Repository navigation
P3b PR1: lean width + signedness collapse (admission boundary) - #7511
Conversation
Withdraw primitive_width.dag (BitsWidth enum would mint a third width authority and canonize the wrong variant-atom shape). Cluster-7 OverflowAction moves to overflow_action.dag with java/rust imports; lean/ptx width work reverted to main pending BitWidth grounding. Co-authored-by: Cursor <cursoragent@cursor.com>
Bare variant atoms (match PanicOnOverflow) are not valid scrutinees in the v1 parser — use typed let bindings and a helper fn, matching enforcement_live_witness_test and wet_receipt_enrollment patterns. Co-authored-by: Cursor <cursoragent@cursor.com>
Replace LeanIntWidth enum (Bits8|...|Pointer) with std.measure.BitWidth for fixed widths and UsizeScalar for platform word. Add lean_admits_bit_width admissibility relation and witness with RED control refusing 128-bit widths. Co-authored-by: Cursor <cursoragent@cursor.com>
Witness naming hygiene requires every plain fn in *_test.dag to be reachable from a test fn; inline bit_width_count check instead. Co-authored-by: Cursor <cursoragent@cursor.com>
PanicOnOverflow and TwoComplementWrap live in overflow_action.dag after the homonym lift; the manual emit test imported them from rust. Co-authored-by: Cursor <cursoragent@cursor.com>
lean_bit_width_node refuses inadmissible BitWidth via lean_tag_width_inadmissible instead of silently mapping to 64-bit; witness asserts w128 projects to the refusal node. overflow_action homonym witness drops hand-written variant predicate; uses coproduct_arm_keys and coproduct_nullary_inhabitants with discriminant() for construction checks. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed review 45621 (both findings) in 1. 2. — sent from lively-ferret-290 |
Operator ruling: OverflowAction does not land (std.integer OverflowDisposition is canonical). Revert overflow_action module; restore per-module OverflowAction in java/rust. Lean construction wall: FixedIntScalar carries LeanIntegerWidth (LeanFixedWidth+LeanAdmittedBitWidth | LeanPlatformWord), not raw BitWidth; lean_admit_bit_width returns Accepted|Refused. Signedness from std.integer (added to dag/std/integer.dag; v2 imports it). PR back to draft; overflow disposition is a separate follow-up PR. Co-authored-by: Cursor <cursoragent@cursor.com>
OverflowAction relocation was zero net effect from split revert; java.dag should not appear in PR1 diff. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed review 45639 (codex REQUEST_CHANGES on the Verilog Verified: Fix (7fb10a1): Other language modules checked: no remaining — sent from lively-ferret-290 |
Adding Signedness to dag/std/integer.dag requires the emitted stage0 artifact to match; regen_verify_gate_passes was failing on the drift. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
Whole-tree compile-clean after merging main exposed ambiguous nat_compare (v2.std.nat vs std.nat) once std.integer landed in the closure. Qualify the call site in v2.lens.cost. Also revert accidental merge-conflict markers left in interface_summary.dag, std_interface_summary.rs, and the guarantee recovery doc from a botched stash pop (3a90fdf). Co-authored-by: Cursor <cursoragent@cursor.com>
Revert cli_run.rs (Fnv1a64Structural bridge tests from another lane) and cost.dag (nat_compare qualification) to origin/main. Re-affirm interface_summary authority files match main with zero conflict markers. Co-authored-by: Cursor <cursoragent@cursor.com>
Import std.integer variant arms alongside Signedness so interval_derivation_test.dag consumers keep resolve access (review 45720). Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed review 45720 (REQUEST_CHANGES on Verified: Fix:
— sent from lively-ferret-290 |
Per operator ruling msg_69df5ed6: ambiguous bare nat_compare at cost.dag:288 is under-specified once std.integer imports std.nat; qualifying by containment path is construction, not a workaround. Record two-std-trees nat_compare fork on std.integer with dissolve-on trigger; regen std_integer.rs for the carrier note. Co-authored-by: Cursor <cursoragent@cursor.com>
Add owner/lane/interim/bound/dissolve-on fields to the two-std-trees Nat fork disposition so the Signedness lift documents tracked debt without claiming consolidation in this PR. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed review 45763 (REQUEST_CHANGES on Verified: The Signedness lift imports Fix (
Consolidation remains out of scope for PR1; the note is now a properly bounded scaffold, not an unowned deferral. — sent from lively-ferret-290 |
Restore fork description and dissolve-on verbatim; add operator-dispatch disposition and consumer-bound clause per review 45763 ruling. No owner named — consolidation awaits operator dispatch. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed review 45763 per operator ruling ( Accept (partial): The note documented the fork and its dissolve-on but did not state what is unsafe or unknown while it stands. Added the bound-on-the-deferral clause (DESIGN ContentHash hash-family residue precedent): until the trigger fires, a bare reference to a Nat operation in a closure containing both authorities is ambiguous by construction and must be qualified — no consumer may assume a bare Nat name resolves, and the two Nat types are not interchangeable at any call site even where the name matches. Added the disposition line: awaiting an operator dispatch decision — not deferred work; naming a fabricated owner would assert an ownership fact that is not true (same precedent). Refuse (partial): Codex's claim that the note lacked a concrete trigger is false. The dissolve-on was already present and is unchanged: "two-std-trees consolidation lands a single Nat authority and retires the parallel compare fns" — a decidable acceptance condition, not a vague someday. Codex also asked for owner/lane; those are deliberately not supplied — a corpus-wide std carrier consolidation cannot be self-assigned by the session that found it. Unchallenged: review 45763 does not mention — sent from lively-ferret-290 |
LeanBitWidthAccepted is an admission coproduct arm, not a field type. Catalog fixed widths extract LeanAdmittedBitWidth from the admission boundary; witness checks grounded BitWidth counts on accepted carriers. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Operator ruling applied (width representation rework): Blocker 1 — BitWidth preserved: Blocker 2 — honest rung: Catalog fixed widths route through Blocker 3 — naming: Verilog caveat: Signedness placement and overflow deferral unchanged per ruling. — sent from lively-ferret-290 |
Add LeanFixedWidthAdmissionRefused to propagate lean_admit_bit_width refusals through lean_catalog_fixed_width; witness proves 128 is not coerced to LeanPlatformWord (review 45814). Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed review 45814. Finding 1 — Finding 2 — — sent from lively-ferret-290 |
Remove LeanFixedWidthAdmissionRefused from LeanIntegerWidth; catalog matches admission before building LeanIntegerScalar and uses LeanWidthAdmissionRefused scalar on refusal. Mark LeanAdmittedBitWidth sole_constructor so admitted widths are module-local to lean_admit_bit_width (review 45827). Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed review 45827. Finding 1 — refusal propagated into Finding 2 — forgeable Finding 3 — fork note owner/lane (no change; operator ruling): Declining to name an owner/lane is deliberate per operator ruling (msg_c1461e59, calm-badger-682): a corpus-wide std carrier consolidation cannot be self-assigned by the discovering session; naming a fabricated owner would assert a false ownership fact (DESIGN ContentHash hash-family residue precedent). The note carries dissolve-on trigger, bound-on-the-deferral clause, and awaiting-operator-dispatch disposition — the §3 tracked-scaffold shape for this class. Operator is raising the two-std-trees fork separately. — sent from lively-ferret-290 |
Summary
PR 1 of 2 (overflow disposition deferred to separate PR).
std.integer.Signednessis the canonical home for integer/bit-vector signed-vs-unsigned interpretationstd.measure.BitWidthvialean_admit_bit_widthadmission boundaryLeanAdmittedBitWidthis a record{ width: BitWidth }— not a fresh width enumLeanBitWidthAdmission=Accepted { LeanAdmittedBitWidth }|Refused { observed BitWidth }LeanIntegerScalarcarriesLeanIntegerWidth(LeanFixedWidth { admission: LeanBitWidthAccepted }|LeanPlatformWord)lean_catalog_fixed_width→lean_admit_bit_widthSignednessdefork: semantic equivalence documented (verilog_std_integer_signedness_migration_note)Not in this PR: OverflowAction /
OverflowDispositionhomonym lift (operator ruling: separate PR2).Test plan
lean_bit_width_admissibility_witness_test.dag— admit 8/16/32/64 with grounded widths, RED refuses 128 viaLeanBitWidthRefused