Skip to content

Refuse named arguments on function-value calls (compiler P0) - #7834

Merged
gunbai-bot[bot] merged 13 commits into
mainfrom
session/sharp-seal-527
Aug 5, 2026
Merged

gunbai-bot[bot] merged 13 commits into
mainfrom
session/sharp-seal-527

Conversation

@briansrls

@briansrls briansrls commented Aug 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

gunbc binds call arguments by name, but function-value types (fn(A, B) -> Bool) carry no parameter labels. Higher-order calls like agree(a: x, b: y) therefore passed typecheck and failed at runtime with call-contract mismatch.

This PR enforces the operator-specified split:

  • Direct declaration calls — named arguments allowed (including reordered).
  • Function-value applications — positional only; named invocation is a typed, blocking compile refusal (CallNamedArgOnFunctionValue).

Honest ceiling: checker refusal at the compile seam (structurally guaranteed for the function-value path via body_locals detection), not a carrier that makes the bad call unwritable.

Test plan

  • cargo test -p v1-compiler --lib function_value_named_application_controls_witness — all five operator controls green by execution:
    1. Direct declaration with reordered named args → ADMIT
    2. Higher-order callback applied positionally → ADMIT
    3. Named args on function-value call → REFUSE (CallNamedArgOnFunctionValue)
    4. Wrong higher-order arity → REFUSE (CallPositionalSurplus)
    5. Swapped positional callback args → semantic RED (compile admits; runtime proves bind order)
  • cargo test -p v1-compiler --lib call_shape_wall_witness — regression green

Brian Searls and others added 2 commits August 5, 2026 04:28
Direct declaration calls keep named-argument binding; higher-order
function-value applications require positional arguments only. Adds
CallNamedArgOnFunctionValue blocking diagnostic, arity surplus check
on the function-value path, and an executing witness covering all five
operator controls including semantic RED for swapped positional args.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 5, 2026 04:36
@gunbai-bot gunbai-bot Bot changed the title Higher-order named application: refuse named args on function-value calls (compiler P0) Refuse named arguments on function-value calls (compiler P0) Aug 5, 2026
Brian Searls and others added 2 commits August 5, 2026 04:43
Enumerates which ExprCall/ExprMethodCall routes hit body_locals wall,
#7519 sig wall, or remain uncovered (field-held fn via method syntax),
with honest class rung at mitigatable minimum.

Co-authored-by: Cursor <cursoragent@cursor.com>
… probe.

Registers ct_function_value_named_application_controls_witness_test and
ct_function_value_field_method_known_hole_probe_test in the authority
(compiler_tests_rust.dag, language_source_scaffold_index) and regen chain.
The hole probe executes path (5): field-held fn via ExprMethodCall with
named actuals compiles clean today (tripwire for method-call label wall).
Carrier note states mitigatable-minimum rung with path (5) as reason.
Relabels keyed_row/keyed_roster/tokenize HO call sites to positional args
so regen_stage0 self-compile stays green.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Addressed review 48513 (REQUEST_CHANGES on witness authority):

  • Added ct_function_value_named_application_controls_witness_test() and ct_function_value_field_method_known_hole_probe_test() to src/v1/compiler_tests_rust.dag and compiler_tests_source().
  • Registered both in dag/gunbc/language_source_scaffold_index.dag.
  • Ran cargo run -p v1-compiler --bin regen_stage0 (twice: rebuild then regen so compiler_tests.rs picks up the emitted compiler_tests_source() chain).

Addressed loyal-ram-550 merge gate on path (1):

  • function_value_field_method_known_hole_probe is a known-hole probe (not a desired-behavior control): compiles cfg.callback(a: 1, b: 2) and asserts zero diagnostics today, plus asserts CallNamedArgOnFunctionValue does not fire on the ExprMethodCall path.
  • function_value_named_application_wall_note now opens with RUNG (§4b): mitigatable minimum and names path (5) + the executing probe symbol.

Corpus fallout for regen self-compile: relabeled key_eq/pred HO invocations in dag/std/keyed_row.dag, dag/std/keyed_roster.dag, src/v1/01_tokenize.dag to positional (same class this PR walls).

Tests green locally:

  • cargo test -p v1-compiler --lib function_value_named_application_controls_witness
  • cargo test -p v1-compiler --lib function_value_field_method_known_hole_probe

— sent from sharp-seal-527

@gunbai-bot

gunbai-bot Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Verified review 48518 (claude-opus-4-7 APPROVE) against current HEAD 80649a520a — finding holds; no correction needed.

Spot-checks on the reviewed claims:

  • CallNamedArgOnFunctionValue is a blocking diagnostic (default is_error_diagnostic / is_interpreter_blocking_diagnostic arms in v1_std_core; witness asserts both on every refusal).
  • Wall fires on body_locals ExprCall path via function_value_call_named_arg_diags in 04_infer / v1_compiler_infer.rs.
  • Wall note documents §4b coverage honestly: paths (1)/(2)/(4) walled, path (5) cfg.callback(a:) uncovered ExprMethodCall hole with dissolve-on, path (6) unwritable-as-Accepted.
  • Controls witness covers ADMIT (direct reordered named + positional HO), REFUSE (named on function value + arity surplus), semantic RED (interpreter bind order).

Post-review timestamp (80649a520a, after 04:53Z) adds without contradicting this verdict:

  • Witness authority in compiler_tests_rust.dag + regen chain (review 48513).
  • Executing known-hole probe function_value_field_method_known_hole_probe for path (5) — asserts compile-clean today; tripwire for method-call label wall.

No additional code changes required for this APPROVE artifact.

— sent from sharp-seal-527

@gunbai-bot

gunbai-bot Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

review 48522 (REQUEST_CHANGES) — finding was correct at review time (04:56Z); already fixed on HEAD 80649a520a (04:58Z). No further code change needed for this item.

What the review asked for, verified on current tree:

  1. src/v1/compiler_tests_rust.dag — ct_function_value_named_application_controls_witness_test() added (~line 1778); enrolled in compiler_tests_source() after ct_call_shape_wall_witness_test() (~lines 2288–2289). Also ct_function_value_field_method_known_hole_probe_test() for the executing path-(5) tripwire.

  2. dag/gunbc/language_source_scaffold_index.dag — scaffold rows ct_row_ct_function_value_named_application_controls_witness_test and ct_row_ct_function_value_field_method_known_hole_probe_test enrolled in language_source_scaffold_roster.

  3. Emitted chain — cargo run -p v1-compiler --bin regen_stage0 regenerated v1_compiler_compiler_tests_rust.rs (compiler_tests_source() includes both new ct_* blobs) and compiler_tests.rs (witnesses at ~539 and ~652). compiler_tests.rs is not hand-authored; it matches the .dag authority.

  4. Corpus fallout — keyed_row/keyed_roster/01_tokenize HO sites relabeled positional so regen self-compile stays green.

Commit: 80649a520a — "Land function-value witnesses in compiler_tests_rust.dag and add hole probe."

The parallel-representation fork the review flagged existed on the pre-80649a520a snapshot; it is closed on HEAD.

— sent from sharp-seal-527

@gunbai-bot

gunbai-bot Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Verified review 48533 (claude-opus-4-7 APPROVE) against HEAD 80649a520a — finding is accurate; no code change required.

Spot-checks:

  • CallNamedArgOnFunctionValue + function_value_call_named_arg_diags in 04_infer.dag and emitted v1_compiler_infer.rs.
  • Corpus callsites relabeled positional: dag/std/keyed_row.dag, dag/std/keyed_roster.dag, src/v1/01_tokenize.dag (pred/key_eq HO invocations).
  • function_value_named_application_wall_note states mitigatable-minimum rung, enumerates coverage paths, names path (5) hole + dissolve-on; executing probe ct_function_value_field_method_known_hole_probe_test enrolled via compiler_tests_rust.dag, scaffold index, and compiler_tests_source().
  • Controls witness + hole probe in emitted compiler_tests.rs; semantic RED uses compile_to_resolved + run_in_context.
  • Witness asserts is_error_diagnostic and is_interpreter_blocking_diagnostic on CallNamedArgOnFunctionValue refusals.

This APPROVE matches the post-80649a520a tree (witness authority + hole probe landed after earlier REQUEST_CHANGES artifacts).

— sent from sharp-seal-527

@cursor

cursor Bot commented Aug 5, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@gunbai-bot

gunbai-bot Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

review 48537 (cursor/composer-2.5 REQUEST_CHANGES) — valid for change.dag; addressed in 3e3d361753.

The core finding is right: key_eq / value_eq / equal passed as function parameters and invoked with a: / b: labels inside nested closures are exactly what function_value_call_named_arg_diags refuses (CallNamedArgOnFunctionValue). dag/std/change.dag had 19 such sites; all are now positional (same relabel pattern as keyed_row / keyed_roster).

Census (HEAD): files that declare key_eq: fn / value_eq: fn / equal: fn parameters and still call those parameters with named actuals — only change.dag (before this fix). membership_reconcile.dag declares the params but already calls them positionally.

The cited workflow_reconcile.dag and src/v2/compiler/04_infer.dag examples are module-level function names (workflow_fact_key_equal, infer_branch_type_atoms_equal, …), not HOF parameters in body_locals. Those calls route through the #7519 direct-call label wall (sig-resolved ExprCall), not function_value_call_named_arg_diags. They are out of scope for this PR’s function-value wall and were not blocking compile-clean on the v1 path for this change class.

Witness function_value_named_application_controls_witness green by execution on HEAD.

— sent from sharp-seal-527

@gunbai-bot

gunbai-bot Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Verified review 48544 (cursor/composer-2.5 APPROVE) against HEAD 3e3d361753 — finding is accurate; no code change required.

Spot-checks match the review:

  • CallNamedArgOnFunctionValue wired through body_shadow_aware_func_sig / function_value_call_named_arg_diags on body_locals callees.
  • function_value_named_application_wall_note documents mitigatable-minimum rung, callee-path coverage, and the ExprMethodCall hole with dissolution trigger.
  • Witness suite: admit (direct-decl named args, positional HO), refuse (named HO + surplus arity), semantic RED, hole probe enrolled via compiler_tests_rust.dag + scaffold index.
  • Corpus fallout positional in change.dag, keyed_roster.dag, keyed_row.dag for fn-typed parameters.

build CI SUCCESS on this commit; regen / heal_generated_artifacts still queued.

— sent from sharp-seal-527

Brian Searls and others added 2 commits August 5, 2026 05:55
apply_emit_spelling_transform passes its transform parameter positionally;
named actual on the body-local callee blocked heal_generated_artifacts
during main_wet artifact generation.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Verified review 48554 (cursor/composer-2.5 APPROVE) against HEAD c730a462ef — finding is accurate; no code change required.

Wall substrate (CallNamedArgOnFunctionValue, function_value_call_named_arg_diags on body_locals), blocking classification, histogram key, witnesses, scaffold rows, and honest §4b hole documentation all match the review. Corpus fallout includes the full one-pass census relabels (change.dag, keyed_row/keyed_roster, 01_tokenize, target_model, fn_as_value_test, v2_effect_io_pure).

— sent from sharp-seal-527

@gunbai-bot

gunbai-bot Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Verified review 48560 (claude-opus-4-7 APPROVE) against HEAD c730a462ef — finding is accurate; no code change required.

Spot-checks: body-local named-actual wall (CallNamedArgOnFunctionValue / function_value_call_named_arg_diags), honest §4b note with path (5) hole + ct_function_value_field_method_known_hole_probe_test, scaffold rows, executing controls (admit/refuse/semantic RED), and corpus positional migration (change.dag, keyed_roster/keyed_row, 01_tokenize, target_model, fn_as_value_test, v2_effect_io_pure). build CI SUCCESS on this commit.

— sent from sharp-seal-527

Brian Searls and others added 4 commits August 5, 2026 06:29
Aligns ct_function_value_field_method_known_hole_probe comment with
function_value_named_application_wall_note path enumeration (review 48563).

Co-authored-by: Cursor <cursoragent@cursor.com>
Completes emitted chain for review 48563; merge main + main_wet verified
falsifier workflow drift already resolved on merged main.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Verified review 48584 and review 48589 (both APPROVE) against HEAD after merge — findings accurate; no further code change beyond what is pushing now.

Sweep (loyal-ram): whole-tree compile_clean_diagnostic_histogram with COMPILE_CLEAN_HISTOGRAM_DUMP_SITES=1 reports 0 CallNamedArgOnFunctionValue sites after the full roster relabel (7 files, 27 named-to-positional call sites on function-value parameters; each checked for declaration-order before dropping labels).

Merge + heal prep: merged origin/main (falsifier/ci workflow regen from #7812/#7813), ran main_wet (ExitSuccess; no workflow drift beyond main), regen synced compiler_tests.rs hole-probe comment to path (5).

— sent from sharp-seal-527

@gunbai-bot

gunbai-bot Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Verified review 48600 (cursor/composer-2.5 APPROVE) against HEAD 2dfc777409 — finding is accurate; no code change required.

Wall (CallNamedArgOnFunctionValue / function_value_call_named_arg_diags on body_locals ExprCall), full corpus positional migration (27 sites / 7 files), discriminating controls + path-(5) hole probe, scaffold registration, and §4b rung honesty all match the review. CI on this commit: build and heal_generated_artifacts PASS; regen pending.

— sent from sharp-seal-527

@gunbai-bot

gunbai-bot Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Verified review 48648 (claude-opus-4-7 APPROVE) against HEAD bdf7b82e9f — finding is accurate; no code change required.

Spot-checks:

  • CallNamedArgOnFunctionValue + function_value_call_named_arg_diags on body_locals ExprCall; pairs with body_shadow_aware_func_sig so this wall and Call-shape wall: refuse unknown argument labels and surplus positionals at the direct-call seam #7519 do not overlap.
  • function_value_named_application_wall_note documents mitigatable-minimum rung, six callee paths, path-(5) ExprMethodCall hole + dissolve-on; executing probe ct_function_value_field_method_known_hole_probe_test enrolled via compiler_tests_rust.dag, scaffold index, and compiler_tests_source().
  • Corpus fallout positional in change.dag, keyed_roster.dag, keyed_row.dag (and the rest of the one-pass census).
  • falsifier_lane ModeUnrecorded on falsifier_witness_row is F1-transport: row-grain failure_mode edge beside ObservationOutcome #7827 merge fallout (required failure_mode on floor_component_row_of), not named-arg relabeling.

CI on this push: build and heal_generated_artifacts PASS; regen in progress.

— sent from sharp-seal-527

@gunbai-bot

gunbai-bot Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Verified review 48650 (cursor/composer-2.5 APPROVE) against HEAD bdf7b82e9f — finding is accurate; no code change required.

Spot-checks match the review:

  • Core mechanism: function_value_call_named_arg_diags gates on map_get(body_locals, func_name); body_shadow_aware_func_sig keeps sig lookup off body-local callees.
  • Blocking: CallNamedArgOnFunctionValue uses default _ => true arms in is_error_diagnostic / is_interpreter_blocking_diagnostic (00_core.dag).
  • Witnesses: controls witness (admit/refuse/semantic RED) + path-(5) hole probe in compiler_tests_rust.dag; scaffold rows ct_row_ct_function_value_named_application_controls_witness_test and ct_row_ct_function_value_field_method_known_hole_probe_test under compiler_tests_rust_hand_assertion_scaffold_trigger.
  • Local: cargo test -p v1-compiler --lib function_value_named_application_controls_witness green.

— sent from sharp-seal-527

@gunbai-bot
gunbai-bot Bot merged commit 9ce6526 into main Aug 5, 2026
5 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/sharp-seal-527 branch August 5, 2026 09:50
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
lists_agree_at passes agree as fn(A, B) -> Bool; named labels at the
call site are refused after #7834. left_head/right_head are already in
declaration order for both callees (direct_file_dependency_eq,
cross_file_binding_provenance_matches_provider).

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
Resolves conflicts between this PR's duplicate-label wall
(CallArgumentDuplicate, direct-call seam) and #7834's function-value
named-argument wall (CallNamedArgOnFunctionValue), which landed on main
concurrently and touched overlapping files (00_core.dag, 04_infer.dag,
compiler_tests_rust.dag/.rs, cli_run.rs, v1_std_core.rs,
v1_compiler_infer.rs, compiler_tests.rs).

Two files were auto-merged by git WITHOUT conflict markers but silently
dropped one side's additive content at an adjacent-insertion point:
compiler_tests.rs lost #7834's two new test functions, and
v1_std_core.rs lost #7834's entire CallNamedArgOnFunctionValue variant
(enum declaration + 2 match arms). Both were manually restored from
origin/main and verified by grep/build. v1_compiler_compiler_tests_rust.rs
(a self-emitted artifact) was regenerated via regen_stage0 rather than
trusting its auto-merge.

Per parent instruction: merge commit, not rebase.
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
.gitattributes marks the generated stage0 sources merge=generated-artifact.
Merging #7834 (named-argument refusal on function values) resolved
v1_compiler_infer.rs to this branch's side and dropped main's 103-line
addition, while 04_infer.dag -- the authority -- merged correctly and carried
it. Git reported no conflict; the tree was left authority-ahead-of-seed, which
is exactly the state the self-host gate exists to catch, and regen --verify
reported the divergence.

Regenerated from the merged .dag, then bootstrapped properly: rebuild from the
regenerated seed and verify again, because the binary that emitted it predates
the change it was emitting. Second pass reports regen_divergence_count=0.

The two falsifier witnesses that redded main (falsifier_job_steps() arity,
repaired upstream by #7843) now pass here by execution.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
#7834 refuses named arguments on function-value applications; the omit
helper still called total_consumer_handles(case: case) and red the
discovery corpus whenever lens_mock_totality entered the affected set.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
The merge resolved this GENERATED file by taking this branch's copy, which
carries SourceAnnotationRefused but not main's CallNamedArgOnFunctionValue
(#7834) — so the enum lost a variant that main's hand-maintained cli_run.rs
and the generated infer projection both construct, and the workspace stopped
compiling. Regenerated rather than hand-merged: a generated file's authority
is its .dag source, and hand-picking hunks across a merge is how rows go
missing silently.

Both variants are present and the emission is stable across generations.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
#7834 refuses named arguments on function-value calls; use positional
total_consumer_handles(case) instead of total_consumer_handles(case: case).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot
gunbai-bot Bot restored the session/sharp-seal-527 branch August 5, 2026 14:07
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
Lands .dag semantic authority, floor-entry companions, the
seed_runner_bool_false_failure_detail bridge, loudness witnesses with
mutation control, and witness_template #7834 positional fix. Integrates
with main's append_failure_receipt_companion_loudness /
test_module_hygiene authority (#7791) rather than duplicating Rust
companion derivation.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
#7834 refuses named arguments on function-value applications; the omit
helper still called total_consumer_handles(case: case) and red the
discovery corpus whenever lens_mock_totality entered the affected set.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
…rasure (#7807)

* WIP: prose cleanup

* Add the reconciliation worklist section to the prose policy audit

Where a split pass would start: 50% of the time-bound marker mass sits
in 63 of 617 files, and 124 mega-notes carry a marker between them.
Names the two head files that are load-bearing per DESIGN so they do
not lead the pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Recut the prose audit: the defect is lost source-level intent, not low-value prose

Banning // made comment syntax unwritable but not commentary unwritable.
It removed the only structural signal separating commentary from program
data, so the corpus smuggled prose into data String rows where intent is
mechanically undecidable. Verified as three merged PRs:

  #5579 f9cc238  remove DAG comment trivia rules
  #6262 9e7c3c1  hoist .dag // comments to typed data rows
  #6424 c14e001  sweep 215 dead prose data-String rows

Reframes the destination as a modeled source annotation -- a sidecar on
ParseArtifact, never restored trivia, never a namespace binding -- with
the semantic/authored-source projection pair as the load-bearing law.

Corrects the sample's standing: #6424 swept 215 dead rows before it was
drawn, so it measures survivors and cannot refute the dead population or
settle representation. Value and representation are independent axes: a
note can be irreducible and still wrong as data Foo: String.

Replaces D1-D4 (delete rate, ceilings) with D-A..D-D (carrier,
attachment, erasure, migration). Carries the proposed DESIGN paragraph
for review without landing it. Nothing deleted, migrated, or reconciled.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Land the source-annotation policy in DESIGN.md 4c; rule D-A..D-D

Canonical guidance lands through gunbc.design_document section_4c_blocks
with DESIGN.md regenerated, never hand-edited. The rule: prose is not
forbidden; unclassified prose is. // becomes the explicit quarantine
boundary.

Four structural corrections to the destination:

  2a  a THIRD lexical channel (AnnotationRule), not an ordinary
      TokenRule -- a token still joins the semantic stream and buys
      parser filtering, token-order effects, allocator risk
  2b  AuthoredParseArtifact WRAPS the semantic artifact rather than
      widening it, so ordinary compilation receives a type that cannot
      hold annotations; erasure becomes structural. The equality law is
      over the semantic graph projection, excluding textual provenance,
      because inserting a comment necessarily moves byte ranges
  2c  an annotation must NOT consume a semantic OccurrenceId -- the
      allocator is graph-scoped, so a comment could shift declaration
      identities in the same source and in later modules. First carrier
      has no annotation identity; ordered graph carries multiplicity
  2e  attachment narrows to module-item grain only, with an explicit
      AnnotationPlacement observation so trailing stays distinguishable
      after whitespace removal

D-D approved debt-only: SourceAnnotationRationale is not declared in
Slice 1, since a variant with no authoring path or consumer is
speculative vocabulary.

Doc-graph row rebinds from the generic StandingIntent to the seams this
work actually changes: LexRule, ParseArtifact, dag_line_comment_fidelity,
dag_comment_wall_line_comment_refused.

Nothing deleted, migrated, or reconciled; no slice started.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Align the doc-graph dissolution trigger with the ruled D-A/D-C design

review 48112 (cursor/composer-2.5) caught the trigger naming TokenRule
as the target carrier -- the design D-A explicitly rejects. The trigger
was authored before the operator's correction and not updated with the
audit doc and DESIGN 4c, so a typed scaffold marker was steering Slice 2
at the wrong carrier.

Fixes a second stale claim in the same string the review did not reach:
"semantic-erasure proven by identical emitted bytes". Byte equality is
exactly what D-C says is insufficient -- the emitter may ignore
occurrence ids and stay byte-identical while the identity graph moves.
The trigger now names the seven D-C proofs instead.

Trigger now states: AnnotationRule on a third lexical channel (never
TriviaRule, never TokenRule), authored wrapper over an unchanged
semantic artifact, no semantic occurrence identity consumed, module-item
attachment with trailing/body/unattached/block refusing, erasure by the
seven D-C proofs, and the representation partition complete.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* M1 slice 1: AnnotationRule third lexical channel, captured with placement

DESIGN 4c requires a comment to reach neither destination the lexer
already has. TriviaRule consumes and emits nothing, so a comment routed
there is invisible to every parser, lens, census and SCM operation.
TokenRule emits into the semantic stream, so a comment routed there
becomes something every parser must filter and sits in the path of
occurrence allocation. This adds the third:

  LexRule = TokenRule | TriviaRule | AnnotationRule

plus UnboundSourceAnnotation (no identity of its own -- binding is the
parser's job, and minting one here would draw from the semantic
occurrence allocator, which 4c forbids), AnnotationPlacement, and
LexArtifact { tokens, annotations }.

lex_walk_artifact is the authored result; lex_walk is its semantic
projection and is what every existing caller keeps using. One traversal
read two ways, derived in that direction only, so a semantic consumer
cannot reach annotation text.

Placement is observed at capture because it cannot be reconstructed:
whitespace is trivia, so once it is gone a trailing comment and a
leading comment on the next declaration are indistinguishable. The walk
tracks line_has_semantic_token -- set by a token, reset by trivia
carrying a line feed.

Adding the variant redded six matches across three files; each got a
real arm rather than a wildcard, which is the closed-coproduct
discipline working as intended.

Green by execution: lex_match_thunk_claims_holds, and all seven
dag_comment_wall_test probes still pass -- line comments in real .dag
source still REFUSE, because the v1 production tokenizer is untouched
until the realization slice.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* M1 slice 2: one std authority for source annotations, not a v1/v2 fork

Correcting slice 1: AnnotationPlacement was declared inside
v2.std.compilers.lexing, and the v1 seed tokenizer cannot import v2
modules -- so realizing the v1 half would have forced a second spelling
of one concept. That is precisely the nicknaming defect this lane
exists to remove, and it would have been minted BY the lane removing it.

dag/std/source_annotation.dag is now the language-agnostic authority.
It names no .dag syntax and no lexical rule; both seeds import it. v1
files already import std.* (std.types, std.occurrence_identity), so the
seam exists.

Carries AnnotationPlacement, SourceAnnotationDebt, SourceAnnotationGraph
(ordered -- order and multiplicity are the whole of an annotation's
identity when rows carry no key), the typed attachment refusals, and
annotation_placement_is_attachable as the single predicate saying the
first cut admits leading only.

SourceAnnotationDebt deliberately has NO identity field. An OccurrenceId
would draw from the graph-scoped semantic allocator, so inserting a
comment could shift declaration identities later in the same source and
in later-parsed modules. `subject` refers; it never mints. Debt is the
type's standing law rather than a variant, so no rationale category
ships without an authoring path or consumer.

v2.std.compilers.lexing keeps only what is lexical and imports the rest.

Green: lex_match_thunk_claims_holds and the comment wall probes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* chore: regenerate drifted generated artifacts (ci auto-heal)

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* chore: regenerate drifted generated artifacts (ci auto-heal)

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* Thread authored artifact through both v1 frontend paths; five D-C erasure controls

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Physical-line placement, admission wall, single frontend seam

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* Regen stage0: emit annotation channel into the seed; fix import + portability defects regen exposed

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* Restore roster rows dropped by generated-file merge; place std.source_annotation in the stage0 crate partition

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* Rename LATER-cased witness: emitted Rust must be snake_case under -D warnings

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)

* WIP: prose cleanup

* WIP: prose cleanup

* P0-1 blank lines split authored blocks; P0-2 lower the claim to its honest rung

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* chore: regenerate drifted generated artifacts (ci auto-heal)

* D-C property 4: establish semantic erasure at the emitted-bytes boundary

The two byte-equality arms could not be enrolled as .dag witnesses, so they
were established by host execution and the measurement recorded in-carrier
rather than dropped.

Measured: annotated and bare twins emit byte-identical Rust across all six
emitted files (exit 0, zero diagnostics), while a real semantic change to the
same bare twin emits different bytes -- so the equality is not a statement
about an emitter that ignores its input. The enrolled arm proves the annotated
fixture really carried prose (2 rows) where its twin carried none.

Why not enrolled: no .dag-reachable surface returns emitted bytes.
compile_to_resolved from interpreted .dag raises `map_keys expects a map, got
Record` in the RESOLVE half -- reproduced on the smallest possible input, so it
is a pre-existing model-versus-realization fork outside this lane, not a
property of the fixture. The working host arms return a Bool and a diagnostic
census; asserting "both twins compile" through the Bool would wear this
property's name while passing for any pair of compiling programs, and adding a
bytes-returning arm would grow hand-maintained cli_run.rs against its hollowing
plan to satisfy a witness. Next trigger named in the carrier.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WIP: prose cleanup

* WIP: prose cleanup

* WIP: prose cleanup

* Regenerate ci.yml for the new stage0 witness module

Derived-only: the heal exclude list gains
v1_tests_claim_v1_annotation_target_emission_test.rs, projected from the
same stage0 emit roster that regen writes. Committed as author because
workflow paths cannot auto-heal (the App lacks workflows:write).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Regenerate v1_std_core.rs after merging main's function-value call wall

The merge resolved this GENERATED file by taking this branch's copy, which
carries SourceAnnotationRefused but not main's CallNamedArgOnFunctionValue
(#7834) — so the enum lost a variant that main's hand-maintained cli_run.rs
and the generated infer projection both construct, and the workspace stopped
compiling. Regenerated rather than hand-merged: a generated file's authority
is its .dag source, and hand-picking hunks across a merge is how rows go
missing silently.

Both variants are present and the emission is stable across generations.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
Lands .dag semantic authority, floor-entry companions, the
seed_runner_bool_false_failure_detail bridge, loudness witnesses with
mutation control, and witness_template #7834 positional fix. Integrates
with main's append_failure_receipt_companion_loudness /
test_module_hygiene authority (#7791) rather than duplicating Rust
companion derivation.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
Lands .dag semantic authority, floor-entry companions, the
seed_runner_bool_false_failure_detail bridge, loudness witnesses with
mutation control, and witness_template #7834 positional fix. Integrates
with main's append_failure_receipt_companion_loudness /
test_module_hygiene authority (#7791) rather than duplicating Rust
companion derivation.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls pushed a commit that referenced this pull request Aug 5, 2026
…ntry assembly) (#7836)

* WIP: CI Perf (actual benefits)

* Fill composition overlays the closure onto the shared underlay

symbol_index_with_qualified_fill and symbol_index_with_bare_fill composed an
entry's closure census with a per-index underlay memo (whole-pool qualified
fill; whole-tree bare census per source root) by walking the UNDERLAY's key
list, probing the accumulator per key, and path-copying an insert per miss.
The underlay is constant across entries while the closure varies, so every
entry paid O(|whole pool|) work and retained O(|whole pool|) fresh HAMT nodes
to build an index that differs only by its own closure.

Both directions denote the same map -- union of the key sets, closure wins the
intersection -- so overlaying the closure onto the shared memo is identical at
O(|closure|), from an O(1) persistent clone. DESIGN 6 bare-minimum-cost.

Measured, fixed 50-entry cohort, two reproductions per arm:
  symbol-index merge          25,517.7 / 26,279.1 -> 530.6 / 538.8 ms  (-97.9%)
  per-root symbol-index comp  16,734.2 / 17,063.9 -> 531.7 / 491.4 ms  (-97.0%)
  sum exclusive assembly      74,876.0 / 76,535.5 -> 34,856.8 / 33,671.5 (-54.7%)
  additive resolve               129,779 / 132,623 -> 92,332 / 90,940  (-30.2%)
Outcomes byte-identical in both arms (48 PASS / 2 FAIL, same two pre-existing
hermetic-mode refusals); regen_divergence_count=0 with the seed rebuilt from
the changed sources.

symbol_index_fill_overlay_direction_test is the discriminating control on the
direction clause, executed both ways: green as landed, and both arms red on
the winner assertion when the merge direction is flipped in the seed.

This is one slice of the shared-entry-view hypothesis, not the whole of it:
import-string rewiring, the per-entry closure census, and the per-root variant
base are untouched and are different defects. No fleet wall is claimed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Regenerate falsifier.yml (inherited generated-artifact drift)

The heal job reds with HealAuthorCommitRequired: the CI app lacks
workflows:write, so a drifted .github/workflows/** generated artifact can only
be repaired by an author commit. The drift is NOT from this branch --
main's committed falsifier.yml carries no `id: release_bins` while
generated_artifact_gate main_wet emits it, so main has been carrying the drift
since the step id landed in its spec, with every heal attempt unable to push it.

Regenerated with:
  gunbc run --source-root dag --source-root src/v2 \
    --entry dag/tools/generated_artifact_gate.dag --function main_wet

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Commit A: trim the in-code direction note to a statement plus its receipt

The note emitted its whole narrative into the seed -- compile and binary
material inside the PR whose subject is unnecessary work. The mechanism's
detail already has a document authority; the row keeps only the law (closure
overlays the underlay, same denotation, different cost grain) and names the
receipt and the witness.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Commit B: retain the resolver evidence and re-measure on same-tree arms

The first receipt carried conclusions, not the evidence they derive from, and
its base binary predated the main merge -- two variables, not one.

Both arms are now built from ONE tree with ONE variable: the after arm is this
commit, the base arm is this commit with base-arm-revert.patch applied (the two
fill functions and nothing else). Binary digests for both are retained, so a
reader rebuilds an arm and checks a hash instead of trusting a table cell.

Retained under docs/plans/receipts/fill-composition-overlay-direction/:
  subject.tsv            commits, binary digests, host envelope, run order,
                         memory instrument, invocation, selection
  cohort.tsv             50 rows: ordinal, entry, function
  base-r{1,2}.tsv        per-arm scalars + the three receipt lines
  after-r{1,2}.tsv
  *.stderr.txt           full run stderr, as the predecessor receipt retains
  base-arm-revert.patch  the exact one-variable revert
  derive_summary.py      summary.json is computed from the four arm files ONLY;
                         refuses on a missing arm; keeps the inclusive
                         rewire_total_observation row out of the exclusive sum
  summary.json           derived, not transcribed

Corrected figures on the same-tree arms (two reproductions each):
  symbol-index merge          34,654.4 / 28,420.1 -> 624.6 / 585.4    (-98.1%)
  per-root symbol-index comp  27,095.2 / 18,642.2 -> 719.4 / 618.5    (-97.1%)
  sum exclusive assembly     100,773.3 / 83,980.4 -> 41,011.9 / 36,017.0 (-58.3%)
  additive resolve            155,680 / 146,484 -> 105,012 / 94,624   (-33.9%)
  elapsed wall                268,369 / 247,963 -> 200,932 / 183,286  (-25.6%)
  peak RSS (VmHWM)          8,160,560 / 8,108,424 -> 5,804,768 / 5,803,012 (-28.7%)
Outcomes identical in all four arms.

Two honesty notes are recorded in the receipt rather than smoothed: the
import-string rewiring row's +12% mean is one outlier inside a 35% within-arm
spread (its other after run sits inside the base range), and the discovery-path
pair is reported as an UNPAIRED observation because both arms were OOM-killed --
--roster-from-discovery does not restrict discovery to the supplied --entry rows.

The execution grain is also corrected: the cohort is ONE process holding ONE
MultiEntryIndex with 50 entry groups, not 50 invocations.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Regenerate the seed after the merge driver dropped main's emit change

.gitattributes marks the generated stage0 sources merge=generated-artifact.
Merging #7834 (named-argument refusal on function values) resolved
v1_compiler_infer.rs to this branch's side and dropped main's 103-line
addition, while 04_infer.dag -- the authority -- merged correctly and carried
it. Git reported no conflict; the tree was left authority-ahead-of-seed, which
is exactly the state the self-host gate exists to catch, and regen --verify
reported the divergence.

Regenerated from the merged .dag, then bootstrapped properly: rebuild from the
regenerated seed and verify again, because the binary that emitted it predates
the change it was emitting. Second pass reports regen_divergence_count=0.

The two falsifier witnesses that redded main (falsifier_job_steps() arity,
repaired upstream by #7843) now pass here by execution.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Integrate current main; regenerate the seed the merge driver left behind

Second occurrence of the same class: .gitattributes marks generated stage0
sources merge=generated-artifact, so merging main resolved
v1_compiler_infer.rs to this branch's side and dropped main's newer emit
(CallPositionalDeficit, param_node_default_value) while 04_infer.dag -- the
authority -- merged correctly and carried it. Git reported no conflict.

Regenerated from the merged authority, then bootstrapped: rebuild from the
regenerated seed and verify again, because the binary that emitted it predates
the change it was emitting. Second pass reports regen_divergence_count=0.

This branch's own mechanism was verified present in BOTH the authority
(04_infer.dag symbol_index_with_qualified_fill / symbol_index_with_bare_fill)
and the regenerated seed, rather than assumed to have survived the merge.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Mark the fill-composition slice Delivered on the program note

Operator ruling 2026-08-05: the slice's disposition is Delivered and the
broader shared-entry-view program stays Open. The note carried the numbers but
not the ruled status, so the repo's own authority did not say which of the two
it was.

Also records the selection rule for the next slice: identify the duplicated
construction first, never target the largest surviving row on size -- this
receipt's rewiring figure carries a 35% within-arm spread, so size alone
selects nothing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
Lands .dag semantic authority, floor-entry companions, the
seed_runner_bool_false_failure_detail bridge, loudness witnesses with
mutation control, and witness_template #7834 positional fix. Integrates
with main's append_failure_receipt_companion_loudness /
test_module_hygiene authority (#7791) rather than duplicating Rust
companion derivation.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
Lands .dag semantic authority, floor-entry companions, the
seed_runner_bool_false_failure_detail bridge, loudness witnesses with
mutation control, and witness_template #7834 positional fix. Integrates
with main's append_failure_receipt_companion_loudness /
test_module_hygiene authority (#7791) rather than duplicating Rust
companion derivation.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Aug 5, 2026
* Make scope placement gate refusals loud in CI floor receipts.

Lands .dag semantic authority, floor-entry companions, the
seed_runner_bool_false_failure_detail bridge, loudness witnesses with
mutation control, and witness_template #7834 positional fix. Integrates
with main's append_failure_receipt_companion_loudness /
test_module_hygiene authority (#7791) rather than duplicating Rust
companion derivation.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Consolidate failure-receipt naming onto test_module_hygiene.

Address review 48788: delete parallel gunbc.floor_witness_failure_receipt
authority; floor_effect_gate_witness now consumes
gunbc.test_module_hygiene.failure_receipt_companion (same path as
cli_run::failure_receipt_companion). Add HAND-RUST disposition on
seed_runner_bool_false_failure_detail.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix plan modules missing md_helpers imports for compile-clean gate.

branch_merge_admission_model and merge_admission_gate_shape_proposal use
cell/row and other markdown helpers without importing gunbc.plans.md_helpers,
which dag_compile_clean_gate now pulls into the affected closure.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant