Skip to content

Lane A: R1 invert interpreter dispatch authority (roster becomes the authority) - #7682

Merged
briansrls merged 26 commits into
mainfrom
session/merry-bat-341-r1-dispatch-authority
Aug 3, 2026
Merged

briansrls merged 26 commits into
mainfrom
session/merry-bat-341-r1-dispatch-authority

Conversation

@briansrls

@briansrls briansrls commented Aug 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Lane A R1: invert interpreter primitive dispatch authority so the .dag roster is canonical and Rust is derived, not the other way around.

v1_interpreter_authored_roster_arms()  [.dag canonical]
  → v1_interpreter_dispatch_emit        [derives enum + lookup]
  → v1_interpreter_dispatch_generated.rs [drift-gated committed artifact]
  → v1_interpreter.rs                   [lookup_* then exhaustive handler match]

Head: a74dede10a on session/merry-bat-341-r1-dispatch-authority (merge main #7733; no content edits).


Main merge (wind-down, 2026-08-03)

Merged origin/main at 19cc776d4e (#7733 main repair — restores v1_generic_params_needing_clone_bound 9-arg call site lost to stale regen clobber). Merge commit a74dede10a; pushed; CI rerun triggered. No PR content changed — approvals preserved.

Generated-file oracle (git diff origin/main...HEAD -- <file>)

File Three-dot diff Verdict
src/v1/stage0/src/v1_compiler_emit_rust.rs empty OK — branch carries no delta vs main; #7733 already landed the 9-arg v1_generic_params_needing_clone_bound + emit_bare_type_params fixes; merge did not revert
src/v1/stage0/src/std_occurrence_binding.rs empty OK — impl<N: Clone> OccurrenceBindingFoldState<N> intact; no spurious removal
src/v1/stage0/src/v1_interpreter_dispatch_generated.rs new file (+826) OK — intentional branch addition only
src/v1/stage0/src/bootstrap_stage0_crate_layout_generated.rs +1 line (v1_interpreter_dispatch_generated.rs in HAND_MAINTAINED_STAGE0_FILES) OK — additive enrollment only
src/v1/stage0/src/gunbc_stage0_crate_layout_generated.rs +v1_interpreter_dispatch_generated in pub_mod projections OK — additive enrollment only

Local cargo check -p v1-compiler-tests --tests pass after merge.


Done (green by execution where verified)

  • R1 inversion landed: v1_interpreter_authored_roster_arms() — 187 rows, enumeration: AuthoredInRoster; v1_interpreter_dispatch_emit generates lookup + enums; six handler-macro sites consult lookup_* before matching generated enum variants.
  • Deleted on purpose: interpreter_dispatch_arm_rows builtin bridge, per-site *_roster macro expansions, stringly match dispatch at six sites.
  • Drift gate enrolled: V1InterpreterDispatchGeneratedRsArtifact in generated_artifact.dag / generated_artifact_emit.dag / generated_artifact_drift_test.dag; .gitattributes merge driver row added (auto-heal ec50f5c4f8).
  • Regen fixed-point: v1_interpreter_dispatch_generated enrolled in frontier.dag + stage0_crate_layout_generated projections; regen_stage0 --verify passed.
  • Accidental deletion restored: type_ref_hit_ne_bind_measure_active removed alongside intentional roster macro deletion — restored in 04_method.dag / v1_compiler_infer_method.rs.
  • Review fixes landed: stale authority prose + handler macro comments (review 47740); generated-artifact enrollment (review 47731); fail-closed unknown site keys (review 47777); invalid OccurrenceBindingFoldState impl emit repaired (f4e1b865c7, review 47813).
  • CI heal fix: ci.yml heal staging + skew-guard exclude for v1_interpreter_dispatch_generated.rs (5418fa4a72).
  • Local verification (this host): cargo build -p v1-compiler pass; cargo test -p v1-compiler --test interpreter_dispatch_authority — 2/2 pass.
  • Reviews: 2 APPROVE, zero stale providers (per operator wind-down message).

Blocked / not done (operator still-bat-561 corrections — KEEP REWORKING)

PR is not draft but not merge-ready until operator merges: four substantive corrections still open post-R1:

  1. Dead spelling copy — handler macros still carry { "spelling" } literals dispatch ignores; route on arm identity + body only.
  2. Model dispatch site — add InterpreterDispatchSite coproduct per row; stop routing generation via roster_site_key prefix conventions (v4_bridge., native_intercept., etc.).
  3. Collision refusal — pre-generation fold refusing duplicate arm_identity_to_rust_variant mappings and per-site spelling→identity collisions.
  4. Vocabulary cleanup — rename v1_interpreter_derived_arms() (now returns authored rows); retire uninhabited DerivedFromDispatch once witness RED controls allow.

Also open: explicit bidirectional compile-failure construction witnesses per operator (roster-without-handler → non-exhaustive match; handler-without-roster → macro miss).


Findings (not visible in diff alone)

Finding Window / denominator Outcome
Enrolling V1InterpreterDispatchGeneratedRsArtifact without regenerating ci.yml CI run 30781222013 generated_artifact_drift_gate_passes false; heal HealAuthorCommitRequired on ci.yml
cargo test -p v1-compiler interpreter_dispatch_authority name filter 1 invocation, exit 0 False green: 0 tests ran. Correct: --test interpreter_dispatch_authority → 2/2 pass
Bot action_required trap PR runs before force-push Auto-heal bot commits blocked pull_request CI
Roster macro deletion hazard d0ddcef18b diff review type_ref_hit_ne_bind_measure_active deleted accidentally; restored
Main E0061 clobber (6 vs 9 args) main pre-#7733 Textually disjoint merge of regen outputs; repaired on main at 19cc776d4e; branch merge oracle clean
New committed artifact → ci.yml Registry 15→16 static rows ci.yml is AuthorCommitRequired — landed in human commit 5418fa4a72

Test plan


Next (if continued)

  1. Operator corrections 1–4 (above), in order.
  2. Author explicit compile-failure RED fixtures for both roster↔handler directions.
  3. Re-run full CI; confirm heal no longer exits 1 on author-commit drift.

Do not merge from this session — operator merges manually.

@gunbai-bot
gunbai-bot Bot force-pushed the session/merry-bat-341-r1-dispatch-authority branch 4 times, most recently from 92b05f3 to d0ddcef Compare August 3, 2026 02:35
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 3, 2026 02:36
@cursor

cursor Bot commented Aug 3, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@gunbai-bot

gunbai-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Addressed all three findings from review 47740 in 6b1e184365:

v1_interpreter_primitive_surface_authority_note — Replaced the pre-R1 "DERIVED, NOT TRANSCRIBED from macro token lists" paragraph with the inverted model: v1_interpreter_authored_roster_arms() is canonical, v1_interpreter_dispatch_emit generates drift-gated lookup/enums, and handler macros align at compile time via the generated enum match.

derived_versus_declared_note — Updated to describe the current ArmEnumeration population: almost all rows are AuthoredInRoster; the two DeclaredHere frontier rows remain; DerivedFromDispatch is documented as uninhabited legacy kept for witness RED controls.

v1_interpreter.rs handler macro comments — Removed stale "SINGLE AUTHORITY" / v1_builtin_roster / dual-expansion claims across all six handler macros (v1_builtin_arms, v1_algebra_method_arms, bridge/map/intercept/parse-table). Comments now state roster authority lives in .dag and generated lookup_* routes spellings before the exhaustive enum match.

Operator corrections 1–4 from still-bat-561 (dead spelling copy in macros, modeled dispatch site, collision refusal, vocabulary cleanup) remain open and are tracked separately from this doc-only pass.

Brian Searls and others added 3 commits August 3, 2026 04:11
…ated module

Regen was failing because type_ref_hit_ne_bind_measure_active was accidentally
dropped from the builtin registry, and v1_interpreter_dispatch_generated was
not enrolled in the stage0 crate layout (lib.rs drift). Register the scaffold in
frontier, sync crate-layout projections, and land R1 roster authority on main.

Co-authored-by: Cursor <cursoragent@cursor.com>
Update v1_interpreter_primitive_surface authority prose and handler macro
comments to describe the post-R1 model: authored roster in .dag, generated
lookup routing, and compile-time handler alignment — not the pre-inversion
macro-token derivation story review 47740 flagged.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot
gunbai-bot Bot force-pushed the session/merry-bat-341-r1-dispatch-authority branch from 9ed0d40 to a209c48 Compare August 3, 2026 04:11
Close review 47777 fail-open: expected_v1_interpreter_dispatch_generated_rs
now refuses when any authored row's roster_site_key falls outside
known_dispatch_emit_site_keys instead of silently omitting it from
generated lookup. Witnesses cover live-roster success and bare eval_call
site-key RED control.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Addressed review 47777 in 58000573b4.

Finding confirmed: expected_v1_interpreter_dispatch_generated_rs walked a hardcoded site_keys list while roster_site_key could yield bare "eval_call" for malformed rows — those rows were silently omitted from generated lookup with no refusal.

Fix:

  • known_dispatch_emit_site_keys() is the single closed site list; generation uses it exclusively.
  • roster_rows_with_unknown_emit_site() collects rows whose roster_site_key is outside that list.
  • expected_v1_interpreter_dispatch_generated_rs() now returns V1InterpreterDispatchGenerated | V1InterpreterDispatchGenerationRefused and refuses when count(unknown) > 0.
  • generated_artifact_emit propagates refusal into ArtifactGenerationRefused (drift gate goes red).
  • Acceptance test adds: every_authored_roster_row_maps_to_known_emit_site, dispatch_emit_succeeds_on_live_roster, and RED control bare_eval_call_site_key_is_not_emittable ("eval_call" ∉ known sites; "eval_call_bridge" ∈).

Live roster (187 rows) still emits successfully; only the failure path is newly fail-closed.

Brian Searls and others added 5 commits August 3, 2026 04:18
Merge main (#7709) regressed v1_generic_params_needing_clone_bound to a
6-arg call site against the 9-arg signature; restore ret/bounds/type_decl
arguments so the build job compiles.

Co-authored-by: Cursor <cursoragent@cursor.com>
Tighten closing-contract prose per review 47801: single-family dispatch
sites get compile-time enum exhaustiveness; bridge/native-intercept
multi-family sites honestly disclose the wildcard/unreachable! backstop.
Propagate V1InterpreterDispatchGenerationRefused.reason through artifact
emit. Add v1_interpreter_dispatch_generated.rs to ci.yml heal staging.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Thanks for the approvals (reviews 47788, 47799, 47801).

Review 47801 — landed in 5418fa4a72:

  • Tightened closing_contract_note / roadmap execution contract: compile-time exhaustiveness is now scoped honestly — single-family sites (eval_builtin_inner, eval_algebra_method_inner, map grounding, parse-table) vs multi-family bridge/native-intercept sites where the per-family wildcard means a missing handler body is unreachable!, not a compile error. Per-family enum split stays follow-up.
  • generated_artifact_emit now forwards V1InterpreterDispatchGenerationRefused.reason instead of substituting a fixed string.
  • Also committed the pending ci.yml heal staging for v1_interpreter_dispatch_generated.rs (HealAuthorCommitRequired class from the prior heal run).

Reviews 47788 / 47799: no action — nothing to block.

— sent from merry-bat-341

@gunbai-bot

gunbai-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review 47803: No action — the two honesty items (multi-family wildcard backstop, hand-maintained roster scaffold) are already named in the diff with dissolution triggers; agree with APPROVE.

Pushed regen fixed-point fix separately (emit_bare_type_params in seed) — CI was failing regen_verify_gate_passes because the post-#7709 emitter used bounded type params twice on enum accessor impls.

— sent from merry-bat-341

Revert the regen typo that emitted `OccurrenceBindingFoldState<N: Clone>`
(E0229). With emit_bare_type_params already in the seed, the correct
application form is `OccurrenceBindingFoldState<N>`; regen --verify passes.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review 47813 — fixed in f4e1b865c7 (HEAD).

Verified against current tree:

  • std_occurrence_binding.rs:94 is back to valid Rust: impl<N: Clone> OccurrenceBindingFoldState<N> { (not <N: Clone> in the applied position). cargo check -p v1-compiler-tests --tests compiles; regen_stage0 --verify reports regen_divergence_count=0.

  • The emit_bare_type_params change in emit_enum_shared_accessors is the correct direction, not the regression: the pre-Fix leaf-keyed qualified lookup collision in Rust emit #7709 seed duplicated type_params (<N: Clone>) for both the impl header and the type application, which is exactly how you get OccurrenceBindingFoldState<N: Clone>. The fix keeps bounded params on the impl (impl<N: Clone>) and bare names on the application (OccurrenceBindingFoldState<N> via emit_bare_type_params).

  • What landed badly was f5c828d87d (WIP auto-heal/regen): it committed the broken OccurrenceBindingFoldState<N: Clone> bytes while the seed fix was still mid-flight. f4e1b865c7 restores the fixed-point bytes the emitter now produces; no further emitter edit needed for this blocker.

Please re-review on f4e1b865c7 — build was red on f5c828d only.

— sent from merry-bat-341

@gunbai-bot

gunbai-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review 47816: No action — agrees with the honest exhaustiveness scoping already in the closing contract (5418fa4a72 / f4e1b865c7). Shared-enum unreachable! backstop and per-family enum split as follow-up are documented; no new edits warranted by this review.

— sent from merry-bat-341

@gunbai-bot

gunbai-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review 47818: No action — APPROVE aligns with current tree: roster authority, drift-gated emit, deleted dual-authority bridge, and honestly documented residuals (shared-enum unreachable!, handler-body scaffold) are already in the closing contract and scaffold rows. Nothing new to land from this review.

— sent from merry-bat-341

Brian Searls and others added 5 commits August 3, 2026 06:18
HealAuthorCommitRequired was failing because hand-edited ci.yml skew-guard
exclude ordering did not match expected_ci_yml(). Regenerated via main_wet.

Fixed v1_interpreter_dispatch_emit to emit fully-qualified enum paths in
identity arm macros and #![rustfmt::skip] so pre-commit fmt does not fight
the generated-artifact fixed point.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

#![rustfmt::skip] is unstable in submodule files (E0658 on CI). Emit
#[rustfmt::skip] on each generated enum, lookup fn, and arm macro instead.
macro_export arm macros cannot be invoked via $crate:: from another
macro (macro_expanded_macro_exports_accessed_by_absolute_paths). Drop
#[macro_export] from dispatch emit and call through
v1_interpreter_dispatch_generated:: in handler macro expansions.

Co-authored-by: Cursor <cursoragent@cursor.com>
…xpansion

macro_export arm macros cannot be invoked from nested macro_rules! via
$crate:: (macro_expanded_macro_exports_accessed_by_absolute_paths) and
non-exported module-path invocation does not resolve. Import generated
arm macros with #[macro_use] on v1_interpreter_dispatch_generated before
v1_interpreter and call them by bare name in handler expansions.

Align roadmap node v1-interpreter-primitive-dispatch-authority with the
site-scoped exhaustiveness contract (review 47830): compile-time refusal
on single-family sites, unreachable! backstop on bridge/native-intercept.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review 47831: No action — APPROVE matches current tree; nothing new to land from this review.

CI fix pushed (452a8154de): f1a810b broke build because module-path macro invocation does not resolve for non-macro_export rules, and $crate:: on macro_export rules trips macro_expanded_macro_exports_accessed_by_absolute_paths from nested handler macros. Fix: #[macro_use] on v1_interpreter_dispatch_generated (declared before v1_interpreter) + bare arm-macro names in handler expansions. Also aligned roadmap node v1-interpreter-primitive-dispatch-authority with site-scoped exhaustiveness (review 47830).

— sent from merry-bat-341

Brian Searls and others added 3 commits August 3, 2026 08:05
Hand-editing lib.rs for #[macro_use] was overwritten by regen_stage0.
Teach emit_lib_rs_from_files to emit macro_use on
v1_interpreter_dispatch_generated and order it before v1_interpreter in
the file-derived mod list; sync gunbc_stage0_crate_layout_generated.rs
with the frontier hand-maintained block. regen_stage0 --verify now passes.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review 47834: No action — APPROVE matches current tree; nothing new to land from this review.

CI fix pushed: regen was failing because lib.rs #[macro_use] did not survive regen_stage0. Fixed in emit (05_emit_rust.dag) + synced gunbc_stage0_crate_layout_generated.rs; regen_stage0 --verify passes locally.

— sent from merry-bat-341

Brian Searls and others added 3 commits August 3, 2026 13:02
Merge main (#7606 keyed-roster) left lib.rs missing std_keyed_roster and
std_keyed_row module declarations. Regenerated ci.yml and .gitattributes via
main_wet so heal skew-guard excludes match expected_ci_yml() after the merge.

Co-authored-by: Cursor <cursoragent@cursor.com>
Review 47840: v1_interpreter_primitive_surface_authority_note claimed all
roster/handler mismatches fail at compile time; align with the honest
site-scoped bar already in roadmap_authority and the acceptance contract
(single-family sites compile-time; bridge/native-intercept unreachable!
until per-family enum split).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review 47840 — fixed: narrowed v1_interpreter_primitive_surface_authority_note to the site-scoped exhaustiveness bar (single-family sites → compile-time inner-match refusal; eval_call_bridge / eval_call_native_intercept → runtime unreachable! until per-family enum split). Matches roadmap_authority.dag and the acceptance contract.

— sent from merry-bat-341

@gunbai-bot

gunbai-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review 47843 — addressed in HEAD:

  1. Variant collision (fixed): expected_v1_interpreter_dispatch_generated_rs now refuses when distinct_identities ≠ distinct_rust_variants within any emit site. Witness: live_roster_has_no_rust_variant_collisions + rust_variant_collision_synthetic_red_control (synthetic.one_two / synthetic.one.two).

  2. Dispatch-site routing scaffold (fixed): dispatch_emit_site_routing_scaffold_note on v1_interpreter_dispatch_emit names the interim prefix-convention routing and a Dissolve-on: trigger for modeled dispatch_emit_site per row; enrolled in acceptance contract.

  3. Closing-contract overclaim (fixed): closing_contract_note no longer says a discriminating RED lives in interpreter_dispatch_authority.rs — that file is lookup positive control only; REDs are bare_eval_call_site_key_is_not_emittable_red_control, rust_variant_collision_synthetic_red_control, and cargo build on single-family sites.

  4. Bridge unreachable! (no code change): intentionally narrowed bar already in roadmap_authority.dag, acceptance contract, and handler macros — runtime backstop until per-family enum split, not claimed as compile-time refusal.

— sent from merry-bat-341

v1_interpreter_dispatch_emit.dag failed v1 parse (expected expression,
found EqEq) when == started a continuation line in
rust_variant_collision_synthetic_red_control. Single-line the equality
and use negated == for identity inequality.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review 47850: No action — APPROVE matches current tree; scaffolds and dissolution triggers already enrolled as described.

— sent from merry-bat-341

@briansrls
briansrls merged commit 44126ca into main Aug 3, 2026
1 of 3 checks passed
@briansrls
briansrls deleted the session/merry-bat-341-r1-dispatch-authority branch August 3, 2026 17:05
gunbai-bot Bot pushed a commit that referenced this pull request Aug 3, 2026
main_wet regenerated ci.yml to add v1_tests_claim_occurrence_identity_debt_receipt_test.rs to the heal merge exclude roster; heal could not auto-push (GitHubAppLacksWorkflowsWrite).

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Aug 3, 2026
…en (#7697)

* WIP: Lane E: self-host frontier 27-row exact-head closeout, totality wall gre

* WIP: Lane E: self-host frontier 27-row exact-head closeout, totality wall gre

* WIP audit: push interim exact-head frontier probe census (17/27 at HEAD).

Land execution-measured TSV + audit note for 17 surveyed compiler modules:
dominant RealizationGap(parse_grammar_choice_overlap_residue) at ProbeStageAssemble,
minority NameResolutionGap(resolve_module_not_found) on three modules. This is an
interim survey receipt, not roster acceptance or totality-wall closeout.

Move per-module survey driver from scripts/ (does not exist on main) to
docs/probes/ as a declared scaffold with dissolution trigger on frontier transport.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP audit: hand-authored 17 frontier rows from survey; add compare oracle.

Document 12 pre-closeout declared-vs-survey mismatches in audit md (not
silently reconciled). Update measured_probe on 17 surveyed modules by hand
using TSV evidence; migration triggers remain authored claims. Add
diff_frontier_declared_vs_survey.sh (refuses on mismatch; does not write rows).
Do not land row-writer script — measurement is not declaration.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix CI: doc-graph bind for probe audit md; reorder sweep for rank monotonicity.

Hand-updating roster rows to RealizationGap raised tractability ranks above
interleaved NameResolutionGap modules and broke compiler_frontier_sweep_order
rank nondecreasing. Reorder sweep by blocker band. Register the interim survey
receipt in doc_graph_roots so doc_reachability does not orphan it.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Align per-module survey scaffold order with frontier sweep_order.

Keeps the hand-Rust probe driver consistent with compiler_frontier_sweep_order
after the tractability-rank reorder fix.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane E: self-host frontier 27-row exact-head closeout, totality wall gre

* Fix invalid enum accessor impl after stage0 regen.

Regen with a stale emitter seed duplicated `<N: Clone>` onto the impl
target (`OccurrenceBindingFoldState<N: Clone>`), which rustc rejects
(E0229). Restore `OccurrenceBindingFoldState<N>`; regen --verify green.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Name offline consumer for frontier per-module probe witness.

Per-PR CI excludes test/claim/long/ at dir grain but never ran this probe;
add a file-grain exclusion row and exclusion note with the full local
claim_batch recipe so survey evidence is not implied by green CI.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Document survey stale-head drift and spot-check at current main.

State 9f978aa is 44 commits behind 19cc776 with five emitter-path
commits in between; record four-module spot-check where verdicts held.

Co-authored-by: Cursor <cursoragent@cursor.com>

* P2: selection degradation receipts (selected/total + reason) (#7722)

* WIP: P2: selection degradation receipts (selected/total + reason)

* P2: emit selection degradation receipts on every floor discovery run.

Every discovery completion now prints selection_state, selected/total entry groups, ratio, and fallback_reason so whole-corpus affected runs are counted degradations, not quiet success.

Co-authored-by: Cursor <cursoragent@cursor.com>

* P2: wire selection degradation into every floor receipt path.

Publish selection_state, counts, ratio, and fallback_reason on the
measurement tail, resolve receipt, floor-component JSON, and dedicated
receipt file so carrier-only emission cannot satisfy the P2 bar.

Co-authored-by: Cursor <cursoragent@cursor.com>

* P2: drop stale prep-tax doc; prove executed-only selected count.

Remove docs/plans/floor-prep-tax-program.md (owned by #7721). Add a
discriminating test that skip-before-resolve rows do not inflate
selected_entry_groups toward total.

Co-authored-by: Cursor <cursoragent@cursor.com>

* P2: drop duplicate selection-degradation stderr emission.

run_discovery_corpus_with_options already emits via
emit_selection_degradation_receipt; remove the second DAG eval in
run_discovery_batch_node (review 47735).

Co-authored-by: Cursor <cursoragent@cursor.com>

* P2: thread walk source_roots into resolve receipt writer.

Fix E0425: claim_executor bin cannot call pub(crate) default_source_roots;
pass the walk's source_roots through write_resolve_receipt_at like the
selection-degradation receipt path already does.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: P2: selection degradation receipts (selected/total + reason)

* P2: add SELECTION_DEGRADATION_CENSUS_MARKER to cli_run seed.

Roster bidirectional hygiene: observation_emit_census cites
cli_run.rs for [selection-degradation]; mirror other frontier sites
with a const the witness grep can find (review 47746).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: P2: selection degradation receipts (selected/total + reason)

* P2: rustfmt selection_degradation_interp_ctx map_err closure.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Merge origin/main; restore v1_generic_params_needing_clone_bound arity.

Main merge regressed emit_rust to the 6-arg call site; trait_derive_emit
requires ret/bounds/type_decl_items (E0061 on CI merge commit).

Co-authored-by: Cursor <cursoragent@cursor.com>

* P2: witness unknown-tag SelectionUnavailable path (review 47814).

Document that Unavailable is fail-closed for unknown mode tags only;
categorization_unavailable stays on Applied/Superset fallback_reason.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: P2: selection degradation receipts (selected/total + reason)

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* Discharge namespace occurrence identity receipts (#7559)

* WIP: Namespace occurrence debt receipts

* WIP: Namespace occurrence debt receipts

* Restore generated occurrence allocator

* Enroll occurrence debt receipts in Cargo CI

* Track parser receipt CI enrollment debt

* WIP: Namespace occurrence debt receipts

* Track split rebuild receipt enrollment

* WIP: Namespace occurrence debt receipts

* Keep parser receipts outside compile-clean roots

* Prepare governed parser receipt enrollment

* Keep occurrence debts live until roster enrollment

* Import receipt newline index in generated projection

* WIP: Namespace occurrence debt receipts

* Derive occurrence acceptance closure from receipts

* Bind occurrence closure to its law authority

* Clarify occurrence denominator tripwire

* WIP: Namespace occurrence debt receipts

* Complete occurrence acceptance workflow relocation

* WIP: debt receipts

* Register std.occurrence_binding{,_resolve} seed modules; regen

PR #7559's build job fails because the generated witness
v1_tests_claim_occurrence_identity_debt_receipt_test.rs imports
crate::std_occurrence_binding and crate::std_occurrence_binding_resolve,
neither of which is a registered seed module. This registers both in
gunbc.stage0_emit_model generated_stage0_files and stage0 lib.rs and
regenerates.

Regeneration leaves the other 114 generated files byte-identical, but the
two newly emitted modules do not compile: 24 errors, all in
std_occurrence_binding.rs. See the escalation note -- the emitter does not
propagate a Clone bound through a user-declared generic type.

* chore: regenerate drifted generated artifacts (ci auto-heal)

* WIP: Finish PR 7559 adoption: main is repaired (19cc776), so the inherited

* Roster occurrence_identity_closing_complete for non-fold residue gate

PR #7559's acceptance-closure carrier introduces a wildcard match arm that
must be enrolled in gunbc.non_fold_residue before the always-on corpus witness
can pass. Companion to the regenerated ci.yml heal exclude for the new stage0
projection file.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Finish PR 7559 adoption: main is repaired (19cc776), so the inherited

* Fix main-merge regen: restore keyed stage0 modules and total receipt_passed

Merge resolution dropped main's std_keyed_roster/row from the generated emit
plan and lib.rs; regen_stage0 from the merged tree restores both alongside
the debt-receipt module. Total occurrence_identity_receipt_passed over the
closed OccurrenceIdentityReceiptExecution coproduct instead of rostering a
non-fold residue row (closing_complete remains total from 806a0d8).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Finish PR 7559 adoption: main is repaired (19cc776), so the inherited

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* Root-cause disk-tier repeat-resolve memory growth (>8GiB OOM on second resolve through v1 disk cache seam) (#7728)

* WIP: Root-cause disk-tier repeat-resolve memory growth (>8GiB OOM on second r

* WIP: Root-cause disk-tier repeat-resolve memory growth (>8GiB OOM on second r

* Remove debug RSS instrumentation swept in by auto-WIP

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Coordinator replay: wet witness per-row outcomes visible in CI job log (#7702)

* Coordinator replay for wet witness row outcomes in claim_executor.

Ordinary floor worker writes target/floor-wet-witness-row-outcome-receipt.tsv
with passed | failed | selection-skipped per row; coordinator replays into
job log on worker exit and spawn-failure paths. Unit tests discriminate the
three outcomes (claim_executor binary, not claim_batch).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix wet witness outcome TSV parsing for empty detail columns.

Rust tab-split drops trailing empty fields; accept 4- or 5-column rows
so passed rows with no detail replay correctly.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: falsifier is flakey on budget - please investigate (#7738)

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>

* P1 retention vs drain cohort receipt (authoritative) (#7725)

* WIP: P1 retention vs drain cohort receipt (authoritative)

* P1 retention vs drain cohort receipt: REJECT — eviction is not the tax source

Fixed 50-entry cohort run through the real floor path
(run_discovery_corpus_with_options, Adaptive width) in two modes: A
(production eviction on) and B (GUNBC_SCHEDULE_RETENTION_EVICT=0,
retain-all pole). Entries 2..34 (Mode B OOM-killed at 34/50 after
unbounded RSS growth, honestly reported and not backfilled) show
statistically indistinguishable wall/resolve times between modes —
disabling schedule-retention eviction does not collapse the ~1-2s
per-entry tax. Verdict: REJECT the retention hypothesis; redirect to
assembly/materialization reuse, per the parent's stated criterion.

Also fixes the cargo fmt violation from the prior P1 instrumentation
commit that was failing CI on this PR.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* WIP: P1 retention vs drain cohort receipt (authoritative)

* P1 receipt: fix cited SHA, rename mislabeled field, align scaffold wording

Per review 47754 (cursor/composer-2.5, REQUEST_CHANGES), three fixes:

1. Receipt cited b53aec1 (this PR's initial WIP commit) as the
   reproduction SHA, but p1_cohort_probe.rs doesn't exist in that
   commit's tree. Corrected to dddc795, where the probe first
   lands in git history.

2. emit_p1_cohort_entry_line's `schedule_cache_hit` field actually
   logged typecheck_compute_count() movement (a typecheck-memo
   hit/miss), not schedule-retention cache occupancy -- mislabeled
   instrumentation on a measurement-only PR. Renamed to
   `typecheck_cache_hit` everywhere (code, doc comment, receipt);
   raw checked-in logs left unedited as captured evidence, with a
   note explaining the field rename maps onto the same underlying
   signal.

3. Receipt said the probe was "kept in tree; reusable for future
   retention receipts", contradicting the in-code scaffold/dissolve-on
   framing now that P1's REJECT verdict is recorded. Reworded to
   match: probe-only scaffolding, deletes per its named trigger.

No measurement data or verdict changed -- only citation accuracy and
field/wording honesty.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* WIP: P1 retention vs drain cohort receipt (authoritative)

* chore: retrigger CI now that main's E0061 (v1_generic_params_needing_clone_bound arity) is fixed by #7733

No content change on this branch — forces GitHub to recompute the PR merge-ref against main's current (fixed) tip, since a rerun of the prior failed run reused a stale merge-ref captured before #7733 landed.

* P1 scaffold: gate per-group timing/subject-tracking behind p1_cohort_receipt_enabled()

Per review 47844: the Instant/typecheck_compute_count() timing pair and
the resolved_graph_hit subject-set scan ran on every width-1 inline
discovery-drain group regardless of GUNBC_P1_COHORT_RECEIPT — only the
eprintln emission was gated. Wraps the bookkeeping in the same
p1_cohort_detail check as its emission, so the default production floor
path (env unset) pays none of this scaffold's cost, matching the
env-gated discipline the receipt doc already claims.

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* Sole modeled publisher (model + shadow): policy-derived projection, publisher authority, shadow replay (#7594)

* Sole modeled publisher (model + shadow): rebase PR-B onto main.

Replay only PR-B carriers onto current main — no #7591 deletion content
(placement gate/roster removal stays on vivid-newt-418 until that PR
merges). Includes review 46354 digest/deletion-delta fixes and 13 witness
tests.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address review 46417: prune dead variant and dissolve parallel argv surface.

Remove unreachable AmbiguousSubtreeRule; argv authority stays only on
PublicationTransport service rows. Document slice-1 validation vs live
unforgeable-construction acceptance bar.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Sole modeled publisher: ordinary sessions lose public-write capability;

* Address review 46429: align transport, delta taxonomy, and publisher gates.

Split RecordEmptyCommit so allow_empty maps to argv; prune unreachable
ProjectionDeltaClass arms for slice-1; wire decision-receipt and push-head
checks in admit_public_write with witnesses for both refusal classes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Refuse sole-publisher admission when no pushed refs are presented.

Close the empty-pushed_refs vacuous-pass fail-open before live-slice
binding; witness sole_publisher_refuses_empty_pushed_refs.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Gate projection on AdmittedPublicationPolicy; match disposition directly.

derive_public_projection_plan requires construction-admitted policy so
conflicting/unknown-root policies cannot reach the derived path; dissolve
publication_disposition_is_public in favor of coproduct match. Witness
publication_policy_refuses_conflicting_prefix_rules.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address review 46476: full receipt auth and posture fold.

publication_decision_authorizes_newly_public checks policy_version,
authority, and universal audience; invalid receipts refuse with
DecisionReceiptNotAuthorizing. Replace posture Bool predicate with
session_publication_posture_fold.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Sole modeled publisher: ordinary sessions lose public-write capability;

* Route publication ContentHash through std.content_hash.

Main moved ContentHash off std.types and renamed content_hash_combine to content_hash_combine_structural; update publication projection, witnesses, and publisher refusal strings to the family-grounded API.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Sole modeled publisher: ordinary sessions lose public-write capability;

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* Lane A: R1 invert interpreter dispatch authority (roster becomes the authority) (#7682)

* fix(r1-dispatch): restore regen fixed-point and enroll dispatch generated module

Regen was failing because type_ref_hit_ne_bind_measure_active was accidentally
dropped from the builtin registry, and v1_interpreter_dispatch_generated was
not enrolled in the stage0 crate layout (lib.rs drift). Register the scaffold in
frontier, sync crate-layout projections, and land R1 roster authority on main.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* docs(r1-dispatch): refresh authority notes for roster inversion

Update v1_interpreter_primitive_surface authority prose and handler macro
comments to describe the post-R1 model: authored roster in .dag, generated
lookup routing, and compile-time handler alignment — not the pre-inversion
macro-token derivation story review 47740 flagged.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(r1-dispatch): refuse emit when roster row maps to unknown site

Close review 47777 fail-open: expected_v1_interpreter_dispatch_generated_rs
now refuses when any authored row's roster_site_key falls outside
known_dispatch_emit_site_keys instead of silently omitting it from
generated lookup. Witnesses cover live-roster success and bare eval_call
site-key RED control.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* fix(r1-dispatch): restore clone-bound call after main merge

Merge main (#7709) regressed v1_generic_params_needing_clone_bound to a
6-arg call site against the 9-arg signature; restore ret/bounds/type_decl
arguments so the build job compiles.

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)

* fix(r1-dispatch): honest exhaustiveness note and ci heal paths

Tighten closing-contract prose per review 47801: single-family dispatch
sites get compile-time enum exhaustiveness; bridge/native-intercept
multi-family sites honestly disclose the wildcard/unreachable! backstop.
Propagate V1InterpreterDispatchGenerationRefused.reason through artifact
emit. Add v1_interpreter_dispatch_generated.rs to ci.yml heal staging.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* fix(r1-dispatch): repair invalid OccurrenceBindingFoldState impl emit

Revert the regen typo that emitted `OccurrenceBindingFoldState<N: Clone>`
(E0229). With emit_bare_type_params already in the seed, the correct
application form is `OccurrenceBindingFoldState<N>`; regen --verify passes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(r1-dispatch): regen ci.yml and dispatch artifact to clear drift gate

HealAuthorCommitRequired was failing because hand-edited ci.yml skew-guard
exclude ordering did not match expected_ci_yml(). Regenerated via main_wet.

Fixed v1_interpreter_dispatch_emit to emit fully-qualified enum paths in
identity arm macros and #![rustfmt::skip] so pre-commit fmt does not fight
the generated-artifact fixed point.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* fix(r1-dispatch): use item-level rustfmt::skip in dispatch emit

Co-authored-by: Cursor <cursoragent@cursor.com>

#![rustfmt::skip] is unstable in submodule files (E0658 on CI). Emit
#[rustfmt::skip] on each generated enum, lookup fn, and arm macro instead.

* fix(r1-dispatch): module-scope arm macros, not macro_export

macro_export arm macros cannot be invoked via $crate:: from another
macro (macro_expanded_macro_exports_accessed_by_absolute_paths). Drop
#[macro_export] from dispatch emit and call through
v1_interpreter_dispatch_generated:: in handler macro expansions.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(r1-dispatch): hoist arm macros via macro_use for nested handler expansion

macro_export arm macros cannot be invoked from nested macro_rules! via
$crate:: (macro_expanded_macro_exports_accessed_by_absolute_paths) and
non-exported module-path invocation does not resolve. Import generated
arm macros with #[macro_use] on v1_interpreter_dispatch_generated before
v1_interpreter and call them by bare name in handler expansions.

Align roadmap node v1-interpreter-primitive-dispatch-authority with the
site-scoped exhaustiveness contract (review 47830): compile-time refusal
on single-family sites, unreachable! backstop on bridge/native-intercept.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* chore: regenerate drifted generated artifacts (ci auto-heal)

* fix(r1-dispatch): make lib.rs macro_use survive regen fixed-point

Hand-editing lib.rs for #[macro_use] was overwritten by regen_stage0.
Teach emit_lib_rs_from_files to emit macro_use on
v1_interpreter_dispatch_generated and order it before v1_interpreter in
the file-derived mod list; sync gunbc_stage0_crate_layout_generated.rs
with the frontier hand-maintained block. regen_stage0 --verify now passes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(r1-dispatch): resolve main merge — lib.rs modules and ci.yml drift

Merge main (#7606 keyed-roster) left lib.rs missing std_keyed_roster and
std_keyed_row module declarations. Regenerated ci.yml and .gitattributes via
main_wet so heal skew-guard excludes match expected_ci_yml() after the merge.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(r1-dispatch): narrow authority note to site-scoped exhaustiveness

Review 47840: v1_interpreter_primitive_surface_authority_note claimed all
roster/handler mismatches fail at compile time; align with the honest
site-scoped bar already in roadmap_authority and the acceptance contract
(single-family sites compile-time; bridge/native-intercept unreachable!
until per-family enum split).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* fix(r1-dispatch): repair dispatch emit dag parse for collision RED

v1_interpreter_dispatch_emit.dag failed v1 parse (expected expression,
found EqEq) when == started a continuation line in
rust_variant_collision_synthetic_red_control. Single-line the equality
and use negated == for identity inequality.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>

* Fix audit scaffold fail-open and rename inflated closeout note.

Probe survey script now refuses on per-module failure instead of || true
stale-row widening; rename frontier_probe_exact_head_interim_audit_note
to match 17/27 interim state and empty manifest stub.

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Align probe note and survey md with interim audit framing.

Rename closeout wording in wave2 sizing note; document that 17 frontier.dag
rows were hand-authored in this PR and oracle diff greens for surveyed slice.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane E: self-host frontier 27-row exact-head closeout, totality wall gre

* Regen stage0 lib.rs for regen_verify gate.

Adds v1_tests_claim_occurrence_identity_debt_receipt_test mod export
so regen_verify_gate_passes matches fresh self-compile.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant