Skip to content

namespace/substrate/determinism/numeric tower - #7739

Closed
briansrls wants to merge 12 commits into
mainfrom
roadmap/kernel-authority-amendment
Closed

briansrls wants to merge 12 commits into
mainfrom
roadmap/kernel-authority-amendment

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session calm-badger-682.
Pushing to roadmap/kernel-authority-amendment advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

Brian Searls and others added 12 commits August 1, 2026 01:26
…nt' into roadmap/kernel-authority-amendment
#7508 merged the supplied-candidate binding kernel, resolving P2a's
implementation dependency — but no RoadmapAcceptanceReceipt existed, so
the roadmap still said its own prerequisite was unaccepted. node_is_startable
reads exactly that, so P2a was being worked on while not startable under the
roadmap's own definition. Two truths for one fact.

The criteria digest 2eba4715cdef42eb is the post-#7530 value and was DERIVED
BY EXECUTION, not transcribed: #7530 rewrote this node's boundary, red_control
and out_of_scope to cut authority from retirement, and roadmap_criteria_digest
covers brief + red_control + handback, so any pre-amendment digest is stale by
construction. node_criteria_digest was run against the live node on this tree.

Proven end-to-end rather than by inspection: namespace-binding-kernel goes
2 -> 0 occurrences in the regenerated ROADMAP.md, which only happens if the
receipt matches the node and the node leaves the active set. A wrong digest
leaves the row in place. witness_stale_criteria_digest_refuses_acceptance
returns true.

Also removes dag/tools/kernel_digest_probe.dag, a throwaway probe that the
autosave committed while it was being used to compute the digest.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Two conflicts, both in the roadmap carrier.

dag/gunbc/roadmap_authority.dag: both sides added a note around
scm_prerequisite_acceptance_note — this branch added
namespace_binding_kernel_acceptance_note before it, main added
scm_p0_acceptance_evidence_note after it. Both kept.

Main had ALSO edited scm_prerequisite_acceptance_note itself (to record P0
acceptance and its twenty-two executing journey witnesses), which is why the
two sides shared no identical line and a naive union left the row declared
twice. Main's newer text is kept and this branch's stale pre-P0 copy deleted —
verified by assertion before deleting, not by eye.

ROADMAP.md is a generated artifact, so it was regenerated from the authority
rather than hand-merged; hand-resolving a generated file makes the committed
bytes disagree with their source and detonates on the next .dag PR.

Verified after resolution: no conflict markers anywhere in the tree; the
kernel node is still absent from ROADMAP.md, so the acceptance receipt remains
effective; scm_p0_acceptance_evidence_note is present, so main's work survived;
scm_prerequisite_acceptance_note is declared exactly once.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Six commits behind. roadmap_authority.dag auto-merged cleanly this time; only
ROADMAP.md conflicted, and it is a generated artifact, so it was regenerated
from the authority rather than hand-resolved. Hand-resolving a generated file
makes the committed bytes disagree with their source and detonates on the next
.dag PR.

Verified after: the kernel row stays absent from ROADMAP.md so the acceptance
receipt remains effective, and no conflict markers survive.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls marked this pull request as ready for review August 3, 2026 16:59
@cursor

cursor Bot commented Aug 3, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@gunbai-bot

gunbai-bot Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Closing unmerged after triage: every deliverable on this branch has already landed on main via other PRs, and nothing here needs porting.

What the size actually is

The genuinely authored commits also landed elsewhere

The only three branch-only files would be regressions

  • dag/tools/merge_admission_{gate,stamp}.dag — an earlier shape; main carries a different, larger merge-admission carrier set.
  • src/v1/stage0/src/bin/measure_repeated_typecheck_attribution.rs — deliberately deleted on main by Close the union probe and decompose per-entry assembly #7628 ("the one-shot ratio instrument was deleted after the merged-SHA provenance receipt", DESIGN). Merging would resurrect it.

Net against current main the branch is +4,238 / −16,217 — overwhelmingly a rollback. Resolving 73 conflicts would buy content main already has, plus three regressions to catch.

No work is lost by closing. Follow-on namespace-lane work is being dispatched fresh off main.

@gunbai-bot gunbai-bot Bot closed this Aug 4, 2026
briansrls pushed a commit that referenced this pull request Aug 4, 2026
…ved-closure

namespace-reference-derived-closure carried a six-capability set-difference
closing contract in which every row read Unavailable, while the node itself was
the only dispatchable thing in the lane -- one startable row standing for three
separable pieces of work with different substrates.

The cut follows the contract's own triggers, which already record what each
capability waits on:

  namespace-structural-observations   4 caps, P2aStructuralCandidateProducer7515
  namespace-cross-file-provenance     1 cap,  P2aReferenceDependencyProjection7515
  namespace-pool-independence         1 cap,  P2aPoolIndependentDependencyProjection7515

The first two are parallel -- no dependency runs between the same-file rules and
the cross-file projection. Pool independence depends on cross-file provenance
because a differential needs a projector to perturb.

No new identity was minted for integration or for the census.
namespace-reference-derived-closure keeps its durable identity and now denotes
the aggregate handback (its first_slice moved; its boundary, which still covers
all six, did not). namespace-ambiguity-discharge keeps its identity and its
existing dependency on the closure node.

The three new rows are deliberately ExecutionContractUnspecified. Each first_slice
names authoring its own closing check as its first act, per
v1_lane_binding_survey_note: the contract follows the witness, never precedes it.
The derived closing-contract tasks for the two startable rows are the honest
fail-closed state, not a gap; pool-independence gets none because it is
dependency-held, and could not carry one anyway -- its differential compares an
output shape its prerequisite has not yet produced.

Also adds roadmap-receipt-continuity (roadmap-runtime, off the namespace spine):
a receipt that was valid and is now absent refuses unless an explicit revocation
names the exact node, the exact record, a reason and its disposition. Motivated
by #7739, where a branch spent real effort reconstructing an acceptance record
that already existed because nothing refused when it went missing. Distinct from
startable_nodes_missing_closing_contract, which finds nodes that never had a
check rather than accepted state that vanished.

Evidence, by execution on this tree:
- roadmap_authority_test: 42/42 witnesses PASS
- generated_artifact_drift_test: 7/7 PASS
- ROADMAP.md regenerated via main_wet on dag/tools/generated_artifact_gate.dag;
  the projection shows reference-derived-closure requiring the two new
  prerequisites, and derived closing-contract tasks appearing for exactly the
  two startable unbound rows.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 4, 2026
…ved-closure (#7773)

* WIP: import -> namespace (import deletion)

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Namespace closure: three prerequisite rows in front of reference-derived-closure

namespace-reference-derived-closure carried a six-capability set-difference
closing contract in which every row read Unavailable, while the node itself was
the only dispatchable thing in the lane -- one startable row standing for three
separable pieces of work with different substrates.

The cut follows the contract's own triggers, which already record what each
capability waits on:

  namespace-structural-observations   4 caps, P2aStructuralCandidateProducer7515
  namespace-cross-file-provenance     1 cap,  P2aReferenceDependencyProjection7515
  namespace-pool-independence         1 cap,  P2aPoolIndependentDependencyProjection7515

The first two are parallel -- no dependency runs between the same-file rules and
the cross-file projection. Pool independence depends on cross-file provenance
because a differential needs a projector to perturb.

No new identity was minted for integration or for the census.
namespace-reference-derived-closure keeps its durable identity and now denotes
the aggregate handback (its first_slice moved; its boundary, which still covers
all six, did not). namespace-ambiguity-discharge keeps its identity and its
existing dependency on the closure node.

The three new rows are deliberately ExecutionContractUnspecified. Each first_slice
names authoring its own closing check as its first act, per
v1_lane_binding_survey_note: the contract follows the witness, never precedes it.
The derived closing-contract tasks for the two startable rows are the honest
fail-closed state, not a gap; pool-independence gets none because it is
dependency-held, and could not carry one anyway -- its differential compares an
output shape its prerequisite has not yet produced.

Also adds roadmap-receipt-continuity (roadmap-runtime, off the namespace spine):
a receipt that was valid and is now absent refuses unless an explicit revocation
names the exact node, the exact record, a reason and its disposition. Motivated
by #7739, where a branch spent real effort reconstructing an acceptance record
that already existed because nothing refused when it went missing. Distinct from
startable_nodes_missing_closing_contract, which finds nodes that never had a
check rather than accepted state that vanished.

Evidence, by execution on this tree:
- roadmap_authority_test: 42/42 witnesses PASS
- generated_artifact_drift_test: 7/7 PASS
- ROADMAP.md regenerated via main_wet on dag/tools/generated_artifact_gate.dag;
  the projection shows reference-derived-closure requiring the two new
  prerequisites, and derived closing-contract tasks appearing for exactly the
  two startable unbound rows.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 4, 2026
* WIP: import -> namespace (import deletion)

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Namespace closure: three prerequisite rows in front of reference-derived-closure

namespace-reference-derived-closure carried a six-capability set-difference
closing contract in which every row read Unavailable, while the node itself was
the only dispatchable thing in the lane -- one startable row standing for three
separable pieces of work with different substrates.

The cut follows the contract's own triggers, which already record what each
capability waits on:

  namespace-structural-observations   4 caps, P2aStructuralCandidateProducer7515
  namespace-cross-file-provenance     1 cap,  P2aReferenceDependencyProjection7515
  namespace-pool-independence         1 cap,  P2aPoolIndependentDependencyProjection7515

The first two are parallel -- no dependency runs between the same-file rules and
the cross-file projection. Pool independence depends on cross-file provenance
because a differential needs a projector to perturb.

No new identity was minted for integration or for the census.
namespace-reference-derived-closure keeps its durable identity and now denotes
the aggregate handback (its first_slice moved; its boundary, which still covers
all six, did not). namespace-ambiguity-discharge keeps its identity and its
existing dependency on the closure node.

The three new rows are deliberately ExecutionContractUnspecified. Each first_slice
names authoring its own closing check as its first act, per
v1_lane_binding_survey_note: the contract follows the witness, never precedes it.
The derived closing-contract tasks for the two startable rows are the honest
fail-closed state, not a gap; pool-independence gets none because it is
dependency-held, and could not carry one anyway -- its differential compares an
output shape its prerequisite has not yet produced.

Also adds roadmap-receipt-continuity (roadmap-runtime, off the namespace spine):
a receipt that was valid and is now absent refuses unless an explicit revocation
names the exact node, the exact record, a reason and its disposition. Motivated
by #7739, where a branch spent real effort reconstructing an acceptance record
that already existed because nothing refused when it went missing. Distinct from
startable_nodes_missing_closing_contract, which finds nodes that never had a
check rather than accepted state that vanished.

Evidence, by execution on this tree:
- roadmap_authority_test: 42/42 witnesses PASS
- generated_artifact_drift_test: 7/7 PASS
- ROADMAP.md regenerated via main_wet on dag/tools/generated_artifact_gate.dag;
  the projection shows reference-derived-closure requiring the two new
  prerequisites, and derived closing-contract tasks appearing for exactly the
  two startable unbound rows.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: Accepted-receipt continuity wall: a vanished acceptance receipt with no

* Fix acceptance-receipt continuity wall types and drop count oracle.

Use a named refusal variant instead of a single-variant coproduct the
compiler rejected; remove the live witness population-count pin per DESIGN
section 5 and document the validation-residue ceiling in the wall note.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Accepted-receipt continuity wall: a vanished acceptance receipt with no

* WIP: Accepted-receipt continuity wall: a vanished acceptance receipt with no

* WIP: Accepted-receipt continuity wall: a vanished acceptance receipt with no

* WIP: Accepted-receipt continuity wall: a vanished acceptance receipt with no

* WIP: Accepted-receipt continuity wall: a vanished acceptance receipt with no

* WIP: Accepted-receipt continuity wall: a vanished acceptance receipt with no

* WIP: Wire prior_history to a real base observation on the live receipt-contin

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Refuse integrity when git prior observation fails instead of fabricating prior.

PriorHistoryGitObservationRefused now maps to AcceptanceHistoryIntegrityRefusedPriorHistoryObservation rather than returning current_history, with a planted RED witness and a ReadsLiveTree wet lane for the live git-observed path.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Wire prior_history to a real base observation on the live receipt-contin

* Promote receipt continuity contract to test fn for naming hygiene.

Plain fn in *_test.dag was orphan after removing the self-recursing wrapper; execution contract already resolves test fn declarations.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls pushed a commit that referenced this pull request Aug 6, 2026
…les from the path roster (#7830)

* WIP: import -> namespace (import deletion)

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Namespace closure: three prerequisite rows in front of reference-derived-closure

namespace-reference-derived-closure carried a six-capability set-difference
closing contract in which every row read Unavailable, while the node itself was
the only dispatchable thing in the lane -- one startable row standing for three
separable pieces of work with different substrates.

The cut follows the contract's own triggers, which already record what each
capability waits on:

  namespace-structural-observations   4 caps, P2aStructuralCandidateProducer7515
  namespace-cross-file-provenance     1 cap,  P2aReferenceDependencyProjection7515
  namespace-pool-independence         1 cap,  P2aPoolIndependentDependencyProjection7515

The first two are parallel -- no dependency runs between the same-file rules and
the cross-file projection. Pool independence depends on cross-file provenance
because a differential needs a projector to perturb.

No new identity was minted for integration or for the census.
namespace-reference-derived-closure keeps its durable identity and now denotes
the aggregate handback (its first_slice moved; its boundary, which still covers
all six, did not). namespace-ambiguity-discharge keeps its identity and its
existing dependency on the closure node.

The three new rows are deliberately ExecutionContractUnspecified. Each first_slice
names authoring its own closing check as its first act, per
v1_lane_binding_survey_note: the contract follows the witness, never precedes it.
The derived closing-contract tasks for the two startable rows are the honest
fail-closed state, not a gap; pool-independence gets none because it is
dependency-held, and could not carry one anyway -- its differential compares an
output shape its prerequisite has not yet produced.

Also adds roadmap-receipt-continuity (roadmap-runtime, off the namespace spine):
a receipt that was valid and is now absent refuses unless an explicit revocation
names the exact node, the exact record, a reason and its disposition. Motivated
by #7739, where a branch spent real effort reconstructing an acceptance record
that already existed because nothing refused when it went missing. Distinct from
startable_nodes_missing_closing_contract, which finds nodes that never had a
check rather than accepted state that vanished.

Evidence, by execution on this tree:
- roadmap_authority_test: 42/42 witnesses PASS
- generated_artifact_drift_test: 7/7 PASS
- ROADMAP.md regenerated via main_wet on dag/tools/generated_artifact_gate.dag;
  the projection shows reference-derived-closure requiring the two new
  prerequisites, and derived closing-contract tasks appearing for exactly the
  two startable unbound rows.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: import -> namespace (import deletion)

* Remove stray empty file committed by WIP auto-commit

An empty file named 'true' was created in the worktree by a shell-quoting
mishap while sending dashboard messages, then picked up and committed by
the WIP auto-commit process. It is not on main and carries no content.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: import -> namespace (import deletion)

* Regenerate ci.yml: heal repair artifact publishes its hidden payload

Author-committed because the GitHub App lacks workflows:write, so the
heal job can detect this drift but can never push the fix.

Emitted from the ci_workflow.dag change in this branch; the value is
derived from author_commit_required_committed_artifact_paths(), not
hard-coded.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Correct the incident enumeration in the hidden-files note

The first draft cited "#7770 twice, #7791, #7835, #7857". Two errors:
#7770 hit the author-commit-required class three times on 2026-08-05
(ci.yml at 04:39 and 17:42, falsifier.yml at 06:34), and #7835 was only
a prospective warning, never a confirmed incident — the real fourth PR
is #7772. Verified against this lane's dispatch receipts rather than
recall, and the count is now stated as a floor rather than a census.

A wrong enumeration inside a canonical carrier is the citation class
DESIGN §3 names, so it gets the same bar as any other cited fact.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Regenerate ci.yml against merged main (author-committed)

The merge brought in 52 commits of main, and the generated-artifact merge
driver keeps this side's copy for generated paths, so the merged ci.yml
was this branch's pre-merge bytes: it was missing main's new registered
plans and stage0 modules in AUTHORED_CONFLICTS, the heal commit's
--no-verify, several step ids, and a test-negation respelling.

Regenerated from the authority rather than hand-merged. The output now
differs from origin/main by exactly one line — the include-hidden-files
key this branch adds — which is the check that the regeneration is
correct rather than a plausible-looking text merge.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: import -> namespace (import deletion)

* WIP: import -> namespace (import deletion)

* Remove the floor/heal gating model change: it belongs to #7882, not here

review 49102 is correct and this was my error. ci_workflow.dag declared
needs: [build, regen, heal_generated_artifacts] with a job-level if, while
the committed ci.yml carried neither -- an internally inconsistent PR that
would have failed ci_yaml_parse_witness, since expected_ci_yml() serializes
the model.

The cause was mechanical rather than a decision: the gating work was in this
worktree when the WIP auto-commit picked it up and pushed the .dag half,
while the regenerated ci.yml was discarded by a local reset moments later.
The two halves were split across a push boundary.

The fix is removal, not regeneration. That change is not in this PR's scope
and already exists as #7882, authored on main with its own witnesses and a
proven RED control. Regenerating ci.yml here would have made this PR
self-consistent by duplicating another PR's change, which is the worse
resolution of the two.

The three files are restored to cfea75a, the last head where this branch
carried only the heal-artifact fix. Regen after the restore produces no
ci.yml drift, which is the check that model and artifact now agree.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant