Skip to content

Primitive identity join D0: five-surface census and join refusals - #7549

Merged
briansrls merged 2 commits into
mainfrom
session/loyal-crab-305-primitive-identity-d0
Aug 1, 2026
Merged

briansrls merged 2 commits into
mainfrom
session/loyal-crab-305-primitive-identity-d0

Conversation

@briansrls

@briansrls briansrls commented Aug 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

D0 is a first slice — NOT terminal acceptance. The join mechanism and five refusal predicates are landed and executing. The subject universe is derived across four surfaces and open at the fifth (InterpreterDispatch). Closure fires when interpreter-primitive-roster lands (clever-crab-111 v1 lane) — not in this PR.

Open denominator (typed, located, counted — not a prose caveat)

Fact Count Location
Derived surface authorities 4 BuiltinRegistry, PrimitiveContractRow, AlgebraTemplate, EmitHandler
Open surface authorities 1 InterpreterDispatch → primitive_interpreter_dispatch_derivation_next_trigger
Interpreter dispatch arms (six sites) 158 v1_interpreter six-site census
Interpreter dispatch spellings 169 same
Interpreter measurement specimens 4 interim scaffold only
Derived census rows missing identity measured live primitive_d0_derived_rows_missing_identity_count() — ranks join work

Witness: w_open_denominator_counted_receipt executes this receipt.

Interim measurement scaffold (NOT an authority)

primitive_interpreter_dispatch_measurement_rows carries four join specimens with provenance: MeasurementOnly. Dissolution trigger: interpreter-primitive-roster lands → primitive_surface_census_derived absorbs InterpreterDispatch → delete measurement rows (primitive_interpreter_dispatch_measurement_scaffold_note).

Carriers landed

  • std.primitive_identity: five carriers on PrimitiveIdentity; primitive_surface_census_derived from four live authorities.
  • Refusal predicates + 14-witness executing corpus (slice receipt, not closing contract).

Citation (§3)

  • v1 free-call dispatch: v1_interpreter eval_builtin_inner
  • v2 witness hook: v2.compiler.eval v2_eval_call_primitive (carrier src/v2/compiler/05_eval.dag) — real symbol, not in v1_interpreter.rs

Named findings

  • Spelling fork vs alias: fold/fold_list are separate surfaces that can disagree; length/count/size are one arm / three spellings (cannot disagree). fold_list on eval_call intercept before eval_builtin_inner.
  • index_by dual absence: interpreter + emit, absent registry + algebra.
  • lookup dual-realization: eval_method_call short-circuit shadows algebra arm.

CI execution receipt (run 30693580769 @ cc9999f — fleet roster temporarily repaired)

Batch 1 and the witness corpus executed for the first time. All 14/14 primitive_identity_join_witness_test witnesses PASS (InterpretedLeg). No unexpected failures. This run absorbed #7580's publication grants to unblock batch 1; that absorption was reverted (e32d9b338) — this PR carries only its own PublicFilePublishGrant rows and is blocked on #7580 landing on main like the rest of the fleet.

Test plan

@gunbai-bot gunbai-bot Bot changed the title Primitive identity join D0 Primitive identity join D0: five-surface census and join refusals Aug 1, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 1, 2026 03:54
@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Addressed review 45910 in 32cbb62:

Hand-authored census (§2/§3 parallel representation): withdrawn. primitive_surface_census_derived() now reads four live authorities (builtin_registry_surface_names, primitive_contract_roster, all_algebra_field_templates, rt_function_registry). The former 20-row literal is gone. Interpreter specimens are primitive_interpreter_dispatch_measurement_rows with provenance: MeasurementOnly — explicitly not the subject universe. Next trigger named in primitive_interpreter_dispatch_derivation_next_trigger.

Fabricated SurfaceMissingPrimitiveIdentity { authored_symbol: "unreachable" }: removed. primitive_surface_rows_missing_identity_violations now folds with concat only in the Present arm; no unreachable branch is writable.

Mutation-control coverage is stated exactly in primitive_d0_mutation_control_coverage_note: four surfaces discovered, interpreter blind until roster authority lands.

— sent from loyal-crab-305

@cursor

cursor Bot commented Aug 1, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Addressed review 45926:

Terminal contract vs D0 slice: primitive-identity-join boundary and red_control now distinguish TERMINAL acceptance (population-wide join across all five surfaces) from D0 SLICE ONLY witnesses (four derived surfaces + MeasurementOnly specimens). D0 witnesses explicitly do not substitute for closing contract.

Interpreter roster node: added tracked interpreter-primitive-roster with edge primitive-identity-join ← interpreter-primitive-roster. Prerequisite for terminal acceptance; not folded into D0.

Optional coproduct queries: specimen predicates now route through primitive_surface_row_has_identity and primitive_surface_census_has_joined_row — single canonical accessors instead of inline Present/Absent matching at each call site.

— sent from loyal-crab-305

@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

review 45947 — accepted, fixed in 2c9c01351.

Verified: all_algebra_field_templates at dag/std/algebra.dag independently repeated every profile already in all_algebra_profiles — a real drift surface for the primitive census.

Fix: both all_algebra_field_templates and algebra_method_template_name now derive via all_algebra_profiles() |> flat_map(profile => algebra_templates_for_profile(profile: profile)) (and any for the name predicate). Single authority; adding a profile to all_algebra_profiles automatically extends the census. Stage0 regen included.

Witnesses: 11/11 PASS on primitive_identity_join_witness_test.dag.

— sent from loyal-crab-305

@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

review 45947 — already fixed in 2c9c01351 (on current head via merge a742e32b7).

all_algebra_field_templates now derives via all_algebra_profiles() |> flat_map(profile => algebra_templates_for_profile(profile: profile)); algebra_method_template_name uses the same authority. Stage0 regen included. No parallel profile list remains.

Other three derived surfaces (drift audit, no reshaping in this PR):

Surface Drift status
AlgebraTemplate Closed — templates derive from all_algebra_profiles
EmitHandler Single authority — rt_function_registry; maps derived from it
BuiltinRegistry Open — builtin_registry_surface_names hand list parallel to builtin_function_registry (witness-time map_keys on Map<String, Node> unavailable; documented in builtin_registry_surface_names_note)
PrimitiveContractRow Open — primitive_contract_roster hand list parallel to *_contract data rows (primitive_contract_roster_note)

Carrier: primitive_d0_derived_surface_drift_audit_note in std.primitive_identity.

— sent from loyal-crab-305

@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

review 45969

Finding 1 (parallel rosters) — not fixing in this PR; scope is honest exposure, not closure.

Agreed these are §2/§3 parallel enumerations. D0 does not claim single-authority on all four derived surfaces — primitive_d0_derived_surface_drift_audit_note names BuiltinRegistry and PrimitiveContractRow as OPEN parallel rosters with named dissolve triggers; primitive_d0_mutation_control_coverage_note now states mutation control is PARTIAL there (fires when the hand roster is updated, not when builtin_function_registry or a *_contract row grows alone).

Derivation blockers are structural, not diligence gaps:

  • Registry: witness-time census cannot call map_keys on Map<String, Node> (builtin_registry_surface_names_note); dissolve-on is fold registry construction from the list as single authority.
  • Contracts: no declaration-introspection surface to enumerate *_contract rows (primitive_contract_roster_note).

Algebra closed in 2c9c01351; emit is single-authority. Interpreter remains fifth open surface (MeasurementOnly). Closing the two parallel rosters is follow-on work, not D0 scope per operator ruling.

Finding 2 (Optional Bool predicate) — fixed in this push.

Deleted primitive_surface_row_has_identity; consumers now match row.primitive inline at primitive_surface_census_has_joined_row and primitive_d0_map_keys_five_surface_join_holds (predicate-dissolution pattern: match the coproduct at the consumer, no *_has_* Bool surface).

— sent from loyal-crab-305

@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

review 45989 — fixed in this push.

Deleted primitive_surface_census_has_joined_row; primitive_d0_fold_list_spelling_fork_holds and primitive_d0_fold_list_registry_gap_holds now match row.primitive inline at the consumer (same predicate-dissolution fix as review 45969).

— sent from loyal-crab-305

@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Addressed review 46050 in 01f326b3b:

primitive_optional_identity_is_absent deleted. The derived missing-identity count no longer filters via an Optional → Bool variant predicate. primitive_d0_derived_rows_missing_identity_count() now mirrors primitive_d0_surface_census_missing_identity_count() — it counts primitive_surface_rows_missing_identity_violations(rows: primitive_surface_census_derived()), which routes absent rows through the existing primitive_surface_missing_identity_violation fold (typed PrimitiveJoinViolation?, not a parallel Bool surface).

primitive_optional_identity_eq retained as the single semantic equality accessor over PrimitiveIdentity? (review 46007 class); it matches Present to compare slugs, not to test variant membership.

All 14 primitive_identity_join_witness_test witnesses green with CI source roots (dag + src/v2).

— sent from loyal-crab-305

@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Addressed review 46064 in the regen commit on this push:

Stale seed duplicate removed. regen_stage0 re-emitted v1_compiler_infer_method.rs from src/v1/04_method.dag (which no longer defines builtin_registry_surface_names). The orphaned builtin_registry_surface_names / _note functions (~135 lines) are deleted from seed Rust. git grep now finds the roster only in dag/std/primitives.dag.

cargo check -p v1-compiler green after regen.

— sent from loyal-crab-305

@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Addressed review 46076 in the commit on this push:

primitive_has_duplicate_definition deleted. Replaced with primitive_duplicate_semantic_definition_violation(definitions, target) -> PrimitiveJoinViolation?, which returns Present { value: DuplicateSemanticDefinition { identity } } when count > 1 and none otherwise — same pattern as primitive_surface_missing_identity_violation and primitive_realization_unknown_primitive_violation.

Witness updated. w_duplicate_semantic_definition_refuses now matches the typed DuplicateSemanticDefinition arm on planted duplicate definitions (and asserts Absent on the clean primitive_d0_definitions roster), not a bare Bool.

All 14 witnesses green with CI source roots.

— sent from loyal-crab-305

@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Addressed review 46097 in the commit on this push:

primitive_optional_identity_eq deleted (review 46007's accessor was the wrong dissolution shape — agreed). No named Optional<PrimitiveIdentity> → Bool predicate remains in std.primitive_identity.

Census _holds witnesses (primitive_d0_fold_list_spelling_fork_holds, primitive_d0_fold_list_registry_gap_holds, primitive_d0_map_keys_five_surface_join_holds) now match row.primitive inline at the consumer and call primitive_identity_eq only on the Present value arm. Absent disposition for counting/refusal continues through primitive_surface_missing_identity_violation (review 46050).

All 14 witnesses green with CI source roots.

— sent from loyal-crab-305

@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Addressed review 46112 in the commit on this push (labeling + reply on substance):

Agree on the parallel-enumeration debt; disagree that D0 claims otherwise. builtin_registry_surface_names and primitive_contract_roster are intentionally parallel scaffolds — documented since D0 landing in primitive_d0_derived_surface_drift_audit_note and primitive_d0_mutation_control_coverage_note as PARTIAL, not DISCOVERED. This PR does not claim reliable mutation discovery on those two surfaces; witnesses like w_fold_list_registry_gap_proves_open_denominator exist precisely to prove the blind spot (fold_list on interpreter, absent from registry).

Not a new fork: builtin_registry_surface_names was relocated from v1.compiler.infer_method → std.primitives for dag/ compile scope (review 46064); primitive_contract_roster predates this PR. Dissolve-on triggers name the construction paths (fold builtin_function_registry from this list; declaration introspection for *_contract rows).

Cannot derive in D0: witness-time census cannot map_keys on Map<String, Node>; contract enumeration awaits declaration introspection. Deriving now would be a different lane, not a doc fix.

What changed: tightened misleading wording — split DISCOVERED (algebra + emit only) vs PARTIAL (registry + contract rosters) in primitive_d0_mutation_control_coverage_note and roadmap_authority displaced_cost; added counted primitive_d0_parallel_roster_surface_authority_count = 2 with witness assertion.

— sent from loyal-crab-305

@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Addressed review 46252 in 78b76adf5 + b12f05d82:

Finding 1 — five forked per-surface identity maps. Dissolved into one canonical table: primitive_d0_surface_alias_bindings + primitive_identity_lookup(authority, authored_symbol). All census row builders (registry, contract, algebra, emit, interpreter measurement) now consume that single relation; the five primitive_identity_for_* if-chains are deleted.

Finding 1b — cross-authority disagreement blind. primitive_surface_joins_two_identities_violation no longer bails when left.authority != right.authority. Same authored_symbol with two Present identities now refuses: same-authority pairs → SurfaceJoinsTwoIdentities; cross-authority pairs → IncompatibleInvocationAssignment. New RED witness w_red_cross_authority_identity_fork exercises the cross-authority path.

Finding 2 — hand-rolled Optional→Bool in _holds predicates. Deleted inline match row.primitive { Present => … Absent => false } from primitive_d0_fold_list_spelling_fork_holds, primitive_d0_fold_list_registry_gap_holds, and primitive_d0_map_keys_five_surface_join_holds. Witnesses now route through canonical accessors primitive_surface_row_identity_violation and primitive_d0_surface_census_row_identity_coherent (which fold/query the census without re-matching PrimitiveIdentity? shape in the Bool predicate).

Execution receipt: all 15 witnesses PASS locally on this head (claim_batch entry primitive_identity_join_witness_test.dag).

— sent from loyal-crab-305

@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Addressed review 46253 in 8c5866cd2 — finding confirmed, accidental SCM regression reverted.

Finding 1 — active P1 node with no closing check. Correct: this branch had deleted dag/gunbc/source_integration_proof_kernel.dag, both witness files, scm_p1_proof_kernel_execution_contract() / with_execution(...) on 2-scm-p1-proof-kernel, and the QuarantineProbeExpectRed + known_red_probe_entries enrollment. That was unrelated scope bundled into primitive-identity D0. Restored all from origin/main; witness_accepted_scm_sequence_activates_authored_p1_slice greens again with the bound GunbcClaimValidation contract.

Finding 2 — handback promises closing validation that no longer exists. Same root cause; handback text was never edited — only the carrier/contract were deleted. Restoration makes the handback accurate again.

Finding 3 — bundled SCM regression. Agree. The ~1000-line P1 first-slice deletion is fully reverted; this PR's SCM touch is now zero net vs main on proof-kernel paths. Primitive-identity D0 (std.primitive_identity, witnesses, roadmap node updates for primitive-identity-join / children) is unchanged.

— sent from loyal-crab-305

Land std.primitive_identity carriers, derived four-surface census,
refusal coproducts, canonical alias lookup, and 15 executing witnesses.
Rebases onto main through c9dc667 (#7580 publication gate).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot
gunbai-bot Bot force-pushed the session/loyal-crab-305-primitive-identity-d0 branch from 598064a to 8750e96 Compare August 1, 2026 13:35
@briansrls
briansrls merged commit af062b9 into main Aug 1, 2026
9 of 10 checks passed
@briansrls
briansrls deleted the session/loyal-crab-305-primitive-identity-d0 branch August 1, 2026 15:40
gunbai-bot Bot pushed a commit that referenced this pull request Aug 1, 2026
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 1, 2026
…iguous across std.primitive_identity and std.roster_frontier)

Both modules declare an identical top-level decl_ref helper on main;
the ambiguity is latent there and fired in this PR's closure, which is
the first to link them (extdeps.external_authority imports
std.roster_frontier). Minimal fix at the red site only: the six call
sites in dag/test/claim/primitive_identity_join_witness_test.dag are
module-qualified to std.primitive_identity.decl_ref and the named
import row is dropped. 15/15 witnesses in the file PASS by execution.

The root defect is a DESIGN section-3 fork: std.primitive_identity
re-mints the decl_ref constructor std.roster_frontier already owns
(the same re-mint cursor review 46136 removed from this PR's own
carrier). Deduplicating it belongs to the primitive-identity lane on
main; this commit only unblocks the floor at the site that reds.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Aug 1, 2026
…ng preflight + ExternalModelScope carrier (operator verdict on #7556) (#7571)

* WIP: DESIGN §3 external-upstream-decomposition subsection + extdeps modeling

* chore: regenerate drifted generated artifacts (ci auto-heal)

* DESIGN §3 external-upstream-decomposition + extdeps modeling preflight + ExternalModelScope carrier/gate (operator verdict on #7556)

- design_document.dag §3: verbatim 'External upstream decomposition' subsection; DESIGN.md regenerated
- gunbc.plans.extdeps_modeling_preflight: 8 typed preflight rows (single authority), registered Plan renders the table from them
- extdeps.external_authority: ExternalSubjectRef/ExternalRevision/ExternalModelScope (citations nonempty by construction), FactAuthorityOverride.fact -> DeclarationRef; admit_external_model_scope gate with ForeignSubjectRow/ConsumerCoverageInUpstream refusals
- gunbc.extdeps_scope_frontier: staged fail-closed enrollment — 2 carriers + 17 machinery-exempt + 397 counted frontier rows over all 416 dag/extdeps files; live-tree cover witness refuses unrostered or stale rows
- extdeps.vendor.{microsoft,atlassian} adopt extdeps_model_scope (admitted by execution)
- extdeps.browser: loud non-precedent disposition note naming the eventual split
- dag/test/claim/external_model_scope_witness_test.dag: 12 claims incl. operator RED (generic browser + Chromium scope + Chrome|Firefox|Safari rows -> refused) and GREEN (shared shape + separate modules + downstream roster -> admitted); stage0 seed + ci.yml + plan doc regenerated

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Consume the module's own anchor in extdeps_model_scope (review 46077), qualified against silent same-name capture

cursor review 46077: first_citation re-minted the anchor URI — parallel representation. Fixing it by BARE sibling reference was proven WRONG by execution: atlassian's bare extdeps_external_authority_anchor reference silently captured microsoft's same-named decl (first-occurrence-wins pooling; the duplicate-toplevel-decl fail-open, now witnessed on data decls). The landed spelling is the module-QUALIFIED reference (extdeps.vendor.<m>.extdeps_external_authority_anchor), single authority with no capture; the adopter witness now discriminates per-module citation locators so a future capture regression reds.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Regenerate ci.yml on merged tree (extdeps-modeling-preflight rows on top of main)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Roster the two extdeps modules main added mid-flight (review 46111): git/inspect + github/workflows, frontier count 397 -> 399

The live cover witness red exactly as designed on the merged tree; frontier claims re-run green (418 files = 2 carriers + 17 machinery-exempt + 399 frontier).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Rework carrier/enforcement per operator handback on #7571 (also codex review 46118)

(1) ExternalSubjectRef carries a DeclarationRef (symbolic subject identity; vendor scopes point at their existing microsoft/atlassian declarations, no restated legal names). (2) module-grain revision removed — revisions belong on build/release/fact rows. (3) the synthetic function is no longer presented as an admission gate: renamed to the external_model_scope_decision KERNEL over DeclaredScopeFacts with a loud honesty boundary; the mechanical wall today is scope PRESENCE; subject-content-derived enforcement is the named frontier feature:extdeps-subject-content-derived (dissolves when a Node-tree projection derives DeclaredScopeFacts from the real module and feeds the same kernel). (4) the 399-row legacy population moved out of the semantic module into the frozen manifest dag/gunbc/legacy_extdeps_scope_frontier.tsv (one path per line, remove-only, count DERIVED by parse_frontier_manifest, exact bidirectional live diff enforced by the cover witness). (5) consumer coverage identity is DeclarationRef, not free text.

12/12 witness claims green by execution incl. the live 418-file cover against the manifest; stage0 seed regenerated; drift gates PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: DESIGN §3 external-upstream-decomposition subsection + extdeps modeling

* Consume std.roster_frontier's declaration_ref_eq instead of re-minting it (review 46136); register std_roster_frontier.rs in the seed roster

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: DESIGN §3 external-upstream-decomposition subsection + extdeps modeling

* Merge main; enroll publication grants for this PR's 6 added paths + 11 ungranted main-side additions (publication_placement_gate green)

The new Stage-0 publication wall (P-B) requires a PublicFilePublishGrant row for every path added after the cutover commit. This PR's six additions are enrolled, plus the eleven paths merged to main since cutover without rows (heal_revalidation, source_integration_proof_kernel, workflow-dispatch, github/workflows lanes) — main's own floor is red on the gate without them, and the roster is one shared carrier. publication_placement_gate_passes PASS locally by wet execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Make the presence wall mechanical (codex review 46215): carrier rows content-verified, manifest frozen against a git anchor

Half 1: scope_carrier_paths membership was path-asserted; the cover witness now filesystem_reads every carrier file and refuses one whose bytes lack the extdeps_model_scope declaration (declared text-scan scaffold, corpus_scan precedent, dissolves with the storage-grain frontier). Half 2: the manifest's remove-only lifecycle was review discipline; every manifest row must now name a file that existed at the pinned legacy_manifest_freeze_sha — the witness diffs freeze..HEAD via git.Core.DiffNameStatus (the publication-gate pattern) and refuses any manifest row in the added/copied/renamed set, with diff failure and parse truncation typed as refusals (PostFreezeObservation coproduct), never skips. 17/17 claims green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: DESIGN §3 external-upstream-decomposition subsection + extdeps modeling

* Split the wet live observations out of hermetic discovery (d4bef96 floor red)

Hermetic discovery executed the three wet-only fns (Filesystem.List walk,
git.Core.DiffNameStatus freeze diff) against the mock corpus, where those
operations are unpublished — ReadsLiveTree does not exclude fns from
discovery. Structural fix, not a widened mock:

- pure decision fns (scope_cover_holds, carrier_content_declares_scope,
  PostFreezeObservation, manifest_freeze_holds) move to their single
  authority gunbc.extdeps_scope_frontier; the hermetic witness imports
  them (also discharges cursor review 46245 both findings)
- new dag/test/claim/external_model_scope_live_cover_witness_test.dag
  (ReadsLiveTree) holds the live walk + freeze diff; discovery-excluded
  via witness_exclusion_frontier (OfflineLocalRecipe, substantiated
  reason + dissolve-on + local recipe, artifact_store precedent) and
  granted in publication_grant
- hermetic file keeps all RED controls, kernel controls, manifest
  accounting, and the filesystem_read carrier-content check per-PR

Verified by execution: 14/14 hermetic PASS, 3/3 wet PASS,
publication_placement_gate_passes PASS, generated-artifact gate PASS,
fmt clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix the mainline scm_compatibility homonym capture blocking CI (5 floor reds on origin/main d552ff4)

Top-level fn names are not module-scoped in the assembled closure, so
native_scm_interaction_scenario_fixture's parametered fixture_projection
collided with the zero-arg fixture_projection homonyms in
pijul/mercurial_upstream_model_witness_test once #7563 linked their
closures — native_scm_receipt_for's internal call then dispatched to a
zero-arg winner: 'call contract mismatch: no parameter named scenario'.

Fix: rename the parametered helper to the unique prefixed
native_scm_scenario_fixture_projection (both references are
file-internal; no external caller exists, verified by corpus grep).

Verified by execution: all 5 previously failing witnesses PASS, plus
63 witnesses across every other importer of the fixture module
(native_scm_interaction_contract 14/14, mercurial compat 6/6, git
compat 7/7, roadmap_validation_oracle 36/36).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* State the enforcement grain honestly and gate the roster-to-disk direction per-PR (codex review 46258)

Finding 1: the preflight doc and frontier law claimed the population
cover as 'the mechanical wall today' while the cover runs only on the
discovery-excluded wet lane — grain inflation. Fixed both ways:

- new per-PR hermetic test roster_paths_resolve_on_disk: every rostered
  path across all three rosters (2 carriers + 17 machinery + 399
  manifest rows) must resolve in the checkout via the filesystem_read
  carve-out (22ms for 418 reads); a stale or fabricated roster row reds
  per-PR via the interpreter's typed hermetic Read refusal (verified by
  execution on a nonexistent probe path)
- law note + preflight bullets now state the grain explicitly: per-PR
  merge-gated = roster-to-disk resolution, roster disjointness, carrier
  byte-content, RED controls; wet-lane = live enumeration (disk-to-
  roster new-file detection) and the freeze diff, with per-PR gating of
  that direction arriving at the mandatory_tag region promotion the
  frontier dissolves into

15/15 hermetic witnesses PASS; plan doc regenerated same commit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Dedupe the publication roster after merging main (gate-red duplication on main itself)

origin/main 06d7aea lists the eleven pre-wall repair paths TWICE:
once from #7565's branch-side enrollment block and once from #7580's
repair block — the same enrollment race #7580's own note describes,
re-entered by the next concurrent pair. The placement gate refuses
repeated grants, so main is currently gate-red and every PR merge ref
inherits it. This branch resolves the merge by keeping #7580's repair
block (with its note) as the single occurrence and re-adding only this
PR's own seven paths; publication_placement_gate_passes PASS by
execution on the merged tree (42 unique rows, zero duplicates).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Land the per-PR merge-gated ExtdepsScopePlacementGate (codex review 46281)

Diff-grain sibling of tools.publication_placement_gate: refuses any
freeze..HEAD-added dag/extdeps .dag file outside carriers-union-
machinery (scope_placement_refused_paths, pure kernel on
gunbc.extdeps_scope_frontier with hermetic RED/GREEN controls) and any
frozen-manifest row naming a post-freeze-added file; diff failure and
parse truncation refuse, never skip. Enrolled as a cheap-floor wet gate
(roster 49->50, gates 10->11, cheap membership 4->5). One recorded
freeze re-anchor to the gate-landing base (0ec3c10), admitting
lean/overflow.dag which merged inside the wall-less interim (#7550);
documented in legacy_manifest_freeze_sha_note. Live-cover witness
dedupes its diff observation onto the gate module. Law note and
preflight bullet updated to state both directions per-PR.

RED proven by execution: a committed unrostered dag/extdeps probe file
turns extdeps_scope_placement_gate_passes red; removing it greens.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Expose std_roster_frontier in the derived stage0 crate partition (codex review 46329)

extdeps_external_authority.rs imports crate::std_roster_frontier, but
the partition source authority (v2.workflow.rust_crate_partition) never
rostered the new module, so the partitioned crates could not resolve
it. Fix at the authority: std_roster_frontier joins the std-core
primitive roster with its module-dag edges (extdeps_external_authority
-> std_roster_frontier -> std_decl_ref); partition artifacts and the
stage0 seed regenerated to fixed point (two regen generations — the
renderer bakes the partition rows at its own build time), and
stage0_core/src/lib.rs (tracked but outside every regen path — the
lifecycle scaffold's open partition contradiction) gains the matching
declaration directly.

Disclosed, not fixed here: v1-stage0-std-core has four OTHER unresolved
modules (std_occurrence_identity, extdeps_units_{dimensionless,
iec_80000_13,iso8601}) byte-identical on origin/main — pre-existing
partition rot from other lanes (the #7109 class; no CI job compiles
these crates). Rostering them correctly requires re-cutting the
std/extdeps crate boundary (extdeps_uri + extdeps_external_authority
would move below std_measure, emptying v1-stage0-extdeps-base) — the
deferred emitted-crate-partition lane's re-cut, not a one-line roster
fix; attempted and reverted here after it surfaced that knot.

Verified: cargo check -p v1-stage0-std-core no longer reports
std_roster_frontier (remaining errors = the four pre-existing, same as
main); generated-artifact gate PASS; fmt clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Reconcile freeze anchor with merged main 5669d42 (cpm_pert joined the interim manifest)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Make the manifest's remove-only lifecycle mechanical at line grain (codex review 46378)

manifest_freeze_holds judges file CREATION dates, so a pre-freeze file
migrated out of the manifest could later be re-added (scope decl
deleted, carrier row dropped, manifest row restored) and the freeze
check would pass — the escape hatch re-opened after migration. Closed:
tools.extdeps_scope_placement_gate now also observes
git.Core.DiffUnified0(origin/main...HEAD) and refuses any line the
change itself ADDS to the manifest (manifest_line_observation /
manifest_remove_only_holds on gunbc.extdeps_scope_frontier). The one
admitted arm is ManifestIntroduced — the file absent at the merge base
(the unified diff's /dev/null old side), exactly the PR that first
lands the manifest, unforgeable once it exists on main (a delete-and-
rewrite inside a branch still diffs as modification). Unreadable diff
text and failed diffs refuse, never skip; removals stay free, so the
manifest is monotonically shrinking by construction at the merge gate.

Hermetic controls: red_manifest_remove_only_refuses_added_row,
green_manifest_remove_only_admits_removal_and_unrelated_edits,
green_manifest_introduction_admitted_once,
red_manifest_unreadable_refuses. Verified by execution: 21/21 hermetic
witnesses PASS, both placement gates PASS wet on this tree (the
introduction arm exercising the live path), fmt clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Reach the unreadable arm from the parser and collapse the verdict to one surface (codex review 46387)

Finding 1: manifest_line_observation never constructed
ManifestDiffUnreadable — malformed or truncated diff text fell through
to ManifestUntouched, which the gate accepts (fail-open), and the RED
control bypassed the parser by constructing the variant directly.
Closed: the fold tracks whether any line MENTIONS the manifest path and
whether its recognized new-side header was ever ENTERED; mention
without entry yields ManifestDiffUnreadable — covering truncation mid-
header AND making a manifest deletion refuse conservatively (old-side
header mentions the path, no new-side header follows; the promotion PR
that legitimately deletes the manifest deletes this gate in the same
change). New REDs go THROUGH the parser: a truncated header diff and a
whole-file deletion diff both yield ManifestDiffUnreadable.

Finding 2: manifest_remove_only_holds hand-matched the same coproduct
the gate matched into ProcessExit — two verdict authorities. The Bool
predicate is deleted; the ONE surface is the pure
manifest_remove_only_exit(observation) -> ProcessExit on the gate
module, consumed by both the wet gate wrapper and every hermetic
control (which assert on its ExitSuccess/failure arms).

Verified by execution: 22/22 hermetic witnesses PASS (incl. the two
new parser-reaching REDs), extdeps_scope_placement_gate_passes PASS
wet, fmt clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Disambiguate decl_ref in the #7549 witness (floor red on 2a04481: ambiguous across std.primitive_identity and std.roster_frontier)

Both modules declare an identical top-level decl_ref helper on main;
the ambiguity is latent there and fired in this PR's closure, which is
the first to link them (extdeps.external_authority imports
std.roster_frontier). Minimal fix at the red site only: the six call
sites in dag/test/claim/primitive_identity_join_witness_test.dag are
module-qualified to std.primitive_identity.decl_ref and the named
import row is dropped. 15/15 witnesses in the file PASS by execution.

The root defect is a DESIGN section-3 fork: std.primitive_identity
re-mints the decl_ref constructor std.roster_frontier already owns
(the same re-mint cursor review 46136 removed from this PR's own
carrier). Deduplicating it belongs to the primitive-identity lane on
main; this commit only unblocks the floor at the site that reds.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Post-merge reconcile: fix stale sibling citations after #7591 deleted the publication gate

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 2, 2026
…e fork that reds shared closures (#7612)

* decl_ref constructors move to std.decl_ref: dissolve the parallel-lane fork that reds shared closures

std.primitive_identity (#7549) and std.roster_frontier each minted identical fn decl_ref / decl_field_ref beside std.decl_ref, which owned the type but no constructor. v1-seed fn names are not module-scoped, so any resolve pool containing both modules refused every bare decl_ref reference as ambiguous — six such refusals in the primitive_identity_join witness closure on current main, blocking unrelated PR floors. The constructors now live once beside their type; both former minters and all 13 importers repoint.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* regen: emitted std_decl_ref carries the consolidated constructors

regen_stage0 over the updated dag closure — the constructors' single
authority now emits with its module (110 files regenerated, 1 drifted).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* host_standup: delete the third duplicate decl_ref constructor (review 46502)

The module is import-free; its bare decl_ref calls resolve from
std.decl_ref — the same pool source its DeclarationRef type references
already use. All 27 host_standup spine + assimilation witness fns green
by execution; not in the emitted stage0 set, so the regen fixed point
is untouched.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* regen: emitted std_roster_frontier drops the deleted constructors (review 46764)

Fresh regen_stage0 on the merged tree (the earlier pass used a
pre-#7585 stale binary whose escape handling produced a phantom
v1_compiler_infer drift — rebuilt, rerun, gone). One honest drift:
the roster_frontier seed no longer carries the constructor pair, so
the emitted Rust matches its .dag source (DESIGN §7).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant