Skip to content

Witnesses on v2: fix the native path (9/9 families green) + enroll them on the falsifier wet cadence - #6990

Merged
briansrls merged 19 commits into
mainfrom
session/emit-host-sorted-fields
Jul 22, 2026
Merged

briansrls merged 19 commits into
mainfrom
session/emit-host-sorted-fields

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

9/9 witness families now execute as emitted native Rust, all agreeing with the interpreted oracle

Verified on srv1 (wet, all 7 aggregates PASS, ~90-128s each): add/kernel, field_access, complement, match+loop+fold_closure, meet_join, variant_construct, classical_not_ingested.

Fixes

  1. Interpreter (sorted_fields): fields_get is a binary search by Symbol id, but both EmitHostTransportResult builders constructed 7-field vecs in declaration order — interning-order-dependent, accidentally sorted until effect-grants PR-3: build-transport admission as a construction wall in the emit-host dispatch (+ 39707/39684 folds) #6904 shifted interning, after which every .success lookup failed and all 9 families' wet legs broke. Both sites wrapped in sorted_fields; audit: the other 16 raw-vec Record sites are 0/1-field.
  2. Lane 2 witness fan-out: field_access + complement family suites (emit-on-demand kernel extension) #6893 fixture defect: the native_content_change_cold_rebuild legs in field_access/complement reused the wrong-field refusal fixture as their "changed content" success probe — it emits r.1 on a 1-tuple (rustc E0609) and can never run. Replaced with the kernel's valid-alt pattern (descent-parameterized facts → new content key, same valid program); complement's hardwired octet corrected; RED-control roles preserved.

CI on v2 — first slice

The breakage was invisible: test/claim/execution/ is excluded from hermetic discovery AND the offline roster, so the flagship v2 execution path rotted with zero signal (the enrolled-but-never-run class). This PR enrolls the 7 family aggregates on the falsifier nightly wet cadence (the established lane for emit→build→run→equals receipts) as the rot-detector. Per-PR stays hermetic/flat-cost. The full P6 cutover additionally needs: the is_hermetic() blanket refusal in emit_host_run_transport replaced by the computed Admitted verdict (effect-grants seam), and the content-keyed result store so builds amortize instead of taxing every run.

Follow-up worth its own change: materialize the toolchain pin into the emitted workspace (toolchain identity is already in ArtifactKey; a host without a rustup default currently fails every native build as emit_host_exit_not_ok).

🤖 Generated with Claude Code

briansrls and others added 4 commits July 20, 2026 21:52
…ruction

fields_get resolves record fields by binary search on Symbol id, so a
multi-field intrinsic record must be sorted at construction. Both
EmitHostTransportResult builders (emit_host_run_transport + _cached) built
their 7-field vec in declaration order, which is interning-order-dependent:
it happened to be sorted until #6904's admission wiring interned additional
symbols first, after which .success lookups failed ('no field success on
type EmitHostTransportResult') and all 9 emit-on-demand families broke on
their wet legs — invisible to CI because test/claim/execution/ is excluded
from both hermetic discovery and the offline roster. Wrap both in
sorted_fields (the existing invariant helper). Class audit: these were the
only multi-field raw-vec Record constructions in the interpreter; the other
16 raw sites are 0/1-field (trivially sorted).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…s (9/9 families)

The emit-on-demand native_content_change_cold_rebuild legs in the
field_access and complement families (landed in #6893) reused each
family's semantic-mismatch RED fixture as the "different content" tree
and asserted a SUCCESSFUL native run — but a refusal fixture is not a
valid alternative program:

- field_access: the wrong-field tree emits fn get(r: (i32,)) -> i32
  { r.1 } — rustc E0609 (no field 1 on a 1-tuple) -> RunFailed. The
  domain conj models exactly ONE field (r: Rec realized "(i32,)"), so
  no 2-field reading exists; the emitter truncates nothing.
- complement: the swapped-arms tree IS a valid program (the identity
  fn), but the helper hardwired the primary's octets [0,0,0,0,0] while
  identity(True) natively yields [0,1,0,0,0].

Fix mirrors the passing kernel and meet_join legs:

- field_access: new emit_field_eval_alt_descent_producer_tree — same
  root, facts differing only in the descent ranking symbol (digested
  via ranking_dimension_digest) -> different inferred_tree_digest ->
  new native key, emitted Rust stays the valid r.0 program (octet 9).
  Exactly kernel_alt_subject_tree's same-root/different-facts pattern.
  The now-dead wrong-field arrow producer is deleted (the wrong-field
  BODY stays as the eval-side RED control in wrong_fixture_refuses).
- complement: thread expected_octet per tree (meet_join pattern);
  primary legs expect 0, the swapped-arms alt run expects its derived
  1. The swapped fixture keeps its RED role in the equals-claim leg.

Verified by execution on srv1 (fix-test @ c7d53ac + this change):
both previously-red legs PASS, and all 7 aggregate fns PASS wet —
kernel 100.8s, field_access 88.6s, complement 90.2s, match_loop_fold
105.3s, meet_join 87.0s, variant_construct 88.1s,
classical_not_ingested 127.9s — 9/9 witness families executed as
emitted native Rust agreeing with the interpreted oracle.
cargo fmt --all --check clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The 2026-07-20 breakage proved this class invisible to CI. The nightly wet
lane is the established home (same emit->build->run->equals class as the
self-host template row); per-PR stays hermetic. Full CI-on-v2 (P6) remains
gated on the is_hermetic->Admitted flip + the result store.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@cursor

cursor Bot commented Jul 21, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

briansrls and others added 10 commits July 21, 2026 11:35
…ted-fields

# Conflicts:
#	src/v2/compiler/self_host/wet_receipt_enrollment.dag
FLIP (build_transport_admission.dag:20's declared step, operator-assigned):
emit_host_run_transport(_cached) intrinsics gain a leading admission argument
and run ONLY on an Admitted verdict, in every mode — the blanket is_hermetic()
early-returns are deleted (the law is path containment, not a mode bit).
emit_host.dag threads the verdict from the Admitted match arm; the only two
raw call sites live inside run_host_process_admitted. Unit tests: Admitted
passes hermetic; EffectOutsideGrant/missing verdict refuse typed, every mode.

DURABLE CACHE (first PerRunnerFilesystem realization row):
- GUNBC_NATIVE_CACHE_ROOT rebases the declared /tmp/gunbc_ scratch prefix
  (root is WHERE, never WHAT — content-hash path components stay the key);
  exported in the shared CI prelude at RUNNER_TOOL_CACHE/gunbc-native, which
  survives the RUNNER_TEMP wipe.
- GUNBC_CI_NATIVE_CACHE_COLD_CONTROL falsifier step (widen-only, the
  compile-clean cold-control pattern) re-runs the wet receipt batch cold via
  gunbc_falsifier_native_cache_cold_batches.
- [native-cache] key/compile_skipped receipt line per cached invocation.
- extdeps/realization/native_artifact_cache.dag: the catalog row (eviction:
  Manual — honest today; SizeBounded is the named dissolve-on).
- 7 family cache-root literals consolidated onto std.emit_on_demand
  emit_on_demand_family_cache_root (single prefix authority).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
… sides

With GUNBC_NATIVE_CACHE_ROOT set, a raw shell.Remove on the .dag-composed
/tmp path would miss the rebased workspace and falsely leave it warm — the
cold/content-change legs would red on the second run. Extract the rebase
into native_cache_rebase_workspace_dir and route eviction through a new
emit_host_native_cache_evict intrinsic (wet-only, idempotent) sharing it
with the cached transport. Registry row in 04_method.dag (regen to follow).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
… step

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Probe receipt: under GUNBC_CI_NATIVE_CACHE_COLD_CONTROL=1 the cold_then_warm
legs correctly FAIL (the control destroys the warm-ness they assert), so the
falsifier cold step must not run the full aggregates — it runs the 9-leg
cold-valid roster (falsifier_native_cache_cold_entries) instead. The warm
nightly batch keeps the full aggregates.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…ld-control term; template roster 2 -> 9

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls and others added 4 commits July 21, 2026 21:54
…iliation

Union: cache-root single authority + family_closure_digest coexist; migrated
complement/meet_join files taken from main (pure receipts); cold roster
re-pointed at family_crate_member_change_cold_rebuild_holds; family-crate
aggregate enrolled on the wet cadence (was executing-consumer-without-cadence);
family_crate_cache_root re-grounded on emit_on_demand_family_cache_root
(identical string, single authority). Template roster 9 -> 10.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…e 'T' failure) + regen deploy scripts

The unannotated field-access lambda (#7047's form) fails inference as 'no
field command_path on type T' when this branch's added modules shift the
closure; a named helper with explicit params gives inference the call-arg
constraint both parse paths accept. Generator ExitSuccess on the merged
tree (srv1 receipt); seed regen at fixed point (99 files, 0 diffs).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…paths_match)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ily rows expect FalsifierSelfHostWet

Main's new admission test asserted the family rows as OfflineLocalRecipe —
written against pre-enrollment main. The rows now have real executing
consumers: the wet template (aggregates) and the native-cache cold roster
(agreement legs), which consumer_for_explicit_rosters previously did not
consult (misclassifying falsifier-executed rows as offline).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@briansrls
briansrls force-pushed the session/emit-host-sorted-fields branch from ff91aa8 to a6ecd34 Compare July 22, 2026 03:14
briansrls added a commit that referenced this pull request Jul 22, 2026
… (kernel, variant_construct, classical_not_ingested, field_access, match_loop_fold family crate) — ~35 redundant cargo builds per corpus pass deleted; field_access alt leg quarantined KNOWN-RED (E0609, owner #6990) (#7042)

* WIP: witness_native_flip lane (parallel, NOT post-fixed-point — operator-dire

* WIP: witness_native_flip lane (parallel, NOT post-fixed-point — operator-dire

* WIP: witness_native_flip lane (parallel, NOT post-fixed-point — operator-dire

* WIP: witness_native_flip lane (parallel, NOT post-fixed-point — operator-dire

* WIP: witness_native_flip lane (parallel, NOT post-fixed-point — operator-dire

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Field_access: one-build base + valid-alt graft (alt_descent producer, alt
cold leg restored, quarantine + SCOPE-CORRECTION admission deleted). Cold
roster re-authored onto the 9 standalone equals_eval agreement suites
(cold-valid by construction; #7042 deleted the per-witness fns).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant