Repository navigation
Primitive identity join D0: five-surface census and join refusals - #7549
Conversation
|
Addressed review 45910 in 32cbb62: Hand-authored census (§2/§3 parallel representation): withdrawn. Fabricated Mutation-control coverage is stated exactly in — sent from loyal-crab-305 |
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
|
Addressed review 45926: Terminal contract vs D0 slice: Interpreter roster node: added tracked Optional coproduct queries: specimen predicates now route through — sent from loyal-crab-305 |
|
review 45947 — accepted, fixed in Verified: Fix: both Witnesses: 11/11 PASS on — sent from loyal-crab-305 |
|
review 45947 — already fixed in
Other three derived surfaces (drift audit, no reshaping in this PR):
Carrier: — sent from loyal-crab-305 |
|
review 45969 Finding 1 (parallel rosters) — not fixing in this PR; scope is honest exposure, not closure. Agreed these are §2/§3 parallel enumerations. D0 does not claim single-authority on all four derived surfaces — Derivation blockers are structural, not diligence gaps:
Algebra closed in Finding 2 (Optional Bool predicate) — fixed in this push. Deleted — sent from loyal-crab-305 |
|
review 45989 — fixed in this push. Deleted — sent from loyal-crab-305 |
|
Addressed review 46050 in
All 14 — sent from loyal-crab-305 |
|
Addressed review 46064 in the regen commit on this push: Stale seed duplicate removed.
— sent from loyal-crab-305 |
|
Addressed review 46076 in the commit on this push:
Witness updated. All 14 witnesses green with CI source roots. — sent from loyal-crab-305 |
|
Addressed review 46097 in the commit on this push:
Census All 14 witnesses green with CI source roots. — sent from loyal-crab-305 |
|
Addressed review 46112 in the commit on this push (labeling + reply on substance): Agree on the parallel-enumeration debt; disagree that D0 claims otherwise. Not a new fork: Cannot derive in D0: witness-time census cannot What changed: tightened misleading wording — split DISCOVERED (algebra + emit only) vs PARTIAL (registry + contract rosters) in — sent from loyal-crab-305 |
|
Addressed review 46252 in Finding 1 — five forked per-surface identity maps. Dissolved into one canonical table: Finding 1b — cross-authority disagreement blind. Finding 2 — hand-rolled Optional→Bool in Execution receipt: all 15 witnesses PASS locally on this head ( — sent from loyal-crab-305 |
|
Addressed review 46253 in Finding 1 — active P1 node with no closing check. Correct: this branch had deleted Finding 2 — handback promises closing validation that no longer exists. Same root cause; handback text was never edited — only the carrier/contract were deleted. Restoration makes the handback accurate again. Finding 3 — bundled SCM regression. Agree. The ~1000-line P1 first-slice deletion is fully reverted; this PR's SCM touch is now zero net vs main on proof-kernel paths. Primitive-identity D0 ( — sent from loyal-crab-305 |
598064a to
8750e96
Compare
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…iguous across std.primitive_identity and std.roster_frontier) Both modules declare an identical top-level decl_ref helper on main; the ambiguity is latent there and fired in this PR's closure, which is the first to link them (extdeps.external_authority imports std.roster_frontier). Minimal fix at the red site only: the six call sites in dag/test/claim/primitive_identity_join_witness_test.dag are module-qualified to std.primitive_identity.decl_ref and the named import row is dropped. 15/15 witnesses in the file PASS by execution. The root defect is a DESIGN section-3 fork: std.primitive_identity re-mints the decl_ref constructor std.roster_frontier already owns (the same re-mint cursor review 46136 removed from this PR's own carrier). Deduplicating it belongs to the primitive-identity lane on main; this commit only unblocks the floor at the site that reds. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ng preflight + ExternalModelScope carrier (operator verdict on #7556) (#7571) * WIP: DESIGN §3 external-upstream-decomposition subsection + extdeps modeling * chore: regenerate drifted generated artifacts (ci auto-heal) * DESIGN §3 external-upstream-decomposition + extdeps modeling preflight + ExternalModelScope carrier/gate (operator verdict on #7556) - design_document.dag §3: verbatim 'External upstream decomposition' subsection; DESIGN.md regenerated - gunbc.plans.extdeps_modeling_preflight: 8 typed preflight rows (single authority), registered Plan renders the table from them - extdeps.external_authority: ExternalSubjectRef/ExternalRevision/ExternalModelScope (citations nonempty by construction), FactAuthorityOverride.fact -> DeclarationRef; admit_external_model_scope gate with ForeignSubjectRow/ConsumerCoverageInUpstream refusals - gunbc.extdeps_scope_frontier: staged fail-closed enrollment — 2 carriers + 17 machinery-exempt + 397 counted frontier rows over all 416 dag/extdeps files; live-tree cover witness refuses unrostered or stale rows - extdeps.vendor.{microsoft,atlassian} adopt extdeps_model_scope (admitted by execution) - extdeps.browser: loud non-precedent disposition note naming the eventual split - dag/test/claim/external_model_scope_witness_test.dag: 12 claims incl. operator RED (generic browser + Chromium scope + Chrome|Firefox|Safari rows -> refused) and GREEN (shared shape + separate modules + downstream roster -> admitted); stage0 seed + ci.yml + plan doc regenerated Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Consume the module's own anchor in extdeps_model_scope (review 46077), qualified against silent same-name capture cursor review 46077: first_citation re-minted the anchor URI — parallel representation. Fixing it by BARE sibling reference was proven WRONG by execution: atlassian's bare extdeps_external_authority_anchor reference silently captured microsoft's same-named decl (first-occurrence-wins pooling; the duplicate-toplevel-decl fail-open, now witnessed on data decls). The landed spelling is the module-QUALIFIED reference (extdeps.vendor.<m>.extdeps_external_authority_anchor), single authority with no capture; the adopter witness now discriminates per-module citation locators so a future capture regression reds. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Regenerate ci.yml on merged tree (extdeps-modeling-preflight rows on top of main) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Roster the two extdeps modules main added mid-flight (review 46111): git/inspect + github/workflows, frontier count 397 -> 399 The live cover witness red exactly as designed on the merged tree; frontier claims re-run green (418 files = 2 carriers + 17 machinery-exempt + 399 frontier). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Rework carrier/enforcement per operator handback on #7571 (also codex review 46118) (1) ExternalSubjectRef carries a DeclarationRef (symbolic subject identity; vendor scopes point at their existing microsoft/atlassian declarations, no restated legal names). (2) module-grain revision removed — revisions belong on build/release/fact rows. (3) the synthetic function is no longer presented as an admission gate: renamed to the external_model_scope_decision KERNEL over DeclaredScopeFacts with a loud honesty boundary; the mechanical wall today is scope PRESENCE; subject-content-derived enforcement is the named frontier feature:extdeps-subject-content-derived (dissolves when a Node-tree projection derives DeclaredScopeFacts from the real module and feeds the same kernel). (4) the 399-row legacy population moved out of the semantic module into the frozen manifest dag/gunbc/legacy_extdeps_scope_frontier.tsv (one path per line, remove-only, count DERIVED by parse_frontier_manifest, exact bidirectional live diff enforced by the cover witness). (5) consumer coverage identity is DeclarationRef, not free text. 12/12 witness claims green by execution incl. the live 418-file cover against the manifest; stage0 seed regenerated; drift gates PASS. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: DESIGN §3 external-upstream-decomposition subsection + extdeps modeling * Consume std.roster_frontier's declaration_ref_eq instead of re-minting it (review 46136); register std_roster_frontier.rs in the seed roster Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: DESIGN §3 external-upstream-decomposition subsection + extdeps modeling * Merge main; enroll publication grants for this PR's 6 added paths + 11 ungranted main-side additions (publication_placement_gate green) The new Stage-0 publication wall (P-B) requires a PublicFilePublishGrant row for every path added after the cutover commit. This PR's six additions are enrolled, plus the eleven paths merged to main since cutover without rows (heal_revalidation, source_integration_proof_kernel, workflow-dispatch, github/workflows lanes) — main's own floor is red on the gate without them, and the roster is one shared carrier. publication_placement_gate_passes PASS locally by wet execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Make the presence wall mechanical (codex review 46215): carrier rows content-verified, manifest frozen against a git anchor Half 1: scope_carrier_paths membership was path-asserted; the cover witness now filesystem_reads every carrier file and refuses one whose bytes lack the extdeps_model_scope declaration (declared text-scan scaffold, corpus_scan precedent, dissolves with the storage-grain frontier). Half 2: the manifest's remove-only lifecycle was review discipline; every manifest row must now name a file that existed at the pinned legacy_manifest_freeze_sha — the witness diffs freeze..HEAD via git.Core.DiffNameStatus (the publication-gate pattern) and refuses any manifest row in the added/copied/renamed set, with diff failure and parse truncation typed as refusals (PostFreezeObservation coproduct), never skips. 17/17 claims green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: DESIGN §3 external-upstream-decomposition subsection + extdeps modeling * Split the wet live observations out of hermetic discovery (d4bef96 floor red) Hermetic discovery executed the three wet-only fns (Filesystem.List walk, git.Core.DiffNameStatus freeze diff) against the mock corpus, where those operations are unpublished — ReadsLiveTree does not exclude fns from discovery. Structural fix, not a widened mock: - pure decision fns (scope_cover_holds, carrier_content_declares_scope, PostFreezeObservation, manifest_freeze_holds) move to their single authority gunbc.extdeps_scope_frontier; the hermetic witness imports them (also discharges cursor review 46245 both findings) - new dag/test/claim/external_model_scope_live_cover_witness_test.dag (ReadsLiveTree) holds the live walk + freeze diff; discovery-excluded via witness_exclusion_frontier (OfflineLocalRecipe, substantiated reason + dissolve-on + local recipe, artifact_store precedent) and granted in publication_grant - hermetic file keeps all RED controls, kernel controls, manifest accounting, and the filesystem_read carrier-content check per-PR Verified by execution: 14/14 hermetic PASS, 3/3 wet PASS, publication_placement_gate_passes PASS, generated-artifact gate PASS, fmt clean. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Fix the mainline scm_compatibility homonym capture blocking CI (5 floor reds on origin/main d552ff4) Top-level fn names are not module-scoped in the assembled closure, so native_scm_interaction_scenario_fixture's parametered fixture_projection collided with the zero-arg fixture_projection homonyms in pijul/mercurial_upstream_model_witness_test once #7563 linked their closures — native_scm_receipt_for's internal call then dispatched to a zero-arg winner: 'call contract mismatch: no parameter named scenario'. Fix: rename the parametered helper to the unique prefixed native_scm_scenario_fixture_projection (both references are file-internal; no external caller exists, verified by corpus grep). Verified by execution: all 5 previously failing witnesses PASS, plus 63 witnesses across every other importer of the fixture module (native_scm_interaction_contract 14/14, mercurial compat 6/6, git compat 7/7, roadmap_validation_oracle 36/36). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * State the enforcement grain honestly and gate the roster-to-disk direction per-PR (codex review 46258) Finding 1: the preflight doc and frontier law claimed the population cover as 'the mechanical wall today' while the cover runs only on the discovery-excluded wet lane — grain inflation. Fixed both ways: - new per-PR hermetic test roster_paths_resolve_on_disk: every rostered path across all three rosters (2 carriers + 17 machinery + 399 manifest rows) must resolve in the checkout via the filesystem_read carve-out (22ms for 418 reads); a stale or fabricated roster row reds per-PR via the interpreter's typed hermetic Read refusal (verified by execution on a nonexistent probe path) - law note + preflight bullets now state the grain explicitly: per-PR merge-gated = roster-to-disk resolution, roster disjointness, carrier byte-content, RED controls; wet-lane = live enumeration (disk-to- roster new-file detection) and the freeze diff, with per-PR gating of that direction arriving at the mandatory_tag region promotion the frontier dissolves into 15/15 hermetic witnesses PASS; plan doc regenerated same commit. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Dedupe the publication roster after merging main (gate-red duplication on main itself) origin/main 06d7aea lists the eleven pre-wall repair paths TWICE: once from #7565's branch-side enrollment block and once from #7580's repair block — the same enrollment race #7580's own note describes, re-entered by the next concurrent pair. The placement gate refuses repeated grants, so main is currently gate-red and every PR merge ref inherits it. This branch resolves the merge by keeping #7580's repair block (with its note) as the single occurrence and re-adding only this PR's own seven paths; publication_placement_gate_passes PASS by execution on the merged tree (42 unique rows, zero duplicates). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Land the per-PR merge-gated ExtdepsScopePlacementGate (codex review 46281) Diff-grain sibling of tools.publication_placement_gate: refuses any freeze..HEAD-added dag/extdeps .dag file outside carriers-union- machinery (scope_placement_refused_paths, pure kernel on gunbc.extdeps_scope_frontier with hermetic RED/GREEN controls) and any frozen-manifest row naming a post-freeze-added file; diff failure and parse truncation refuse, never skip. Enrolled as a cheap-floor wet gate (roster 49->50, gates 10->11, cheap membership 4->5). One recorded freeze re-anchor to the gate-landing base (0ec3c10), admitting lean/overflow.dag which merged inside the wall-less interim (#7550); documented in legacy_manifest_freeze_sha_note. Live-cover witness dedupes its diff observation onto the gate module. Law note and preflight bullet updated to state both directions per-PR. RED proven by execution: a committed unrostered dag/extdeps probe file turns extdeps_scope_placement_gate_passes red; removing it greens. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Expose std_roster_frontier in the derived stage0 crate partition (codex review 46329) extdeps_external_authority.rs imports crate::std_roster_frontier, but the partition source authority (v2.workflow.rust_crate_partition) never rostered the new module, so the partitioned crates could not resolve it. Fix at the authority: std_roster_frontier joins the std-core primitive roster with its module-dag edges (extdeps_external_authority -> std_roster_frontier -> std_decl_ref); partition artifacts and the stage0 seed regenerated to fixed point (two regen generations — the renderer bakes the partition rows at its own build time), and stage0_core/src/lib.rs (tracked but outside every regen path — the lifecycle scaffold's open partition contradiction) gains the matching declaration directly. Disclosed, not fixed here: v1-stage0-std-core has four OTHER unresolved modules (std_occurrence_identity, extdeps_units_{dimensionless, iec_80000_13,iso8601}) byte-identical on origin/main — pre-existing partition rot from other lanes (the #7109 class; no CI job compiles these crates). Rostering them correctly requires re-cutting the std/extdeps crate boundary (extdeps_uri + extdeps_external_authority would move below std_measure, emptying v1-stage0-extdeps-base) — the deferred emitted-crate-partition lane's re-cut, not a one-line roster fix; attempted and reverted here after it surfaced that knot. Verified: cargo check -p v1-stage0-std-core no longer reports std_roster_frontier (remaining errors = the four pre-existing, same as main); generated-artifact gate PASS; fmt clean. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Reconcile freeze anchor with merged main 5669d42 (cpm_pert joined the interim manifest) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Make the manifest's remove-only lifecycle mechanical at line grain (codex review 46378) manifest_freeze_holds judges file CREATION dates, so a pre-freeze file migrated out of the manifest could later be re-added (scope decl deleted, carrier row dropped, manifest row restored) and the freeze check would pass — the escape hatch re-opened after migration. Closed: tools.extdeps_scope_placement_gate now also observes git.Core.DiffUnified0(origin/main...HEAD) and refuses any line the change itself ADDS to the manifest (manifest_line_observation / manifest_remove_only_holds on gunbc.extdeps_scope_frontier). The one admitted arm is ManifestIntroduced — the file absent at the merge base (the unified diff's /dev/null old side), exactly the PR that first lands the manifest, unforgeable once it exists on main (a delete-and- rewrite inside a branch still diffs as modification). Unreadable diff text and failed diffs refuse, never skip; removals stay free, so the manifest is monotonically shrinking by construction at the merge gate. Hermetic controls: red_manifest_remove_only_refuses_added_row, green_manifest_remove_only_admits_removal_and_unrelated_edits, green_manifest_introduction_admitted_once, red_manifest_unreadable_refuses. Verified by execution: 21/21 hermetic witnesses PASS, both placement gates PASS wet on this tree (the introduction arm exercising the live path), fmt clean. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Reach the unreadable arm from the parser and collapse the verdict to one surface (codex review 46387) Finding 1: manifest_line_observation never constructed ManifestDiffUnreadable — malformed or truncated diff text fell through to ManifestUntouched, which the gate accepts (fail-open), and the RED control bypassed the parser by constructing the variant directly. Closed: the fold tracks whether any line MENTIONS the manifest path and whether its recognized new-side header was ever ENTERED; mention without entry yields ManifestDiffUnreadable — covering truncation mid- header AND making a manifest deletion refuse conservatively (old-side header mentions the path, no new-side header follows; the promotion PR that legitimately deletes the manifest deletes this gate in the same change). New REDs go THROUGH the parser: a truncated header diff and a whole-file deletion diff both yield ManifestDiffUnreadable. Finding 2: manifest_remove_only_holds hand-matched the same coproduct the gate matched into ProcessExit — two verdict authorities. The Bool predicate is deleted; the ONE surface is the pure manifest_remove_only_exit(observation) -> ProcessExit on the gate module, consumed by both the wet gate wrapper and every hermetic control (which assert on its ExitSuccess/failure arms). Verified by execution: 22/22 hermetic witnesses PASS (incl. the two new parser-reaching REDs), extdeps_scope_placement_gate_passes PASS wet, fmt clean. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Disambiguate decl_ref in the #7549 witness (floor red on 2a04481: ambiguous across std.primitive_identity and std.roster_frontier) Both modules declare an identical top-level decl_ref helper on main; the ambiguity is latent there and fired in this PR's closure, which is the first to link them (extdeps.external_authority imports std.roster_frontier). Minimal fix at the red site only: the six call sites in dag/test/claim/primitive_identity_join_witness_test.dag are module-qualified to std.primitive_identity.decl_ref and the named import row is dropped. 15/15 witnesses in the file PASS by execution. The root defect is a DESIGN section-3 fork: std.primitive_identity re-mints the decl_ref constructor std.roster_frontier already owns (the same re-mint cursor review 46136 removed from this PR's own carrier). Deduplicating it belongs to the primitive-identity lane on main; this commit only unblocks the floor at the site that reds. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Post-merge reconcile: fix stale sibling citations after #7591 deleted the publication gate Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…e fork that reds shared closures (#7612) * decl_ref constructors move to std.decl_ref: dissolve the parallel-lane fork that reds shared closures std.primitive_identity (#7549) and std.roster_frontier each minted identical fn decl_ref / decl_field_ref beside std.decl_ref, which owned the type but no constructor. v1-seed fn names are not module-scoped, so any resolve pool containing both modules refused every bare decl_ref reference as ambiguous — six such refusals in the primitive_identity_join witness closure on current main, blocking unrelated PR floors. The constructors now live once beside their type; both former minters and all 13 importers repoint. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * regen: emitted std_decl_ref carries the consolidated constructors regen_stage0 over the updated dag closure — the constructors' single authority now emits with its module (110 files regenerated, 1 drifted). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * host_standup: delete the third duplicate decl_ref constructor (review 46502) The module is import-free; its bare decl_ref calls resolve from std.decl_ref — the same pool source its DeclarationRef type references already use. All 27 host_standup spine + assimilation witness fns green by execution; not in the emitted stage0 set, so the regen fixed point is untouched. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * regen: emitted std_roster_frontier drops the deleted constructors (review 46764) Fresh regen_stage0 on the merged tree (the earlier pass used a pre-#7585 stale binary whose escape handling produced a phantom v1_compiler_infer drift — rebuilt, rerun, gone). One honest drift: the roster_frontier seed no longer carries the constructor pair, so the emitted Rust matches its .dag source (DESIGN §7). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Summary
D0 is a first slice — NOT terminal acceptance. The join mechanism and five refusal predicates are landed and executing. The subject universe is derived across four surfaces and open at the fifth (
InterpreterDispatch). Closure fires wheninterpreter-primitive-rosterlands (clever-crab-111 v1 lane) — not in this PR.Open denominator (typed, located, counted — not a prose caveat)
BuiltinRegistry,PrimitiveContractRow,AlgebraTemplate,EmitHandlerInterpreterDispatch→primitive_interpreter_dispatch_derivation_next_triggerv1_interpretersix-site censusprimitive_d0_derived_rows_missing_identity_count()— ranks join workWitness:
w_open_denominator_counted_receiptexecutes this receipt.Interim measurement scaffold (NOT an authority)
primitive_interpreter_dispatch_measurement_rowscarries four join specimens withprovenance: MeasurementOnly. Dissolution trigger:interpreter-primitive-rosterlands →primitive_surface_census_derivedabsorbsInterpreterDispatch→ delete measurement rows (primitive_interpreter_dispatch_measurement_scaffold_note).Carriers landed
std.primitive_identity: five carriers onPrimitiveIdentity;primitive_surface_census_derivedfrom four live authorities.Citation (§3)
v1_interpretereval_builtin_innerv2.compiler.evalv2_eval_call_primitive(carriersrc/v2/compiler/05_eval.dag) — real symbol, not inv1_interpreter.rsNamed findings
fold/fold_listare separate surfaces that can disagree;length/count/sizeare one arm / three spellings (cannot disagree).fold_listoneval_callintercept beforeeval_builtin_inner.eval_method_callshort-circuit shadows algebra arm.CI execution receipt (run 30693580769 @ cc9999f — fleet roster temporarily repaired)
Batch 1 and the witness corpus executed for the first time. All 14/14
primitive_identity_join_witness_testwitnesses PASS (InterpretedLeg). No unexpected failures. This run absorbed #7580's publication grants to unblock batch 1; that absorption was reverted (e32d9b338) — this PR carries only its ownPublicFilePublishGrantrows and is blocked on #7580 landing on main like the rest of the fleet.Test plan
claim_batchwithdag+src/v2roots — 14/14 PASS