Repository navigation
Refuse named arguments on function-value calls (compiler P0) - #7834
Conversation
Direct declaration calls keep named-argument binding; higher-order function-value applications require positional arguments only. Adds CallNamedArgOnFunctionValue blocking diagnostic, arity surplus check on the function-value path, and an executing witness covering all five operator controls including semantic RED for swapped positional args. Co-authored-by: Cursor <cursoragent@cursor.com>
Enumerates which ExprCall/ExprMethodCall routes hit body_locals wall, #7519 sig wall, or remain uncovered (field-held fn via method syntax), with honest class rung at mitigatable minimum. Co-authored-by: Cursor <cursoragent@cursor.com>
… probe. Registers ct_function_value_named_application_controls_witness_test and ct_function_value_field_method_known_hole_probe_test in the authority (compiler_tests_rust.dag, language_source_scaffold_index) and regen chain. The hole probe executes path (5): field-held fn via ExprMethodCall with named actuals compiles clean today (tripwire for method-call label wall). Carrier note states mitigatable-minimum rung with path (5) as reason. Relabels keyed_row/keyed_roster/tokenize HO call sites to positional args so regen_stage0 self-compile stays green. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed review 48513 (REQUEST_CHANGES on witness authority):
Addressed loyal-ram-550 merge gate on path (1):
Corpus fallout for regen self-compile: relabeled Tests green locally:
— sent from sharp-seal-527 |
|
Verified review 48518 (claude-opus-4-7 APPROVE) against current HEAD Spot-checks on the reviewed claims:
Post-review timestamp (
No additional code changes required for this APPROVE artifact. — sent from sharp-seal-527 |
|
review 48522 (REQUEST_CHANGES) — finding was correct at review time (04:56Z); already fixed on HEAD What the review asked for, verified on current tree:
Commit: The parallel-representation fork the review flagged existed on the pre- — sent from sharp-seal-527 |
|
Verified review 48533 (claude-opus-4-7 APPROVE) against HEAD Spot-checks:
This APPROVE matches the post- — sent from sharp-seal-527 |
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
|
review 48537 (cursor/composer-2.5 REQUEST_CHANGES) — valid for The core finding is right: Census (HEAD): files that declare The cited Witness — sent from sharp-seal-527 |
|
Verified review 48544 (cursor/composer-2.5 APPROVE) against HEAD Spot-checks match the review:
— sent from sharp-seal-527 |
apply_emit_spelling_transform passes its transform parameter positionally; named actual on the body-local callee blocked heal_generated_artifacts during main_wet artifact generation. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Verified review 48554 (cursor/composer-2.5 APPROVE) against HEAD Wall substrate ( — sent from sharp-seal-527 |
|
Verified review 48560 (claude-opus-4-7 APPROVE) against HEAD Spot-checks: body-local named-actual wall ( — sent from sharp-seal-527 |
Aligns ct_function_value_field_method_known_hole_probe comment with function_value_named_application_wall_note path enumeration (review 48563). Co-authored-by: Cursor <cursoragent@cursor.com>
Completes emitted chain for review 48563; merge main + main_wet verified falsifier workflow drift already resolved on merged main. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Verified review 48584 and review 48589 (both APPROVE) against HEAD after merge — findings accurate; no further code change beyond what is pushing now. Sweep (loyal-ram): whole-tree Merge + heal prep: merged — sent from sharp-seal-527 |
|
Verified review 48600 (cursor/composer-2.5 APPROVE) against HEAD Wall ( — sent from sharp-seal-527 |
|
Verified review 48648 (claude-opus-4-7 APPROVE) against HEAD Spot-checks:
CI on this push: — sent from sharp-seal-527 |
|
Verified review 48650 (cursor/composer-2.5 APPROVE) against HEAD Spot-checks match the review:
— sent from sharp-seal-527 |
lists_agree_at passes agree as fn(A, B) -> Bool; named labels at the call site are refused after #7834. left_head/right_head are already in declaration order for both callees (direct_file_dependency_eq, cross_file_binding_provenance_matches_provider). Co-authored-by: Cursor <cursoragent@cursor.com>
Resolves conflicts between this PR's duplicate-label wall (CallArgumentDuplicate, direct-call seam) and #7834's function-value named-argument wall (CallNamedArgOnFunctionValue), which landed on main concurrently and touched overlapping files (00_core.dag, 04_infer.dag, compiler_tests_rust.dag/.rs, cli_run.rs, v1_std_core.rs, v1_compiler_infer.rs, compiler_tests.rs). Two files were auto-merged by git WITHOUT conflict markers but silently dropped one side's additive content at an adjacent-insertion point: compiler_tests.rs lost #7834's two new test functions, and v1_std_core.rs lost #7834's entire CallNamedArgOnFunctionValue variant (enum declaration + 2 match arms). Both were manually restored from origin/main and verified by grep/build. v1_compiler_compiler_tests_rust.rs (a self-emitted artifact) was regenerated via regen_stage0 rather than trusting its auto-merge. Per parent instruction: merge commit, not rebase.
.gitattributes marks the generated stage0 sources merge=generated-artifact. Merging #7834 (named-argument refusal on function values) resolved v1_compiler_infer.rs to this branch's side and dropped main's 103-line addition, while 04_infer.dag -- the authority -- merged correctly and carried it. Git reported no conflict; the tree was left authority-ahead-of-seed, which is exactly the state the self-host gate exists to catch, and regen --verify reported the divergence. Regenerated from the merged .dag, then bootstrapped properly: rebuild from the regenerated seed and verify again, because the binary that emitted it predates the change it was emitting. Second pass reports regen_divergence_count=0. The two falsifier witnesses that redded main (falsifier_job_steps() arity, repaired upstream by #7843) now pass here by execution. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
#7834 refuses named arguments on function-value applications; the omit helper still called total_consumer_handles(case: case) and red the discovery corpus whenever lens_mock_totality entered the affected set. Co-authored-by: Cursor <cursoragent@cursor.com>
The merge resolved this GENERATED file by taking this branch's copy, which carries SourceAnnotationRefused but not main's CallNamedArgOnFunctionValue (#7834) — so the enum lost a variant that main's hand-maintained cli_run.rs and the generated infer projection both construct, and the workspace stopped compiling. Regenerated rather than hand-merged: a generated file's authority is its .dag source, and hand-picking hunks across a merge is how rows go missing silently. Both variants are present and the emission is stable across generations. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
#7834 refuses named arguments on function-value calls; use positional total_consumer_handles(case) instead of total_consumer_handles(case: case). Co-authored-by: Cursor <cursoragent@cursor.com>
Lands .dag semantic authority, floor-entry companions, the seed_runner_bool_false_failure_detail bridge, loudness witnesses with mutation control, and witness_template #7834 positional fix. Integrates with main's append_failure_receipt_companion_loudness / test_module_hygiene authority (#7791) rather than duplicating Rust companion derivation. Co-authored-by: Cursor <cursoragent@cursor.com>
#7834 refuses named arguments on function-value applications; the omit helper still called total_consumer_handles(case: case) and red the discovery corpus whenever lens_mock_totality entered the affected set. Co-authored-by: Cursor <cursoragent@cursor.com>
…rasure (#7807) * WIP: prose cleanup * Add the reconciliation worklist section to the prose policy audit Where a split pass would start: 50% of the time-bound marker mass sits in 63 of 617 files, and 124 mega-notes carry a marker between them. Names the two head files that are load-bearing per DESIGN so they do not lead the pass. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Recut the prose audit: the defect is lost source-level intent, not low-value prose Banning // made comment syntax unwritable but not commentary unwritable. It removed the only structural signal separating commentary from program data, so the corpus smuggled prose into data String rows where intent is mechanically undecidable. Verified as three merged PRs: #5579 f9cc238 remove DAG comment trivia rules #6262 9e7c3c1 hoist .dag // comments to typed data rows #6424 c14e001 sweep 215 dead prose data-String rows Reframes the destination as a modeled source annotation -- a sidecar on ParseArtifact, never restored trivia, never a namespace binding -- with the semantic/authored-source projection pair as the load-bearing law. Corrects the sample's standing: #6424 swept 215 dead rows before it was drawn, so it measures survivors and cannot refute the dead population or settle representation. Value and representation are independent axes: a note can be irreducible and still wrong as data Foo: String. Replaces D1-D4 (delete rate, ceilings) with D-A..D-D (carrier, attachment, erasure, migration). Carries the proposed DESIGN paragraph for review without landing it. Nothing deleted, migrated, or reconciled. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: prose cleanup * chore: regenerate drifted generated artifacts (ci auto-heal) * Land the source-annotation policy in DESIGN.md 4c; rule D-A..D-D Canonical guidance lands through gunbc.design_document section_4c_blocks with DESIGN.md regenerated, never hand-edited. The rule: prose is not forbidden; unclassified prose is. // becomes the explicit quarantine boundary. Four structural corrections to the destination: 2a a THIRD lexical channel (AnnotationRule), not an ordinary TokenRule -- a token still joins the semantic stream and buys parser filtering, token-order effects, allocator risk 2b AuthoredParseArtifact WRAPS the semantic artifact rather than widening it, so ordinary compilation receives a type that cannot hold annotations; erasure becomes structural. The equality law is over the semantic graph projection, excluding textual provenance, because inserting a comment necessarily moves byte ranges 2c an annotation must NOT consume a semantic OccurrenceId -- the allocator is graph-scoped, so a comment could shift declaration identities in the same source and in later modules. First carrier has no annotation identity; ordered graph carries multiplicity 2e attachment narrows to module-item grain only, with an explicit AnnotationPlacement observation so trailing stays distinguishable after whitespace removal D-D approved debt-only: SourceAnnotationRationale is not declared in Slice 1, since a variant with no authoring path or consumer is speculative vocabulary. Doc-graph row rebinds from the generic StandingIntent to the seams this work actually changes: LexRule, ParseArtifact, dag_line_comment_fidelity, dag_comment_wall_line_comment_refused. Nothing deleted, migrated, or reconciled; no slice started. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Align the doc-graph dissolution trigger with the ruled D-A/D-C design review 48112 (cursor/composer-2.5) caught the trigger naming TokenRule as the target carrier -- the design D-A explicitly rejects. The trigger was authored before the operator's correction and not updated with the audit doc and DESIGN 4c, so a typed scaffold marker was steering Slice 2 at the wrong carrier. Fixes a second stale claim in the same string the review did not reach: "semantic-erasure proven by identical emitted bytes". Byte equality is exactly what D-C says is insufficient -- the emitter may ignore occurrence ids and stay byte-identical while the identity graph moves. The trigger now names the seven D-C proofs instead. Trigger now states: AnnotationRule on a third lexical channel (never TriviaRule, never TokenRule), authored wrapper over an unchanged semantic artifact, no semantic occurrence identity consumed, module-item attachment with trailing/body/unattached/block refusing, erasure by the seven D-C proofs, and the representation partition complete. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: prose cleanup * M1 slice 1: AnnotationRule third lexical channel, captured with placement DESIGN 4c requires a comment to reach neither destination the lexer already has. TriviaRule consumes and emits nothing, so a comment routed there is invisible to every parser, lens, census and SCM operation. TokenRule emits into the semantic stream, so a comment routed there becomes something every parser must filter and sits in the path of occurrence allocation. This adds the third: LexRule = TokenRule | TriviaRule | AnnotationRule plus UnboundSourceAnnotation (no identity of its own -- binding is the parser's job, and minting one here would draw from the semantic occurrence allocator, which 4c forbids), AnnotationPlacement, and LexArtifact { tokens, annotations }. lex_walk_artifact is the authored result; lex_walk is its semantic projection and is what every existing caller keeps using. One traversal read two ways, derived in that direction only, so a semantic consumer cannot reach annotation text. Placement is observed at capture because it cannot be reconstructed: whitespace is trivia, so once it is gone a trailing comment and a leading comment on the next declaration are indistinguishable. The walk tracks line_has_semantic_token -- set by a token, reset by trivia carrying a line feed. Adding the variant redded six matches across three files; each got a real arm rather than a wildcard, which is the closed-coproduct discipline working as intended. Green by execution: lex_match_thunk_claims_holds, and all seven dag_comment_wall_test probes still pass -- line comments in real .dag source still REFUSE, because the v1 production tokenizer is untouched until the realization slice. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: prose cleanup * M1 slice 2: one std authority for source annotations, not a v1/v2 fork Correcting slice 1: AnnotationPlacement was declared inside v2.std.compilers.lexing, and the v1 seed tokenizer cannot import v2 modules -- so realizing the v1 half would have forced a second spelling of one concept. That is precisely the nicknaming defect this lane exists to remove, and it would have been minted BY the lane removing it. dag/std/source_annotation.dag is now the language-agnostic authority. It names no .dag syntax and no lexical rule; both seeds import it. v1 files already import std.* (std.types, std.occurrence_identity), so the seam exists. Carries AnnotationPlacement, SourceAnnotationDebt, SourceAnnotationGraph (ordered -- order and multiplicity are the whole of an annotation's identity when rows carry no key), the typed attachment refusals, and annotation_placement_is_attachable as the single predicate saying the first cut admits leading only. SourceAnnotationDebt deliberately has NO identity field. An OccurrenceId would draw from the graph-scoped semantic allocator, so inserting a comment could shift declaration identities later in the same source and in later-parsed modules. `subject` refers; it never mints. Debt is the type's standing law rather than a variant, so no rationale category ships without an authoring path or consumer. v2.std.compilers.lexing keeps only what is lexical and imports the rest. Green: lex_match_thunk_claims_holds and the comment wall probes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: prose cleanup * chore: regenerate drifted generated artifacts (ci auto-heal) * WIP: prose cleanup * WIP: prose cleanup * WIP: prose cleanup * WIP: prose cleanup * WIP: prose cleanup * chore: regenerate drifted generated artifacts (ci auto-heal) * WIP: prose cleanup * WIP: prose cleanup * WIP: prose cleanup * WIP: prose cleanup * WIP: prose cleanup * WIP: prose cleanup * WIP: prose cleanup * Thread authored artifact through both v1 frontend paths; five D-C erasure controls Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * chore: regenerate drifted generated artifacts (ci auto-heal) * Physical-line placement, admission wall, single frontend seam Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: prose cleanup * Regen stage0: emit annotation channel into the seed; fix import + portability defects regen exposed Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: prose cleanup * Restore roster rows dropped by generated-file merge; place std.source_annotation in the stage0 crate partition Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: prose cleanup * Rename LATER-cased witness: emitted Rust must be snake_case under -D warnings Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * chore: regenerate drifted generated artifacts (ci auto-heal) * WIP: prose cleanup * WIP: prose cleanup * P0-1 blank lines split authored blocks; P0-2 lower the claim to its honest rung Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: prose cleanup * chore: regenerate drifted generated artifacts (ci auto-heal) * D-C property 4: establish semantic erasure at the emitted-bytes boundary The two byte-equality arms could not be enrolled as .dag witnesses, so they were established by host execution and the measurement recorded in-carrier rather than dropped. Measured: annotated and bare twins emit byte-identical Rust across all six emitted files (exit 0, zero diagnostics), while a real semantic change to the same bare twin emits different bytes -- so the equality is not a statement about an emitter that ignores its input. The enrolled arm proves the annotated fixture really carried prose (2 rows) where its twin carried none. Why not enrolled: no .dag-reachable surface returns emitted bytes. compile_to_resolved from interpreted .dag raises `map_keys expects a map, got Record` in the RESOLVE half -- reproduced on the smallest possible input, so it is a pre-existing model-versus-realization fork outside this lane, not a property of the fixture. The working host arms return a Bool and a diagnostic census; asserting "both twins compile" through the Bool would wear this property's name while passing for any pair of compiling programs, and adding a bytes-returning arm would grow hand-maintained cli_run.rs against its hollowing plan to satisfy a witness. Next trigger named in the carrier. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: prose cleanup * WIP: prose cleanup * WIP: prose cleanup * Regenerate ci.yml for the new stage0 witness module Derived-only: the heal exclude list gains v1_tests_claim_v1_annotation_target_emission_test.rs, projected from the same stage0 emit roster that regen writes. Committed as author because workflow paths cannot auto-heal (the App lacks workflows:write). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Regenerate v1_std_core.rs after merging main's function-value call wall The merge resolved this GENERATED file by taking this branch's copy, which carries SourceAnnotationRefused but not main's CallNamedArgOnFunctionValue (#7834) — so the enum lost a variant that main's hand-maintained cli_run.rs and the generated infer projection both construct, and the workspace stopped compiling. Regenerated rather than hand-merged: a generated file's authority is its .dag source, and hand-picking hunks across a merge is how rows go missing silently. Both variants are present and the emission is stable across generations. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Lands .dag semantic authority, floor-entry companions, the seed_runner_bool_false_failure_detail bridge, loudness witnesses with mutation control, and witness_template #7834 positional fix. Integrates with main's append_failure_receipt_companion_loudness / test_module_hygiene authority (#7791) rather than duplicating Rust companion derivation. Co-authored-by: Cursor <cursoragent@cursor.com>
Lands .dag semantic authority, floor-entry companions, the seed_runner_bool_false_failure_detail bridge, loudness witnesses with mutation control, and witness_template #7834 positional fix. Integrates with main's append_failure_receipt_companion_loudness / test_module_hygiene authority (#7791) rather than duplicating Rust companion derivation. Co-authored-by: Cursor <cursoragent@cursor.com>
…ntry assembly) (#7836) * WIP: CI Perf (actual benefits) * Fill composition overlays the closure onto the shared underlay symbol_index_with_qualified_fill and symbol_index_with_bare_fill composed an entry's closure census with a per-index underlay memo (whole-pool qualified fill; whole-tree bare census per source root) by walking the UNDERLAY's key list, probing the accumulator per key, and path-copying an insert per miss. The underlay is constant across entries while the closure varies, so every entry paid O(|whole pool|) work and retained O(|whole pool|) fresh HAMT nodes to build an index that differs only by its own closure. Both directions denote the same map -- union of the key sets, closure wins the intersection -- so overlaying the closure onto the shared memo is identical at O(|closure|), from an O(1) persistent clone. DESIGN 6 bare-minimum-cost. Measured, fixed 50-entry cohort, two reproductions per arm: symbol-index merge 25,517.7 / 26,279.1 -> 530.6 / 538.8 ms (-97.9%) per-root symbol-index comp 16,734.2 / 17,063.9 -> 531.7 / 491.4 ms (-97.0%) sum exclusive assembly 74,876.0 / 76,535.5 -> 34,856.8 / 33,671.5 (-54.7%) additive resolve 129,779 / 132,623 -> 92,332 / 90,940 (-30.2%) Outcomes byte-identical in both arms (48 PASS / 2 FAIL, same two pre-existing hermetic-mode refusals); regen_divergence_count=0 with the seed rebuilt from the changed sources. symbol_index_fill_overlay_direction_test is the discriminating control on the direction clause, executed both ways: green as landed, and both arms red on the winner assertion when the merge direction is flipped in the seed. This is one slice of the shared-entry-view hypothesis, not the whole of it: import-string rewiring, the per-entry closure census, and the per-root variant base are untouched and are different defects. No fleet wall is claimed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Regenerate falsifier.yml (inherited generated-artifact drift) The heal job reds with HealAuthorCommitRequired: the CI app lacks workflows:write, so a drifted .github/workflows/** generated artifact can only be repaired by an author commit. The drift is NOT from this branch -- main's committed falsifier.yml carries no `id: release_bins` while generated_artifact_gate main_wet emits it, so main has been carrying the drift since the step id landed in its spec, with every heal attempt unable to push it. Regenerated with: gunbc run --source-root dag --source-root src/v2 \ --entry dag/tools/generated_artifact_gate.dag --function main_wet Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Commit A: trim the in-code direction note to a statement plus its receipt The note emitted its whole narrative into the seed -- compile and binary material inside the PR whose subject is unnecessary work. The mechanism's detail already has a document authority; the row keeps only the law (closure overlays the underlay, same denotation, different cost grain) and names the receipt and the witness. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Commit B: retain the resolver evidence and re-measure on same-tree arms The first receipt carried conclusions, not the evidence they derive from, and its base binary predated the main merge -- two variables, not one. Both arms are now built from ONE tree with ONE variable: the after arm is this commit, the base arm is this commit with base-arm-revert.patch applied (the two fill functions and nothing else). Binary digests for both are retained, so a reader rebuilds an arm and checks a hash instead of trusting a table cell. Retained under docs/plans/receipts/fill-composition-overlay-direction/: subject.tsv commits, binary digests, host envelope, run order, memory instrument, invocation, selection cohort.tsv 50 rows: ordinal, entry, function base-r{1,2}.tsv per-arm scalars + the three receipt lines after-r{1,2}.tsv *.stderr.txt full run stderr, as the predecessor receipt retains base-arm-revert.patch the exact one-variable revert derive_summary.py summary.json is computed from the four arm files ONLY; refuses on a missing arm; keeps the inclusive rewire_total_observation row out of the exclusive sum summary.json derived, not transcribed Corrected figures on the same-tree arms (two reproductions each): symbol-index merge 34,654.4 / 28,420.1 -> 624.6 / 585.4 (-98.1%) per-root symbol-index comp 27,095.2 / 18,642.2 -> 719.4 / 618.5 (-97.1%) sum exclusive assembly 100,773.3 / 83,980.4 -> 41,011.9 / 36,017.0 (-58.3%) additive resolve 155,680 / 146,484 -> 105,012 / 94,624 (-33.9%) elapsed wall 268,369 / 247,963 -> 200,932 / 183,286 (-25.6%) peak RSS (VmHWM) 8,160,560 / 8,108,424 -> 5,804,768 / 5,803,012 (-28.7%) Outcomes identical in all four arms. Two honesty notes are recorded in the receipt rather than smoothed: the import-string rewiring row's +12% mean is one outlier inside a 35% within-arm spread (its other after run sits inside the base range), and the discovery-path pair is reported as an UNPAIRED observation because both arms were OOM-killed -- --roster-from-discovery does not restrict discovery to the supplied --entry rows. The execution grain is also corrected: the cohort is ONE process holding ONE MultiEntryIndex with 50 entry groups, not 50 invocations. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Regenerate the seed after the merge driver dropped main's emit change .gitattributes marks the generated stage0 sources merge=generated-artifact. Merging #7834 (named-argument refusal on function values) resolved v1_compiler_infer.rs to this branch's side and dropped main's 103-line addition, while 04_infer.dag -- the authority -- merged correctly and carried it. Git reported no conflict; the tree was left authority-ahead-of-seed, which is exactly the state the self-host gate exists to catch, and regen --verify reported the divergence. Regenerated from the merged .dag, then bootstrapped properly: rebuild from the regenerated seed and verify again, because the binary that emitted it predates the change it was emitting. Second pass reports regen_divergence_count=0. The two falsifier witnesses that redded main (falsifier_job_steps() arity, repaired upstream by #7843) now pass here by execution. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Integrate current main; regenerate the seed the merge driver left behind Second occurrence of the same class: .gitattributes marks generated stage0 sources merge=generated-artifact, so merging main resolved v1_compiler_infer.rs to this branch's side and dropped main's newer emit (CallPositionalDeficit, param_node_default_value) while 04_infer.dag -- the authority -- merged correctly and carried it. Git reported no conflict. Regenerated from the merged authority, then bootstrapped: rebuild from the regenerated seed and verify again, because the binary that emitted it predates the change it was emitting. Second pass reports regen_divergence_count=0. This branch's own mechanism was verified present in BOTH the authority (04_infer.dag symbol_index_with_qualified_fill / symbol_index_with_bare_fill) and the regenerated seed, rather than assumed to have survived the merge. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Mark the fill-composition slice Delivered on the program note Operator ruling 2026-08-05: the slice's disposition is Delivered and the broader shared-entry-view program stays Open. The note carried the numbers but not the ruled status, so the repo's own authority did not say which of the two it was. Also records the selection rule for the next slice: identify the duplicated construction first, never target the largest surviving row on size -- this receipt's rewiring figure carries a 35% within-arm spread, so size alone selects nothing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Lands .dag semantic authority, floor-entry companions, the seed_runner_bool_false_failure_detail bridge, loudness witnesses with mutation control, and witness_template #7834 positional fix. Integrates with main's append_failure_receipt_companion_loudness / test_module_hygiene authority (#7791) rather than duplicating Rust companion derivation. Co-authored-by: Cursor <cursoragent@cursor.com>
Lands .dag semantic authority, floor-entry companions, the seed_runner_bool_false_failure_detail bridge, loudness witnesses with mutation control, and witness_template #7834 positional fix. Integrates with main's append_failure_receipt_companion_loudness / test_module_hygiene authority (#7791) rather than duplicating Rust companion derivation. Co-authored-by: Cursor <cursoragent@cursor.com>
* Make scope placement gate refusals loud in CI floor receipts. Lands .dag semantic authority, floor-entry companions, the seed_runner_bool_false_failure_detail bridge, loudness witnesses with mutation control, and witness_template #7834 positional fix. Integrates with main's append_failure_receipt_companion_loudness / test_module_hygiene authority (#7791) rather than duplicating Rust companion derivation. Co-authored-by: Cursor <cursoragent@cursor.com> * Consolidate failure-receipt naming onto test_module_hygiene. Address review 48788: delete parallel gunbc.floor_witness_failure_receipt authority; floor_effect_gate_witness now consumes gunbc.test_module_hygiene.failure_receipt_companion (same path as cli_run::failure_receipt_companion). Add HAND-RUST disposition on seed_runner_bool_false_failure_detail. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix plan modules missing md_helpers imports for compile-clean gate. branch_merge_admission_model and merge_admission_gate_shape_proposal use cell/row and other markdown helpers without importing gunbc.plans.md_helpers, which dag_compile_clean_gate now pulls into the affected closure. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com>
Summary
gunbc binds call arguments by name, but function-value types (
fn(A, B) -> Bool) carry no parameter labels. Higher-order calls likeagree(a: x, b: y)therefore passed typecheck and failed at runtime with call-contract mismatch.This PR enforces the operator-specified split:
CallNamedArgOnFunctionValue).Honest ceiling: checker refusal at the compile seam (structurally guaranteed for the function-value path via
body_localsdetection), not a carrier that makes the bad call unwritable.Test plan
cargo test -p v1-compiler --lib function_value_named_application_controls_witness— all five operator controls green by execution:CallNamedArgOnFunctionValue)CallPositionalSurplus)cargo test -p v1-compiler --lib call_shape_wall_witness— regression green