Skip to content

Phase C: refuse undetermined none/None carrier (Value::Null split) - #7292

Merged
briansrls merged 4 commits into
mainfrom
session/keen-ferret-250-phase-c
Jul 26, 2026
Merged

briansrls merged 4 commits into
mainfrom
session/keen-ferret-250-phase-c

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jul 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Closes the fail-open default at emit_var_ref / emit_typed_expr_base (sharp-bee-290 msg_6317aebe / DESIGN §5): when none/None had no variant_parent, the emitter emitted Rust None via emit_keyword(null) even when the carrier was undetermined — fabricated plausible output.

Single decision (emit_none_keyword_for_resolved_type):

  • CardOptional → type-directed Rust None
  • determined non-optional carrier → typed refuse (emit_error_expr)
  • undetermined inferred type → typed refuse (emit_error_expr)
  • never null as a fabricated default

Both call sites in src/v1/05_emit_rust.dag route through that function; seed regenerated. Discriminating RED (host-Rust, RetainedNonMigratable): src/v1/tests/src/none_undetermined_carrier_refuse_test.rs + dag/test/retirement/none_undetermined_carrier_refuse_retained.dag.

Probe / metric (no A/B delta claimed)

The two TSV receipts are independent observations at different shas, not a clean before/after of this PR:

receipt git_sha gunbc_sha (prefix) notes
BEFORE (value_null_split_phase_c_BEFORE_2026-07-26.tsv) efe67794 (banked #7275) 09aa03de… banked refresh; TOTAL E0308 = 837
AFTER (value_null_split_phase_c_AFTER_2026-07-26.tsv) aa383585 (this PR pre-retention-receipt) 1fbda554… fresh local build mtime 2026-07-26 17:24:35 UTC; TOTAL E0308 = 839

Between those shas, main-side movements already change the surface (emit_host 88→91 files emitted, materialization_carriers 41→44, and materialization_carriers first_error Measure→Outcome). No E0308 delta is attributed to this PR. The probe is a construction-wall observation that the refuse arm did not light up on the canonical seven (uncoded_UNRESOLVED_CompilerError stays 1 in both tables) — near-zero corpus cost for closing the fail-open. Reachability evidence is the unit RED below, not the probe corpus.

Local RED receipt (CI does not run cargo test)

CTRL_BUILD_BYPASS_SHIMS=1 cargo test -p v1-compiler-tests --lib none_undetermined_carrier_refuse -- --nocapture

test result: ok. 3 passed; 0 failed on head d2412ceb. Printed outputs of emit_none_keyword_for_resolved_type (same API the tests call):

case result
undetermined (None inferred) panic!("none/None with undetermined carrier — refuse fail-open null default")
CardOptional None
determined non-optional (Required) panic!("none/None with non-optional resolved carrier — refuse fail-open null default")

Test plan

  • Local discriminating RED — 3/3 PASS (command + printed cases above)
  • Probe TSVs banked; PR body states independent observations / no delta claimed
  • No restore of escaping null default; refuse is the undetermined arm
  • HAND-RUST GATE retention receipt (*_retained.dag)

briansrls and others added 3 commits July 26, 2026 17:11
Close the fabricated-plausible default at emit_var_ref / emit_typed_expr_base
(sharp-bee-290 msg_6317aebe): CardOptional type-directs to Rust None; any other
determined carrier or undetermined inferred type refuses via emit_error_expr.
Discriminating RED lives in a hand stage0 integration test (not a ct_ roster blob).

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Fresh gunbc (sha 1fbda554, mtime 2026-07-26 17:24:35 UTC) on aa38358:
E0308 837 → 839 (+2 on emit_host / materialization_carriers). Declared as
construction-wall measurement, not a burn-down claim; emit file counts also
moved vs the banked baseline (main drift possible).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 26, 2026 18:02
Move none_undetermined_carrier_refuse into src/v1/tests with a
RetainedNonMigratable retirement row (Value::Null-split lane / ROADMAP
fail-closed meta band), matching e0308_mechanical_trio.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 26, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 43410 (codex REQUEST_CHANGES — HAND-RUST GATE):

  • Moved the discriminating RED out of ad-hoc src/v1/stage0/tests/ into the accounted src/v1/tests surface as none_undetermined_carrier_refuse_test.rs.
  • Added checkable retention receipt dag/test/retirement/none_undetermined_carrier_refuse_retained.dag (RetainedNonMigratable), naming lane gunbc.plans.value_null_split / ROADMAP fail-closed meta band (Value::Null split) and the same non-migratable reason class as e0308_mechanical_trio_retained.
  • 3/3 tests still green locally via cargo test -p v1-compiler-tests --lib none_undetermined_carrier_refuse.

— sent from keen-ferret-250

@gunbai-bot

gunbai-bot Bot commented Jul 26, 2026

Copy link
Copy Markdown
Contributor Author

Read review 43419 (codex APPROVE). Artifact is verdict-only — no non-blocking line items to land. Phase C diff stands as-is.

— sent from keen-ferret-250

@briansrls
briansrls merged commit 13d0a16 into main Jul 26, 2026
5 checks passed
@briansrls
briansrls deleted the session/keen-ferret-250-phase-c branch July 26, 2026 22:24
briansrls added a commit that referenced this pull request Jul 26, 2026
Authorized by clever-pike-49 (msg_ed3b8c19): branch behind main; not a revert.
briansrls added a commit that referenced this pull request Jul 27, 2026
review 43574 (cursor, REQUEST_CHANGES) is correct. The previous commit
corrected DESIGN to PARTIAL and left dag/gunbc/plans/shell_emission_model.dag
asserting "Phase 1 LANDED (#6832)" in three places -- a §3 parallel-authority
fork on the same fact, created by the PR whose purpose is removing them. Same
failure the census documents: a correction is not done until the text it
supersedes is gone.

Corrected surgically, not by blanket replace, because "LANDED" was not
uniformly false:

- Phase 1 headline -> PARTIAL, with the three verified specifics and a note
  that roadmap_authority.dag `6-shell-intent-phase1` needs the same rewrite.
- The two While/BoundedPoll claims -> split. `While` emission genuinely DID
  land in #6832, so that survives, scoped to `While`. `BoundedPoll` is marked
  UNCONSUMED: its only construction sites tree-wide are in
  orchestration_bounded_poll_emit_test.dag, and both production match arms
  return Absent -- counting it as landed measures capability, not use.

Two `LANDED (#6832)` strings remain on purpose and are now true as scoped.

Verified: rebuilt the seed first (the main merge brought src/v1 emitter
changes #7292 that the prior binary predates), quote scan clean, then
main_wet -> ExitSuccess writing only docs/plans/shell-emission-model.md --
no unrelated drift from the fresh seed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 27, 2026
…erequisite (#7294)

* WIP: shell -> dag migration

* Fix the census row I got wrong: the bash-AST sidecar vocabulary is extinct, not confined

review 43441 requested changes on the first correction pass, correctly. The
replacement row listed seven files as live ShellProgram/serialize_bash
construction sites; every one of those hits is prose. That reproduced the
exact error this PR set out to remove.

Verified hit-by-hit: ShellProgram, serialize_bash and ShellStmt have ZERO
construction sites, because the declaring module dag/extdeps/languages/bash/
program.dag was DELETED in #6831 Phase 0. What remains is design_document and
plans/ prose, two dissolution reason: fields, and one witness that matches the
grep precisely because it asserts the string is ABSENT. bash_command_fold and
bash_build are the genuinely live replacement, and build_step.dag constructs
plain Node, not ShellStmt -- so §1.D's ShellStmt AST library line was stale too
and is corrected.

Added a method note, because the row has now been wrong twice in opposite
directions with one shared cause: git grep -l answers which files CONTAIN a
string, not which files CONSTRUCT the thing. Three classes match and none is a
construction site -- prose (including dissolution notes saying the builder was
removed), absence-asserting witnesses, and different identifiers sharing a
substring (ProjectionShellProgram, ExprCmdSubst).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag migration

* Classify the frozen .diff fixtures the occurrence census missed

review 43455 is correct: the prior pass scoped the tree-wide occurrence count
to dag/** and src/v2/**, so five RawLine occurrences in two recorded .diff
fixtures under src/v1/stage0/testdata/ went unclassified. The construction-site
conclusion (zero) is unaffected -- a fixture is not a construction site -- but
a section that teaches hit-by-hit classification cannot leave a whole class out.

Adds class (d) frozen historical artifacts to the method note. These capture the
tree as it was, match forever, and must never be cleaned up -- they are test
data. The sharpest case is a - deletion line (-  RawLine,), which matches a
search for the symbol precisely because it records the symbol's removal: the
strongest available evidence of absence and the easiest to miscount as presence.

Also states the census scope explicitly (whole repo, all file types, no
pathspec) so the claim is checkable rather than taken on faith, and picks up
DESIGN.md and the dag_only fixture in the sidecar-vocabulary row.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Give the CaptureSpec finding an owner and a trigger, and correct it to the verified form

review 43467 is correct under DESIGN 6: a confirmed defect recorded as
'currently unowned' with no bounded lane or trigger is untracked debt, not a
filing. Fixed.

The note also still carried the DISPROVED version of the finding -- 'TeeTo and
CmdSubst are declared but unreachable' -- which I had already corrected in the
carrier and in dispatch messages but not here. That is the third instance in
this PR of the defect the PR exists to remove, and the review did not catch it;
I found it re-reading the line under challenge.

Corrected form: CmdSubst is genuinely dead (zero constructors). TeeTo is LIVE
but INERT -- ci_retry_body_run constructs it, orch_retry_step_command discards
redirect/capture, and the identical tee is hardcoded at bash.dag:1093-1133, so
the model is the copy that does nothing. It is a divergence rather than one bug:
the ordinary Run path refuses the same field fail-closed and typed.

Disposition now names owner (this lane), a dissolution trigger (thread
redirect/capture through the retry path and delete the hardcoded tokens), and a
discriminating acceptance bar (rename the log, regen, ci.yml must CHANGE --
today it is byte-identical, which is the defect). Records why it is sequenced
rather than dispatched: the fix direction is undecided and lands in bash.dag, a
load-bearing grammar file, moving with the Run.command -> Do{effect} decision.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag migration

* Reconcile the action rows that still chase a deletion which already happened

review 43477 is correct and the contradiction was worse than the three cited
lines. The document established in 4.G that program.dag / ShellProgram /
serialize_bash are extinct, while four other places still directed workers at
them as live targets:

- 1.E named program.dag 'the sidecar - the deletion target' and gated it behind
  a bash_program_importer_count_baseline = 19 ratchet. Verified: that identifier
  appears NOWHERE in the repository except this document -- the baseline was
  measuring a mechanism deleted with the sidecar (shell_emission_model.dag:50
  records it as pruned-because-vacuous). bash_program_emit.dag, also named
  there, does not exist either.
- 3 was titled 'to program.dag deletion' with a 'The join - delete program.dag'
  section describing the arc's terminal step as importers draining until the
  ratchet floors. All of it already happened in #6831 Phase 0. Retitled; the
  real terminus is the Phase-3 wall (4.F): brand TransportScript and activate
  the inert lens, turning 'no sidecar exists' into 'a hand-built transport
  string is unwritable'.
- P3 said the pre-push hook and cron lines stay serialize_bash permanently. They
  stay SHELL permanently, emitted through the v2 bash rows. Permanently-shell is
  not permanently-on-a-deleted-sidecar.
- 4.F and 5.E both proposed branding TransportScript so it is produced only by
  emit(intent,Bash)/serialize_bash. Naming a deleted sidecar as a second
  sanctioned producer would re-open the hole the brand exists to close; a wall
  with two doors is not a wall.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* True up the Phase-3 wall rows: it landed 2026-07-24 and branding was refuted, not pending

review 43486 is correct. 4.F still described transport_script_from_body as a
live 26-site constructor and directed Phase 3 to brand TransportScript. Verified
against the tree: the free minter is DELETED from extdeps.shell.exec -- zero
live sites -- and the surviving occurrences are a note recording its
replacement, two compile-RED controls asserting the deleted-minter fake FAILS to
compile, and v1-seed detector code. The single sanctioned mint is now
gunbc.retained_shell_script, which takes a RECORD.

The sharper point, and the reason this kept recurring: the document had already
superseded itself IN PLACE. 5.E's ruling block, ~275 lines below 4.F, records
that branding was refuted BY EXECUTION -- TransportScript is a transparent
brand, peel_nominal_alias_identity peels it to its base, so a computed String
flows into the position with no cast -- and that the host_language_transport_
script lens is deliberately green on computed concats and never caught the
#7064 fake. Neither the 4.F table nor 5.E's own bullet list was updated to
match. A worker reading either would have executed refuted work.

Both are now marked: 4.F carries the landed state per row, and 5.E's three
original bullets are struck in place with WHY each was refuted, kept because
the correction is only legible against them. Bullet 2 held and is noted as such.

Last round I edited these same two lines and only removed a stale producer name
without re-deriving whether the row itself was live -- the exact failure the
method note in 4.G warns about.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Sweep the three remaining wall directives, including one I introduced last round

Fixing the two lines review 43486 cited was not enough -- a grep for the pattern
found three more, and one of them was mine.

- Line 141: I wrote 'the terminus is the Phase-3 wall: brand TransportScript and
  activate the inert lens' ONE ROUND AGO, while fixing the program.dag
  staleness. Both halves had already been refuted by execution, in this
  document's own 5.E ruling block, before I wrote it. Fixing a stale directive
  by writing a differently-stale directive is the failure mode this document
  keeps reproducing.
- Sequence step 2 still listed 5.E as pending work; it landed as #7184, which
  section 4.I of this same document already recorded.
- The 4.0 probe table's P6 row characterised the boundary as porous with 26
  sites; that is a historical finding at 78f43c3, now labelled as such rather
  than reading as a live count.

Both terminals the document builds toward -- the program.dag deletion and the
Phase-3 wall -- are behind us. What genuinely remains is meta-exec confinement
plus the per-site migration.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag migration

* Reconcile the three lens cross-references, and correct the 'inert' claim I introduced

review 43494 is correct on all three, and chasing them found a fourth defect
that was mine and a fifth worth an operator decision.

Cited and fixed:
- 4.G header said 'already confined' while its own body says EXTINCT. Retitled.
- The 07-26 ledger Net dispatched 'host_language_transport_script lens
  promotion' as remaining 4.F work, which 4.F now explicitly forbids. Corrected
  to meta-exec confinement only.
- The section-4 dissolution trigger said the punch-list folds into that lens
  'going live'. The construction wall it was waiting on landed as #7184; the
  wall stops NEW concats but does not dissolve existing rows, so the trigger now
  says what actually closes the list. Also names why the two are not
  interchangeable: a lens going live is validation, the record edge is
  construction, and DESIGN 5 prefers the second because it makes the state
  unwritable rather than flagged.

Mine, introduced last round: the 4.F row called the lens 'inert, and
deliberately so'. That is wrong -- I carried the stale characterisation forward
while rewriting the table around it. wall_residue_live_test.dag:4 says the
previously-inert lens IS wired as a per-PR live consumer, ReadsLiveTree, reddin
a new raw literal at an enrolled Run position. It is live but deliberately green
on ComputedApplication, which is why it never caught the #7064 computed-join
fake. Live-but-scoped, not inert.

Flagged, not acted on: this document's OWN dissolution trigger has fired. It
said dissolve when the lens goes live and program.dag deletes; #7184 and #6831
did both. The trigger was mis-specified rather than unmet -- it names mechanism
events, while what keeps the doc alive is the per-site punch-list. Three
sessions are working rows in it right now, so re-specifying the trigger is an
operator call, not a census edit.

Note for a follow-up outside this PR: fail_closed_lockdown.dag:32 and
design_document.dag:157 both still describe this lens as inert. Both are stale
for the same reason. Not touched here -- DESIGN is load-bearing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Re-state the TeeTo finding for the fix landing in flight (#7293)

My census note claimed TeeTo is 'live but inert, constructed at ci_spec.dag:226'.
wise-crane-222's #7293 removes that constructor -- ci_retry_body_run is now
Absent/Absent and the retry path refuses any Present redirect/capture rather
than silently dropping it, with a discriminating RED asserting a retry-body
TeeTo is Rejected. Verified on its branch: TeeTo will have zero production
constructors, the only survivor being that refusal control.

So the claim I was about to land is invalidated by another in-flight PR. That is
the same stale-authority defect this PR has spent six review rounds removing,
and shipping it would have been the seventh. The row now states both states
explicitly and names #7293 as the boundary between them.

The disposition also changes, and honestly: I filed this owned-by-me and
sequenced behind the arc-close decision, with the fix direction 'thread
redirect/capture through the retry path'. The child took a different and better
direction -- delete the inert declaration instead of making it load-bearing --
because an inert declaration is worse than an absent one, since it lies. Most of
the finding is discharged.

The residue is smaller and different in kind: no longer a 3 dual
representation but an honest modelling gap, since the intent layer now cannot
express a tee at all and the semantics live solely as fixed tokens in the
grammar row. Trigger restated to match: dissolves when the bash rows grow a
modelled tee/redirect construct Retry can carry.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag migration

* Bring the sibling rows up to date, and stop spot-fixing: full sweep this time

review 43501 cited three stale siblings; a systematic pass over every
vocabulary and lens claim in the document found three more. All six verified
against the tree rather than reasoned about.

Cited:
- host_prelude.dag row claimed 'residual typed ShellStmt builders'. ShellStmt
  occurs ZERO times in that file, and its own witness_invocation_doc records the
  former builders as dissolved with the typed WitnessBin path.
- local_tidy_spec row said the pre-push hook emits 'via serialize_bash'. Doubly
  wrong: the sidecar is deleted AND this hook never used one -- githooks_pre_push
  _emit.dag builds it with concat. That makes it a genuine live punch-list row
  (stays shell, should be EMITTED rather than concat-assembled), not a closed one.
- The section-4 trigger footnote I wrote last round said the lens 'is inert by
  design', contradicting 4.F in the same edit pass. It is live but deliberately
  green on ComputedApplication.

Found by sweeping rather than by citation:
- The category legend defined 'oracle/scaffold' as 'serialize_bash retained only
  for a test' -- defining an empty class by a deleted mechanism instead of by its
  role.
- The 4.0 probe table's P7 row, like P6, needed labelling as a finding at
  78f43c3 rather than a live surface.
- 1.B said 'they emit through the v2 bash rows' of all three bootstrap rows,
  when two dissolved to typed reconcile and emit nothing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag migration

* Delete the superseded TeeTo disposition, and name the rule that keeps failing

review 43513 is correct. When I re-stated the TeeTo finding for #7293 I wrote
the new disposition and left the old one standing directly beneath it. The two
are mutually exclusive: the new one says #7293 deliberately DELETED the inert
declaration; the old one directs the owner to THREAD that declaration through
the retry path and uses renaming it as the acceptance bar. A worker could have
executed the rejected fix. Deleted rather than struck -- the surviving paragraph
already records the direction change and why it is correct, so nothing readable
was lost.

Swept for other duplicate dispositions: exactly one remains, and its mention of
the old direction is explicitly marked as the path not taken.

Also added the second method rule to 4.G, because this is now the dominant
failure across eight rounds and the note only covered the grep half. The
recurring root was never getting a fact wrong -- it was writing the corrected
fact BESIDE the stale one and leaving both, which is strictly worse than the
original error because the stale half then looks reviewed. Rule: delete a
superseded directive; strike it in place with the reason only when the
correction is illegible without it (as with 5.E's refuted bullets); never
simply append.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Fix the third 'inert' slip, and separate refuted-plan from completed-plan

review 43519 (APPROVE, non-blocking) caught the word 'inert' surviving in the
4.F ledger footnote at :354, in the same edit pass where :306 says the lens is
LIVE and :522 explicitly warns that calling it inert was wrong. Third time I
have written it wrongly. Fixed to 'already live, deliberately green on the
computed concats'.

Swept every remaining occurrence: :306 denies it, :509/:514 are about the TeeTo
DECLARATION being inert (a different subject, still accurate pre-#7293), and
:143 quotes the superseded text, which is correct usage.

While in :143 I also split a conflation of my own making. It said both halves of
the old terminus were 'refuted by execution'. Only the brand was refuted -- it
does not work, the idea was wrong. The lens directive was overtaken by
COMPLETION: #7184 had already activated it. Both read as 'stale directive' but
only the first means the plan was mistaken, and a reader deciding whether to
revisit an approach needs to know which one they are looking at.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag migration

* Classify HOW each superseded directive died: refuted vs completed vs partial

review 43522 is correct on both, and both sit in the very bullets where I
introduced the refuted-vs-completed distinction one round earlier -- I applied
it at :143 and left the bullets it was about still conflated.

- The lens directive was labelled REFUTED. It was COMPLETED: #7184 activated the
  lens and it is live. What is true is that activation alone was never
  SUFFICIENT (deliberately green on ComputedApplication, so it could not catch
  the #7064 computed-join fake). Insufficient is not wrong, and labelling it
  refuted would send someone to re-argue a settled design.
- The typed-argv bullet was labelled 'held ... landed'. Verified against the
  tree: ShellOnHost.script is RetainedShellScript, whose body is a STRING
  (host_effect_realize.dag:167, retained_shell_script.dag:9-10) -- a record edge,
  not the List<String> retype the bullet describes. The doc's own ruling block
  at :619 already said these are distinct sinks. Marking it landed deleted live
  5.A/5.B work from the plan.

Swept for the same defect and found one more I had written myself: Sequence step
2 struck 5.E through entirely as 'LANDED #7184', retiring the same open
typed-argv edge. Corrected.

Added the third method rule to 4.G, since this class outlived both earlier
rules: a stale directive dies one of three ways -- refuted (never retry),
completed (do not re-do), partially superseded (part is live residue) -- and all
three read identically as 'out of date'. A bare strike-through loses exactly the
information a reader needs, and the partial case is the dangerous one because
striking it whole retires work that is still open.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Make the census receipt reproducible: exclude the census document itself

review 43530 is correct and the finding is sharper than a miscount. 4.G states
its counts come from an unscoped git grep -- . , but this document is a census
OF those names and now contains 11 RawLine lines of pure self-reference from its
own corrections. Run the documented command and you do not get the documented
number, which destroys the one property a census receipt exists to have.

The classification was never wrong -- six occurrences, none a construction site
-- but 'six' is only true excluding this file. Now stated explicitly, with a
copy-pasteable command carrying the pathspec exclusion that reproduces exactly 6,
and the per-file split (1 + 4 + 1).

Recorded two further reproducibility traps while there, since a stated command
is a promise: git grep -c counts matching LINES while git grep -o | wc -l counts
OCCURRENCES, and the two differ wherever a line names a term twice; and any
count is relative to a commit.

Self-reference is the general hazard -- any document that inventories a term
becomes a source of that term, so its own counts decay as it is edited. The
exclusion is what makes the number stable under further editing of this file.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* True up the last three sentences still describing the closed string sink as open

review 43537 is correct, and it is the failure the method note I added two
rounds ago describes: a stale directive left beside its correction. Three sites,
not the one cited -- I swept the claim rather than the line.

- 5 intro (:536) called shell.Exec.Run / ShellOnHost{script: String} 'the
  remaining hole'. Verified: host_effect_realize.dag:167 types that edge as
  RetainedShellScript, whose body is a String INSIDE a record -- so a hand
  assembled String no longer typechecks there and the free minter is deleted.
  COMPLETED by #7184, not open.
- The 5.E heading was imperative -- THE ENABLER THAT MUST COME FIRST -- for work
  that has landed.
- Its premise paragraph was present tense: rows 'can be faked', the sink 'is
  reachable'. Both now past tense.

Kept the superseded intro sentence with a marked supersession block rather than
rewriting it, because the four-path end state it introduces is still the live
plan and only its stated blocker changed -- that is the strike-in-place case the
method note reserves for corrections that are illegible without the original.

Also recorded the nuance that matters for anyone reading the wall as absolute:
what closed is SILENT faking. Authoring a counted RetainedShellScript row with a
hand-built body remains possible by design -- it is the reviewed escape carrying
a reason and a dissolves_to, and that visibility is the mechanism, not a leak.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Stop reporting an unmerged branch as current state, and rewrite instead of appending

review 43544 is correct on both, and the first is the more serious of the two.

1. The TeeTo disposition said 'mostly DISCHARGED by #7293'. #7293 is OPEN.
   Verified on origin/main: ci_spec.dag:226 still constructs TeeTo, and
   05_emit_orchestration.dag:628 still returns only r.command, silently dropping
   capture. The defect is LIVE. An unmerged branch is not current state, and a
   census reporting a branch's intended result as done is the fabricated-green
   failure DESIGN 5 names -- if #7293 were abandoned this row would have quietly
   retired a real violation. Row now states the live defect first, the in-flight
   fix as in-flight, and the post-merge residue as explicitly not-yet-current,
   with the flip conditioned on #7293 actually landing.

2. At the 5 intro I APPENDED a supersession notice under the stale sentence
   instead of rewriting it, leaving two mutually exclusive current-state claims
   in one paragraph. That misapplied this document's own rule: strike-in-place
   is reserved for corrections illegible without the original, and this was not
   one -- the four-path end state survives a rewrite intact, so only the blocker
   claim needed replacing. Rewritten inline; the notice is gone.

Swept the rest for the same in-flight-as-landed error. The remaining DISCHARGED
and LANDED claims check out: line 201's is correctly scoped to
dag/gunbc/live_deploy/ and holds on main, and #7265 is genuinely merged.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Reconcile the canonical authorities that still call the transport lens inert

review 43555 is correct, and it closes a gap I identified myself several rounds
ago and deferred with reasons that have since expired.

DESIGN (dag/gunbc/design_document.dag, the source DESIGN.md is generated from)
and dag/gunbc/plans/fail_closed_lockdown.dag both still described
host_language_transport_script as inert. DESIGN is the single authority; leaving
it contradicting this census means the census removes a misdispatch while the
MORE authoritative document keeps dispatching it. That is exactly the 3
violation this PR exists to fix, one layer up.

What changed, minimally -- the premise, not the conclusion:
- DESIGN said meta-exec is unwalled BECAUSE the lens is inert. The conclusion
  holds (module-level sequestration is genuinely still open) but the reason was
  false: #7184 activated the lens, and the transport-script hole it was cited
  for is closed by construction (ShellOnHost.script is the RetainedShellScript
  record, free minter deleted). Now says module-walled, with the lens status
  corrected inline and the still-open part named precisely.
- fail_closed_lockdown 2 listed the lens under coverage-by-illusion with state
  inert; it is now LIVE (#7184) with the ComputedApplication nuance stated, so
  nobody reads it as a fail-open hole.
- Its promote-or-delete task no longer lists this lens among the inert ones to
  promote -- that work is done.

I deferred this earlier on three grounds: sequencing behind this PR, collision
surface with four in-flight PRs, and needing regen. The first two have expired
(#7293 and #7298 are at the approval bar and touch neither file), and the third
is handled by the heal_generated_artifacts job, which regenerates via main_wet
and pushes DESIGN.md back to the branch. Expect one transient drift red before
heal lands the regenerated bytes; that loop is byte-idempotent by design.

I applied the same standard to myself that I applied to a child an hour ago: a
defensible deferral that blocks is still blocked.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag migration

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Fix parse error in design_document.dag + regenerate both artifacts

b338924 introduced an unescaped `"` inside a .dag string literal in
dag/gunbc/design_document.dag. The quote closed the string early and the
remainder lexed as garbage:

  for_each_parsed_module_binding: parse error in dag/gunbc/design_document.dag:
  expected RParen, found Unknown

This took down BOTH `regen` and `heal_generated_artifacts` with the same
panic. heal could not absorb it: heal runs main_wet, which must parse the
authority to project it, so the bad edit killed the healer itself. This was
a defect in the diff, not the transient drift I predicted.

- escape both quotes as \" (the idiom every sibling li(text:) already uses)
- regenerate DESIGN.md and docs/plans/fail-closed-lockdown.md via main_wet

The lockdown .md was separately drifted: b338924 edited the .dag authority
without regenerating its projection. The parse error was masking that red.

Verified by execution, not by a text heuristic: built gunbc locally
(CTRL_BUILD_BYPASS_SHIMS=1 -- `ctrl-build` exits 0 but builds remotely and
uploads 0 artifacts, leaving no local binary) and ran the exact CI command
`gunbc run --entry dag/tools/generated_artifact_gate.dag --function main_wet`
-> ExitSuccess. main_wet wrote exactly these two artifacts, nothing wider.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag migration

* DESIGN: Phase 1 orchestration emit is PARTIAL, not LANDED

An audit of the two shell-arc roadmap rows prompted re-verifying DESIGN's
own Phase-1 claim against current main. It does not hold:

- `While`   — one production consumer (`ci_floor_peak_emit`), and its cond
              and body are still raw shell strings
              (`ci_floor_peak_while_body_command: String = "d=$(dirname ...)"`)
- `BoundedPoll` — ZERO production construction sites. Only
              `orchestration_bounded_poll_emit_test.dag:23,36` build one;
              production has match arms only, two returning `Absent`.
- `Retry`   — `orch_retry_body_command` takes `list_head(body.steps)` and
              never inspects the tail, so a multi-step Pipeline emits as a
              one-step retry with no refusal, no diagnostic, no count; and
              `orch_emit_retry_run` hardcodes `redirect: Absent, capture: Absent`.

The Retry tail-drop is a DESIGN §5 silent-widen (fabricated plausible
output from an input it cannot faithfully represent), not a §6 residue --
so it is a defect, not merely unfinished scope.

This PR exists to make lane claims match the tree; leaving a verified-false
LANDED in the same li(text:) entry it edits would undercut that premise.
Approvals covered the diff, not DESIGN's unedited sentences.

Verified: quote scan clean, then `main_wet` -> ExitSuccess, writing DESIGN.md
and nothing wider.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag migration

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Bring shell_emission_model along: Phase 1 is PARTIAL there too

review 43574 (cursor, REQUEST_CHANGES) is correct. The previous commit
corrected DESIGN to PARTIAL and left dag/gunbc/plans/shell_emission_model.dag
asserting "Phase 1 LANDED (#6832)" in three places -- a §3 parallel-authority
fork on the same fact, created by the PR whose purpose is removing them. Same
failure the census documents: a correction is not done until the text it
supersedes is gone.

Corrected surgically, not by blanket replace, because "LANDED" was not
uniformly false:

- Phase 1 headline -> PARTIAL, with the three verified specifics and a note
  that roadmap_authority.dag `6-shell-intent-phase1` needs the same rewrite.
- The two While/BoundedPoll claims -> split. `While` emission genuinely DID
  land in #6832, so that survives, scoped to `While`. `BoundedPoll` is marked
  UNCONSUMED: its only construction sites tree-wide are in
  orchestration_bounded_poll_emit_test.dag, and both production match arms
  return Absent -- counting it as landed measures capability, not use.

Two `LANDED (#6832)` strings remain on purpose and are now true as scoped.

Verified: rebuilt the seed first (the main merge brought src/v1 emitter
changes #7292 that the prior binary predates), quote scan clean, then
main_wet -> ExitSuccess writing only docs/plans/shell-emission-model.md --
no unrelated drift from the fresh seed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag migration

* Scope the #7184 wall honestly: ShellOnHost only, shell.Exec.Run still open

review 43600 (codex, REQUEST_CHANGES) is correct on both counts, verified
against the tree.

The census claimed a raw-string shell.Exec.Run / hand-built transport was
"already unwritable" and that #7184 "retyped that edge" to RetainedShellScript.
Neither holds:

- #7184 record-walled the ShellOnHost REALIZATION edge
  (ResolvedHostEffectCell.ShellOnHost { script: RetainedShellScript },
  host_effect_realize.dag:167) and deleted the free minter
  transport_script_from_body. That part is real.
- It did NOT retype shell.Exec.Run, which still declares
  `input { script: TransportScript }` (extdeps/shell/exec.dag:26) over a
  TRANSPARENT brand, `type TransportScript = String where brand(...)` (:16).
  So `"..." as TransportScript` remains writable from any module.

Direct in-tree proof the class is still writable:
  src/v2/test/fixture/meta_exec_confinement_scan/leak/plant.dag:6
    let result = shell.Exec.Run(script: "true" as TransportScript)

That sink is guarded by LENSES (meta_exec_confinement, which the fixture feeds,
plus host_language_transport_script) -- validation, not construction. DESIGN §5
is explicit that a lens concedes the bad state is writable. The code already
said so: retained_shell_script_wall_note files the surviving cast-mint's
closure on the visibility-grants lane (the Reference verb governs base->brand).

Corrected in three places so the authorities do not fork -- the failure
review 43574 caught one round ago:
- census:1 "PARTIALLY landed", punch-list NOT closed at the top
- census:2 the sink "remains open", with what #7184 did and did not do
- design_document.dag "closed by construction ON THE ShellOnHost ROUTE ONLY"

This is the third "wall landed" claim in this lane to overstate its scope. The
recurring error is checking that a carrier exists rather than that every route
into it is closed -- named in the census so the next reader inherits the rule,
not just the corrected number.

Verified: quote scan clean, main_wet -> ExitSuccess writing only DESIGN.md.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag migration

* Sweep the fourth BoundedPoll claim: sweep by CLAIM, not by string

review 43607 (cursor, REQUEST_CHANGES) is correct. shell_emission_model.dag:31
(and its .md projection) still read "#6832 ... which landed While/BoundedPoll
emit for the ci_floor_peak_emit readiness-poll", contradicting the same file's
now-corrected rows at :19, :44 and :50 -- two mutually exclusive instructions
in one authority pair.

The claim is wrong for BoundedPoll specifically: the readiness-poll reaches
only While. #6832 did land BoundedPoll EMIT, but it never acquired a
production consumer, so citing the poll as evidence of both is false.

Root cause of the miss, which matters more than the line: I swept the previous
round by grepping the exact string "LANDED (#6832)" and this site says
"landed" in running prose. Sweeping by STRING finds the sentences you already
know about; sweeping by CLAIM finds the ones you do not. Re-swept properly --
every BoundedPoll mention tree-wide, checked for an adjacent landing claim --
and this was the only survivor in files I own.

roadmap_authority.dag:972 carries the same overstatement in its row brief and
is deliberately NOT touched here: it is another lane's authority, already
flagged to its owner along with the Phase 1 / 6-shell-slice2 rewrites.

Verified: quote scan clean, main_wet -> ExitSuccess writing only
docs/plans/shell-emission-model.md; stale phrasing count in the projection
is now 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag migration

* WIP: shell -> dag migration

* Scope every wall-closure claim to ShellOnHost: 9 sites, enumerated by subject

review 43614 (codex) cited lines 618 and 689. Enumerating by SUBJECT rather
than by phrase found SEVEN more asserting the same thing, so this fixes nine:

  301  §4.F heading        "Phase-3 WALL -- LANDED"
  303  §4.F true-up note   "The wall landed on 2026-07-24"
  366  §4.F net note       "the construction wall landed (#7184)"
  413  §5.B status         "(the wall landed, #7184)"
  414  §5.E status         "construction wall -- LANDED #7184"
  544  §4 trigger          "the wall stops new concats"
  616  §5.E heading        "LANDED #7184 (close the string sink)"
  618  §5.E true-up note   "It is closed; both are now past tense"   [cited]
  689  dissolution trigger "the wall stops *new* concats"            [cited]

All now scope the landed part to the ShellOnHost record edge and say the
shell.Exec.Run sink remains open (transparent TransportScript brand,
extdeps/shell/exec.dag:16,26).

Method change, which is the actual fix. The previous two rounds swept by
guessing PREDICATE phrasing ("sole mint", "already landed", "transport wall")
and missed sites that say "string sink closed" or "prevents new concats".
This round enumerated by SUBJECT -- every line naming #7184,
RetainedShellScript, TransportScript, sink, wall, concat, minter, ShellOnHost
(88 lines) -- then read all of them and triaged. Predicate-guessing cannot be
exhaustive because it requires knowing the wording in advance; subject
enumeration is bounded and checkable.

Two false negatives worth noting: my own filter twice missed correctly-scoped
text because markdown bold splits the phrase ("It is **not** the global
transport wall" does not contain "not the global"). A substring scan over
marked-up prose is not a reliable oracle in either direction.

Left deliberately unscoped because they are accurate as written: per-site
punch-list rows marked LANDED (A1, A2, hostname) -- those are individual
migrations that genuinely completed; the minter-DELETED rows; and the §5.E
ruling-block quotes describing why branding failed and a record works.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Scope transport-script wall to ShellOnHost

Correct the fail-closed census after review 43625: RetainedShellScript makes bare strings unwritable only at ShellOnHost.script. Direct shell.Exec.Run computed and cast inputs remain open until meta-exec confinement.

* Refresh shell census after PR2a merged

Record #7293 as landed, discharge the TeeTo dual-representation finding on current main, and keep #7303's separate retry-fidelity residue explicitly in flight.

* Separate meta-exec import and construction walls

Refresh the shell-intent authority against the empty exception roster and the transparent TransportScript brand: Wave A1 landed import validation, while the direct computed/cast input path remains open pending construction confinement.

* docs(shell): scope transport wall to ShellOnHost

The phase-3 action table still generalized the record wall across direct shell.Exec.Run. Record the live string-taking bridges and transparent cast path explicitly, as requested in review 43645.

* docs(shell): keep direct Exec construction open

Scope the enabler claim to the ShellOnHost record wall and preserve the direct shell.Exec.Run construction-confinement work identified by review 43653.

* docs: distinguish retry refusal from tail drop

* docs: mark shell intent phase one partial

* docs: keep direct Exec fake risk live

* docs: reconcile shell roster after merged slices

* docs: make remaining shell roster symbol-exact

* docs: account for regen rustfmt emitter

* docs: distinguish meta-exec import and construction walls

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant