Skip to content

Move floor naming helpers to their single authority - #7516

Merged
briansrls merged 9 commits into
mainfrom
session/eager-ram-208-floor-naming
Jul 31, 2026
Merged

briansrls merged 9 commits into
mainfrom
session/eager-ram-208-floor-naming

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jul 31, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Moves the floor test-declaration scan and filename-hygiene predicate from floor_discovery_producer to the existing floor_naming_hygiene authority. All real consumers move with the definitions, including the producer internal tokenizer call, hygiene witness, test-module hygiene entry, and the hand-maintained CLI entry resolver; the producer scaffold now binds the new exact authority.

This is the prerequisite split from #7508 so the namespace-cardinality PR does not carry an unrelated floor authority relocation. The CLI entry adapter is explicitly censused at +8/-2 (net +6), names its exact helper, and dissolves under roadmap node v1-hand-queue-drain.

Provenance

  • Base: 11655a3dc9a2
  • Extraction source: b222f079a0
  • Proposed head: 715333c814d1

Test plan

  • cargo fmt --all -- --check
  • cargo run -p v1-compiler --bin regen_stage0
  • cargo run -p v1-compiler --bin regen_stage0 -- --verify — regen_divergence_count=0
  • cargo run -p v1-compiler --bin gunbc -- run --claim-run --source-root src/v2 --source-root dag --entry dag/test/claim/floor_discovery_hand_rust_equivalence_witness_test.dag --function floor_discovery_surface_text_scan_scaffold_on_carrier — returned true
  • cargo run -p v1-compiler --bin gunbc -- run --claim-run --source-root src/v2 --source-root dag --entry dag/test/claim/floor_discovery_hand_rust_equivalence_witness_test.dag --function floor_naming_hygiene_entry_hand_rust_growth_is_censused — returned true

The similarly named Rust unit-test filter matched zero tests and is intentionally not counted as verification.

@gunbai-bot gunbai-bot Bot changed the title P1 cardinality kernel Move floor naming helpers to their single authority Jul 31, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 31, 2026 20:16
@gunbai-bot gunbai-bot Bot mentioned this pull request Jul 31, 2026
6 tasks
@briansrls
briansrls merged commit 5579e37 into main Jul 31, 2026
3 checks passed
@briansrls
briansrls deleted the session/eager-ram-208-floor-naming branch July 31, 2026 21:19
gunbai-bot Bot added a commit that referenced this pull request Jul 31, 2026
* WIP: P1 cardinality kernel

* Complete floor naming authority move

* Import moved floor tokenizer helper

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Census floor naming CLI adapter

* chore: regenerate drifted generated artifacts (ci auto-heal)

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
briansrls added a commit that referenced this pull request Aug 3, 2026
* Close the four review blockers on the merged run_stage extraction

Follow-up to #7499 (merged as 7cff3d7). These were requested in review
but were not in the merged head, so they land as a fresh change on a
branch restarted from main rather than stacked on merged history.

1. walk_plan_note contradicted itself. It asserted both that heavy
   whole-tree stage claims refuse (the current implementation) and that
   the arm-time validator no longer refuses them (stale text from a prior
   revision). Because this is the canonical carrier, the generated stage0
   projection reproduced the contradiction. Replaced with a CLOSED
   enumeration of all five refusals — a partial list is how the
   contradiction arose, so the shape is the fix, not just the wording.

   Also corrected the dissolve-on. The four profile restrictions name
   DIFFERENT triggers and do not dissolve together, and the
   undeclared-profile refusal has none at all — it is the fail-closed
   floor. The heavy trigger is two ordered steps: split execution-slot
   from resident-reservation accounting, THEN take a context-lifetime
   reservation. Naming the lease alone understated it; a lease against
   today's single `active` counter deadlocks.

2. Rust comments still stated the retracted contract — "members run
   concurrently", "same governor admission", "same derived cost clamp".
   All now match the carrier: distinct spawned groups MAY overlap subject
   to per-lane admission; "same clamp MECHANISM", since ordinary batches
   supply clamp parameters and stages deliberately pass None.

3. Receipt identity was half closed, and the merged PR body claimed it was
   closed. Per-stage receipts were attempt-scoped and payload-stamped; the
   aggregate had identity in neither path nor payload. Both aggregate write
   sites are now scoped and stamped, including the skip case, which refuses
   rather than writing unattributably.

   `entry` is now carried ON ClaimResult rather than recovered by lookup:
   searching a stage's runnables for a matching function name would
   reproduce exactly the ambiguity that makes a function name insufficient
   as a declaration identity. 16 construction sites. The two with no single
   declaring entry — the unmapped-node sentinel and the discovery aggregate
   — say so explicitly, because a blank field reads as "unknown" when the
   truth is "not one entry". plan_site added to both receipt headers.

4. The §7 seed deferral for run_stage/spawn_units/join_units/receipt
   writers is authored here, at its own carrier, with a SCAFFOLD marker on
   the Rust. A first draft had it in the downstream fixture branch, which
   reverses ownership: the debt belongs to the change that added the Rust,
   and a consumer documenting its parent's deferral lets the parent land
   without one.

Verification state, stated exactly:
- The four #[cfg(test)] sites missing `entry` were found by running the
  suite UNFILTERED. `cargo build` does not compile test targets, so every
  "build clean" check in this arc was structurally incapable of catching
  them, and a grep filter then rendered the compile error as an empty
  section rather than as failure. Both gates are corrected: the chain now
  runs `cargo test --no-run` and pipes the suite through `tail`, not grep.
- Test-binary compile, regen, fmt, and suite were green on the pre-rebase
  tree. The same gate is re-running on this rebased base and had not
  finished when this was committed. If it reds, that is a defect in this
  commit, not a flake, and the next commit fixes it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N7LfCpidMuDjV3FxYUHv1K

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Success-stage materialization receipt on attempt-scoped path (#7499 blocker 6).

Harvest ordinary-floor materialization before on_success_stages; write a second
receipt under target/floor-attempt-<attempt_id>/ after stage_memo drops, with
attempt_id= in the payload and the same keyed/unkeyed/memo fields. No
post-harvest reset — the ordinary take drains the accumulator atomically.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Align walk_plan_note and executor comments with per-lane admission (review 45660).

Heavy-whole-tree-resolve still refuses at arm time (memo lane, unadmitted);
retract the note's claim that the validator dropped that refusal. Update
spawn_units and run_walk comments to match the weaker overlap contract.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Dispatch A: production-path stage executor fixture (#7499 blocker 3) - f

* Mark walk_plan_stage production-path fixture tests ignored in default CI.

Each control is proven by execution via claim_executor recipes in
plan.dag; the integration tests remain for local/operator runs (~7m
each due to the naming-hygiene walk) without blocking every PR build.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Dispatch A: production-path stage executor fixture (#7499 blocker 3) - f

* Fix overlap_coordination sleep import for module-qualified service access.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Dispatch A: production-path stage executor fixture (#7499 blocker 3) - f

* Exclude walk_plan_stage fixtures from witness discovery (CI fix).

These Wet production-path controls are driven only via plan.dag
claim_executor recipes; as hermetic discovery witnesses they fail with
missing mock_response or BY-DESIGN reds when the PR touches their closure.
Mirror floor_skip's dir-grain FixtureExplicitRoster exclusion.

* chore: regenerate drifted generated artifacts (ci auto-heal)

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Regenerate the stage0 seed for the corrected walk_plan_note

The branch carried a std_realization_schedule.rs that did not match its
own .dag source: the carrier has walk_plan_run_stage_claim_executor_seed_deferral
and the corrected refusal enumeration, the seed had neither (611 lines vs
the 620 a fresh self-compile produces). `regen_stage0 --emit-fresh
--verify` now reports regen_divergence_count=0.

Cause, stated correctly after an initial misattribution: commit 242be6b
carried only the two authored files. Replaying the blocker fixes onto the
rebased main used a two-file patch by design — the seed had to be
regenerated against the new base rather than carried across — and it was
then committed before that regeneration ran.

An earlier version of THIS message blamed the CI auto-heal commit
(44393e0) that happened to sit in between, claiming it had pushed a
seed contradicting its own tree. That was false. Auto-heal changed
exactly one file, docs/plans/fail-closed-lockdown.md, and
std_realization_schedule.rs is not in its roster at all — it is a
regen_stage0 output, a different artifact family. The observation that
regen re-modifies the file at 44393e0 was correct; the inference that
heal had written it was not, and the discriminating check (does that
commit touch the file?) had not been run before the claim was made.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N7LfCpidMuDjV3FxYUHv1K

* WIP: Dispatch D: v2 WalkPlan schedule-lens PR - rename ordinary lens to Reali

* Move floor naming helpers to their single authority (#7516)

* WIP: P1 cardinality kernel

* Complete floor naming authority move

* Import moved floor tokenizer helper

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Census floor naming CLI adapter

* chore: regenerate drifted generated artifacts (ci auto-heal)

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>

* WIP: Dispatch A: production-path stage executor fixture (#7499 blocker 3) - f

* WIP: Dispatch A: production-path stage executor fixture (#7499 blocker 3) - f

* WIP: Dispatch A: production-path stage executor fixture (#7499 blocker 3) - f

* Fix walk_plan_stage fixtures for attempt-scoped receipts (review 45688).

Supply GUNBC_WALK_ATTEMPT_ID in the integration harness; route barrier,
cleanup, and poison claims through one path authority in common.dag.
Capture stdout and stderr separately (PASS/FAIL on stdout, progress on
stderr). Tighten panic and receipt-refusal oracles. Remove the run_stage
§7 deferral row and SCAFFOLD marker — owned by #7518, not the fixture PR.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Complete WalkPlan schedule lens coverage

* WIP: Dispatch D: v2 WalkPlan schedule-lens PR - rename ordinary lens to Reali

* WIP: Dispatch E: merge-admission occupants (task #14) atomic with orphaned sh

* Record measured admission resolve count and baseline

* Defuse merge-admission capture identity closure

* Name the de-fused carrier for its tested subject

* Lock tested-subject wire bytes across de-fusion

* Make admission-stage budgets and resolves honest

* WIP: Dispatch E: merge-admission occupants (task #14) atomic with orphaned sh

* WIP: Dispatch E: merge-admission occupants (task #14) atomic with orphaned sh

* Run merge subject capture in typed subprocess

* WIP: Dispatch E: merge-admission occupants (task #14) atomic with orphaned sh

* WIP: Dispatch E: merge-admission occupants (task #14) atomic with orphaned sh

* Keep merge-admission stages on the warm executor index

* Regenerate stage0 from the current compiler

* Resolve CI floor witness import merge

* WIP: Dispatch E: merge-admission occupants (task #14) atomic with orphaned sh

* Reconcile merge admission with grounded Git object IDs

* Merge repaired main while preserving warm admission stages

* WIP: Dispatch E: merge-admission occupants (task #14) atomic with orphaned sh

* Heal ci.yml on the merged tree; pass the typed stall deadline at the staging context's fetch (review 47488)

The heal job flagged .github/workflows/ci.yml drifted after the main merge —
workflow files are author-commit-required, so the main_wet regeneration lands
here (in-executor admission shape: shell stamp step deleted, wrapper 95m).

merge_admission_current_context.dag's FetchNoTags call predated this PR's
stall_deadline_seconds required input (cursor review 47488) — it now imports
and passes the same merge_admission_fetch_stall_deadline_seconds authority the
walk uses (single authority, no second constant). Entry compiles clean by
execution (gunbc compile --target dag, exit 0).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Delete the dead include_admission_capture parameter (review 47503)

The Bool was threaded through floor_nodes / floor_data_dependencies /
floor_dependencies_with / floor_schedule_via_runner_for /
floor_schedule_for_with_capture, but no body ever read it — a parallel
representation of a decision the code does not make (the admission capture
actually rides WalkPlan.pre_walk_execution, not the schedule graph). The
parameter and the _with_capture wrapper delete; floor_schedule_for calls the
runner directly and gunbc_ci_floor_schedule_inner collapses onto it. Affected
witnesses green by execution (pr_native_batch pair, disjoint-budget pin,
ci_workflow_witness_holds).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Dispatch A->C

* Address review 47517: typed capture refusal, one untagged-oid decoder, named walk-overhead budget term, seed-deferral extension

1. capture_tested_subject no longer collapses seven failure causes to bare
   false: the core returns TestedSubjectCapture with a typed refusal coproduct,
   and the Bool claim projection durably writes the labeled cause to
   target/merge-admission-capture-refusal.txt (the population-budget-refusal
   pattern) before returning false; run_pre_walk_execution reads the wire into
   its located PRE-WALK-REFUSED line, with wire-absent reported as its own state.
2. The hex-length family guess moves to its single authority:
   extdeps.git.object_store git_object_id_from_untagged_hex decodes git's own
   untagged plumbing output (40/64 canonical widths, refusing others); the
   capture tool and merge_admission_walk both consume it and the per-consumer
   re-guess deletes.
3. The wrapper budget names the wall outside both populations:
   gunbc_ci_walk_overhead_allowance_minutes (5m) joins the sum, wrapper = 65m,
   so a slow pre-walk or finalization cannot silently eat the ordinary
   allowance; witness pins the three-term sum, ci.yml regenerated.
4. walk_plan_run_stage_claim_executor_seed_deferral extended to name the
   pre-walk parser, budget watchdogs, refusal writer, and memory snapshots as
   the same seed debt on the same dissolution trigger.

regen divergence 0; ci_workflow and disjoint-budget witnesses green; fmt clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Correct the stale lane-placement claim in merge_admission_walk_note (review 47528)

The note said the two on-success claims take spawned lanes; they route through
population_unit_lane to the main thread, and the executor's population_unit_lane
plus its tests are the placement authority. Doc-only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Type the stage-2 refresh refusal; the cause rides a durable wire into the stage-failure line (CI run 30764945450)

The floor redded at on-success stage 2 with refresh_current_target_and_gate
returning bare Bool(false) — review 47542 finding 3 made blocking: seven
failure causes conflated, the red undiagnosable from the log. Same repair
shape as the pre-walk capture: merge_target_refresh returns a typed sum
(MergeTargetRefreshRefusal — fetch-refused carrying the operation's own
stderr, attempt-identity-absent, subject/receipt wire missing, target-tree
observation refused with its cause, oid unparseable, verdict-denied with the
verdict label), and the Bool claim projection durably writes the labeled
cause to target/merge-admission-refresh-refusal.txt before returning false.
claim_executor's stage-failure line now reads that wire, so the next run
names its own cause. Also widens the pre-walk wire-absent message per review
47542 finding 1 (child-crashed vs wire-write-refused are indistinguishable
from the parent by construction, and the message now says so).

Walk entry compiles clean by execution (0 blocking); fmt clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Dispatch A->C

* Route wire relpaths through paired consts, bin path through release_bin_rel_path, and declare the ratchet-off widening as a Scaffold Disposition (review 47596)

Finding 1: MERGE_ADMISSION_{CAPTURE,REFRESH}_REFUSAL_WIRE consts in claim_executor.rs
with pairing doc-comments; _seed_pairing notes beside both dag relpath authorities.
Finding 2: merge_admission_capture_transport routes the claim_batch bin path through
gunbc.cli_invoke release_bin_rel_path instead of minting the string.
Finding 3: merge_admission_refresh_ratchet_off_widening_{note,disposition} — the
ratchet-off else arm is a declared Scaffold bound to the
merge_freshness_verdict_is_consumed_to_block flip, per the fleet-gating shadow-phase
policy; the flip commit deletes the arm and the row together.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Consume the typed target tree hash directly; delete the debug-render re-parse that could never succeed (CI run 30769177034)

The typed refusal wire did its job on the first red it carried:
cause=target-oid-unparseable observed=GitSha1ObjectId { digest: ... } — the
stage-2 arm cast observe_merge_target_tree_hash's already-typed GitObjectId
to String (its record rendering) and re-parsed it as untagged hex, a §3
re-guess of a fact the producer's type already carries. The classifier takes
GitObjectId, so the hash now flows through directly; the unreachable-by-type
RefreshTargetOidUnparseable arm and the object_store import are deleted with
it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Dispatch A->C

* Replace the unevaluable '300 as Seconds' cast with a bare-literal data row (review 47638)

The interpreter has no cast into a branded scalar; the corpus idiom is a
bare-literal data row, the same shape as this PR's
merge_admission_fetch_stall_deadline_seconds = 240 which already executed on
CI. fetch_pr_head_ref now reads review_fetch_stall_deadline_seconds = 300.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Post-merge repairs: regenerate ci.yml from the merged authority, anchor wire reads at git toplevel, import std.decl_ref explicitly (reviews 47663, 47665)

- ci.yml regenerated via generated_artifact_gate main_wet on the merged tree:
  restores the heal skew-guard's stage0 emitted-Rust exclusions the text merge
  had dropped (review 47665 finding 2) and clears HealAuthorCommitRequired
  from run 30774448327.
- claim_executor's two refusal-wire reads now anchor on git rev-parse
  --show-toplevel, matching the .dag writers' git.Inspect.Toplevel() anchor,
  so a non-root cwd cannot turn a written typed cause into a false
  wire-absent (review 47663).
- merge_admission_walk.dag imports DeclarationRef/WholeDeclaration explicitly
  from std.decl_ref instead of relying on bare-name resolution (review 47665
  finding 1).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant