Repository navigation
Delete live-snapshot count pins (wave 1) - #7615
Merged
Merged
Conversation
Remove witness count transcriptions that only mirrored live derived state (v1 interpreter primitive surface, E0599 censuses, stage0 emit model, observation emit roster magnitude). Strip mutable numeric prose from the primitive-surface authority note. Restore vacuity_test.dag — jolly-fox-325 owns that pin replacement separately. Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot
Bot
force-pushed
the
session/clever-otter-130
branch
from
August 1, 2026 19:44
ab7ea09 to
d8bcbc0
Compare
Re-add declared-row dissolution, derived-enumeration, and declared-site set-law checks without count conjuncts or prose-length proxies. Co-authored-by: Cursor <cursoragent@cursor.com>
Require representative bridge/method rows so empty filtered lists cannot pass all-derived checks; assert dissolve_on names a trigger via "dissolves when" prose instead of length > 0. Co-authored-by: Cursor <cursoragent@cursor.com>
Contributor
|
Addressed review 46631 (codex REQUEST_CHANGES) in
— sent from clever-otter-130 |
4 tasks done
briansrls
pushed a commit
that referenced
this pull request
Aug 2, 2026
Adds the closing contract v1-interpreter-primitive-roster never had, then accepts the node against it. The closing check is deliberately structural, not a population pin: named dispatch sites contribute derived rows, duplicate row keys refuse, shadows are exactly the known set by name, declared rows carry their own dissolution triggers, an arm with no semantic primitive identity stays representable, and an unrecognised form label refuses rather than defaulting. Binding it to counts would have recreated at the acceptance layer the defect #7615 removed from the witness layer -- the five deleted witnesses pinned live-population numbers copied from the tree, which DESIGN.md §5 rules is not an oracle, and they duly behaved as change detectors that redded main twice. One handback clause of the node was genuinely amended, not reworded: it demanded "witnesses asserting exact values rather than lower bounds", and those witnesses no longer exist on main. Every exact assertion grounded in a named identity or a controlled fixture survived #7615 untouched; only the tree-copied census literals went, and the three denominators gained a better consumer at D1 that joins census to roster by identity. The digest moves because the bar moved; read it as a real amendment. Criteria digest f0f450f4ddc82fe9 derived by execution via node_criteria_digest against the live amended node, with the pre-amendment wording yielding d2e455ab49e472e2 as the control that the pin tracks the criteria text. Also corrects the record on PR #7624, whose title claimed R1 but whose entire merged diff is two lines adding an import. R1 is unstarted. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Aug 2, 2026
review 46974 caught a real defect. The representability clause discharged "the roster can carry an arm with no semantic primitive identity" with primitive_d0_derived_rows_missing_identity_count() > 0, which measures how far the semantic identity join has got rather than what the roster can represent. It would have gone RED exactly when that join succeeded for every derived row -- legitimate downstream progress reddening an upstream node's acceptance check. That is the same defect class #7615 removed from the census witnesses, relocated onto join state, and it contradicts this PR's own framing. The structural fact is that InterpreterPrimitiveDispatchArm carries an interpreter-local arm identity and no semantic-primitive-identity field at all, so every row already is such an arm. The clause now constructs one and shows the roster's operations are total over it, plus that no live row carries an empty interpreter-local identity. The std.primitive_identity dependency is gone. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Aug 2, 2026
* WIP: v1 deletion * Bind and accept the interpreter primitive roster (R0) Adds the closing contract v1-interpreter-primitive-roster never had, then accepts the node against it. The closing check is deliberately structural, not a population pin: named dispatch sites contribute derived rows, duplicate row keys refuse, shadows are exactly the known set by name, declared rows carry their own dissolution triggers, an arm with no semantic primitive identity stays representable, and an unrecognised form label refuses rather than defaulting. Binding it to counts would have recreated at the acceptance layer the defect #7615 removed from the witness layer -- the five deleted witnesses pinned live-population numbers copied from the tree, which DESIGN.md §5 rules is not an oracle, and they duly behaved as change detectors that redded main twice. One handback clause of the node was genuinely amended, not reworded: it demanded "witnesses asserting exact values rather than lower bounds", and those witnesses no longer exist on main. Every exact assertion grounded in a named identity or a controlled fixture survived #7615 untouched; only the tree-copied census literals went, and the three denominators gained a better consumer at D1 that joins census to roster by identity. The digest moves because the bar moved; read it as a real amendment. Criteria digest f0f450f4ddc82fe9 derived by execution via node_criteria_digest against the live amended node, with the pre-amendment wording yielding d2e455ab49e472e2 as the control that the pin tracks the criteria text. Also corrects the record on PR #7624, whose title claimed R1 but whose entire merged diff is two lines adding an import. R1 is unstarted. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Assert roster representability structurally, not as join progress review 46974 caught a real defect. The representability clause discharged "the roster can carry an arm with no semantic primitive identity" with primitive_d0_derived_rows_missing_identity_count() > 0, which measures how far the semantic identity join has got rather than what the roster can represent. It would have gone RED exactly when that join succeeded for every derived row -- legitimate downstream progress reddening an upstream node's acceptance check. That is the same defect class #7615 removed from the census witnesses, relocated onto join state, and it contradicts this PR's own framing. The structural fact is that InterpreterPrimitiveDispatchArm carries an interpreter-local arm identity and no semantic-primitive-identity field at all, so every row already is such an arm. The clause now constructs one and shows the roster's operations are total over it, plus that no live row carries an empty interpreter-local identity. The std.primitive_identity dependency is gone. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Correct the denominator-consumer claim; re-derive the digest review 46995 is right on both counts, and this was the same failure the repository keeps paying for: a sentence that reads well while the evidence it cites does not establish it. The amended handback claimed each of the three denominators has "a live consumer that joins them by identity". Neither half held. dispatch_site_count has NO external consumer at all — the only mention outside its own carrier was the acceptance note asserting it had one. And w_interpreter_census_consumes_roster_authority does not join by identity. It executes distinct_arm_identity_count, authored_spelling_count and v1_interpreter_row_count, asserting the ordering relation plus primitive_d0_interpreter_census_matches_roster — which is primitive_d0_interpreter_surface_row_count() == v1_interpreter_row_count(), a count equality between two independent derivations. That is a legitimate cross-derivation reconciliation and not a tree-copied literal, but DESIGN.md §5 is explicit that completeness is an identity join rather than a count equality, so it must not be described as one. Citing that very expression as proof of an identity join was the error. The handback clause now claims only what is delivered: three denominators derived from the roster rather than pinned as literals. The acceptance note records the retraction, states the count-equality distinction, names dispatch_site_count as consumer-less residue, and carries a dissolve-on for the D0 identity join reaching arm grain. Digest re-derived by execution: 581758f45921b40a. The two superseded values (d2e455ab49e472e2 pre-amendment, f0f450f4ddc82fe9 pre-correction) are recorded as the control that the pin tracks the criteria text. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Mint the ArmEnumeration dissolution-trigger accessor; both readers consume it review 47180 is right that a second hand-rolled match over ArmEnumeration is duplication, so the fix is the single authority rather than a disposition: the carrier now owns arm_declares_dissolution_trigger, and BOTH readers consume it — the new acceptance contract and the pre-existing witness that first hand-rolled the match. Migrating only the new one would have left the duplication in place while claiming it was removed. Two things in the review did not check out and are recorded rather than silently accepted. There was no canonical accessor to consume — this commit creates the first one. And DESIGN.md contains no 'predicate/walker dissolution rule' by that name; the correct grounding for the change is DESIGN §2 minimize-redundancy and §3 single-authority, which the fix satisfies. Contract green, surface witnesses 19/19. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: v1 deletion * Revert "WIP: v1 deletion" This reverts commit a3a45ad. * Scope the ticket-brief budget to authored nodes; drop a ledger from one boundary Two independent causes, both surfaced by accepting R0. FIRST: roadmap_ticket_brief_violations walked doc_all_nodes(roadmap_authority()), which includes the DERIVED closing-contract task nodes whose boundary is a fixed prefix plus the target node's red_control. That made the page budget a second, undeclared constraint on red_control length — accepting any node could push a DIFFERENT node over budget, because acceptance makes the next node startable-and-unbound and derives a closing-contract row for it. Accepting v1-interpreter-primitive-roster did exactly that to v1-interpreter-primitive-dispatch-authority, whose six-clause red_control then overran. The only remedies available were to trim a carefully authored acceptance bar to satisfy a page constraint, or to leave every PR touching roadmap_authority.dag red. A derived brief is a projection of a field already governed where it is authored, so the budget now walks declared_roadmap_nodes(). The planted-fixture RED control is untouched and still refuses at the threshold. SECOND: native-selected-witness-bundle's boundary was 105 words because it was carrying a mutable execution ledger — PR number, head SHA, session name, date, PASS count, timing measurements — in a criteria field, which witness_authority_contains_no_mutable_execution_ledger exists to forbid. Replaced with the node's actual boundary at 98 words. The node has no acceptance receipt, so no stored criteria digest moves. roadmap_page_witness_test 35/35, roadmap_authority_test 39/39. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Regenerate ROADMAP.md from the merged authority The merge resolution staged main's side of ROADMAP.md and the subsequent regeneration did not make it into the merge commit, so the committed projection still showed v1-interpreter-primitive-roster active. Re-derived from the merged authority: the accepted node leaves the active projection and v1-interpreter-primitive-dispatch-authority moves up as the frontier successor, which is what accepting R0 means. Generated file, so re-derived rather than hand-edited (generated-file conflict policy row 1). --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Aug 11, 2026
The floor finally evaluated this branch — main was red before, then an upstream
timeout cascaded — and found exactly one red witness in 8757:
`v1_interpreter_primitive_dispatch_authority_acceptance_contract_holds`.
It is genuinely this PR's. Deleting `v2.lens.inert_lens` removed the last two
rows carrying `EvalCallBridgeFamilySite { module: v2.lens.inert_lens }`, so the
distinct bridge-family count went 9 -> 8 and
distinct_bridge_family_site_count() == 9
redded. The literal was a population pin — the exact class DESIGN §5 rejects,
and the exact class #7615 removed from this same carrier's census witnesses.
The file's own `closing_contract_note` opens by claiming "The checks here are
structural properties that survive roster growth -- not population pins", so
the clause contradicted its own contract and my deletion is what surfaced it.
Decrementing 9 to 8 would restore green while preserving the defect, so the
control is derived instead: the number of distinct emit-site keys must equal the
number of distinct modules the bridge rows themselves name, and exceed one.
That is not a tautology, because the two sides come from different places — the
left from `dispatch_emit_site_key`'s keying, the right from each row's own
`module` field. Collapsing the families back onto one shared key (the defect the
clause is named for) reds it, 1 != N. Adding or removing a family does not.
The clause now measures what its name claims, in both directions.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi
briansrls
pushed a commit
that referenced
this pull request
Aug 12, 2026
* Make the witness-roster walk demand-directed instead of unconditional pre-plan claim_executor ran discover_floor_witness_roster_with_snapshot once up front, BEFORE resolving the plan, on the stated ground that a naming violation should be "the cheapest possible failure". Measured, that walk is the most expensive phase in the process: 5.9 min of a 56.5-min ordinary floor (run 31477894666), and ~6 min of a ~15-min regen whose plan has exactly two nodes. It is expensive because "naming hygiene" is a misleading label. The four rules in v2.workflow.floor_naming_hygiene are string predicates over file paths and line prefixes, but the roster producer they are reached through also builds module-graph facts, runs a second strict reference-resolution pass, computes path indexes, and runs inert-lens reachability plus the construction- justification census. A two-node regen plan paid all of it to discover a roster it never reads. Hygiene is a property of the witness ROSTER, so it is now paid by the plans that have one: the walk moves to the existing `schedules_discovery` predicate, after the plan's batches settle. The roster is memoized by request digest (IN_PROCESS_ROSTER_BY_REQUEST), so plans that DO schedule discovery pay exactly what they paid before — the corpus batch hits the memo this call fills. Plans that do not schedule discovery pay nothing, and cannot be unhygienic: they have no roster. The walk-attempt id is minted unconditionally as before; it is a tracing coordinate every later phase stamps, and it is not the expensive part. This also closes the PRELUDE COVERAGE HOLE gunbc.ci_spec gunbc_ci_floor_batch_wall_budget_note already names: the walk sat outside every batch budget and could only red at the step cap. It is now inside the region the plan accounts for, or absent. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * Update the design authority for the demand-directed hygiene walk (review 51099) review 51099 (cursor/composer-2.5, REQUEST_CHANGES) correctly caught that #8140 changed documented CI behavior without updating its authority. DESIGN.md Building & checks stated the opposite of the new code: "the executor runs the zero-enrollment naming walk when no discovery batch is scheduled" That clause is superseded here in gunbc.design_document (DESIGN.md is generated from it; the heal job regenerates the projection). Both of the reviewer's findings are recorded rather than only the first: (a) SCOPE — discovery-free plans no longer run the corpus-wide nameability rules. Declared as a narrowing, with the honest coverage argument: every PR runs the `ci` job, whose plan schedules discovery and walks the full tree, so per-PR coverage is unchanged; what is deleted is a second redundant walk on regen-only and plan-artifact-only runs. Explicitly NOT backstopped by the affected-set falsifier, which has produced no green verdict since 2026-08-03. (b) ORDERING — for plans that DO schedule discovery the walk now runs after plan resolve/eval, so a naming violation pays ~0.5 min of plan resolution before refusing. The reviewer asked whether the trade is intentional: it is, and it is priced — ~0.5 min later on the refusing path against ~6 min saved on every regen. A dissolve-on is recorded: the clause, the separate walk, and the `__`-basename rule all retire when the placement rules move to canonical source ingestion and test identities derive from parser-produced declarations. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * chore: regenerate drifted generated artifacts (ci auto-heal) * Repair the stale output-policy comment left by the walk move (review 51101) review 51101 (cursor/composer-2.5) caught claim_executor.rs:10283 still asserting "The walk still runs before plan evaluation, so a naming violation stays the cheapest failure" — the exact opposite of what this PR does. Non-blocking as a defect, but it is the same class the PR itself is about: a comment standing as authority for behavior the code no longer has. #8140's own receipt was a block comment whose stated premise had been false for months. The paragraph's real subject — install output policy BEFORE the walk so the whole-tree read is funnelled rather than emitting ~2.3k `[file] read` lines — is unchanged and still correct; the walk simply moved further away from it. Rewritten to say that, rather than deleted, so the ordering requirement keeps its rationale. Swept the rest of claim_executor.rs / cli_run.rs for other assertions of the old ordering: the only remaining hits are this PR's own comment describing the prior behavior in the past tense. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * Delete supply-side lens enforcement from floor discovery Two censuses ran inside `discover_floor_witness_roster` — the inert-lens reach walk and the construction-justification census. Both asked a question about who authored a lens, and both answered it by acquiring a whole-corpus module graph. Every discovery run paid that: every PR, regen, and every coordinated scoped worker, all of which wanted a witness roster and nothing else. The unit of computation was the world; the unit of fact was one module's authorship. Deleted end-to-end, not merely unwired: - `v2.lens.inert_lens` (its `.dag` surface was two self-recursive stubs, `fn f() { f() }`, reachable only because the interpreter intercepted them) - its two host builtins, both interpreter dispatch registrations, the generated bridge family, the `04_method` type-table entries and the `std.primitives` roster rows - the `InertLens` registry variant, its registry row, contract row and `lens_module_gate` invariant surface - `inert_lens_modules`, `inert_lens_modules_legacy`, `lens_justification_census`, `unjustified_lens_modules`, `declares_construction_justification` and both floor refusal arms (`cli_run.rs` and `floor_discovery_snapshot.rs`) - the long witness and its frozen deferral row (shrink logged) `build_module_graph_facts_live` still runs on this path and this change does not claim otherwise: effect-reach derivation and the cross-worker snapshot transport both consume it. `refuse_on_module_graph_read_refusals` and its two red controls are retained and re-homed, since the fail-closed arm now guards those consumers rather than the deleted censuses. This is a scope narrowing, not a climb. A new lens with no witness, and a lens recording no `construction_justification`, are both writable again and nothing detects either. Declared in DESIGN §6 with its next-rung trigger: authorship belongs on the module's own declaration, checked where the module is already parsed, rather than reconstructed corpus-wide by a consumer that wanted a roster. Two citations repaired rather than left stale (§3): the roadmap acceptance note cited a shadow witness this change renames and weakens, and `source_authority` cited the inert-lens stubs as its example of host interception. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * chore: regenerate drifted generated artifacts (ci auto-heal) * Reconcile the plan carrier and stale comments with the deleted enforcement Review 51113 (cursor/composer-2.5) found two second authorities still claiming enforcement the code no longer performs — DESIGN §3 dual representation and §4b rung honesty. Both confirmed against the current head, both fixed. `gunbc.plans.construction_justification_rule` said the presence check "run[s] in `discover_floor_corpus_rows`" and listed it as current status. Its retirement condition also named that check as its trigger, so after the deletion the condition could never fire — an unreachable lifecycle claim that structurally cannot report itself satisfied. The plan now leads with a supersession notice, §2/§3/§4 are marked historical rather than reworded, and a new §5 records what was deleted, what it costs (a lens added tomorrow with no justification lands green; the 35-module classification in §4 is a historical measurement, not a maintained invariant), and the next-rung trigger. The retirement condition is replaced with a reachable one and says why. `floor_discovery_snapshot.rs`'s consumer census still listed the two gates and still called the roster walk "pre-plan", which #8140 already made false. Swept the rest rather than fixing only what was reported: eight comments in `cli_run.rs` and one in `claim_executor.rs` named the inert-lens reach as a live consumer of the observation rows, the reference-edge producer, and the selection tier. Repointed to the consumers that remain. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * Delete the dead lens classifier and date-scope the cost claim Two bounded review corrections. `is_top_level_lens_module` survived the census deletion with no remaining caller — only its own definition. It compiled clean because the crate carries a blanket allow, which is exactly why the residue needed finding by reading rather than by warning. Deleted; the PR's bar is end-to-end with zero residue, and a dead classifier left behind is the pattern this change exists to close. The new DESIGN paragraph asserted the censuses charged "every discovery run — on every PR, on regen, in every coordinated worker". True before #8140, false on this PR's base: #8140 made the roster walk demand-directed, so a discovery-free plan such as regen already stopped paying. Both DESIGN and the plan carrier now split the claim by era — unconditional before #8140, regen exempt after it, the censuses burdening every remaining discovery-bearing execution until this deletion. A change removing stale supply-side enforcement must not land a fresh stale assertion in the same diff. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * chore: regenerate drifted generated artifacts (ci auto-heal) * Repoint the sibling plan authorities that still advertise the deleted census Review 51154 caught a consistency failure in my own work: I applied the stale-authority fix to `construction_justification_rule.dag` and then judged `inert_layer_lens.dag` "historical prose" without running the same test on it. It fails that test. It is a registered plan whose §3 tells a future worker that Tier 1 is "buildable now (reuse #5433)" and to extend `inert_lens_modules` — a function this PR deletes — and §7 goes further, advising them to extend it behind a flag rather than fork it. Someone following that plan would go looking for machinery that is gone. Four rows repointed rather than deleted, since the design reasoning survives even though its cited mechanism does not: - §3 Tier 1 now leads with the supersession, names `v2.lens.module_graph` as the surviving reachability authority, and says plainly that "reuse the existing walk" now means "build the walk", which is a larger job than the paragraph reads. - §6's reuse map repoints the transitive-reachability-BFS row off `cli_run.rs:2558-2606` — a positional citation into a file that has since moved several thousand lines, which is the §3 rot mode exactly. - §7's seed caveat drops the extend-behind-a-flag advice and states the real constraint: whatever Tier 1 becomes must not reintroduce a corpus-wide walk inside floor discovery, because the placement was the defect, not the walk. - §5's "fail closed exactly as #5433 does" moves to past tense; no lens-inertness gate runs today. Also marked the two remaining historical citations, in the same plan's landed doc-graph receipt and in `axiom_syllogism_lens.dag`'s precedent table, so every surviving mention of a deleted symbol carries its deletion beside it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * chore: regenerate drifted generated artifacts (ci auto-heal) * Derive the bridge-family split control instead of pinning its population The floor finally evaluated this branch — main was red before, then an upstream timeout cascaded — and found exactly one red witness in 8757: `v1_interpreter_primitive_dispatch_authority_acceptance_contract_holds`. It is genuinely this PR's. Deleting `v2.lens.inert_lens` removed the last two rows carrying `EvalCallBridgeFamilySite { module: v2.lens.inert_lens }`, so the distinct bridge-family count went 9 -> 8 and distinct_bridge_family_site_count() == 9 redded. The literal was a population pin — the exact class DESIGN §5 rejects, and the exact class #7615 removed from this same carrier's census witnesses. The file's own `closing_contract_note` opens by claiming "The checks here are structural properties that survive roster growth -- not population pins", so the clause contradicted its own contract and my deletion is what surfaced it. Decrementing 9 to 8 would restore green while preserving the defect, so the control is derived instead: the number of distinct emit-site keys must equal the number of distinct modules the bridge rows themselves name, and exceed one. That is not a tautology, because the two sides come from different places — the left from `dispatch_emit_site_key`'s keying, the right from each row's own `module` field. Collapsing the families back onto one shared key (the defect the clause is named for) reds it, 1 != N. Adding or removing a family does not. The clause now measures what its name claims, in both directions. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
briansrls
pushed a commit
that referenced
this pull request
Aug 12, 2026
… discovery (#8167) * Make the witness-roster walk demand-directed instead of unconditional pre-plan claim_executor ran discover_floor_witness_roster_with_snapshot once up front, BEFORE resolving the plan, on the stated ground that a naming violation should be "the cheapest possible failure". Measured, that walk is the most expensive phase in the process: 5.9 min of a 56.5-min ordinary floor (run 31477894666), and ~6 min of a ~15-min regen whose plan has exactly two nodes. It is expensive because "naming hygiene" is a misleading label. The four rules in v2.workflow.floor_naming_hygiene are string predicates over file paths and line prefixes, but the roster producer they are reached through also builds module-graph facts, runs a second strict reference-resolution pass, computes path indexes, and runs inert-lens reachability plus the construction- justification census. A two-node regen plan paid all of it to discover a roster it never reads. Hygiene is a property of the witness ROSTER, so it is now paid by the plans that have one: the walk moves to the existing `schedules_discovery` predicate, after the plan's batches settle. The roster is memoized by request digest (IN_PROCESS_ROSTER_BY_REQUEST), so plans that DO schedule discovery pay exactly what they paid before — the corpus batch hits the memo this call fills. Plans that do not schedule discovery pay nothing, and cannot be unhygienic: they have no roster. The walk-attempt id is minted unconditionally as before; it is a tracing coordinate every later phase stamps, and it is not the expensive part. This also closes the PRELUDE COVERAGE HOLE gunbc.ci_spec gunbc_ci_floor_batch_wall_budget_note already names: the walk sat outside every batch budget and could only red at the step cap. It is now inside the region the plan accounts for, or absent. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * Update the design authority for the demand-directed hygiene walk (review 51099) review 51099 (cursor/composer-2.5, REQUEST_CHANGES) correctly caught that #8140 changed documented CI behavior without updating its authority. DESIGN.md Building & checks stated the opposite of the new code: "the executor runs the zero-enrollment naming walk when no discovery batch is scheduled" That clause is superseded here in gunbc.design_document (DESIGN.md is generated from it; the heal job regenerates the projection). Both of the reviewer's findings are recorded rather than only the first: (a) SCOPE — discovery-free plans no longer run the corpus-wide nameability rules. Declared as a narrowing, with the honest coverage argument: every PR runs the `ci` job, whose plan schedules discovery and walks the full tree, so per-PR coverage is unchanged; what is deleted is a second redundant walk on regen-only and plan-artifact-only runs. Explicitly NOT backstopped by the affected-set falsifier, which has produced no green verdict since 2026-08-03. (b) ORDERING — for plans that DO schedule discovery the walk now runs after plan resolve/eval, so a naming violation pays ~0.5 min of plan resolution before refusing. The reviewer asked whether the trade is intentional: it is, and it is priced — ~0.5 min later on the refusing path against ~6 min saved on every regen. A dissolve-on is recorded: the clause, the separate walk, and the `__`-basename rule all retire when the placement rules move to canonical source ingestion and test identities derive from parser-produced declarations. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * chore: regenerate drifted generated artifacts (ci auto-heal) * Repair the stale output-policy comment left by the walk move (review 51101) review 51101 (cursor/composer-2.5) caught claim_executor.rs:10283 still asserting "The walk still runs before plan evaluation, so a naming violation stays the cheapest failure" — the exact opposite of what this PR does. Non-blocking as a defect, but it is the same class the PR itself is about: a comment standing as authority for behavior the code no longer has. #8140's own receipt was a block comment whose stated premise had been false for months. The paragraph's real subject — install output policy BEFORE the walk so the whole-tree read is funnelled rather than emitting ~2.3k `[file] read` lines — is unchanged and still correct; the walk simply moved further away from it. Rewritten to say that, rather than deleted, so the ordering requirement keeps its rationale. Swept the rest of claim_executor.rs / cli_run.rs for other assertions of the old ordering: the only remaining hits are this PR's own comment describing the prior behavior in the past tense. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * Delete supply-side lens enforcement from floor discovery Two censuses ran inside `discover_floor_witness_roster` — the inert-lens reach walk and the construction-justification census. Both asked a question about who authored a lens, and both answered it by acquiring a whole-corpus module graph. Every discovery run paid that: every PR, regen, and every coordinated scoped worker, all of which wanted a witness roster and nothing else. The unit of computation was the world; the unit of fact was one module's authorship. Deleted end-to-end, not merely unwired: - `v2.lens.inert_lens` (its `.dag` surface was two self-recursive stubs, `fn f() { f() }`, reachable only because the interpreter intercepted them) - its two host builtins, both interpreter dispatch registrations, the generated bridge family, the `04_method` type-table entries and the `std.primitives` roster rows - the `InertLens` registry variant, its registry row, contract row and `lens_module_gate` invariant surface - `inert_lens_modules`, `inert_lens_modules_legacy`, `lens_justification_census`, `unjustified_lens_modules`, `declares_construction_justification` and both floor refusal arms (`cli_run.rs` and `floor_discovery_snapshot.rs`) - the long witness and its frozen deferral row (shrink logged) `build_module_graph_facts_live` still runs on this path and this change does not claim otherwise: effect-reach derivation and the cross-worker snapshot transport both consume it. `refuse_on_module_graph_read_refusals` and its two red controls are retained and re-homed, since the fail-closed arm now guards those consumers rather than the deleted censuses. This is a scope narrowing, not a climb. A new lens with no witness, and a lens recording no `construction_justification`, are both writable again and nothing detects either. Declared in DESIGN §6 with its next-rung trigger: authorship belongs on the module's own declaration, checked where the module is already parsed, rather than reconstructed corpus-wide by a consumer that wanted a roster. Two citations repaired rather than left stale (§3): the roadmap acceptance note cited a shadow witness this change renames and weakens, and `source_authority` cited the inert-lens stubs as its example of host interception. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * chore: regenerate drifted generated artifacts (ci auto-heal) * Reconcile the plan carrier and stale comments with the deleted enforcement Review 51113 (cursor/composer-2.5) found two second authorities still claiming enforcement the code no longer performs — DESIGN §3 dual representation and §4b rung honesty. Both confirmed against the current head, both fixed. `gunbc.plans.construction_justification_rule` said the presence check "run[s] in `discover_floor_corpus_rows`" and listed it as current status. Its retirement condition also named that check as its trigger, so after the deletion the condition could never fire — an unreachable lifecycle claim that structurally cannot report itself satisfied. The plan now leads with a supersession notice, §2/§3/§4 are marked historical rather than reworded, and a new §5 records what was deleted, what it costs (a lens added tomorrow with no justification lands green; the 35-module classification in §4 is a historical measurement, not a maintained invariant), and the next-rung trigger. The retirement condition is replaced with a reachable one and says why. `floor_discovery_snapshot.rs`'s consumer census still listed the two gates and still called the roster walk "pre-plan", which #8140 already made false. Swept the rest rather than fixing only what was reported: eight comments in `cli_run.rs` and one in `claim_executor.rs` named the inert-lens reach as a live consumer of the observation rows, the reference-edge producer, and the selection tier. Repointed to the consumers that remain. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * Delete the dead lens classifier and date-scope the cost claim Two bounded review corrections. `is_top_level_lens_module` survived the census deletion with no remaining caller — only its own definition. It compiled clean because the crate carries a blanket allow, which is exactly why the residue needed finding by reading rather than by warning. Deleted; the PR's bar is end-to-end with zero residue, and a dead classifier left behind is the pattern this change exists to close. The new DESIGN paragraph asserted the censuses charged "every discovery run — on every PR, on regen, in every coordinated worker". True before #8140, false on this PR's base: #8140 made the roster walk demand-directed, so a discovery-free plan such as regen already stopped paying. Both DESIGN and the plan carrier now split the claim by era — unconditional before #8140, regen exempt after it, the censuses burdening every remaining discovery-bearing execution until this deletion. A change removing stale supply-side enforcement must not land a fresh stale assertion in the same diff. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * chore: regenerate drifted generated artifacts (ci auto-heal) * Repoint the sibling plan authorities that still advertise the deleted census Review 51154 caught a consistency failure in my own work: I applied the stale-authority fix to `construction_justification_rule.dag` and then judged `inert_layer_lens.dag` "historical prose" without running the same test on it. It fails that test. It is a registered plan whose §3 tells a future worker that Tier 1 is "buildable now (reuse #5433)" and to extend `inert_lens_modules` — a function this PR deletes — and §7 goes further, advising them to extend it behind a flag rather than fork it. Someone following that plan would go looking for machinery that is gone. Four rows repointed rather than deleted, since the design reasoning survives even though its cited mechanism does not: - §3 Tier 1 now leads with the supersession, names `v2.lens.module_graph` as the surviving reachability authority, and says plainly that "reuse the existing walk" now means "build the walk", which is a larger job than the paragraph reads. - §6's reuse map repoints the transitive-reachability-BFS row off `cli_run.rs:2558-2606` — a positional citation into a file that has since moved several thousand lines, which is the §3 rot mode exactly. - §7's seed caveat drops the extend-behind-a-flag advice and states the real constraint: whatever Tier 1 becomes must not reintroduce a corpus-wide walk inside floor discovery, because the placement was the defect, not the walk. - §5's "fail closed exactly as #5433 does" moves to past tense; no lens-inertness gate runs today. Also marked the two remaining historical citations, in the same plan's landed doc-graph receipt and in `axiom_syllogism_lens.dag`'s precedent table, so every surviving mention of a deleted symbol carries its deletion beside it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * chore: regenerate drifted generated artifacts (ci auto-heal) * Derive the bridge-family split control instead of pinning its population The floor finally evaluated this branch — main was red before, then an upstream timeout cascaded — and found exactly one red witness in 8757: `v1_interpreter_primitive_dispatch_authority_acceptance_contract_holds`. It is genuinely this PR's. Deleting `v2.lens.inert_lens` removed the last two rows carrying `EvalCallBridgeFamilySite { module: v2.lens.inert_lens }`, so the distinct bridge-family count went 9 -> 8 and distinct_bridge_family_site_count() == 9 redded. The literal was a population pin — the exact class DESIGN §5 rejects, and the exact class #7615 removed from this same carrier's census witnesses. The file's own `closing_contract_note` opens by claiming "The checks here are structural properties that survive roster growth -- not population pins", so the clause contradicted its own contract and my deletion is what surfaced it. Decrementing 9 to 8 would restore green while preserving the defect, so the control is derived instead: the number of distinct emit-site keys must equal the number of distinct modules the bridge rows themselves name, and exceed one. That is not a tautology, because the two sides come from different places — the left from `dispatch_emit_site_key`'s keying, the right from each row's own `module` field. Collapsing the families back onto one shared key (the defect the clause is named for) reds it, 1 != N. Adding or removing a family does not. The clause now measures what its name claims, in both directions. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * Delete the orphan-helper census and the `__` filename rule from floor discovery Two more required-path phases whose cost was denominated in the corpus and whose answer nobody consumed. Net −1446/+39. **The `__`-basename rule.** A census found ZERO offending basenames in the tree and no stated rationale anywhere for the ban — it guarded an empty population. It was not free: reaching the predicate meant collecting every `.dag` path in the corpus and then resolving a SEPARATE `.dag` entry (`FLOOR_NAMING_HYGIENE_ENTRY` -> `floor_filename_hygiene_refusal_via_producer`) on every discovery-bearing run, so a zero-population style rule cost a whole-tree walk plus an entry resolve. Both are gone, along with the snapshot's `naming_hygiene_refusal` field and the two witness controls. **The orphan-helper census.** It walked every `*_test.dag`, parsed each one, projected `DeclSurface`/`ModuleSurface` values, resolved a second interpreter context, and ran a fuelled reachability fixpoint against a hand-authored cross-module export exception roster — to decide whether a plain helper in a test file was referenced. An unreferenced test helper is dead-code hygiene. It is not evidence that the compiler or the tests are correct, and it did not justify a recurring whole-corpus traversal on a required path. `gunbc.test_module_hygiene` goes 661 -> 106 lines, the Rust bridge 835 -> ~320, and `test_module_hygiene_scaffold.dag` deletes whole (its dissolution obligation is discharged by the deletion, not carried forward). **Scope narrowing, declared rather than implied.** An unreferenced test helper and a `__` basename are both writable again and nothing detects either. The orphan class had fourteen enrolled witnesses and they are deleted with it — §4b permits that only because the class is ABANDONED, not climbing: there is no higher rung for the evidence to guard, and keeping fixtures for a fold nothing calls would be specification-without-execution one level up. Recorded in DESIGN, in the module authority note, and in the witness file that used to hold them. **What survives, and why:** the `test fn` placement rule, the file-grain expand half, and `failure_receipt_companion` — the naming convention `claim_executor` actually invokes. That last one was only ever exercised through the census's whole-corpus walk, so it would have silently lost its executing consumer; it gains direct unit and `.dag` witnesses here instead. **Not in scope, deliberately:** the line-scanned test-identity derivation. That is the second parser, and replacing it needs the canonical parser to retain the `test` marker — which `drop_leading_test_marker` discards, because `test` is a live module-path segment (`test.claim.*`, `extdeps.test.*`) and cannot be lexed as a keyword. `realization_attempt.dag` already names the prerequisite: a contextual-keyword terminal in `GrammarExpr`, which does not exist yet. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * Refresh the two authority notes the deletion falsified Review 51262 found `floor_naming_hygiene_note` still asserting, in a file this PR edits, that the module sits where it does so "orphan/filename hygiene resolve stays free of the Filesystem service closure" and that it dissolves the hand-Rust mirror `check_floor_filename_hygiene`. Neither survives the deletion: there is no orphan census and no filename-hygiene resolve left to keep free of anything, and the filename half of that dissolution obligation is discharged by deletion rather than by dissolution — no equivalence receipt was ever owed for a rule with a zero-row population. The note now states what remains true instead, including the part worth carrying: the test-decl line scan is still a second parser, and replacing it is not a refactor of this module — it needs the canonical parser to retain the `test` marker, which `drop_leading_test_marker` discards, and `test` cannot become a lex keyword because it is a live module-path segment. Swept for the same class rather than fixing only what was reported: `floor_discovery_dissolve_trigger` still described "the producer and filename-hygiene entries" as two typed entry values resolved through `resolve_workspace_entry`. There is one now. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * chore: regenerate drifted generated artifacts (ci auto-heal) * Carry the deleted-witness rationale as an authored annotation, not a prose data row `prose_row_introduction_gate` refused this change: `test_module_hygiene_orphan_witness_deletion_note` is a `data NAME_note: String` declaration introduced under `dag/test/claim/test_module_hygiene_hand_rust_equivalence_witness_test.dag`, a path already on `gunbc.prose_row_frontier` `prose_row_migration_scope`. DESIGN §4c: prose is not forbidden, unclassified prose is, and a `String` declaration whose sole purpose is commentary is misplaced data. The rationale is irreducible — it records why fourteen witnesses were deleted with the machinery they tested, and why §4b's dissolution-on-climb rule does not save them (the class is abandoned, not climbed) — so it becomes a leading `//` block attached to the declaration below it. The PR-number and section references in the prose are dropped rather than carried across: those are exactly the machine-consumed facts §4c says belong in a typed carrier, not in commentary. The two other in-scope rows this change touches (`test_module_hygiene_authority_note`, `failure_receipt_companion_note`) are pre-existing declaration names whose content was rewritten, not introductions, and the gate does not refuse them. They are left as rows rather than swept here. Green by execution: the edited witness parses and `test_module_hygiene_file_grain_empty_function_holds` returns `true`. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * chore: regenerate drifted generated artifacts (ci auto-heal) * Make the deleted censuses past tense in the Building & checks paragraph Review 51377: the paragraph describing the naming-hygiene walk's measured cost still said the roster producer "runs inert-lens reachability plus the construction-justification census" — present tense, about two censuses gunbc#8141 deleted. `claim_executor` already says "(until gunbc#8141 deleted them)" and the §6 bullet in this same document records the deletion in past tense, so the canonical authority contradicted both. The measurement itself stands: those censuses WERE part of what made the walk the most expensive phase when it was measured. What was wrong is the tense, which asserts a superseded population as the present one — and doing that inside a deletion diff is the exact failure #8141's own review caught, recorded a few paragraphs above in this file. Reworded to "and — until gunbc#8141 deleted them — ran", preserving the cost claim as the historical fact it is. Swept for other occurrences: the §6 bullet is already past tense; this was the only stale one. DESIGN.md is a projection of this authority and is regenerated by `heal_generated_artifacts`, so it is not hand-edited here. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * Drop orphan/helpers from the snapshot consumer-census row Review 51382: the module header still listed "Naming hygiene, orphan/helpers" as what the demand-directed roster walk reads, in a file this PR edits. The orphan-helper census and the `__`-basename rule are deleted here, so the row named work that no longer happens — doc drift inside the diff that removed the subject. The row now names what the walk actually still does: `test fn` placement hygiene, producer roster, module-graph facts, effect-reach derivation, with the deletion noted so a reader is not left wondering where the other two went. The same review's DESIGN.md finding is real and is NOT fixed by hand: DESIGN.md is a generated projection of `dag/gunbc/design_document.dag`, whose wording was corrected in 69009a3. Editing the projection directly would author bytes no authority produced, and `heal_generated_artifacts` reverts exactly that. Heal last ran against the previous head (a5b441b, before the authority fix); its run on this head re-projects the corrected sentence. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi * chore: regenerate drifted generated artifacts (ci auto-heal) * Repair the comment whose contrast named a deleted function Review 51390: a comment justifying why a wiring test calls the producer seam argued by contrast with `floor_filename_hygiene_refusal_for_paths` — which this PR deletes. The live half of the argument still holds (the seam is where a wire-contract violation is observable, and the rule itself is owned content-side by `floor_discovery_equivalence_misplaced_wire_contract_refuses_holds`, so re-deriving it here would be a second representation). Only the contrast was dangling. Rewritten to state the positive reason, with the retired comparison noted as history rather than silently dropped: a reader who remembers the old sentence should find out where it went, not wonder whether the argument changed. No code, assertion, or behavior change. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Deletes live-snapshot count pins (wave 1): witness tests and authority notes that only transcribed derived population sizes, which re-pinned on unrelated growth (e.g. PR #7614) without catching defects.
Scope correction:
src/v2/lens/vacuity_test.dagandsrc/v2/lens/vacuity.dagare untouched — vacuity distribution pin replacement is owned by jolly-fox-325.Removed pins:
v1_interpreter_primitive_surface_witness_test.dag— population/ratio count witnesses andexact_count_witness_note(discriminating duplicate/shadow/unknown-form detectors retained)v1_interpreter_primitive_surface.dag— mutable numeric prose in authority/derived/shadow notese0599_probe_census_witness_test.dag— pattern/module/blob line-count pinse0599_emitter_decision_census_witness_test.dag— lowering-row count and inhabited-operation count pinsstage0_emit_model_witness_test.dag—generated_stage0_file_count >= 101observation_emit_census_witness_test.dag— frontier== 8and roster== 14RED packet
All via
target/debug/claim_batch --source-root dag --source-root src/v2.duplicate_detector_catches_a_row_repeated_under_one_identityshadow_detector_catches_a_planted_duplicatean_unrecognised_form_label_refuses_rather_than_defaultingfree_call_shadowing_is_exactly_the_two_inert_lens_bridgesOther modified witness files: all remaining tests PASS (stage0 emit 3/3, observation census 16/16, e0599 probe 13/13, e0599 emitter decision 25/25).
Test plan
claim_batchRED packet (above)cargo fmt --all --check(pre-push hook)