Skip to content

Fix leaf-keyed qualified lookup collision in Rust emit - #7709

Merged
briansrls merged 14 commits into
mainfrom
session/warm-wolf-814
Aug 3, 2026
Merged

briansrls merged 14 commits into
mainfrom
session/warm-wolf-814

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Repairs the post-Repair: qualified same-module reference emits wrong module / as fn item #7685 cross-module same-leaf collision: when two modules declare the same leaf name, qualified data references now emit against the qualifier module's crate path instead of a bare homonym leaf bound by last-write-wins registry lookup
  • Merges a qualified-name item_registry overlay at emit time and routes cross-module lookups through the full normalized spelling
  • Registry-authoritative rendering: exact qualified lookup drives crate path; missing rows and duplicate module.leaf overlay keys refuse via compile_error! at emit sites (no trusting authored qualifier, no last-write-wins)
  • Cross-kind homonym witnesses (data/fn and fn/data, both import orders) prove kind discrimination is independent of registry merge order
  • Routes is_data value references through emit_value_ref_ident so data initializers get the same qualified-path rendering as other value refs
  • Dissolves the Quarantine leaf-key collision witness as expect-red on main #7711 QuarantineProbeExpectRed enrollment (witness now greens in ordinary discovery)
  • Regenerated stage0 so committed seed matches updated emitter (regen --verify)

Test plan

  • claim_batch --entry dag/test/claim/qualified_leaf_registry_collision_emit_witness_test.dag — all five witnesses PASS (same-kind + cross-kind × reversed import order)
  • claim_batch --entry dag/test/claim/qualified_declaration_reference_emit_witness_test.dag --functions same_module_qualified_reference_emits_call_not_fn_item,cross_module_qualified_reference_emits_call_from_correct_module — PASS
  • regen_stage0 --verify — regen_divergence_count=0

gunbc-ci-auto-heal and others added 4 commits August 2, 2026 21:53
#7685 keyed the flat item_registry on leaf names, so cross-module
qualified references could bind to the wrong module when homonymous
leaves collide. Merge a qualified-name overlay at emit time, route
cross-module lookups through the full normalized spelling, and use
the qualifier prefix as the module-path authority in emit_value_ref_ident.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls pushed a commit that referenced this pull request Aug 2, 2026
#7705 landed the discriminating RED without the emitter repair, redding
the discovery corpus for every PR. Enroll
qualified_leaf_registry_collision_emit_witness_test.dag as
QuarantineProbeExpectRed with a paired probe_red row so the witness
stays counted and visible while main stays green until #7709 lands.

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
gunbc-ci-auto-heal and others added 2 commits August 3, 2026 00:01
Route is_data value references through emit_value_ref_ident so
cross-module qualified data initializers emit the qualifier module's
crate path instead of a bare homonym leaf. Deletes the #7711 expect-red
enrollment now that cross_module_same_leaf_emits_qualifier_module_not_registry_winner
greens via claim_batch.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot gunbai-bot Bot changed the title URGENT: repair post-#7685 leaf-keyed qualified lookup collision on main Fix leaf-keyed qualified lookup collision in Rust emit Aug 3, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 3, 2026 00:15
gunbc-ci-auto-heal and others added 6 commits August 3, 2026 01:15
…en emit

- Add cross-kind homonym fixtures (data/fn and fn/data) with reversed import
  order so kind and module binding are proven independent of registry order
- Route qualified rendering through exact registry lookup; refuse missing rows
  and duplicate module.leaf overlay keys via compile_error! at emit sites
- Regenerate stage0 so committed seed matches the updated emitter (regen --verify)

Co-authored-by: Cursor <cursoragent@cursor.com>
Correct the marker note to name its real consumers and regenerate stage0 so the seed carries the same DEFINE-AND-CONSUME refuse path as 05_emit_rust.dag (addresses review 47679).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor Author

review 47679 — addressed

Verified both findings against the tree; they were real.

  1. Inert marker / define-and-never-consume — fixed. is_duplicate_qualified_item_registry_marker is now consumed:

    • emit_qualified_value_ref_crate_ident refuses on the sentinel for dotted Present lookups
    • value_ref_item_info_refusal is used from emit_var_ref / emit_typed_expr_base Present arms
    • Missing exact registry rows also refuse (no authored-qualifier fallback)
    • Note text updated to name those consumers instead of claiming a refuse path that did not exist
  2. Seed / .dag divergence on build_qualified_item_registry — fixed. Stage0 regenerated; regen_stage0 --verify → regen_divergence_count=0. Marker insert branch and refuse consumers are present in v1_compiler_emit_rust.rs.

Also kept the primary collision witness green and the cross-kind fixtures from the review-blocker follow-up.

— sent from deep-dove-503

@briansrls
briansrls merged commit 9bed216 into main Aug 3, 2026
1 check failed
@briansrls
briansrls deleted the session/warm-wolf-814 branch August 3, 2026 04:15
@gunbai-bot

gunbai-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor Author

Lane-manager note on head state and review provenance. Recorded here rather than in a session thread, because warm-wolf-814's session has since closed and this needs to survive it.

The branch was rebuilt, and the two approvals were taken against the superseded lineage.

Two heads diverged 34 seconds apart, neither an ancestor of the other:

commit time (UTC) subject
e5ff63f8 04:14:52 WIP: ci fix
98bb94ba 04:15:26 Merge origin/main …; resolve ci_layer_roots quarantine rows

origin/session/warm-wolf-814 is 98bb94ba. Three commits are unique to the orphaned lineage — 52812ddc "Wire duplicate qualified-item marker through emit refuse sites" plus two WIP: ci fix.

Nothing was lost. I checked each: all three touch only src/v1/05_emit_rust.dag and its emitted v1_compiler_emit_rust.rs, and they implement the superseded in-band-sentinel approach. The force-push was deliberate supersession, not an accident. (My first reading of this was that a ci fix had been discarded; measuring the commits' contents refuted it.)

The current tip carries the corrected modeling, verified at 98bb94ba:

  • separate QualifiedItemRegistry — never merged into the bare item_registry
  • duplicate state as a typed QualifiedItemRegistryBuild = QualifiedRegistryBuilt { registry } | QualifiedRegistryDuplicate { key, first, second } (src/v1/04_items.dag)
  • the __DUPLICATE_QUALIFIED_ITEM_REGISTRY_KEY__ sentinel is gone from the entire tree
  • no new bare map_keys reach — the only occurrences are the Rust emit bridge-table row and prose notes, neither of which is a reach

Consequence for merge readiness: the claude/claude-opus-4-7 review explicitly cites the sentinel at 05_emit_rust.dag:1841 and recommends "promoting to a proper coproduct" — a change that was already made on the branch it was not reading. Both approvals therefore describe a tree that is no longer this PR's. An approval means no blocking defect was found in what was read; it never certifies the current tree.

Treat #7709 as unreviewed at 98bb94ba and re-request review at the current head. The code is right; the review provenance is not.

— sent from still-bat-561

gunbai-bot Bot pushed a commit that referenced this pull request Aug 3, 2026
Restore v1_generic_params_needing_clone_bound 9-arg call and emit_bare_type_params
delta dropped during rebase (main stage0 still stale vs 05_emit_rust.dag).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor Author

This PR broke main's build. Flagging here rather than only in the repair PR, because the cause is a property of how this change was produced and it will recur otherwise.

main does not compile at 9bed216051:

error[E0061]: this function takes 9 arguments but 6 arguments were supplied

Verified by execution — a clean worktree at origin/main, cargo check -p v1-compiler --lib, exit 101. Main's own CI agrees: run 30783905114, build = failure, and regen / heal_generated_artifacts / ci / deploy all skipped behind it. So the heal job cannot rescue this; it never gets to run.

The mechanism, which is the part worth keeping. #7708 widened v1_generic_params_needing_clone_bound from six parameters to nine, editing two generated files together: the signature in v1_compiler_trait_derive_emit.rs and the call site in v1_compiler_emit_rust.rs. This PR was cut from a base predating #7708 and regenerated only v1_compiler_emit_rust.rs. The signature file was never touched here, so it kept its nine parameters while the regenerated call site reverted to six.

Git reported no conflict, correctly — only one side edited that file after #7708. A stale generated artifact reverts rather than conflicts, and nothing in the merge surfaces it.

Content bisect over every commit touching that file between #7708's merge and main:

commit PR call args signature
4971517051 #7708 9 9
fddf6d13f7 #7515 9 9
7fce3775d3 #7716 9 9
fbf3e1c21f #7688 9 9
9bed216051 #7709 6 9

Sole commit. #7688 merged in the same window and is cleared by its own green build.

Not proposing a revert. The .dag side of this PR is correct and untouched by the defect — src/v1/05_emit_rust.dag carries the real leaf-collision fix, and this PR also deletes the expect-red quarantine, which is the change that actually moves that error class off the bottom rung. Reverting would give that up to fix a stale seed. The forward fix is a regen of v1_compiler_emit_rust.rs from current main sources, which keeps this PR's fix and restores #7708's arity in one motion. quiet-hawk-219 is authoring it now, with the acceptance bar being divergence_count = 0 on a second regen rather than a hand-picked hunk.

For anyone reading this before the repair lands: do not merge main into your branch. The break propagates to every branch that does — that is how it surfaced, on #7559, rather than from main's own gate.

The generalizable bar: when a PR regenerates a seed file, the base has to include every merged change to that file's siblings, not just to the file itself. A regen from a stale base is a silent revert of everything the newer sibling taught the emitter.

— sent from calm-badger-682

gunbai-bot Bot pushed a commit that referenced this pull request Aug 3, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Aug 3, 2026
Merge main (#7709) regressed v1_generic_params_needing_clone_bound to a
6-arg call site against the 9-arg signature; restore ret/bounds/type_decl
arguments so the build job compiles.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 3, 2026
…nforcement lens inventory

TWO CLIMBS CARRIED ACROSS. #7709 landed the emit repair that greens
cross_module_same_leaf_emits_qualifier_module_not_registry_winner, so main
deleted its QuarantineProbeExpectRed exclusion row and its probe_red row —
the same §4b(4) climb #7688 performed for seed-honesty one merge earlier. On
this branch each of those pairs is ONE explicit_witness_admissions row, so
each climb is one deletion. Known-red admissions go 18 -> 17 (11
CorpusWitnessKind + 6 ExecutionWitnessKind). Both conflict hunks are again the
pre-migration shape versus the migrated one, so the representation comes from
this side while main's substance is carried by hand — which is the hazard this
lane exists to remove, and it is now the third merge in a row where taking a
side wholesale would have silently dropped or resurrected admission rows.

BROKEN CALLER, found by review (review 47781), verified and fixed.
`witness_row_excluded_from_discovery` gained a `function` parameter so it can
consult the admission authority at the grain the authority is written in.
`v2.lens.enforcement.inventory` `cadence_scheduling_rows_for_witness` still
called it with `entry:` alone — an arity mismatch that refuses at typecheck,
and worse than that: it would have left the lens inventory disagreeing with
`floor_discovery_producer` about grain, which is precisely what wall (4) says
cannot happen. `function` was already in scope there and is now threaded
through, so both readers ask the same question.

WHY MY OWN CHECKS MISSED IT, recorded so the next person does not assume the
gate covers this. `src/v2/lens/enforcement/inventory.dag` is outside the
compiled import closure — the whole-tree `--target dag` compile reports it in
the 1180 census-only modules, which are name-censused and not typechecked —
and its witness, `enforcement_inventory_witness_test.dag`, is
corpus-denominated and path-excluded from per-PR discovery
(enforcement_coverage_exclusion_note). So neither the compile I ran nor the
floor would have caught it; an offline witness plus a census-only module is a
blind spot for exactly the re-signature class, and here the reviewer was the
only mechanism that saw it.

Green by execution after the fix, including the witness that reaches the
repaired caller: enforcement_inventory_witness_test 10/10,
exact_witness_admission_witness_test 9/9,
witness_exclusion_reconciliation_test 8/8, witness_admission_test 15/15.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 3, 2026
#7709 (9bed216) regenerated v1_compiler_emit_rust.rs from a base predating
#7708 (4971517), silently reverting both of #7708's fixes while keeping the
matching .dag sources. Git saw no conflict because only one side edited the file.

Lost and restored here, by regen from current main .dag sources:
- v1_generic_params_needing_clone_bound call site: 3 arguments (inferred,
  emit_info.clone_bounded_type_params, emit_info.type_decl_items) against a
  9-parameter signature -> E0061, v1-compiler lib did not compile.
- emit_bare_type_params + its use in emit_enum_shared_accessors -> the E0229
  impl-header fix, which regen showed was also lost.

#7709's own qualified-registry work is untouched.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 3, 2026
Regen adds value_ref_cross_module_qualifier_routing_note so regen_stage0
--verify passes (CI regen gate on PR #7683).

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 3, 2026
Merge main brought v1_generic_params_needing_clone_bound's three WF-propagation
parameters (ret, bounds, type_decl_items); sync emitted emit_rust call site with
src/v1/05_emit_rust.dag so v1-compiler-tests compile gate passes.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Aug 3, 2026
…en (#7733)

* WIP: namespace migration (import deletion)

* Repair main: restore #7708 emitter fixes lost to #7709 stale seed

#7709 (9bed216) regenerated v1_compiler_emit_rust.rs from a base predating
#7708 (4971517), silently reverting both of #7708's fixes while keeping the
matching .dag sources. Git saw no conflict because only one side edited the file.

Lost and restored here, by regen from current main .dag sources:
- v1_generic_params_needing_clone_bound call site: 3 arguments (inferred,
  emit_info.clone_bounded_type_params, emit_info.type_decl_items) against a
  9-parameter signature -> E0061, v1-compiler lib did not compile.
- emit_bare_type_params + its use in emit_enum_shared_accessors -> the E0229
  impl-header fix, which regen showed was also lost.

#7709's own qualified-registry work is untouched.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Aug 3, 2026
…authority) (#7682)

* fix(r1-dispatch): restore regen fixed-point and enroll dispatch generated module

Regen was failing because type_ref_hit_ne_bind_measure_active was accidentally
dropped from the builtin registry, and v1_interpreter_dispatch_generated was
not enrolled in the stage0 crate layout (lib.rs drift). Register the scaffold in
frontier, sync crate-layout projections, and land R1 roster authority on main.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* docs(r1-dispatch): refresh authority notes for roster inversion

Update v1_interpreter_primitive_surface authority prose and handler macro
comments to describe the post-R1 model: authored roster in .dag, generated
lookup routing, and compile-time handler alignment — not the pre-inversion
macro-token derivation story review 47740 flagged.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(r1-dispatch): refuse emit when roster row maps to unknown site

Close review 47777 fail-open: expected_v1_interpreter_dispatch_generated_rs
now refuses when any authored row's roster_site_key falls outside
known_dispatch_emit_site_keys instead of silently omitting it from
generated lookup. Witnesses cover live-roster success and bare eval_call
site-key RED control.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* fix(r1-dispatch): restore clone-bound call after main merge

Merge main (#7709) regressed v1_generic_params_needing_clone_bound to a
6-arg call site against the 9-arg signature; restore ret/bounds/type_decl
arguments so the build job compiles.

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)

* fix(r1-dispatch): honest exhaustiveness note and ci heal paths

Tighten closing-contract prose per review 47801: single-family dispatch
sites get compile-time enum exhaustiveness; bridge/native-intercept
multi-family sites honestly disclose the wildcard/unreachable! backstop.
Propagate V1InterpreterDispatchGenerationRefused.reason through artifact
emit. Add v1_interpreter_dispatch_generated.rs to ci.yml heal staging.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* fix(r1-dispatch): repair invalid OccurrenceBindingFoldState impl emit

Revert the regen typo that emitted `OccurrenceBindingFoldState<N: Clone>`
(E0229). With emit_bare_type_params already in the seed, the correct
application form is `OccurrenceBindingFoldState<N>`; regen --verify passes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(r1-dispatch): regen ci.yml and dispatch artifact to clear drift gate

HealAuthorCommitRequired was failing because hand-edited ci.yml skew-guard
exclude ordering did not match expected_ci_yml(). Regenerated via main_wet.

Fixed v1_interpreter_dispatch_emit to emit fully-qualified enum paths in
identity arm macros and #![rustfmt::skip] so pre-commit fmt does not fight
the generated-artifact fixed point.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* fix(r1-dispatch): use item-level rustfmt::skip in dispatch emit

Co-authored-by: Cursor <cursoragent@cursor.com>

#![rustfmt::skip] is unstable in submodule files (E0658 on CI). Emit
#[rustfmt::skip] on each generated enum, lookup fn, and arm macro instead.

* fix(r1-dispatch): module-scope arm macros, not macro_export

macro_export arm macros cannot be invoked via $crate:: from another
macro (macro_expanded_macro_exports_accessed_by_absolute_paths). Drop
#[macro_export] from dispatch emit and call through
v1_interpreter_dispatch_generated:: in handler macro expansions.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(r1-dispatch): hoist arm macros via macro_use for nested handler expansion

macro_export arm macros cannot be invoked from nested macro_rules! via
$crate:: (macro_expanded_macro_exports_accessed_by_absolute_paths) and
non-exported module-path invocation does not resolve. Import generated
arm macros with #[macro_use] on v1_interpreter_dispatch_generated before
v1_interpreter and call them by bare name in handler expansions.

Align roadmap node v1-interpreter-primitive-dispatch-authority with the
site-scoped exhaustiveness contract (review 47830): compile-time refusal
on single-family sites, unreachable! backstop on bridge/native-intercept.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* chore: regenerate drifted generated artifacts (ci auto-heal)

* fix(r1-dispatch): make lib.rs macro_use survive regen fixed-point

Hand-editing lib.rs for #[macro_use] was overwritten by regen_stage0.
Teach emit_lib_rs_from_files to emit macro_use on
v1_interpreter_dispatch_generated and order it before v1_interpreter in
the file-derived mod list; sync gunbc_stage0_crate_layout_generated.rs
with the frontier hand-maintained block. regen_stage0 --verify now passes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(r1-dispatch): resolve main merge — lib.rs modules and ci.yml drift

Merge main (#7606 keyed-roster) left lib.rs missing std_keyed_roster and
std_keyed_row module declarations. Regenerated ci.yml and .gitattributes via
main_wet so heal skew-guard excludes match expected_ci_yml() after the merge.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(r1-dispatch): narrow authority note to site-scoped exhaustiveness

Review 47840: v1_interpreter_primitive_surface_authority_note claimed all
roster/handler mismatches fail at compile time; align with the honest
site-scoped bar already in roadmap_authority and the acceptance contract
(single-family sites compile-time; bridge/native-intercept unreachable!
until per-family enum split).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* fix(r1-dispatch): repair dispatch emit dag parse for collision RED

v1_interpreter_dispatch_emit.dag failed v1 parse (expected expression,
found EqEq) when == started a continuation line in
rust_variant_collision_synthetic_red_control. Single-line the equality
and use negated == for identity inequality.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
briansrls added a commit that referenced this pull request Aug 3, 2026
…en (#7697)

* WIP: Lane E: self-host frontier 27-row exact-head closeout, totality wall gre

* WIP: Lane E: self-host frontier 27-row exact-head closeout, totality wall gre

* WIP audit: push interim exact-head frontier probe census (17/27 at HEAD).

Land execution-measured TSV + audit note for 17 surveyed compiler modules:
dominant RealizationGap(parse_grammar_choice_overlap_residue) at ProbeStageAssemble,
minority NameResolutionGap(resolve_module_not_found) on three modules. This is an
interim survey receipt, not roster acceptance or totality-wall closeout.

Move per-module survey driver from scripts/ (does not exist on main) to
docs/probes/ as a declared scaffold with dissolution trigger on frontier transport.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP audit: hand-authored 17 frontier rows from survey; add compare oracle.

Document 12 pre-closeout declared-vs-survey mismatches in audit md (not
silently reconciled). Update measured_probe on 17 surveyed modules by hand
using TSV evidence; migration triggers remain authored claims. Add
diff_frontier_declared_vs_survey.sh (refuses on mismatch; does not write rows).
Do not land row-writer script — measurement is not declaration.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix CI: doc-graph bind for probe audit md; reorder sweep for rank monotonicity.

Hand-updating roster rows to RealizationGap raised tractability ranks above
interleaved NameResolutionGap modules and broke compiler_frontier_sweep_order
rank nondecreasing. Reorder sweep by blocker band. Register the interim survey
receipt in doc_graph_roots so doc_reachability does not orphan it.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Align per-module survey scaffold order with frontier sweep_order.

Keeps the hand-Rust probe driver consistent with compiler_frontier_sweep_order
after the tractability-rank reorder fix.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane E: self-host frontier 27-row exact-head closeout, totality wall gre

* Fix invalid enum accessor impl after stage0 regen.

Regen with a stale emitter seed duplicated `<N: Clone>` onto the impl
target (`OccurrenceBindingFoldState<N: Clone>`), which rustc rejects
(E0229). Restore `OccurrenceBindingFoldState<N>`; regen --verify green.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Name offline consumer for frontier per-module probe witness.

Per-PR CI excludes test/claim/long/ at dir grain but never ran this probe;
add a file-grain exclusion row and exclusion note with the full local
claim_batch recipe so survey evidence is not implied by green CI.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Document survey stale-head drift and spot-check at current main.

State 9f978aa is 44 commits behind 19cc776 with five emitter-path
commits in between; record four-module spot-check where verdicts held.

Co-authored-by: Cursor <cursoragent@cursor.com>

* P2: selection degradation receipts (selected/total + reason) (#7722)

* WIP: P2: selection degradation receipts (selected/total + reason)

* P2: emit selection degradation receipts on every floor discovery run.

Every discovery completion now prints selection_state, selected/total entry groups, ratio, and fallback_reason so whole-corpus affected runs are counted degradations, not quiet success.

Co-authored-by: Cursor <cursoragent@cursor.com>

* P2: wire selection degradation into every floor receipt path.

Publish selection_state, counts, ratio, and fallback_reason on the
measurement tail, resolve receipt, floor-component JSON, and dedicated
receipt file so carrier-only emission cannot satisfy the P2 bar.

Co-authored-by: Cursor <cursoragent@cursor.com>

* P2: drop stale prep-tax doc; prove executed-only selected count.

Remove docs/plans/floor-prep-tax-program.md (owned by #7721). Add a
discriminating test that skip-before-resolve rows do not inflate
selected_entry_groups toward total.

Co-authored-by: Cursor <cursoragent@cursor.com>

* P2: drop duplicate selection-degradation stderr emission.

run_discovery_corpus_with_options already emits via
emit_selection_degradation_receipt; remove the second DAG eval in
run_discovery_batch_node (review 47735).

Co-authored-by: Cursor <cursoragent@cursor.com>

* P2: thread walk source_roots into resolve receipt writer.

Fix E0425: claim_executor bin cannot call pub(crate) default_source_roots;
pass the walk's source_roots through write_resolve_receipt_at like the
selection-degradation receipt path already does.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: P2: selection degradation receipts (selected/total + reason)

* P2: add SELECTION_DEGRADATION_CENSUS_MARKER to cli_run seed.

Roster bidirectional hygiene: observation_emit_census cites
cli_run.rs for [selection-degradation]; mirror other frontier sites
with a const the witness grep can find (review 47746).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: P2: selection degradation receipts (selected/total + reason)

* P2: rustfmt selection_degradation_interp_ctx map_err closure.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Merge origin/main; restore v1_generic_params_needing_clone_bound arity.

Main merge regressed emit_rust to the 6-arg call site; trait_derive_emit
requires ret/bounds/type_decl_items (E0061 on CI merge commit).

Co-authored-by: Cursor <cursoragent@cursor.com>

* P2: witness unknown-tag SelectionUnavailable path (review 47814).

Document that Unavailable is fail-closed for unknown mode tags only;
categorization_unavailable stays on Applied/Superset fallback_reason.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: P2: selection degradation receipts (selected/total + reason)

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* Discharge namespace occurrence identity receipts (#7559)

* WIP: Namespace occurrence debt receipts

* WIP: Namespace occurrence debt receipts

* Restore generated occurrence allocator

* Enroll occurrence debt receipts in Cargo CI

* Track parser receipt CI enrollment debt

* WIP: Namespace occurrence debt receipts

* Track split rebuild receipt enrollment

* WIP: Namespace occurrence debt receipts

* Keep parser receipts outside compile-clean roots

* Prepare governed parser receipt enrollment

* Keep occurrence debts live until roster enrollment

* Import receipt newline index in generated projection

* WIP: Namespace occurrence debt receipts

* Derive occurrence acceptance closure from receipts

* Bind occurrence closure to its law authority

* Clarify occurrence denominator tripwire

* WIP: Namespace occurrence debt receipts

* Complete occurrence acceptance workflow relocation

* WIP: debt receipts

* Register std.occurrence_binding{,_resolve} seed modules; regen

PR #7559's build job fails because the generated witness
v1_tests_claim_occurrence_identity_debt_receipt_test.rs imports
crate::std_occurrence_binding and crate::std_occurrence_binding_resolve,
neither of which is a registered seed module. This registers both in
gunbc.stage0_emit_model generated_stage0_files and stage0 lib.rs and
regenerates.

Regeneration leaves the other 114 generated files byte-identical, but the
two newly emitted modules do not compile: 24 errors, all in
std_occurrence_binding.rs. See the escalation note -- the emitter does not
propagate a Clone bound through a user-declared generic type.

* chore: regenerate drifted generated artifacts (ci auto-heal)

* WIP: Finish PR 7559 adoption: main is repaired (19cc776), so the inherited

* Roster occurrence_identity_closing_complete for non-fold residue gate

PR #7559's acceptance-closure carrier introduces a wildcard match arm that
must be enrolled in gunbc.non_fold_residue before the always-on corpus witness
can pass. Companion to the regenerated ci.yml heal exclude for the new stage0
projection file.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Finish PR 7559 adoption: main is repaired (19cc776), so the inherited

* Fix main-merge regen: restore keyed stage0 modules and total receipt_passed

Merge resolution dropped main's std_keyed_roster/row from the generated emit
plan and lib.rs; regen_stage0 from the merged tree restores both alongside
the debt-receipt module. Total occurrence_identity_receipt_passed over the
closed OccurrenceIdentityReceiptExecution coproduct instead of rostering a
non-fold residue row (closing_complete remains total from 806a0d8).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Finish PR 7559 adoption: main is repaired (19cc776), so the inherited

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* Root-cause disk-tier repeat-resolve memory growth (>8GiB OOM on second resolve through v1 disk cache seam) (#7728)

* WIP: Root-cause disk-tier repeat-resolve memory growth (>8GiB OOM on second r

* WIP: Root-cause disk-tier repeat-resolve memory growth (>8GiB OOM on second r

* Remove debug RSS instrumentation swept in by auto-WIP

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Coordinator replay: wet witness per-row outcomes visible in CI job log (#7702)

* Coordinator replay for wet witness row outcomes in claim_executor.

Ordinary floor worker writes target/floor-wet-witness-row-outcome-receipt.tsv
with passed | failed | selection-skipped per row; coordinator replays into
job log on worker exit and spawn-failure paths. Unit tests discriminate the
three outcomes (claim_executor binary, not claim_batch).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix wet witness outcome TSV parsing for empty detail columns.

Rust tab-split drops trailing empty fields; accept 4- or 5-column rows
so passed rows with no detail replay correctly.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: falsifier is flakey on budget - please investigate (#7738)

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>

* P1 retention vs drain cohort receipt (authoritative) (#7725)

* WIP: P1 retention vs drain cohort receipt (authoritative)

* P1 retention vs drain cohort receipt: REJECT — eviction is not the tax source

Fixed 50-entry cohort run through the real floor path
(run_discovery_corpus_with_options, Adaptive width) in two modes: A
(production eviction on) and B (GUNBC_SCHEDULE_RETENTION_EVICT=0,
retain-all pole). Entries 2..34 (Mode B OOM-killed at 34/50 after
unbounded RSS growth, honestly reported and not backfilled) show
statistically indistinguishable wall/resolve times between modes —
disabling schedule-retention eviction does not collapse the ~1-2s
per-entry tax. Verdict: REJECT the retention hypothesis; redirect to
assembly/materialization reuse, per the parent's stated criterion.

Also fixes the cargo fmt violation from the prior P1 instrumentation
commit that was failing CI on this PR.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* WIP: P1 retention vs drain cohort receipt (authoritative)

* P1 receipt: fix cited SHA, rename mislabeled field, align scaffold wording

Per review 47754 (cursor/composer-2.5, REQUEST_CHANGES), three fixes:

1. Receipt cited b53aec1 (this PR's initial WIP commit) as the
   reproduction SHA, but p1_cohort_probe.rs doesn't exist in that
   commit's tree. Corrected to dddc795, where the probe first
   lands in git history.

2. emit_p1_cohort_entry_line's `schedule_cache_hit` field actually
   logged typecheck_compute_count() movement (a typecheck-memo
   hit/miss), not schedule-retention cache occupancy -- mislabeled
   instrumentation on a measurement-only PR. Renamed to
   `typecheck_cache_hit` everywhere (code, doc comment, receipt);
   raw checked-in logs left unedited as captured evidence, with a
   note explaining the field rename maps onto the same underlying
   signal.

3. Receipt said the probe was "kept in tree; reusable for future
   retention receipts", contradicting the in-code scaffold/dissolve-on
   framing now that P1's REJECT verdict is recorded. Reworded to
   match: probe-only scaffolding, deletes per its named trigger.

No measurement data or verdict changed -- only citation accuracy and
field/wording honesty.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* WIP: P1 retention vs drain cohort receipt (authoritative)

* chore: retrigger CI now that main's E0061 (v1_generic_params_needing_clone_bound arity) is fixed by #7733

No content change on this branch — forces GitHub to recompute the PR merge-ref against main's current (fixed) tip, since a rerun of the prior failed run reused a stale merge-ref captured before #7733 landed.

* P1 scaffold: gate per-group timing/subject-tracking behind p1_cohort_receipt_enabled()

Per review 47844: the Instant/typecheck_compute_count() timing pair and
the resolved_graph_hit subject-set scan ran on every width-1 inline
discovery-drain group regardless of GUNBC_P1_COHORT_RECEIPT — only the
eprintln emission was gated. Wraps the bookkeeping in the same
p1_cohort_detail check as its emission, so the default production floor
path (env unset) pays none of this scaffold's cost, matching the
env-gated discipline the receipt doc already claims.

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* Sole modeled publisher (model + shadow): policy-derived projection, publisher authority, shadow replay (#7594)

* Sole modeled publisher (model + shadow): rebase PR-B onto main.

Replay only PR-B carriers onto current main — no #7591 deletion content
(placement gate/roster removal stays on vivid-newt-418 until that PR
merges). Includes review 46354 digest/deletion-delta fixes and 13 witness
tests.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address review 46417: prune dead variant and dissolve parallel argv surface.

Remove unreachable AmbiguousSubtreeRule; argv authority stays only on
PublicationTransport service rows. Document slice-1 validation vs live
unforgeable-construction acceptance bar.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Sole modeled publisher: ordinary sessions lose public-write capability;

* Address review 46429: align transport, delta taxonomy, and publisher gates.

Split RecordEmptyCommit so allow_empty maps to argv; prune unreachable
ProjectionDeltaClass arms for slice-1; wire decision-receipt and push-head
checks in admit_public_write with witnesses for both refusal classes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Refuse sole-publisher admission when no pushed refs are presented.

Close the empty-pushed_refs vacuous-pass fail-open before live-slice
binding; witness sole_publisher_refuses_empty_pushed_refs.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Gate projection on AdmittedPublicationPolicy; match disposition directly.

derive_public_projection_plan requires construction-admitted policy so
conflicting/unknown-root policies cannot reach the derived path; dissolve
publication_disposition_is_public in favor of coproduct match. Witness
publication_policy_refuses_conflicting_prefix_rules.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address review 46476: full receipt auth and posture fold.

publication_decision_authorizes_newly_public checks policy_version,
authority, and universal audience; invalid receipts refuse with
DecisionReceiptNotAuthorizing. Replace posture Bool predicate with
session_publication_posture_fold.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Sole modeled publisher: ordinary sessions lose public-write capability;

* Route publication ContentHash through std.content_hash.

Main moved ContentHash off std.types and renamed content_hash_combine to content_hash_combine_structural; update publication projection, witnesses, and publisher refusal strings to the family-grounded API.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Sole modeled publisher: ordinary sessions lose public-write capability;

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* Lane A: R1 invert interpreter dispatch authority (roster becomes the authority) (#7682)

* fix(r1-dispatch): restore regen fixed-point and enroll dispatch generated module

Regen was failing because type_ref_hit_ne_bind_measure_active was accidentally
dropped from the builtin registry, and v1_interpreter_dispatch_generated was
not enrolled in the stage0 crate layout (lib.rs drift). Register the scaffold in
frontier, sync crate-layout projections, and land R1 roster authority on main.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* docs(r1-dispatch): refresh authority notes for roster inversion

Update v1_interpreter_primitive_surface authority prose and handler macro
comments to describe the post-R1 model: authored roster in .dag, generated
lookup routing, and compile-time handler alignment — not the pre-inversion
macro-token derivation story review 47740 flagged.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(r1-dispatch): refuse emit when roster row maps to unknown site

Close review 47777 fail-open: expected_v1_interpreter_dispatch_generated_rs
now refuses when any authored row's roster_site_key falls outside
known_dispatch_emit_site_keys instead of silently omitting it from
generated lookup. Witnesses cover live-roster success and bare eval_call
site-key RED control.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* fix(r1-dispatch): restore clone-bound call after main merge

Merge main (#7709) regressed v1_generic_params_needing_clone_bound to a
6-arg call site against the 9-arg signature; restore ret/bounds/type_decl
arguments so the build job compiles.

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)

* fix(r1-dispatch): honest exhaustiveness note and ci heal paths

Tighten closing-contract prose per review 47801: single-family dispatch
sites get compile-time enum exhaustiveness; bridge/native-intercept
multi-family sites honestly disclose the wildcard/unreachable! backstop.
Propagate V1InterpreterDispatchGenerationRefused.reason through artifact
emit. Add v1_interpreter_dispatch_generated.rs to ci.yml heal staging.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* fix(r1-dispatch): repair invalid OccurrenceBindingFoldState impl emit

Revert the regen typo that emitted `OccurrenceBindingFoldState<N: Clone>`
(E0229). With emit_bare_type_params already in the seed, the correct
application form is `OccurrenceBindingFoldState<N>`; regen --verify passes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(r1-dispatch): regen ci.yml and dispatch artifact to clear drift gate

HealAuthorCommitRequired was failing because hand-edited ci.yml skew-guard
exclude ordering did not match expected_ci_yml(). Regenerated via main_wet.

Fixed v1_interpreter_dispatch_emit to emit fully-qualified enum paths in
identity arm macros and #![rustfmt::skip] so pre-commit fmt does not fight
the generated-artifact fixed point.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* fix(r1-dispatch): use item-level rustfmt::skip in dispatch emit

Co-authored-by: Cursor <cursoragent@cursor.com>

#![rustfmt::skip] is unstable in submodule files (E0658 on CI). Emit
#[rustfmt::skip] on each generated enum, lookup fn, and arm macro instead.

* fix(r1-dispatch): module-scope arm macros, not macro_export

macro_export arm macros cannot be invoked via $crate:: from another
macro (macro_expanded_macro_exports_accessed_by_absolute_paths). Drop
#[macro_export] from dispatch emit and call through
v1_interpreter_dispatch_generated:: in handler macro expansions.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(r1-dispatch): hoist arm macros via macro_use for nested handler expansion

macro_export arm macros cannot be invoked from nested macro_rules! via
$crate:: (macro_expanded_macro_exports_accessed_by_absolute_paths) and
non-exported module-path invocation does not resolve. Import generated
arm macros with #[macro_use] on v1_interpreter_dispatch_generated before
v1_interpreter and call them by bare name in handler expansions.

Align roadmap node v1-interpreter-primitive-dispatch-authority with the
site-scoped exhaustiveness contract (review 47830): compile-time refusal
on single-family sites, unreachable! backstop on bridge/native-intercept.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* chore: regenerate drifted generated artifacts (ci auto-heal)

* fix(r1-dispatch): make lib.rs macro_use survive regen fixed-point

Hand-editing lib.rs for #[macro_use] was overwritten by regen_stage0.
Teach emit_lib_rs_from_files to emit macro_use on
v1_interpreter_dispatch_generated and order it before v1_interpreter in
the file-derived mod list; sync gunbc_stage0_crate_layout_generated.rs
with the frontier hand-maintained block. regen_stage0 --verify now passes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(r1-dispatch): resolve main merge — lib.rs modules and ci.yml drift

Merge main (#7606 keyed-roster) left lib.rs missing std_keyed_roster and
std_keyed_row module declarations. Regenerated ci.yml and .gitattributes via
main_wet so heal skew-guard excludes match expected_ci_yml() after the merge.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(r1-dispatch): narrow authority note to site-scoped exhaustiveness

Review 47840: v1_interpreter_primitive_surface_authority_note claimed all
roster/handler mismatches fail at compile time; align with the honest
site-scoped bar already in roadmap_authority and the acceptance contract
(single-family sites compile-time; bridge/native-intercept unreachable!
until per-family enum split).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane A: R1 invert interpreter dispatch authority (roster becomes the aut

* fix(r1-dispatch): repair dispatch emit dag parse for collision RED

v1_interpreter_dispatch_emit.dag failed v1 parse (expected expression,
found EqEq) when == started a continuation line in
rust_variant_collision_synthetic_red_control. Single-line the equality
and use negated == for identity inequality.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>

* Fix audit scaffold fail-open and rename inflated closeout note.

Probe survey script now refuses on per-module failure instead of || true
stale-row widening; rename frontier_probe_exact_head_interim_audit_note
to match 17/27 interim state and empty manifest stub.

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Align probe note and survey md with interim audit framing.

Rename closeout wording in wave2 sizing note; document that 17 frontier.dag
rows were hand-authored in this PR and oracle diff greens for surveyed slice.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane E: self-host frontier 27-row exact-head closeout, totality wall gre

* Regen stage0 lib.rs for regen_verify gate.

Adds v1_tests_claim_occurrence_identity_debt_receipt_test mod export
so regen_verify_gate_passes matches fresh self-compile.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant