS lock before listing Opaque(T) as worker-autonomous. Pattern continues; reading source-of-truth before authoring options is the discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place) Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter already exist at dag.rs:186, :217 — explicitly authored for the R2 Dimensions consumer per the doc comment at dag.rs:148-160. phantom_unit_mismatch already wired at infer.rs:1057, :1132. The substrate is fully landed; my brief framing it as 'producer sub-lane to land carrier' is wrong on the same feedback_audit_adjacent_authority_first violation that hit nested-optional / unhandled-diagnostic / unenumerated- effects. Reframed the substrate-side brief as no-op / closed-by-audit: - Documents the audit receipt (5 sites confirming substrate exists) - States the lane is closed - Routes T-Modeling Dimensions consumer to dispatch immediately against the existing carrier - Records the lesson: 'always grep substrate before authoring producer briefs' — discipline doesn't end at brief boundaries. Updated r2-modeling-dimensions-phantom-worker.md correspondingly: - Changed gating from 'do not dispatch until producer signal' to 'NOT GATED — dispatch immediately' - Read-first updated with concrete dag.rs/infer.rs cites - Slice §1 changed from 'confirm producer signal' to 'verify substrate at HEAD' - STOP reframed: existing carrier extension would need Substrate Manager call, not autonomous worker pick Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit both verified — no existing substrate (no is_nominal_opaque / MagnitudeBound patterns in dag.rs); both still legitimately producer-side work. Pattern is now four reframes deep on the R2 spin-up wave. The lesson saved is structural: read source-of-truth before authoring options. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority Codex BLOCKING on #836: my new R2 spin-up brief duplicates the existing t-substrate-cardinality-int-lit-worker.md, which carries the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64) stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane). Single-authority violation per INVARIANTS P2. Same feedback_audit_adjacent_authority_first failure as parametric- algebra-for-Dimensions reframe (4 hours ago): assumed substrate authority didn't exist; should have grepped docs/briefs/ before authoring. This is the SECOND R2 spin-up substrate brief closed as redundant — the discipline lesson is structural. Reframed brief as no-op routing doc (documents the audit receipt; routes consumers to the existing authority); updated r2-modeling-int-lit-magnitude-worker.md to cite t-substrate-cardinality-int-lit-worker.md instead. Pattern across the R2 spin-up wave reframes (5 now): 1. nested-optional gating-on-substrate (substrate already past cardinality bridge) 2. unhandled-diagnostic predicate-entailment default (design doc recommends totality-by-omission) 3. unenumerated-effects 8-req design-doc elision 4. parametric-algebra Producer (Declaration.phantom_params already authored explicitly for this consumer) 5. cardinality-for-int-lit Producer (existing brief …
… + bin-shim emit pattern) (#1176) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c33: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 second-wave worker-escalation fixes Four substantive worker STOP-AND-ESCALATEs from briefs landed in PR #797. All four worker recommendations correct; each needs a Director call + brief update. ## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate Worker correctly identified that brief req 2 (declared-effect carrier as part of fn type signature, per feedback_no_annotations) requires net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots. Without parser surface, every user function would have declared_effects = [] while inference returns non-empty — lens fires EffectLeakageError everywhere on enable. Worker rejected power-through and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map parser split). Director picked split: - NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface syntax + lookahead + body parser + lowerer extension + exhaustive-match audit + coproduct dissolution receipt. - MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to post-parser-extension scope. Pre-flight check NOT a parser-extension step; STOP if parser sub-lane PR not merged. ## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping Worker found load-bearing evidence at infer.rs:3693-3703: DB-11 deliberately strips refinements at operator dispatch as a designed-in fix for symmetric-operators failure mode. Brief's "attach where b != 0 as a proof for a / b" directly contradicts this design choice. STOP-3 (where-clause conflict with DB-11) is real; STOP-1 (substrate scope) needs net-new substrate (per-operator partiality fact + predicate- entailment check + asymmetric per-operand refinement-honoring) — M+ minimum. ownership_lens precedent in original brief is post-hoc observability, not proof carrier. Worker recommended redirect to design/scoping per nested-optional precedent. Director picked redirect. Brief fully rewritten as design/scoping with four-question structure: (1) DB-11 interaction analysis; (2) substrate proposal for proof-or- totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes with acceptance-theatre risk on user-defined-total-wrapper-only); (4) Director-actionable recommendation. Output is doc PR. ## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C) Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int) with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136 closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b) i128 implementation requires either path 1 (hierarchy refactor — contradicts non-goal) or path 2 (regen lie between substrate and emit — violates discipline). Worker leaned option (C) re-scope: land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke) to a sibling sub-lane that does proper Int128/Word128 substrate work. Director picked option (C). Brief req 1 re-scoped to drop canonical- carrier-widening; lane value comes from range facts + reconciliation narrowing + out-of-range diagnostic against existing i64. Req 4 explicitly deferred with sibling-sub-lane reference. Sibling sub-lane NOT to be authored or implied in this PR; tracked separately. ## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change) Worker correctly STOP'd per the brief's own pre-flight check: parser sub-lane has not landed; SurfaceExpr::Map not on main. Director authorized cross-lane reassignment: wise-boar-480 takes the parser sub-lane (t-substrate-valuebody-map-parser-worker.md) since they already have full investigation context. No brief changes needed; the routing decision is in the dispatch. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope Resolves codex P2 inline at sha e35103fad on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still required widening LiteralBits::Int(i64) to an unbounded carrier and passing the i64::MIN smoke. Internally unsatisfiable. Fix: - Slice section retitled "range facts + reconciliation narrowing (against existing i64 carrier)" with explicit note about the re-scope. - Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly forbids touching LiteralBits::Int shape, dag_scalar_generated.rs regen for that variant, or tokenize i64 parse path. - Slice steps 2-5 reframed: range facts use i64-representable magnitudes; reconciliation narrowing uses existing i64 carrier; diagnostic only for i64-representable out-of-range; smoke tests for req 5 only (req 4 i64::MIN deferred). - Acceptance checklist updated: - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as re-scoped/deferred. - LiteralBits::Int(i64) carrier untouched (no widening; no parallel; no shape change). - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference. - STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the carrier" — explicit STOP if execution surfaces range-fact narrowing requiring carrier-widening; that's the boundary the re-scope drew; belongs in sibling Int128/Word128 sub-lane. Brief now consistently treats carrier-widening as out-of-scope across all sections. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty Resolves codex BLOCKING #1 at sha e35103fa on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier but req 2 required range facts using "the SAME magnitude carrier as req 1" — meaning i64-typed range bounds. u64's max (2^64-1) doesn't fit in i64; range fact for u64 would have to truncate, omit, or mirror in Rust (representation drift). All three options violate fail-closed declared-facts discipline (P1 / P3). Fix: - Req 2 rewritten to specify String-decimal representation: range_min_inclusive: String + range_max_inclusive: String fields on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127" for i8; "0"/"18446744073709551615" for u64). - Explicit reasoning why String-decimal: u64's max doesn't fit in i64; binding range bounds to literal carrier forces truncation/ omission/mirror-drift; all violate fail-closed declared-facts discipline. - Bridge framing: String-decimal is pending the sibling Int128/ Word128 sub-lane; both range bounds and literal payload migrate to typed carrier when that lands. - Req 3 updated for String-decimal comparison semantics: reconciliation parses both bounds and literal magnitude into a common comparison space (i128 host comparison primitive — host narrowing, NOT carrier widening). Bounded by what the i64-typed literal can express; any i64-representable literal compares against any width's String-decimal bound. Carrier discipline preserved. Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral) is sha-stale — already resolved at 3e142d169. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback). Real residual: req 2 specifies String-decimal range bounds (to cover u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" / "i64-representable magnitudes" for the range facts. Two incompatible authorities for the same range-fact shape — would let a worker satisfy the slice while truncating/omitting u64 bounds (P3 fail-closed violation). Fix: - Line 31 (req 1 re-scope clarification): updated to explicitly state "range facts (req 2) use String-decimal representation (width- independent; covers u64::MAX which doesn't fit in i64)". Distinguished literal *payload* (stays i64) from range-bound *representation* (String) — both serve req 1's "no carrier widening" boundary. - Line 44 (slice step 2): updated from "Range bounds use i64- representable magnitudes" to "Range bounds use String-decimal representation per req 2" with concrete example (u64 bounds). - Acceptance bullet: updated from "Range facts on integer algebras (substrate-declared, not Rust-mirrored)" to add "using String-decimal representation ... width-independent; u64 bounds expressible without truncation." The brief now consistently treats range bounds as String-decimal across req 2, req 3, slice, acceptance, and the req 1 clarification — no remaining authorities saying i64-typed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing User + PM exchange 2026-04-25 surfaced that the in-flight effects chain was importing wrong assumptions from external languages (declared-effects-as-annotation + lens-vs-declaration check). Right framing under gunbc's closed-system discipline is parallel to complexity: every effect derives structurally from the composition of typed primitive operations; nothing can hide because there's no escape hatch; nothing needs annotation because the structure IS the registry. Four doc-only actions: 1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md. Frames the closed-system answer with PM's 5-behavior synergy table (Value/Transform/Branch/Loop/Bind as universal compositional-fold pattern). Four worked examples; aggressive reading on redundancy (compile-error-by-construction via referential-transparency proof; reread() primitive for legitimate cases); implementation-brief shape in §Q6. 2. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md. 3. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md. Notes Fn→Arrow refactor brief stays dispatchable as independent value. 4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by- construction framing replaces lens-detection framing. Memory file feedback_closed_system_effects.md saved separately; cross-link added to feedback_construction_over_ratchets.md. Net cost: doc-level cleanup. Zero substrate code rework. Foundation (OperationEffect + service-call infrastructure + 5-behavior substrate) already exists. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect Per PM convergence review on #808 + user's deeper 2026-04-25 framing: the closed-system framing landed in #808 retired the user-facing annotation but kept OperationEffect taxonomy as substrate-level tagging. User's deeper framing: the taxonomy ITSELF is parallel-representation — operations are intrinsically read-shaped or write-shaped via their TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns- derived-value-only → read). Tagging operations with Read | Upsert | Create | Append | Delete names what the structure already says. Three changes: 1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as normalized view, or retire as parallel-representation?" - Two paths: (i) tags derived from signature shape (acceptable normalized view) vs (ii) tags declared per-primitive (parallel- representation; retire). - Audit-as-existence-check (Q4 req 2 reframed): all effectful primitives derive cleanly from signature shape → path (i); any primitive needs hand-declared tag → path (ii) by existence proof. - Director default: path (ii). Logging primitives that return Unit are likely the audit's existence-proof. - Two design-question resolutions: (a) external effects not in return type → resource-threading discipline (typed param returned modified, IO-monad-without-the-monad pattern); (b) transactional grouping → derived structural fact from Bind composition + typed transaction primitives. 2. Q4 reqs revised: req 2 from "tag every primitive with explicit OperationEffect signature" to "audit-as-existence-check that every primitive's type signature derives the right effect classification"; req 3 added (resource-threading discipline); req 6 added (transactional-pattern lens). Req 1 (effects lens) anchors on operation type-signature shape, not on hand-declared tags. 3. THESIS:345-347 amendment strengthened — "operations are intrinsically read-shaped or write-shaped via their type-signature shape; consumers walk the signatures directly; there is no parallel taxonomy or annotation layer to declare or maintain. Tracking effects as a separate enumerated concept IS the bug pattern, dissolved by construction." Plus references to resource-threading discipline + transactional grouping as derived structural fact. Memory file feedback_closed_system_effects.md updated to reflect the deeper framing (type-signature-shape, not taxonomy-tagging) + resource-threading discipline section + transactional-patterns section. Net cost: doc-only delta on top of #808. Substrate retirement (OperationEffect enum + derive_op_effect + idempotency.dag re-anchor) deferred to the audit-as-existence-check phase of the implementation brief; surfaced as Q5.5 OPEN CALL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage Resolves codex BLOCKING at sha d49ce79a on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real: the prior text claimed service primitives "already carry typed effect signatures" presenting future audit-state as current substrate fact (P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the OperationEffect line but left a parallel over-claim on the new "signature-shape coverage" framing. Fix: Q4 substrate-state listing rewritten to honestly distinguish: - Live: Behavior enum + substrate foundation (the principle that operations should carry signature shape). - Incomplete: signature-shape coverage across actual primitives. HTTP-derived primitives carry implicit shape via derive_op_effect's method-table; logging/mutation primitives that return Unit or don't thread their target resource do NOT carry the structural shape that would express read-vs-write. Achieving full coverage is required work under reqs 2 + 3, not a current fact. - Pending audit-as-existence-check: OperationEffect + derive_op_effect (path (i) vs (ii) per Q5.5). Honest live-state callout added explicitly: "the closed-system FOUNDATION (5 behaviors + DAG substrate + the principle that operations should carry signature-shape) is live. The IMPLEMENTATION COVERAGE across all effectful primitives is partial. Req 2 + req 3 are the work that closes the gap." Brief now distinguishes principle-is-live (foundation) from coverage-is-partial (audit work) without conflating them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim Per PM follow-up review on #808 + user's stronger discipline framing ("substrate must make bypass structurally impossible at every layer of the transport stack"): the closed-system claim is honest only when typed primitives ARE the path. Today two structural holes exist where bypasses sidestep the typed-primitive substrate. Both surfaced explicitly as Q4.5 pre-conditions — load-bearing for the lens's coverage claim. Three changes: 1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed- system claim)" inserted between Q4 and Q5: P1 — Extdeps typed-primitive consumption structurally enforced. Substrate must make `messages: Json` impossible to declare in service definitions; typed `LlmMessage` / `ContentBlock` / `GitHubAuthToken`-with-full-scopes are the only path. Tracked debt at ROADMAP.md:153-154 (LLM provider flattening) + `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded). Required prereq for full lens coverage; lens can land first + surface structural-coverage-gap diagnostics on bypass surfaces so the gap becomes visible rather than silent. P2 — `ExecuteCommand` fully materialized as typed runner primitive. TESTING.md (post-#782) committed to 0-residual but ExecuteCommand isn't fully materialized; deleting Rust boundary tests creates verification gap. Already named under PB-Runtime in Zero-Floor; signal pending. Pre-requisite for ANY Rust boundary-test deletion. 2. Old leftover duplicate Q5 section deleted (artifact from prior Q5/Q5.5 reshape; second copy of asymmetric-tightening text was in the file alongside the earlier Q5 instance). 3. Worker-discretion-vs-Director-call section in Q4.5: lens implementation worker dispatchable now (reports gaps as findings); P1 closure is substantive substrate work touching extdeps (dedicated lane); P2 closure is PB-Runtime (signal pending). Net: design doc now honestly distinguishes principle-is-live (Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs named explicitly). The closed-system claim has explicit pre- conditions documented; implementation brief discovers them as known dependencies, not as STOP-AND-ESCALATEs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two real residuals after the Q5.5 reframe: 1. Q6's reqs/STOPs/acceptance still framed under path (i) — said "audit + tag std/ primitives — every effectful primitive carries an explicit OperationEffect signature." Directly contradicted Q4 (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment ("there is no parallel taxonomy to declare or maintain"). Worker reading Q6 in isolation would author the retracted shape. 2. Capacity / sequencing table line about "audit lane (tag std/ primitives with effect signatures)" carried the same stale framing. 3. Q6 STOP "primitive performing side effects without an OperationEffect tag" assumed tag-as-authority; under path (ii) the STOP shape is "primitive whose signature doesn't structurally reveal its effect." Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale (already fixed at f073aa95e Q4.5 commit). ## Q6 fixes - Reqs renumbered + reframed: - Req 1 anchors on operation type-signature shape (not hand-declared OperationEffect tags); composition reads from signature shape per Q2 table. - Req 2 changed from "audit + tag every primitive" to "audit-as-existence-check" — verify signature-shape coverage; ANY primitive needing a hand-declared tag IS the existence-proof for path (ii) retirement. - Req 3 added: resource-threading discipline applied to existing primitives (logging that returns Unit gets reshaped per audit). - Req 6 added: transactional-pattern lens (Bind composition + Transaction → Transaction'). - Req 7 added: asymmetric-tightening worked example in PR body (per claude review observation; the one place declaration-shaped surface re-enters). - Req 8 (was 5): tests now reference signature-shape derivation explicitly, not tag lookup. - STOPs reframed: - "OperationEffect retirement decision" — audit produces path (i) vs (ii) verdict; substrate retirement is its own dedicated sub-lane; this lane does NOT absorb it. - Pure/impure carrier STOP notes that "pure" should also derive from signature shape (pure functions don't return modified resources) — so the STOP itself may dissolve under further design. - Q4.5 P1 explicitly NOT a STOP — lens reporting structural- coverage-gap on extdeps bypass surfaces is the lens delivering its foundation-gap-visibility value. - Q4.5 P2 explicitly independent — lens doesn't depend on ExecuteCommand materialization. - Acceptance extended: lens reports gap diagnostics on P1 bypass surfaces; audit produces existence-proof verdict for Director re-decision; asymmetric-tightening worked example in PR body. ## Capacity / sequencing table Replaced "1 audit lane (tag std/ primitives with effect signatures)" with "1 audit-as-existence-check lane (verify primitives' signature- shape coverage; NOT 'tag every primitive') — produces the path (i) vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2 prereq lanes to the net summary. Closing line: "The taxonomy- retirement scope (substrate-side) is not in this lane — it's surfaced by audit and routed to dedicated retirement lane if path (ii) wins." Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity table. Worker reading Q6 in isolation now sees path-(ii)-default framing matching Q4 + Q5.5 + THESIS amendment. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792 Resolves codex inline BLOCKING at sha 191be310 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150. Real: my Q4.5 P2 framing described ExecuteCommand as still NotYetImplemented (M1.5 allowlist + Rust TestRunner returning NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand extension before this PR's authoring. TESTING.md:195 capability-state callout confirms: - Rust TestRunner + M1.5 testgen harness share one std::process path for arbitrary command + args + expect_exit_code. - M1.5 allowlist + fail-closed panic retired. - Distinguishable ClaimResult::Fail messages for spawn / timeout / policy / exit-mismatch. - Linux unshare(1) namespace isolation on host-allowing systems. - T-PB-B-1 boundary migration example landed. Fix: P2 section rewritten: - Header retitled "ExecuteCommand runner primitive: LANDED (PR #792); residual is bulk-migration." - Status update naming PR #792 + the post-#792 capability state (allowlist retired, etc.). - Honest acknowledgement: "My earlier P2 framing was stale." - Residual narrowed to bulk-migration of existing Rust Command::new boundary tests (tracked as ROADMAP residual, not lens prereq). - Sequencing reframed: P2 was always orthogonal to the effects lens itself; bulk migration proceeds at its own pace; lens not blocked. Q4.5 footer updated: - "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via #792; only consumer-side bulk migration remains)" - Worker-discretion-vs-Director-call P2 line updated: "runner primitive landed; only consumer-side bulk migration remains; tracked as ROADMAP residual, independent of the lens." Q6 STOP for P2 updated: - "the lens itself doesn't depend on P2; only TESTING.md's 0-residual claim does" → "runner primitive landed via PR #792 (post-Q4.5- authoring update). The lens itself never depended on P2; bulk consumer migration is residual ROADMAP work and remains independent of this lane." Brief now reflects live state. The closed-system claim's prereq landscape is honest: - P1 (extdeps typed-primitive consumption): real prereq, tracked debt at ROADMAP:153-154. - P2 (ExecuteCommand runner): satisfied via #792; bulk migration is consumer-side residual, not foundation work. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale Resolves codex non-blocking finding at sha bcac41bb on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real residual: capacity-table line still listed P2 as "`ExecuteCommand` materialization" prereq + framed both P1 and P2 as "pre-existing tracked-debt" — but my prior 57a9b1318 fix established that PR #792 already landed the runner primitive, so P2 is no longer a materialization prereq. Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq) from P2 (residual, not prereq): - P1: extdeps typed-primitive consumption — pre-existing tracked debt at ROADMAP:153-154; load-bearing for the lens's full-coverage claim. - P2: ExecuteCommand runner primitive landed via PR #792; only consumer-side bulk migration of existing Rust Command::new boundary tests remains (tracked as ROADMAP residual, independent of the lens; not a materialization prereq). Brief now consistently treats P2 as bulk-migration-residual across: - §Q4.5 P2 section header (LANDED via PR #792; residual is bulk-migration). - §Q4.5 footer (P2: runner primitive landed; only consumer-side bulk migration remains). - Q6 STOP for P2 (runner primitive landed; bulk migration is residual ROADMAP work). - §Capacity / sequencing impact (P2 as residual, not prereq). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349 Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated target-grounding prose; the matching extdeps typed-primitive bypass entries (LLM service flattening, GitHub auth model bypass) live at ROADMAP.md:348-349. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix third stale ROADMAP citation at line 271 Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence at line 271 in the §Q4.5 capacity table. Now consistent with lines 139 and 173 (ROADMAP.md:348-349). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity Codex flagged 'Effect-signature tagging on std/ primitives' as potentially contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240) already explicitly say 'NOT tag every primitive' — but the cross-manager line used sloppy wording. Reworded to make explicit that the audit walks signature shape; no parallel tag added. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5 - B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound - B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause - B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge - B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation) B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25): language vocabulary is primitives + namespacing only; no escape syntax; the §0 sentinels are the compiler itself failing to use primitives + namespacing internally. Eight surface sites dissolve via four substrate carriers (DeclarationRef, structural fold-shape carrier, structural emit-helper carrier, structural extdeps-fixture-set carrier). B1-B3 are independent; dispatch in parallel. B4 is sequential program work; sub-brief dispatch (B4.1-B4.12) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — drop incoherent inner-fallback non-goal Codex P2: the non-goal line excluding the inner declaration().name unwrap_or_else fallback contradicted Slice step 2, which replaces the whole chain with let-Some-else-return. Both fallbacks are in scope by construction; remove the contradictory non-goal. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives PM REQUEST_CHANGES: §Frame listed '4 type connectives (Conjunction | Disjunction | Cardinality | Bit)' which contradicted the canonical thesis source. Replaced with the canonical 6 (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary closes here'. Also removed 'typed substrate carriers' from the vocabulary list — substrate carriers are defined using the vocabulary, not part of it. Added a clarifying note that B4's carriers (DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are typed declarations composed from the vocabulary, not vocabulary extensions. Per feedback_verify_thesis_claims: brief framings citing thesis structure must ground in the canonical source. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of naming the live substrate authority. Two coordinated fixes: 1. §Read first cites src/v3/std/substrate.dag (live .dag substrate authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel meta-type — already exists with consumers in verification.dag, emit_model.dag, python.dag). 2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing DeclarationRef'. The work is consumer migration + any role-extension layer the audit reveals, NOT designing or landing the carrier. Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers) keep their 'new' framing but explicitly require sub-briefs to grep src/v3/std/ + src/v3/spec/ for existing authority before authoring 'design and land' framing — per feedback_verify_thesis_claims + feedback_emitter_workaround_is_gap_symptom. Acceptance + sub-brief dispatch order updated to reflect B4.1's consumer-migration shape. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — tighten Phase 1 umbrella sentence The umbrella 'Land the typed carriers into src/v3/std/' framing was stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced with audit-first wording that covers both the consume-existing case (#1) and the design-and-land case (#2-#4 if their audits show real gaps). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands' which conflicted with the post-reframe reality that B4.1 consumes the existing DeclarationRef. Updated to 'consumes or lands' with explicit existing-authority citation and audit-pending caveat for B4.2-B4.4. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — soften regression-test requirement (3 worker bounces) Three consecutive B1 worker dispatches (zesty-crane-890 cursor → valiant-boar-498 codex → cool-lynx-395 cursor) archived without opening a PR. Likely friction point: brief Slice step 4 asks for a unit test that constructs a Dag with an orphan variant declaration, but emit.rs has zero existing #[test] precedent — emit testing happens via integration fixtures. Workers see 'build novel test harness' inside what's billed as an S-scope fix and bounce. Per feedback_construction_over_ratchets: when a brief has friction, fix the brief, don't ratchet the worker. Softened step 4 + acceptance: regression test stays optional. If test setup requires novel scaffolding, route the gap to follow-up. The structural fail-closed at step 2 is the load-bearing change. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description' is too weak; PR descriptions don't survive squash-merge cleanly. Two coordinated edits: 1. Slice step 4 — explicit substrate-signal framing: skipped test means emit-side hermetic-unit-test infrastructure is the missing substrate (feedback_emitter_workaround_is_gap_symptom). 2. Acceptance — require ROADMAP debt row (new or existing) with named dissolution trigger, referenced in PR body. Converts the skip from PR-local note (transient) into tracked debt (durable, dispatchable). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124 Codex BLOCKING: my earlier softening claimed emit.rs had no #[test] precedent — wrong. The module has #[cfg(test)] mod tests at line 3124 with 12+ tests using compile_to_dag(source, filename) as harness (e.g., go_struct_fields_render_with_separators :3143, shared_walk_to_disj_finds_match_scrutinee_sum_type :3195). This is a feedback_verify_thesis_claims violation on Director-side brief authoring — claim made without grep verification. Fix: restore step 4 as required, with explicit precedent citation. Worker constructs the failure case via the existing harness (direct Dag, fixture string, or BranchPattern exercise; worker's call on cleanest path). STOP-AND-ESCALATE only if construction proves materially harder than precedent suggests, in which case that escalation surfaces a real substrate gap and warrants ROADMAP debt — but the default is 'add the test.' Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites) Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded to 'several using compile_to_dag'. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this is Wave 1 of Director's 14-brief authoring queue, covering B4 program internals. Authored: - b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) — replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag") fold-skip with structural template-formal carrier; mandatory authority audit per feedback_audit_adjacent_authority_first. - b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) — replaces §0.6 emit.rs bind/branch.span.file equality with typed BindEmitParticipation/BranchEmitParticipation roles populated at lowering; aligned with #824 worker's in-flight implementation shape. - b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4 of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with typed substrate authority; explicit pre-promotion-constraint disposition (single-authority vs authority+tracked-debt) addresses parallel-representation risk surfaced on #825. - b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) — names B4.5-B4.12 Phase 2 sites with carrier dependencies, cross-program coordination notes, and skeleton-brief template; full per-site briefs author at dispatch time per #827's Substrate Manager ownership. Cross-cutting discipline applied per inbox #828 reply: - feedback_audit_adjacent_authority_first (mandatory grep before design) - feedback_no_textual_enforcement_bridges (no replacement sentinels) - feedback_parallel_representation_debt (explicit if shape (b)) - feedback_construction_over_ratchets (no parity-by-runtime as primary) - feedback_coproduct_dissolution (receipts for new variants) Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3) Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue. Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by Modeling Manager's Wave 3 worker briefs (gated on these landing). Authored: - r2-substrate-cardinality-for-int-lit-subset.md (M) — produces magnitude carrier consumed by T-Modeling int-lit. Coordinates with PR #806's prior cardinality work; mandatory authority audit guards against #796's rejected IntLiteralMagnitude shape resurfacing. Open design questions: magnitude representation, reconciliation narrowing point, i64::MIN representability. - r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces nominal-opacity carrier consumed by T-Modeling Secret<T>. Open design questions: carrier shape (flag/connective/sealed-accessor), generic-walk discipline, accessor gating. - r2-substrate-parametric-algebra-for-dimensions-subset.md (M) — produces phantom-parameter carrier consumed by T-Modeling Dimension<Carrier>. Open design questions: carrier shape, type-equivalence rule, algebra-method dispatch, lifting/coercion. All three: - Scoped narrowly to their paired R2 consumer; not full substrate-capability lanes. - Mandatory pre-author authority audit per feedback_audit_adjacent_authority_first. - Cross-program readiness signal pattern from #827's manager rework. - Coproduct dissolution receipts required for any new variants. - Open design questions surfaced explicitly so Substrate Manager (or Director pre-spin-up) can resolve at dispatch time. Wave 3 (T-Modeling worker briefs × 4) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4) Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue. Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each gated on a Substrate Manager readiness signal (Wave 2 producers). Authored: - r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2 cardinality-for-int-lit; moves narrowing from tokenizer to reconciliation; MagnitudeOutOfRange diagnostic per C-8. - r2-modeling-secret-graduation-worker.md — gated on Wave 2 nominal-opaque-for-Secret; authors Secret<T> + gated accessors (redact, compare_in_constant_time); C-8 diagnostic on non-gated access; signals Impossible-Bugs Manager on close (thesis claim covered). - r2-modeling-dimensions-phantom-worker.md — gated on Wave 2 parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier> + core SI base units + algebra-method dispatch; cross-dimension arithmetic produces typed diagnostic; signals Impossible-Bugs Manager (thesis claim). - r2-modeling-tokenizer-charclass-phase2-worker.md — gated on T-Substrate ValueBody-list/sum (#790); migrates tokenizer consumers to Char/List<Char>/CharClass canonical types; sibling consumer to Grounding Manager's Engine sharpened-(b). All four: - Explicit gating: 'do not dispatch until producer signal posts.' - Producer/consumer signal pattern from #827. - Cross-program signals to R2 Release Manager (Goal 2 closure) and Impossible-Bugs Manager (thesis-claim coverage). - Spoofing regression tests: discipline anchor against feedback_no_textual_enforcement_bridges. Wave 4 (T-ImpossibleBugs worker briefs × 3) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3) Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue. Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes, consuming the existing design/scoping briefs as authority. Authored: - r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on cardinality refinement substrate (T-Substrate territory adjacent to int-lit / DB-11 alias-where). Implementation: structural normalize of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T?? worker decision (reject vs normalize). Cites t-impossiblebugs-nested-optional-flatten-design.md as authority. - r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated on Tier 2 substrate (predicate-entailment infrastructure; distinct from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes predicate entailment, (b) feedback_totality_by_omission dissolves partial primitives, (c) park. Worker decides at audit time. Cites t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority. - r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate prerequisite per closed-system framing in design doc (#808). Audit- as-existence-check + lens implementation as compositional fold over 5 behaviors; redundancy detection compile-error via referential transparency + reread() escape hatch; path (i/ii) decision on OperationEffect taxonomy retain-vs-retire (default retire). Cites design doc #808 as authority. Cross-cutting: - Each cites prior design/scoping brief as authority (the existing *-design.md / *-worker.md REFRAMED files). - Explicit gating per #827 producer/consumer signal pattern; two briefs gated on substrate, one NOT gated (closed-system). - STOP-AND-ESCALATE includes 'design brief assumptions don't hold' surfacing per feedback_thesis_gate_state_drift. Wave 4 complete. Director's 14-brief queue done; awaiting PM portion (6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4.4 — tighten Slice §3 per PM review on #836 PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b) (authority + tracked debt parallel-rep) as autonomously acceptable contradicts feedback_construction_over_ratchets + feedback_parallel_representation_debt. Tightened: - Shape (a) is the only autonomous worker path. - Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a regen-host-loader sub-lane decision; not authorable without explicit Substrate Manager approval citation in the PR body. - Acceptance bullet requires the approval citation when shape (b) lands. - STOP-AND-ESCALATE rephrased to make this explicit; permanent parallel-representation re-escalates even with manager approval. This preserves shape (a) as autonomous; shape (b) becomes a cross-manager design escalation, not a B4.4 implementation call. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief Cursor review on #836 flagged the Read-first reference to .claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md as machine-specific (outside the repo, not resolvable from a normal clone). Replaced with in-repo prose pointing at the design doc's §Q1-Q3 as canonical authority — the discipline lives there in-repo. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs) Codex flagged: src/v3/std/types.dag does not exist; the canonical authority is at dsl/std/types.dag. Affected briefs (all from R2 spin-up Wave 2 + Wave 3): - r2-substrate-cardinality-for-int-lit-subset.md - r2-substrate-nominal-opaque-for-secret-subset.md - r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs) - r2-modeling-dimensions-phantom-worker.md - r2-modeling-secret-graduation-worker.md feedback_verify_thesis_claims violation on Director-side brief authoring — assumed path without grep. Same family of error as the earlier emit.rs precedent claim. Mass-replaced via perl; verified no remaining stale refs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant Codex BLOCKING on #836: my R2 worker brief gated nested-optional on cardinality refinement substrate, but the design doc verifies v3 is ALREADY past the cardinality bridge — TypeConnective::Cardinality is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is the carrier for Option. The dissolution is an UNGATED implementation via substrate-constructor invariant. feedback_verify_thesis_claims violation again — should have read the design doc fully before assuming the substrate gate. Rewrote brief to match design doc canonical sketch: - Single predicate (cardinality_idempotent_target) owns the rule - Single allocator (alloc_cardinality_decl) is THE substrate-constructor - API closure on TypeConnective::Cardinality payload (modeling-discipline practice 6) — variant cannot be struct-init'd outside the allocator - 3 hand-Rust + ~22 codegen call sites enumerated per design audit - infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as the killer case for generic-instantiation paths - Surface-syntax T?? decision left to worker (Director-lean: silent normalize) Brief now dispatchable immediately, no producer signal needed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment substrate path, but the design doc §4 explicitly recommends totality-by- omission as the Director-actionable path. Predicate-entailment is M+ scope that reopens DB-11's explicitly-closed asymmetric-strip design — design doc explicitly discards it. feedback_verify_thesis_claims violation again — same family as nested- optional reframe. Should have read design doc §4 in full before assuming the path ordering. Rewrote brief to match design doc §4 follow-on shape: - Primary path: per-class totality-by-omission (algebra retype + per- target realization migration). For Int/Int: OrderedRing.div retype at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 / python:486 + python_target.rs:680 helper). - NOT predicate-entailment (out of scope; M+ + DB-11 reopen). - NOT NonZero-typed-input (deferred to separate per-operand-variance substrate brief; STOP-AND-ESCALATE if chosen). - Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i] indexing, quotient, remainder) queue separately per design doc audit. - feedback_totality_by_omission discipline anchor explicit. Brief now matches feedback_totality_by_omission discipline + design doc recommendation. No substrate prerequisite; dispatchable immediately. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a pattern: I authored R2 worker briefs without fully reading each design doc's Director-actionable recommendation. Pre-emptively re-verified unenumerated-effects against design doc §Q6 to catch the same family of error before reviewers do. Findings: brief was substantively close but missing 3 of 8 design-doc reqs: - Req 3: Resource-threading discipline applied to existing primitives - Req 5: reread(key) primitive in std/ as explicit Slice item (was only mentioned in tests) - Req 7: Asymmetric-tightening worked example in PR body Plus: Slice didn't cite the canonical lens path src/v3/lenses/effect_enumeration.dag from design doc. Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6 specifies 4 specific STOPs (path-decision-escalation, pure: Bool carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP) that I had elided. Reframed Slice as 8 numbered reqs matching design doc verbatim; STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs; Acceptance enumerated per req. This is the third reframe in the unhandled-bugs series — same feedback_verify_thesis_claims violation each time. The pattern suggests Director-side R2 brief authoring should ALWAYS read each design doc's §Director-actionable / §Q-recommendation in full first, not assume. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)" listed as a worker-pick option violates THESIS.md substrate-shape lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) are canonical (per #811 thesis additions and #827 PM review); a 7th is a C1 stop signal requiring failed-dissolution evidence + Director substrate-design call, not autonomous worker pick. Removed the "new TypeConnective variant" option; replaced with `inhabits`-edge-shape carrier as third option (audit-time check). The explicit STOP-AND-ESCALATE clause now states: 7th connective is the precondition for failed-dissolution-evidence + Director substrate-design call, not a worker path. feedback_verify_thesis_claims still in play — should have grounded substrate-shape options against the THESIS lock before listing Opaque(T) as worker-autonomous. Pattern continues; reading source-of-truth before authoring options is the discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place) Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter already exist at dag.rs:186, :217 — explicitly authored for the R2 Dimensions consumer per the doc comment at dag.rs:148-160. phantom_unit_mismatch already wired at infer.rs:1057, :1132. The substrate is fully landed; my brief framing it as 'producer sub-lane to land carrier' is wrong on the same feedback_audit_adjacent_authority_first violation that hit nested-optional / unhandled-diagnostic / unenumerated- effects. Reframed the substrate-side brief as no-op / closed-by-audit: - Documents the audit receipt (5 sites confirming substrate exists) - States the lane is closed - Routes T-Modeling Dimensions consumer to dispatch immediately against the existing carrier - Records the lesson: 'always grep substrate before authoring producer briefs' — discipline doesn't end at brief boundaries. Updated r2-modeling-dimensions-phantom-worker.md correspondingly: - Changed gating from 'do not dispatch until producer signal' to 'NOT GATED — dispatch immediately' - Read-first updated with concrete dag.rs/infer.rs cites - Slice §1 changed from 'confirm producer signal' to 'verify substrate at HEAD' - STOP reframed: existing carrier extension would need Substrate Manager call, not autonomous worker pick Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit both verified — no existing substrate (no is_nominal_opaque / MagnitudeBound patterns in dag.rs); both still legitimately producer-side work. Pattern is now four reframes deep on the R2 spin-up wave. The lesson saved is structural: read source-of-truth before authoring options. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority Codex BLOCKING on #836: my new R2 spin-up brief duplicates the existing t-substrate-cardinality-int-lit-worker.md, which carries the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64) stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane). Single-authority violation per INVARIANTS P2. Same feedback_audit_adjacent_authority_first failure as parametric- algebra-for-Dimensions reframe (4 hours ago): assumed substrate authority didn't exist; should have grepped docs/briefs/ before authoring. This is the SECOND R2 spin-up substrate brief closed as redundant — the discipline lesson is structural. Reframed brief as no-op routing doc (documents the audit receipt; routes consumers to the existing authority); updated r2-modeling-int-lit-magnitude-worker.md to cite t-substrate-cardinality-int-lit-worker.md instead. Pattern across the R2 spin-up wave reframes (5 now): 1. nested-optional gating-on-substrate (substrate already past cardinality bridge) 2. unhandled-diagnostic predicate-entailment default (design doc recommends totality-by-omission) 3. unenumerated-effects 8-req design-doc elision 4. parametric-algebra Producer (Declaration.phantom_params already authored explicitly for this consumer) 5. cardinality-for-int-lit Producer (existing brief is autho…
Session
sharp-bear-829(dashboard).Scope — tokenizer half / bounded interim (not full
sub_charclass_in_std_unicodeclosure)Per review (2026-04-24): this PR is an explicit phase-1 slice of ROADMAP.md:354 — std.unicode authority + SG-1 emission path — not the full structural end state.
Shipped
CharClass+char_in_classindsl/std/unicode.dagis_ascii_*; it callstokenize_char_class::byte_matches/TokenizerCharClasstokenize_char_classunit tests (sub_charclass_in_std_unicode_gate) lock ASCII semantics (0..=127) vs Rust helpers and asserts generated output shapeExplicitly not in this PR (follow-up / separate tranches)
syntax.dag/std.syntaxconsumer wiring — noOperatorSpec.symbol/dag_keyword_setretagging hereCharClassconsumption from loweredtokenize.dag— blocked by M1(2.8) class-5 gap . #3 (list / sum-variant literals indatabodies).tokenize_char_class.rsis a documented handwritten mirror until that gap closes; then remove the mirror and read class rows from.dag.Lane status
Use this PR to close tokenizer-side / authority + mirror acceptance; keep syntax + structural
.dagread as open follow-ups so the ledger does not over-claim full lane completion.