Repository navigation
Compiler guarantee recovery — gap analysis vs the recovered THESIS.md tiers (docs + doc-graph binds) - #7486
Conversation
The analysis note landed as an orphan doc: gunbc.doc_graph_roots states that "an unbound doc is an orphan, loudly", and CI duly refused at be1a001 with doc_graph_has_no_orphan_docs returning false in both the dag/test/claim and src/v2/lens consumers. Registered as two HandAuthoredDocBind rows rather than one, because the analysis binds to two independent carriers and they dissolve on different triggers: - v1.compiler.infer module_skips_direct_call_arg_check — the one named violation of the dimension contract's "no escape hatch" clause (docs/thesis/correctness-dimensions.md), exempting v2.* and v1.compiler.* from direct-call argument checking. - v2.std.constraints solve_constraints — passes graph.root as source_facts, algebra AND the sole candidate, so the grounding proof reduces to well_formed(root) and is relabelled CanonicalGrounding. Green by execution, both directions: RED is the CI failure at be1a001; GREEN is all five witnesses in dag/test/claim/doc_reachability_witness_test.dag plus doc_graph_is_clean in src/v2/lens/doc_reachability_test.dag passing locally against the live docs/ tree. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rections adopted, receipts verified
Adopted (all verified on main this pass):
- Cardinality reclassified UNEXPRESSIBLE -> RepresentableButForgeable, not
statically propagated: v2.std.refinement exists, NonEmptyList fixture +
green cardinality_fold_propagation_test exist, and
refined_vacuous_stub_pack's Rejected arm returns Refined { base } (the
carrier proves nothing). New Sec 4b: the operator independently
re-directed this exact guarantee on 2026-07-04
(interface-summary-declared-use-arity.md Sec 3.1, "hard error in the
language") — the intent is not lost; the lattice design pass (FLAG E)
never started.
- Failure history rewritten (Sec 2): the exemption dates to 2026-06-08
(a13fb57), pre-bankruptcy; correctness-dimensions.md marked type
safety "Yes (blocking)" while return position was unchecked — so the
ledger overstated, then the auditable contract was deleted. The
pipeline_steps_empty_arm_note receipt is withdrawn: empty there is a
deliberate total semantics, not a priced-out wall.
- Status vocabulary widened to the review's 11-state lattice; v2 terminal
calibrated (validate_then_compile door + loop-bound wall are real;
InferredTree is still not a proof boundary); application-arity row added
(formal-driven walk, positional fallback for misspelled labels,
ArityMismatch is constructor-arity); PatternLookupBlocked's silent []
arm confirmed (PatternDynamic does diagnose — review corrected there).
- Sec 7b: DESIGN.md is projected from gunbc.design_document, and its "5
behaviors" is stale against v2.std.node's six (Match) — the guarantee
authority lands as .dag rows, never hand-edited prose.
- Sequencing reconciled to 7 stages: claims authority + expecting-red
probe corpus together; zero-resolution method wall now, ambiguity wall
census-first; cardinality vertical slice third.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…el (review 45299) The first HandAuthoredDocBind trigger said "re-homed into DESIGN.md as its specification half" — wording that predates the reconciliation pass's Sec 7b finding that DESIGN.md is a projection of gunbc.design_document. As written, a direct DESIGN.md edit could have satisfied the trigger, which is exactly the Sec 3 parallel-representation failure Sec 7b names. Trigger now requires .dag claim rows projected via gunbc.design_document and states explicitly that a hand edit does not satisfy it. All five doc-reachability witnesses re-run green by execution after the edit. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Fixed in dd7e585. review 45299's finding was correct and self-inflicted: the bind's trigger text was written before the reconciliation pass discovered (§7b) that DESIGN.md is a projection of |
…the safety ladder as the organizing frame Review 45305, both findings verified correct and fixed: - doc_graph_roots: the two HandAuthoredDocBind rows shared (home, slug), which the carrier's own note defines as the symbolic identity — one doc had two independently removable authority rows. Merged to ONE row whose trigger anchors both carriers (module_skips_direct_call_arg_check, solve_constraints) and gates dissolution on BOTH conditions, with the merge provenance recorded on the carrier. (Observed, not fixed here: module-identity-storage-binding-design and accelerator-demo-roundtrip also carry same-slug duplicate rows — pre-existing, follow-up material.) - Sec 8b's example-0 block still said "unexpressible", contradicting the Sec 4 reclassification and mis-aiming the archetypal RED at inventing a carrier instead of sealing/propagating the one that exists. Rewritten: the RED exercises unforgeable construction + seam propagation, expected refusal at the 0..n -> 1..n seam. Operator direction, same pass: the safety ladder is now Sec 1b, the organizing frame — R3 structurally-impossible / R2 structural guarantee / R1 testable / R0 mitigatable / below-the-floor silent (forbidden, Sec 5). Three rules: floor absolute; climb to a STATED ceiling (mathematical / capability / price — the capability ceiling is unforgeable construction, blocked on reference-level visibility: the keyword set has no private/sealed/opaque); reported rung == measured rung, lens-checked for inflation and stalls. Includes the specimen table (the session's classes placed, cross-representation == as the exemplar full climb) and the non-goals roster (external reality, arbitrary predicates, budgets, optimality, self-governance, byte-identical self-emit — low ceilings BY DESIGN). Stage 1 claim rows gain current_rung / ceiling / next_rung_trigger. All five doc-reachability witnesses re-run green by execution after both file changes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Both findings of review 45305 verified correct and fixed in a78e4bf. Same-slug duplicate binds: merged to one Stale "unexpressible" block: the §8b example-0 block was a leftover from before the reconciliation pass and contradicted §4's Same push also lands §1b (operator direction, same session): the safety ladder — R3 unwritable / R2 compile refusal / R1 witnessed / R0 typed-at-runtime / below-the-floor silent (forbidden) — with the specimen table, stated ceilings (mathematical / capability / price), the reported-rung == measured-rung rule, and the non-goals roster. All five doc-reachability witnesses re-run green by execution after both changes. |
|
review 45310 (codex): confirmed and fixed in 5130f7a — and it deserves to be called out as the honesty mechanism working exactly as specified. The specimen table reported "cross-representation ==" at R3-done while only the numeric-tower subset is grounded (#5428); DESIGN's own open thread lists the Same push, per operator directive (2026-07-31): the guarantee ladder lands in the design authority as §4b of Verified by execution after the changes: the four generated-artifact drift witnesses (fixed-point + RED control + all-known + registry-complete) and all five doc-reachability witnesses, green. review 45308 (cursor, APPROVE on re-review): no action required. |
Reverts accidental regression of HandAuthoredDocBind primary_work + additional_works, merged accelerator-demo-roundtrip row, guarantee-recovery dual anchors, and doc_reachability construction witnesses (#7486/#7489). Updates sha256_digest_content_hash_convergence_note to match the construction-walled bridge (as_content_hash_cryptographic), not wire-form rendering prose. Co-authored-by: Cursor <cursoragent@cursor.com>
…7480) * Ground ContentHash on hash family (Phase A: carriers + R0 backstop) Rebased onto main. ContentHash becomes a family coproduct (Fnv1a64 | Sha256Hash | Sha1Hash) with where-refined hex carriers, compare_content_hash cross-family refusals, OCI algorithm-qualified digests, and construction walls (reviews 45496/45505). Co-authored-by: Cursor <cursoragent@cursor.com> * Fix review 45522 regressions and CI compile-gate timeout. - Restore guarantee-ladder and shell→intent authority in design_document.dag and guarantee_ladder_nodes/roadmap_focus in roadmap_authority.dag from main; keep intentional chash Fnv1a64Structural migration only. - Remove git_sha1 witness Absent fallback (mint must succeed or test reds). - Raise v1-compiler-tests compile-gate step budget to 10m (run 30646205825). Co-authored-by: Cursor <cursoragent@cursor.com> * chore: regenerate drifted generated artifacts (ci auto-heal) * Update DESIGN open-thread row for ContentHash Phase A landing (#7480). Replace the stale pre-migration §3 residue with Phase A receipts and an explicit Phase B dissolve-on remainder (union-level == typecheck refusal). Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Ground ContentHash on its hash family so a cross-family comparison is un * chore: regenerate drifted generated artifacts (ci auto-heal) * Move OCI digest algorithm predicates to extdeps.container.oci.digest. Review 45539 flagged OCI-specific algorithm grammar in std.content_hash as a §3 authority inversion. The predicates and where-refinement entry point now live at the OCI digest authority; infer imports oci_other_digest_algorithm from there and stage0 emits extdeps_container_oci_digest.rs. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Ground ContentHash on its hash family so a cross-family comparison is un * WIP: Ground ContentHash on its hash family so a cross-family comparison is un * fix(stage0): commit emitted extdeps_container_oci_digest seed module Regen emits the OCI digest module but it was never tracked in git after rebase, which broke cargo fmt and the build gate on PR #7480. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Ground ContentHash on its hash family so a cross-family comparison is un * fix(oci digest): realign seed parse path and emitter Optional Present arm Review 45614: use `encoded: encoded` in the other-algorithm parse arm (oci_encoded_digest returns NonEmptyStr?, not a record). Route split parts through oci_wire_digest_parts_from_split so the seed types as String. Fix v1 emitter construction so Present{value: <branded scalar cast>} lowers to Some(...) instead of Optional::String. Restore extdeps_base module path for extdeps_container_oci_digest. Co-authored-by: Cursor <cursoragent@cursor.com> * chore: regenerate drifted generated artifacts (ci auto-heal) * WIP: Ground ContentHash on its hash family so a cross-family comparison is un * WIP: Ground ContentHash on its hash family so a cross-family comparison is un * WIP: Ground ContentHash on its hash family so a cross-family comparison is un * WIP: Ground ContentHash on its hash family so a cross-family comparison is un * chore: regenerate drifted generated artifacts (ci auto-heal) * fix(emit-on-demand-host): refuse crypto ContentHash at structural projection Review 45661: replace emit_host_identity_structural sentinel collapse with typed outcome coproducts (EmitHostStructuralIdentityRefusedCrypto, ResolvedBuildContextIdentityRefusedCrypto, ToolchainIdentityRefusedCrypto). Distinct Sha256/Sha1 digests no longer share one fnv1a64 cache key. Witness resolved_build_context_identity_refuses_sha256_observed_tool exercises the refusal path; structural fixture tests route through outcome helpers. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Ground ContentHash on its hash family so a cross-family comparison is un * test(emitter): fix optional Present witness include/exclude patterns The exclude Optional::String substring matches lawful return-type emission; use the broken-body pattern String { value: text instead so the witness discriminates Some(...) lowering from the generic Optional::String variant path. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(emit-on-demand-host): serialize ContentHash cache path segments Route native cache workspace path construction through serialize_content_hash instead of bare as String casts so cache keys use the canonical wire form (review 45713). Co-authored-by: Cursor <cursoragent@cursor.com> * fix(emit-on-demand-host): drop parallel family field from crypto refusals ContentHash already carries its family; RefusedCrypto variants now hold only component and identity. Witness derives family via content_hash_family (review 45721). Co-authored-by: Cursor <cursoragent@cursor.com> * fix: restore doc-graph construction walls from main (review 45726) Reverts accidental regression of HandAuthoredDocBind primary_work + additional_works, merged accelerator-demo-roundtrip row, guarantee-recovery dual anchors, and doc_reachability construction witnesses (#7486/#7489). Updates sha256_digest_content_hash_convergence_note to match the construction-walled bridge (as_content_hash_cryptographic), not wire-form rendering prose. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Ground ContentHash on its hash family so a cross-family comparison is un * fix(oci-digest): construction-wall OciOtherDigestEncoded payload OciOtherDigestBody.encoded is now NonEmptyStr where oci_other_digest_encoded (descriptor.md charset), not a forgeable bare NonEmptyStr (review 45731). Infer where-refinement enrollment mirrors oci_other_digest_algorithm. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(oci-digest): emit parse wire path without NonEmptyStr cast panic Use parts.encoded as OciOtherDigestEncoded after oci_encoded_digest validates (same pattern as sha512 hex), avoiding emitter panic on String→NonEmptyStr cast in the OtherDigest parse arm. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(oci-digest): OciOtherDigestEncoded as String where for emit parity NonEmptyStr where oci_other_digest_encoded made the emitter emit panic() on String→NonEmptyStr cast in parse_oci_content_digest_wire. String where oci_other_digest_encoded matches OciSha512DigestHex and keeps the construction wall (review 45731). Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: gunbc oracle * WIP: gunbc oracle * fix(content-hash): project .digest at string boundaries; repair the last floor reds Three sites where a structural hash reached a String position: - roadmap_dispatch_actuator dispatch_attempt_key and roadmap_belt_actuate belt_uuid_hex32 cast the content_hash_atom / content_hash_combine_structural RESULT to String. content_hash_atom returns Fnv1a64Structural (a record) since the family grounding, so the cast no longer yields the digest text. Notably this is not a typecheck error -- roadmap_belt_actuate's own uuid witnesses passed while the value was wrong -- so the only witness that caught it was the one comparing a parsed branch against the minted one (attempts_parse_roundtrips_the_minted_branch). Both now project .digest, the idiom site/moodboard.dag already used. A regex + paren-matching sweep over every .dag confirms no structural result is cast directly to a string type anywhere. - source_integration_landing_spine's witness compared a receipt against the raw literal "multiplicity-receipt" after construction moved to content_hash_of_value(...), i.e. the field now holds a hash of that string. Verified by execution: dispatch_attempts 9/9, roadmap_belt_actuate uuid witnesses 3/3, source_integration_landing_spine 22/22. (roadmap_belt_actuate's seven belt_exec witnesses fail locally with "hermetic mode: no mock_response for operation Check" -- they shell out to a real host process and never reach hash code; that is the hermetic runner refusing to fabricate, not a regression.) * fix(content-hash): re-home ContentHash imports that arrived with the main merge The floor's dag_compile_clean_gate went red on the merge commit with one hard diagnostic: name 'ContentHash' not found in module 'std.types'. Two witness files came in from main still importing ContentHash from std.types and initializing it from a string literal -- the shape this PR's family grounding removed: dag/test/claim/check_coverage_admission_witness_test.dag (4 rows) src/v2/test/claim/walk_plan_schedule_lens_test.dag (1 row) Both now import from std.content_hash and mint through content_hash_of_value, matching their consumers, which take the union ContentHash (merge_admission check_coverage_admits; the walk-plan target field). My pre-merge sweep for this class was clean and stayed correct -- these files did not exist on this branch when it ran. The sweep has to be re-run after each merge, not once. Re-run now: zero std.types ContentHash imports and zero string-literal ContentHash initializers corpus-wide. Verified by execution: whole-tree `gunbc compile --target dag` reports 0 hard diagnostics (the gate's own check); check_coverage_admission 12/12; walk_plan_schedule_lens 2/2. * WIP: gunbc oracle * revert(v2-node): restore node.dag hash surface to its 2804c8b state The WIP auto-commit at 8212c2a captured a mid-edit working tree: a speculative retype of v2.std.node content_hash / symbol_identity_digest / bag_hash_digest / byte_offset_cache_key_fingerprint to return Hash, snapshotted BEFORE I had fixed a stray argument label it introduced -- fn symbol_identity_digest(sym: Symbol) -> Hash { structural: content_hash_atom(value: sym) # not an expression } -- so that broken form went out on the branch. My subsequent `git checkout --` restored to that bad commit rather than to the intended baseline, which is how it survived. This restores the file byte-for-byte to 2804c8b. The retype is reverted on its merits regardless of the label bug: executed against the three failing classes (Variant-cast, digest-on-String, atom_identity_hash arity) it fixed NONE of them, so it was an unverified edit to a load-bearing substrate file with no demonstrated benefit. The real roots are recorded in the PR comment: five `ContentHash where brand(...)` types that can no longer be cast, and the raw atom_identity_hash / std.content_hash dual surface in 02_parse and self_host. * WIP: gunbc oracle * chore: regenerate drifted generated artifacts (ci auto-heal) * Project the corrected ContentHash bridge claim into DESIGN.md sha256_digest_content_hash is the VALIDATING PARTIAL bridge Digest->ContentHash?; as_content_hash_cryptographic is the TOTAL injection. Regenerated via tools.generated_artifact_gate main_wet; byte-stable on a second pass. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: gunbc oracle * WIP: gunbc oracle * WIP: gunbc oracle * WIP: gunbc oracle * WIP: gunbc oracle * WIP: gunbc oracle * WIP: gunbc oracle * WIP: gunbc oracle * WIP: gunbc oracle * WIP: gunbc oracle * WIP: gunbc oracle * WIP: gunbc oracle * WIP: gunbc oracle * Restore the v1 seed sources an auto-commit reverted to main The session auto-commit fired while src/v1 was checked out to origin/main for a control build, snapshotting main's version as this branch's HEAD; a later 'git checkout HEAD -- src/v1/' then restored that poisoned state. Three files lost their reviewed content and are restored from f9dc5a8: 00_core.dag — 'predicate not enforced at compile time' advisory reason 04_infer.dag — lower_hex_{16,40,64,128} / oci_other_digest_* where-predicates and the structural content-hash rewrite 05_emit_rust.dag — variant_surface_name + fn_returns_optional 05_emit_rust.dag is reconstructed onto main's newer revision rather than overwritten, so main's rust_btree_set_ord name-grain childless gate and its note are preserved; the result is byte-identical to f9dc5a8 apart from that addition. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: gunbc oracle * Remove temporary emitter-probe fixture Diagnostic scaffold for isolating the optional-payload cast emit defect; the repro is recorded in the PR discussion, not enrolled as a witness pending a decision on the emitter fix. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Record the optional-payload cast emit deficit as executing evidence Three poles, each holding one variable constant, isolate the trigger for the E0433 that blocks finding 3's oci_encoded_digest shape: refined return, no cast -> lowers to Some(..) (refined return is harmless) plain String? return, cast inside payload -> broken (the cast alone suffices) cast hoisted to a let -> STILL broken (refutes the workaround) The third pole is load-bearing: hoisting does not avoid the defect, so no respelling both constructs the carrier and lowers correctly, and the emitter repair is required rather than optional. An earlier draft of this file claimed the hoist WAS a working scaffold spelling and briefly landed that spelling in oci_encoded_digest; executing it refuted the claim, and both are reverted -- oci_encoded_digest keeps the reviewed inline shape. Poles 2 and 3 are known-red receipts: they assert the deficit is present, so they pass now and red when the emitter is repaired. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: gunbc oracle * WIP: gunbc oracle * Repair optional-payload cast lowering; regenerate the seed from the authority Confirmed name-loss point (by instrumentation, not by reading): the concrete-type peel in v1.compiler.emit_rust emit_rust_expr_record_lit. A cast reaching an optional payload gives the literal a concrete resolved type, so the peel replaced the authored "Present" with the payload's concrete name; emit_typed_record_lit then missed the optional arm and fabricated "Optional::String { .. }", which is not a Rust constructor (E0433). A probe printing variant_name/tn/peeled at the call site showed the authored name arriving intact and being overwritten. The standing variant_surface_name hypothesis was wrong as a single cause but is a real SECOND contributor: with the peel fixed, optional_variant still keyed off the resolved struct name until variant_surface_name reached the seed. Both were required; neither alone sufficed. The peel is suppressed only when the authored name is a built-in optional constructor AND the concrete type does not itself declare a variant of that name, so a user-defined "Present" still peels (variant_belongs_to_enum finds it) and ordinary variants are untouched. Variant identity is preserved, never inferred from the payload type. Authority is src/v1/05_emit_rust.dag. The seed could not regenerate the fix, so minimal bootstrap edits were lifted by hand and then PROVEN by regeneration: regen_stage0 --verify reports regen_divergence_count=0, so committed stage0 is exactly the fresh self-compile of the authority. Also restores cli_run.rs, the v1_interpreter R0 cross-family guard, and two more hand-written seed files that the earlier auto-commit poisoning reverted to main (the R0 guard is merged onto main's newer interpreter, not overwritten). Witness flipped from known-red receipt to permanent regression control (DESIGN section 4b): 6/6 including the Wrap::Holds and user-defined-Present negative controls. Nested-refinement receipt retains its polarity, 2/2. Whole-tree compile exit 0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Declare publication grants for the 17 ungranted added public paths The Stage-0 visibility guard (tools.publication_placement_gate, run as the Wet floor runnable publication_placement_gate_passes) diffs the publication cutover to HEAD and refuses any added public path with no Publish grant. It reported PublishGuardLocalViolation count=17, which is why the ci floor failed while build, regen and heal all passed. Six are this PR's: the OCI digest carrier, its generated stage0 projection, and the four ContentHash/emitter witness files. The other eleven arrived with main (the heal-revalidation and source-integration-proof-kernel lanes, ci_heal_dispatch, extdeps.github.workflows and the preflight emit pair); the guard diffs from the cutover rather than from the merge base, so it fires on the union and this branch cannot go green while they are undeclared. All seventeen are already merged and pushed to the public repository, so granting records the publication that already happened rather than newly exposing anything. Flagged rather than silent because eleven of the paths are not this PR's to classify. Gate re-run locally: ExitSuccess. publication_placement_gate_test 8/8. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: gunbc oracle * Converge the fnv1a64 dual surface at the 22 sites the re-key stranded The floor's discovery corpus surfaced 22 witnesses this PR broke, in two classes, both instances of the dual surface DESIGN section 3 tracks: v2 code calls the RAW v1 intrinsics while std.content_hash is the modeled surface over the same authority. Re-keying v2.std.node.Hash to Fnv1a64Structural made that fork observable, because a raw intrinsic yields a native String where the modeled carrier is a record. Class 1 (18) -- "cannot access field digest on String": raw atom_identity_hash flowed into Hash positions. Eleven call sites in v2.compiler.02_parse, v2.compiler.self_host and the parse_table_content_key witness now route through v2.std.node symbol_identity_digest, the modeled surface those modules already import. The substitution is value-preserving: content_hash_atom(v) is by definition structural_content_hash(digest: atom_identity_hash(v)). Class 2 (2) -- "atom_identity_hash requires exactly one string argument": the inverse, a structural passed INTO the intrinsic. v2.lens.interface_summary signature_fingerprint_of_node hashed a node content hash that is now a record; it projects .digest first. A direct cast was tried and rejected by the interpreter (cannot cast Record to Fnv1a64Structural), so the original hash-of-hash semantics are kept rather than changed. Plus one value mismatch: the live_deploy readiness witness compared site_artifact_digest(..) as String against the digests the served body embeds, which now project .digest. After this the raw intrinsics appear nowhere outside dag/std/content_hash.dag and the v1 builtin registry, which is the single-authority end state. Re-run green: parse_table_content_key 5/5, interface_summary_firewall 4/4, ingest_bridge 9/9, cross_language_add_python_to_typescript 4/4, inhabitant_neutralization 6/6, parse_table_memo_governed 9/9, self_host_realized_comparison_floor 6/6, parse_stamp_span_index 2/2, live_deploy readiness 25/25. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: gunbc oracle * Address review 2026-08-01: restore roadmap containment wall, narrow optional emitter, correct design authority Three blocking items from the review, each with executing evidence. 1. Roadmap containment wall (regression against the branch base). My earlier merge dropped main's rendered-node containment wall entirely: roadmap_rendered_ghost_count, both RED probes, and all three witnesses were absent from this head. Restored roadmap_spawner.dag from main wholesale (main was a strict superset there) and grafted the import block, note and three tests onto roadmap_authority_test.dag while keeping this PR's Fnv1a64Structural changes. 38/38 green, the count the review predicted. 2. Optional emitter classification was broader than its stated boundary. The fn_returns_optional disjunct is a fact about the ENCLOSING FUNCTION, so a user-defined MyOpt::Present built inside a `-> String?` function emitted Some(..), overriding an effective_parent that had already resolved correctly. Added the negative control the review asked for and CONFIRMED IT RED before changing anything. Then executed all seven poles with the function-wide arm removed: it was load-bearing for none of them, so it is deleted rather than gated -- resolved_type.return_cardinality == CardOptional is the expression-local statement of the same fact, and the disjunct was a second representation of it. 7/7 green; regen_divergence_count=0. 3. Design authority still described the deleted models. Corrected design_document.dag (v2.std.node Hash is Fnv1a64Structural, not std.types.ContentHash -- wrong home and wrong type, contradicting the Phase A row below it), regenerated DESIGN.md, and corrected both locked plan docs to say the unit carries one agnostic identity from which each realization derives its spelling. Corpus sweep for the three stale claims is clean. Also repairs a main red this branch inherited: CompileDiagnosticCensus became an unrostered inert carrier when main's codex-review-46144 repair deleted census_rows(c: CompileDiagnosticCensus), its only production consumer. The three files involved are byte-identical to main, so the red is main's, not this branch's. Rostered with that reason and the standard dissolve trigger. * Discharge the CR/NUL control gap: main's Unicode escapes fired its dissolve-on trigger Round 2 asked for hostile-spelling controls over / \ CR LF NUL and ". CR and NUL were declared as a coverage BOUNDARY rather than faked, because .dag string literals had no numeric-escape form: backslash-r lexed as literal backslash-then-r and the backslash-u brace form lexed as its raw characters, both measured at the time. The note carried an explicit dissolve-on trigger. Main landed Unicode string escapes (#7585), so the trigger fired. The escapes were RE-MEASURED on this head rather than assumed from the commit title: \u{000d} and \u{0000} each yield exactly one character, of codepoint 13 and 0. CR and NUL are now DIRECT witnesses (a%00000db, a%000000b) and both join the output-always-safe control, so the whole requested hostile set is witnessed against the real encoder with no argument from escape-branch genericity standing in for any member. The encoder needed no change -- the genericity argument the boundary rested on turned out to be correct, which is exactly what direct evidence was owed to show. 24/24 green. The note is kept as the receipt that the boundary was declared, triggered and discharged rather than quietly dropped. Also merges current main (4 commits). One conflict, in dag/extdeps/realization/artifact_store_fs.dag: this branch moved ContentHash to std.content_hash while main added std.access {Permit, Deny} from the access-kernel change. Resolved as the union -- both wanted, neither superseding the other. * WIP: gunbc oracle * Merge main (15 commits): repoint four more ContentHash consumers, re-sync the inert roster Same merge class as the last push, caught this time BEFORE pushing by running the whole-tree compile rather than only the marker census. ContentHash home. Four more files main added import ContentHash from std.types, which Phase A moved. Repointed onto the family member their values actually inhabit, not a bare import swap: - gunbc.guarantee_measurement probe_set_digest is folded from content_hash_atom / content_hash_tagged / content_hash_combine, so it is Fnv1a64Structural. Its fold also had to move to the _structural variants, because Phase A DELETED the union-level combine and content_hash_tagged takes a structural payload while returning the union -- the union simply does not typecheck at this position. - gunbc.stage0_rust_honest_frontier_projection and both witnesses carry the same manifest_content_identity field as the previous batch; their "witness-abc123" String casts became Fnv1a64Structural records with valid 16-hex digests. Field rename collision. This branch renamed tested_base_tree -> tested_base_tree_hash and merge_target_tree -> merge_target_tree_hash alongside the GitObjectId retype, and main's #7583/#7619 lane added new callers on the old names. Updated those call sites (dag/tools/merge_admission_current_context.dag and main's new tests in merge_admission_attempt_witness_test.dag). FLAGGING FOR THE OPERATOR: the rename is incidental to this PR's purpose -- only the retype was required -- and it is what made these collisions instead of clean merges. It is kept because the record's sibling field was already base_tree_hash, but it is a fair thing to ask me to revert. The merge_admission witness import conflict resolved as the UNION: this branch's three Phase A symbols plus main's two roster helpers and its new commit_workflow import. All six are used in the file body and all six are declared. Inert roster re-synced, both directions of the check firing as designed: - DownstreamSupportRoster (#7571) is newly inert -- declared, named in plan prose, constructed and read by nothing -- so it is rostered. - AccessPolicy is no longer inert: main's std.effect_grant effect_grant_policy is a real production consumer, so its row was STALE and is DELETED. That is exactly the dissolve the row's own trigger specifies, not a hand-edit. The roster now equals the live inert set exactly. Verified on a binary rebuilt AFTER the merge (main touched src/v1, so the pre-merge binary was not a valid oracle): whole-tree compile 0 blocking errors, regen_divergence_count=0, and green suites -- merge_admission 28/28, guarantee_measurement 9/9, honest_frontier 7/7, lifecycle_scaffold 28/28, emitter poles 7/7, roadmap 39/39, c_compilation_unit 24/24, compilation_unit 15/15, inert_carrier 4/4. * Merge main #7608: ground the new GitSha1ObjectId fixtures on Sha1Digest Phase A made GitObjectId's digest a Sha1Digest record rather than a raw hex String, and main's new commit_writer_admission witness constructs GitSha1ObjectId { digest: "1111..." } directly. Both fixtures now use the tree's existing idiom, Sha1Digest { hex: <40 hex> as Sha1DigestHex }, with the carriers imported from std.content_hash. The object_store.dag import conflict resolved as the union: this branch's Phase A content_hash block plus main's two new imports (PositiveInt, repeat_string). BLOCKED, and NOT worked around: dag/gunbc/commit_workflow.dag fails to compile with "no field 'path' on type 'T'" at commit_writer_index_entries_for_path. This is NOT this branch's defect and it is deliberately left alone rather than papered over with a speculative type annotation (DESIGN section 5: noticing you are implementing a workaround IS the line-stop signal). Evidence it is main's: - the file is BYTE-IDENTICAL to origin/main here; - it reds in its OWN narrow closure, not just whole-tree, so it is a real defect rather than a resolution artifact; - this branch's only 04_infer changes are where-predicate registrations (lower_hex_*, oci_other_digest_*), which cannot affect lambda parameter inference; - main's CI for #7608 (f3df2ce) was still QUEUED when this merge happened, and three of the preceding main commits are outright red, so the commit landed unverified. Hypotheses tested and REFUTED by execution, so the next person does not repeat them: trailing comma in the parameter list; filter over an imported record type (both compile clean in an isolated probe); a shadowing filter declaration; a lambda/parameter name colliding with an imported symbol; cross-call-site unification collapsing the element type (only two callers, both passing List<GitIndexEntry>). The sibling flat_map over the same type and the same `entry` binding compiles, so it is specific to this call. * WIP: gunbc oracle * Remove cw_probe.dag: a scratch bisect probe the auto-commit swept into the branch Not source. It was a copy of commit_workflow.dag under a probe module name, used to bisect the 'no field path on type T' failure to its cause, and it should never have been committed. * Unblock the compile-clean gate: declared scaffold for the filter name capture, two more ContentHash homes THE BLOCKER, root-caused by bisection rather than guessed. dag/gunbc/commit_workflow.dag failed with "no field 'path' on type 'T'". src/v2/std/algebra.dag declares fn filter<T>(xs: FreeMonoid<T>, predicate: fn(T) -> Bool). commit_workflow does NOT import v2.std.algebra -- but it imports v2.compiler.source_authority, which drags the whole v2 compiler closure including v2.std.algebra into the module POOL. The bare name filter then binds to that declaration instead of the builtin, List<GitIndexEntry> does not unify with FreeMonoid<T>, the lambda parameter stays unbound, and the module reds. Discriminating measurement: importing v2.std.algebra for `length` ALONE -- never filter -- reproduces it, and deleting only the source_authority import makes the original filter form compile. So this is name capture by POOL MEMBERSHIP, not by the import list: DESIGN #6985 Class B in its inverting direction, and silent -- nothing reports that filter rebound. Refuted by execution before landing anything, recorded in the carrier so nobody repeats them: trailing comma in the parameter list; filter over an imported record type; List not imported; two filter calls over different element types in one module; a lambda or parameter name colliding with an imported symbol; cross-call-site unification. The import cannot be dropped -- ModuleStorageBinding, ParsedFromSource and ProducedByBehavior are all genuinely used -- so the only local repair routes around the capture. Per DESIGN section 5 that is a WORKAROUND and may only land as a DECLARED SCAFFOLD, never a quiet respelling: the body selects with flat_map (the spelling the sibling function already uses over the same type with the same binding), and commit_writer_index_filter_capture_scaffold states the root cause, the discriminating measurement, the refuted hypotheses, why the import cannot be dropped, and the dissolve-on -- the namespace-only resolution lane, after which the filter spelling is restored and the row deleted. Behaviour is unchanged: it selects exactly the entries whose path matches. commit_writer_admission_witness_test 13/13 exercises admit_commit_writer, which calls this function, so that is verified by execution and not merely by compiling. This is NOT this branch's defect. It is fixed here because it reds main itself and every job on this PR, and main landed #7608 while its own CI was still queued. Also: two more files from main's #7623 import ContentHash from std.types. Same manifest_content_identity field as the two prior batches, so same grounding onto Fnv1a64Structural, with the contract fixture becoming a valid 16-hex digest. Whole-tree compile 0 blocking errors; regen_divergence_count=0; heal no drift; commit_writer_admission 13/13; live_rust_observation_contract 12/12. --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
What this is
A receipt-backed gap analysis answering: what did this compiler intend to guarantee, and what does it guarantee today? Docs-only plus the doc-graph bind rows — no walls, no checks, no compiler changes land here.
Two files:
docs/plans/compiler-guarantee-recovery-gap-analysis.md— the analysis.dag/gunbc/doc_graph_roots.dag— twoHandAuthoredDocBindrows binding the doc to its carriers (v1.compiler.infermodule_skips_direct_call_arg_check;v2.std.constraintssolve_constraints), each with a falsifiable dissolution trigger. This was also the CI fix: the doc first landed as an orphan anddoc_graph_has_no_orphan_docscorrectly refused (RED atbe1a001, GREEN by local execution of all five reachability witnesses plusdoc_graph_is_cleanafter the binds).Provenance and verification
The specification half of the project's authority (guarantee statement, tier claims, claims-list rule) was lost in the 2026-06-16 doc bankruptcy and recovered from
3127161e878^(THESIS.md, INVARIANTS.md, correctness-dimensions.md, error-examples.md). The analysis then went through two audit passes: an initial archaeology pass, and an independent review whose corrections were adopted after each was verified againstmain— the verification ledger, including two corrections to the review and the still-unlocated claims, is §10.Headline findings (each carrier-cited in the doc)
v2.*/v1.compiler.*call-check exemption dates to 2026-06-08, while the era's status ledger marked type safety "Yes (blocking)". Ledger overstated → auditable contract deleted.data/generic inhabitance, andPatternLookupBlockedare fail-open today; v2's generic inference self-certifies (solve_constraintsproveswell_formed(root)and relabels itCanonicalGrounding) while its terminal door and loop-termination wall are real.refined_vacuous_stub_pack'sRejectedarm returnsRefined { base }; the operator independently re-directed the guarantee on 2026-07-04 (interface-summary-declared-use-arity.md§3.1) and the lattice design pass never started.gunbc.design_documentand its "5 behaviors" is stale againstv2.std.node's six — the recovered spec must land as.dagrows, not prose.Open by design
§12's seven-stage sequencing awaits operator sign-off (Stage 1 = claims authority + expecting-red probe corpus, both
.dag); prevalence numbers stay deliberately unmeasured until Stage 7 and are marked UNVERIFIED in §10 wherever carried.🤖 Generated with Claude Code