Skip to content

docs(briefs): rollback PB-1-b (premise invalid) + amend PB-1 working state + author PB-1-e replacement - #786

Merged
briansrls merged 2 commits into
mainfrom
rollback/pb-1-b-rebase-onto-pb-1-e
Apr 25, 2026
Merged

briansrls merged 2 commits into
mainfrom
rollback/pb-1-b-rebase-onto-pb-1-e

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Summary

Three coupled doc changes per `warm-raven-373` worker STOP-AND-ESCALATE on the PB-1-b dispatch.

Finding (verified directly at HEAD): PB-1-a as shipped already covered all four authorities — `bootstrap_generated.rs` (1.0M, full snapshot) includes std + STAGED + V3_SPECS + COMPILER_FILES; `Dag::new()` at `dag.rs:2215` loads it directly; `load_runtime_bootstrap_authorities` at `bootstrap.rs:131` is reached only from regen-scaffold + drift-harness paths, not production. The PB-1-b brief I authored had the same class of failure as the withdrawn v1 PB-Substrate pilot brief #772 — premise didn't match shipped state.

Changes

1. Delete `docs/briefs/pb-1-b-staged-files-worker.md`

Brief premise invalid; brief retired in place rather than amended (matches #774 rollback pattern for #772).

2. Amend `docs/briefs/pb-1-data-driven-bootstrap.md` — new "Working state (verified 2026-04-25)" section

Records PB-1-a-actual-coverage with concrete file/line citations. Re-baselines the sub-lanes:

  • PB-1-a — landed (broader than originally scoped).
  • PB-1-b/c/d — folded into PB-1-a as shipped; not separable dispatch units.
  • PB-1-e — retains residual scope, reframed to retire the regen-scaffold runtime-parse path + re-ground DB-8 cross-check.

Original sub-lane structure retained below the working-state section as historical context.

3. Author `docs/briefs/pb-1-e-residual-scaffold-retirement-worker.md`

PB-1-e replacement worker brief. Two coupled deliverables:

  • Deliverable A — retire `load_runtime_bootstrap_authorities`, `compile_full_bootstrap_dag_from_std_seed`, `bootstrap_std_fixtures_only` (named dissolution trigger comment at `bootstrap.rs:91-99` already names the closure condition).
  • Deliverable B — re-ground DB-8's "fresh parse vs snapshot" cross-check. Three candidate mechanisms (per-authority composition / regen-time fresh-compile gate / hybrid); manager lean (ii); STOP-AND-ESCALATE if none preserves DB-8's no-compromise property.

Companion / no-conflict

Test plan

  • Doc-only diff. No code surface.

🤖 Generated with Claude Code

…rking state + author PB-1-e replacement

Three coupled doc changes per warm-raven-373 worker STOP-AND-ESCALATE
finding that PB-1-a as shipped already covered all four authorities
(std + STAGED + V3_SPECS + COMPILER_FILES via bootstrap_generated.rs
1.0M full snapshot loaded directly from Dag::new()). Verified at HEAD.

1. Delete docs/briefs/pb-1-b-staged-files-worker.md — premise didn't
   match shipped state; same class of failure as withdrawn v1
   PB-Substrate pilot brief #772.

2. Amend docs/briefs/pb-1-data-driven-bootstrap.md with new "Working
   state (verified 2026-04-25)" section recording PB-1-a-actual-
   coverage and re-baselining the sub-lanes:
     - PB-1-a: landed, broader than originally scoped
     - PB-1-b/c/d: folded into PB-1-a-as-shipped
     - PB-1-e: retains residual scope, reframed
   Original sub-lane structure retained as historical context.

3. Author docs/briefs/pb-1-e-residual-scaffold-retirement-worker.md
   targeting load_runtime_bootstrap_authorities retirement +
   bootstrap.rs:91-99's named dissolution trigger + DB-8 cross-check
   re-grounding. Two coupled deliverables (retire + re-ground); three
   candidate mechanisms scoped (per-authority composition / regen-
   time fresh-compile gate / hybrid); manager lean (ii); STOP if
   none preserves DB-8's no-compromise property.

Process lesson noted in director escalation thread: substrate-
evaluability verification miss for second time; manager retrospective
to fold the verification step into brief authoring discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Director review — APPROVE.

Clean rollback executed exactly the way it should be. Worker warm-raven-373 STOP-AND-ESCALATE'd the premise correctly; manager verified at HEAD with concrete file:line citations (bootstrap_generated.rs 1.0M full snapshot covers all four authorities; Dag::new() at dag.rs:2215 calls bootstrapped_fixture_dag() directly; load_runtime_bootstrap_authorities only reachable from regen-scaffold + drift-harness paths — verified as-claimed). Pivoted with the three coupled doc changes that match the #774 rollback pattern.

Approved as-is

  • PB-1 working-state amendment — concrete evidence inline with file:line citations. The "PB-1-b/c/d folded into PB-1-a as shipped; not separable dispatch units" framing is honest about what landed vs what was originally scoped, and the historical-context retention below the working-state section preserves the audit trail without creating two-source contradictions.
  • PB-1-e replacement brief — well-scoped two coupled deliverables (retire scaffold + re-ground DB-8 cross-check). Three-mechanism enumeration with manager lean (ii) + worker discretion + STOP-AND-ESCALATE if none preserves DB-8's no-compromise property is exactly the right pattern. The dissolution-trigger comment at bootstrap.rs:91-99 is correctly identified as the closure condition.
  • Coupling discipline — "retiring the helper without replacing the cross-check is unsafe; replacing the cross-check without retiring the helper is incomplete. Land both in the same PR" is the right call. DB-8 stays no-compromise.
  • PB-1-b brief deleted in place rather than amended (matches docs(briefs): rollback PB-Substrate pilot worker brief from #772 (premise invalidated) #774 rollback pattern). Right discipline — premise-invalid briefs are noise.

Cross-program signal acknowledged

No concerns

  • Doc-only diff; no code surface; no CI risk.
  • DB-8 no-compromise property is explicit STOP gate — Deliverable B can't compromise it without escalation.
  • Manager lean (ii) is well-justified ("cleanest scoping, doesn't require per-authority snapshot split, cheapest in-tree test cost") and worker is welcome to deviate with reasoning.
  • Cross-manager note correctly identifies that no signal is needed at brief-authoring time, with a hook for surfacing substrate-shape implications if Deliverable B's mechanism (i) is picked.

Ship it. Zero-Floor program continues against the verified-shipped state.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: e4f6987a · Trigger: schedule
  • Thinking: 11s wall

Docs-only PR. Reframing of brief structure based on verified working state, with replacement worker brief authored.

Verdict: APPROVE — Pure brief/docs change. Diff is well-grounded: the working-state amendment cites concrete file:line evidence (bootstrap_generated.rs, dag.rs:2215, bootstrap.rs:131) for the rebaseline, and the new PB-1-e brief carries the three properties expected of a tracked bridge — documented dissolution trigger (bootstrap.rs:91-99), bounded scope (Deliverables A+B), and named retirement target. No code under review; no INVARIANTS/CODING/TESTING surface touched.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bf67b5225b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

- `src/v3/compiler/src/bootstrap_generated.rs` (1.0M LOC, full snapshot) covers `std_fixtures` + `STAGED_FILES` + `V3_SPECS` + `COMPILER_FILES`.
- `src/v3/compiler/src/bootstrap_std_generated.rs` (340K LOC, std-only snapshot) is retained for the regen seed path, not as the production runtime authority.
- `Dag::new()` at `dag.rs:2215` calls `bootstrap_generated::bootstrapped_fixture_dag()` directly — the full snapshot, no runtime tokenize/parse/lower of the four authorities.
- `load_runtime_bootstrap_authorities` at `bootstrap.rs:131` is reached only via `compile_full_bootstrap_dag_from_std_seed` (and the `_without_parse_surface` sibling) — both are regen-scaffold + drift-harness paths, not production `Dag::new()` consumers.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Fix incorrect callers listed for load_runtime_bootstrap_authorities

This new working-state evidence says load_runtime_bootstrap_authorities is reachable only from compile_full_bootstrap_dag_from_std_seed (and its _without_parse_surface sibling), but the code path also goes through bootstrap_all_runtime (src/v3/compiler/src/bootstrap.rs:106-121), which is used by compile_full_bootstrap_dag and compile_full_bootstrap_without_parse_surface_dag (src/v3/compiler/src/lib.rs:1201-1210) and exercised in pb1_bootstrap_full_snapshot_test.rs:19-27. The incorrect call graph can mis-scope PB-1-e retirement work and leave runtime-parse bootstrap paths/tests only partially updated.

Useful? React with 👍 / 👎.

@briansrls
briansrls merged commit 39860c8 into main Apr 25, 2026
3 checks passed
@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: codex / codex-default
  • Commit: e4f6987a · Trigger: schedule
  • Thinking: 98s wall

Findings:

  • NON-BLOCKING: docs/briefs/pb-1-data-driven-bootstrap.md:50 and :51 label the generated files as “1.0M LOC” / “340K LOC”, but those are byte sizes; actual line counts are 2,203 and 8,726. This is a small P1 “Documentation Describes Live State” mismatch.

Verdict: APPROVE_WITH_COMMENTS. The substantive re-baseline looks coherent: PB-1-b is correctly withdrawn, PB-1-e is bounded, and the scaffold has documented scope plus a dissolution trigger. No substrate, fail-closed, single-authority, or testing-discipline violation observed in the diff.

briansrls added a commit that referenced this pull request Apr 25, 2026
…ties (codex P2 finding on #786)

Codex P2 inline review caught: my working-state amendment listed
load_runtime_bootstrap_authorities as reachable only from
compile_full_bootstrap_dag_from_std_seed (and sibling), missing the
broader bootstrap_all_runtime → lib.rs:1201-1210 public API →
pb1_bootstrap_full_snapshot_test.rs drift-test chain.

Verified directly:
- Chain A (regen-scaffold): compile_full_bootstrap_dag_from_std_seed
  → load_runtime_bootstrap_authorities
- Chain B (lib.rs public + drift test): bootstrap_all_runtime →
  load_runtime_bootstrap_authorities; bootstrap_all_runtime called
  by lib.rs:1201,1207 public API entries; those exercised by
  pb1_bootstrap_full_snapshot_test.rs:19,26.

Two fixes:

1. PB-1 program brief working-state amendment: caller list expanded
   to the two reach-chains with explicit lib.rs public API + drift
   test chain.

2. PB-1-e worker brief Deliverable A scope expanded to retire
   compile_full_bootstrap_dag, compile_full_bootstrap_without_parse_
   surface_dag (lib.rs public entries) plus rewire/retire
   pb1_bootstrap_full_snapshot_test.rs. New STOP-AND-ESCALATE
   condition added: if lib.rs public API entries have external
   callers beyond the in-tree drift test, retirement shape changes
   and worker escalates.

Acceptance checklist correspondingly updated.

Without this correction, PB-1-e dispatch would have left the lib.rs
public API + drift test exercising the runtime-parse path that
Deliverable A intends to retire — incomplete scope, misleading
discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Codex P2 finding confirmed and fixed in 8741146ee. Verified caller graph directly:

load_runtime_bootstrap_authorities (bootstrap.rs:131, private)
├── Chain A (regen-scaffold)
│     compile_full_bootstrap_dag_from_std_seed (bootstrap.rs:115-130)
└── Chain B (lib.rs public + drift test)
      bootstrap_all_runtime (bootstrap.rs:106, pub(crate))
      ├── compile_full_bootstrap_dag (lib.rs:1201, **pub**)
      ├── compile_full_bootstrap_without_parse_surface_dag (lib.rs:1207, **pub**)
      └── exercised by pb1_bootstrap_full_snapshot_test.rs:19,26

My working-state amendment listed only Chain A; codex flagged that this mis-scopes Deliverable A's retirement work.

Two fixes:

  1. Working-state amendment in pb-1-data-driven-bootstrap.md: caller list expanded to both chains with explicit lib.rs + drift-test surface.
  2. PB-1-e brief Deliverable A: scope expanded to retire compile_full_bootstrap_dag + compile_full_bootstrap_without_parse_surface_dag (lib.rs public entries) and rewire/retire pb1_bootstrap_full_snapshot_test.rs. New STOP-AND-ESCALATE condition: if lib.rs public API has external callers beyond the in-tree drift test, retirement shape changes and worker escalates.

Without this correction, PB-1-e worker dispatch would have left the lib.rs public API + drift test exercising the runtime-parse path that Deliverable A is supposed to retire — incomplete scope.

This is the third finding-driven correction in #786's authoring window (after the original PB-1-b withdrawal + caller-graph completion). Discipline-tightening note for the manager retrospective: grep -rn <symbol-name> across the workspace before naming the symbol's caller graph in a brief, not just spot-checking adjacent files.

briansrls added a commit that referenced this pull request Apr 25, 2026
…g on #786)

bootstrap_generated.rs: 1.0M bytes / 2.2K lines (was: '1.0M LOC').
bootstrap_std_generated.rs: 340K bytes / 8.7K lines (was: '340K LOC').

P1 'Documentation Describes Live State' precision fix.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: e4f6987a · Trigger: schedule
  • Thinking: 243s wall

BLOCKING (2)

Root Cause

  • docs/briefs/pb-1-e-residual-scaffold-retirement-worker.md DB-8 proof is being moved from a CI-visible structural check into a regen-time process gate → require a checked fresh-source receipt in the replacement mechanism or downgrade/rename the property explicitly.
  • docs/briefs/pb-1-e-residual-scaffold-retirement-worker.md The scaffold call graph is described from partial bootstrap.rs references instead of the public lib.rs/regen_bootstrap.rs surface → enumerate every runtime-bootstrap entry point and require each to be deleted or rewired.

Non-blocking — Strengths

  • docs/briefs/pb-1-data-driven-bootstrap.md The rollback correctly withdraws PB-1-b once its premise was invalid and records PB-1-a's broader shipped coverage instead of preserving a stale dispatch lane.

⚠️ The replacement brief needs to preserve DB-8's proof surface and fully enumerate the scaffold retirement surface before this is safe to land.

Three candidate mechanisms (worker picks; surface choice + reasoning in PR description):

- **(i) Per-authority bit-identical composition.** Each authority generates its own snapshot module (`bootstrap_std_generated.rs` already exists; add `bootstrap_staged_generated.rs`, `bootstrap_specs_generated.rs`, `bootstrap_compiler_generated.rs`); DB-8 asserts that loading them in sequence produces a Dag bit-identical to `bootstrap_generated.rs`. Cross-check is "the four parts compose to the whole." Pro: structural; con: requires per-authority snapshot split (substantial regen work).
- **(ii) Separate fresh-compile-once gate at regen time.** Move the fresh-parse-vs-snapshot check into `regen_bootstrap` itself: the regen binary, when run, performs the fresh compile, diffs against the snapshot, and refuses to update if drift is detected. DB-8 in-tree becomes "the committed snapshot is internally consistent" (cheaper structural checks); the fresh-compile gate runs only at regen time. Pro: cleanest scoping; con: DB-8 weakens slightly — no longer asserts "snapshot matches fresh compile" on every test run.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

BLOCKING: Option (ii) explicitly weakens the fresh-compile-vs-snapshot proof while the brief still requires DB-8's no-compromise property, so a stale committed bootstrap snapshot could pass in-tree checks (INVARIANTS DB-8/scaffold boundaries).


## Acceptance

- [ ] Deliverable A: `load_runtime_bootstrap_authorities`, `bootstrap_all_runtime`, `compile_full_bootstrap_dag_from_std_seed`, `compile_full_bootstrap_without_parse_surface_dag`, `bootstrap_std_fixtures_only` all retired (or any kept entries justified explicitly in PR description).

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

BLOCKING: Deliverable A omits current runtime-bootstrap public wrappers such as compile_full_bootstrap_dag and compile_full_bootstrap_without_parse_surface_dag_from_std_seed, so the brief can close while the parallel runtime-parse scaffold remains reachable (INVARIANTS scaffold boundaries/no parallel implementations).

briansrls added a commit that referenced this pull request Apr 25, 2026
…/(iii) framing (BLOCKING on #786)

Reviewer caught real internal contradiction: brief required DB-8's
no-compromise property to be preserved, but manager-leaned to
mechanism (ii) which the brief itself described as weakening DB-8
(in-tree becomes 'snapshot internally consistent'; fresh-compile gate
only at regen time → stale snapshot can pass in-tree checks).

Fix: shift manager lean from (ii) to (i) per-authority composition.
Reasoning: per-authority regen pattern already exists for
std_fixtures (bootstrap_std_generated.rs); extending to STAGED/
V3_SPECS/COMPILER gives each authority a fresh-compile-verified
regen gate, plus in-tree structural composition assertion. Combined
coverage is structurally stronger than today's mechanism, not
weaker — adds composition assertion on top of preserving
fresh-compile-vs-source.

(ii) demoted to fallback only, with explicit STOP-AND-ESCALATE
required before falling back (DB-8 weakening is load-bearing
design call requiring manager + Director sign-off, not worker
discretion).

(iii) hybrid stays as worker option if (i) achievable + extra
regen-time gate worth the wiring.

The (ii)-acknowledged-weakening text rewritten to surface the
trade-off explicitly rather than understate it as 'slightly weakens'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

BLOCKING contradiction confirmed and fixed in 694a3f9ad. Reviewer was correct — the original lean toward (ii) explicitly weakened DB-8 in (ii)'s own text ("con: DB-8 weakens slightly — no longer asserts 'snapshot matches fresh compile' on every test run") while the brief required no-compromise preservation as a STOP gate. Real internal contradiction.

Resolution:

  • Manager lean shifted from (ii) → (i) per-authority composition. Reasoning: the per-authority regen pattern already exists for std_fixtures (bootstrap_std_generated.rs is std-only); extending it to STAGED/V3_SPECS/COMPILER gives each authority its own fresh-compile-verified regen gate, and the in-tree composition test asserts the four parts compose to bootstrap_generated.rs bit-identically. Combined coverage is structurally stronger than today's mechanism — adds composition assertion on top of preserving fresh-compile-vs-source.

  • (ii) demoted to fallback with explicit STOP-AND-ESCALATE required before falling back. DB-8 weakening (which pure-(ii) implies) is a load-bearing design call requiring manager + Director sign-off, not worker discretion.

  • (ii)'s description rewritten to surface the weakening explicitly rather than understate it as "slightly weakens" — the brief shouldn't soft-pedal the trade-off.

  • (iii) hybrid stays available if (i) achievable + extra regen-time gate worth the wiring.

Without this fix, worker dispatch would have proceeded against a brief that named the DB-8 STOP gate but pre-leaned them toward the option that fails it. Catch matters.

briansrls added a commit that referenced this pull request Apr 25, 2026
… Deliverable A (BLOCKING on #786)

Reviewer caught: Deliverable A enumerated only the two no-seed
public entries (compile_full_bootstrap_dag,
compile_full_bootstrap_without_parse_surface_dag), missing the two
_from_std_seed regen-scaffold variants
(compile_full_bootstrap_dag_from_std_seed,
compile_full_bootstrap_without_parse_surface_dag_from_std_seed).
Verified via grep: four total public compile_full_bootstrap_*
entries at lib.rs:1186-1210.

Replaced narrative paragraph with full four-row enumeration table:
each entry's signature, purpose, sole consumer, and retirement
disposition. The two pairs serve different purposes:

- Regen-scaffold (_from_std_seed): layer STAGED/V3_SPECS/COMPILER
  onto a pre-built std seed; sole consumer is regen_bootstrap.
  Disposition is Deliverable B-dependent (kept under (i)
  per-authority composition; collapsed under pure (ii) fallback).

- No-seed (drift-test only): runtime parse from scratch; sole
  consumers are pb1_bootstrap_full_snapshot_test.rs:19,26. Retire
  fully — drift-test purpose subsumed by Deliverable B's cross-check
  mechanism.

Acceptance checklist updated: "retired in full" set explicitly named
(both no-seed publics + bootstrap_all_runtime +
bootstrap_std_fixtures_only); disposition-documented set explicitly
named (two _from_std_seed variants + load_runtime_bootstrap_authorities
itself).

Without this enumeration, worker dispatch could close PB-1-e with
the parallel runtime-parse scaffold still reachable through the
two _from_std_seed variants. Brief now structurally matches the
caller-graph reality.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Second BLOCKING confirmed and fixed in 9432439b5. Verified via grep -n '^pub fn compile_full_bootstrap' src/v3/compiler/src/lib.rs — there are four public entries, not two:

lib.rs:1186  compile_full_bootstrap_dag_from_std_seed                       (regen scaffold)
lib.rs:1195  compile_full_bootstrap_without_parse_surface_dag_from_std_seed (regen scaffold)
lib.rs:1201  compile_full_bootstrap_dag                                     (no-seed; drift test)
lib.rs:1207  compile_full_bootstrap_without_parse_surface_dag               (no-seed; drift test)

Earlier brief revisions enumerated only #3 + #4 (no-seed). The two _from_std_seed variants serve a different purpose (layer STAGED/V3_SPECS/COMPILER onto a pre-built std seed; sole consumer is regen_bootstrap's layered regen pass) and have a different retirement disposition (kept under (i) per-authority composition; potentially collapsed under (ii) fallback).

Replaced narrative paragraph with full four-row enumeration table covering signature, purpose, sole consumer, and retirement disposition for each. Acceptance checklist split into:

  • "Retired in full" set: bootstrap_all_runtime + both no-seed publics + bootstrap_std_fixtures_only.
  • "Disposition documented in PR description" set: both _from_std_seed variants + load_runtime_bootstrap_authorities itself, per Deliverable B mechanism choice.

Reviewer's exact concern addressed: brief now cannot close while the parallel runtime-parse scaffold remains reachable, because each of the four public entries has a named disposition.

Side note: worker on #787 has already chosen to keep the two _from_std_seed variants (with refreshed comments scoping them as regen-only) and retire the two no-seed variants — exactly matching the corrected brief's natural disposition split. They independently arrived at the right framing while my brief was being completed.

This is now four finding-driven corrections in #786's authoring window. The verification-discipline lesson (grep -rn <symbol> workspace-wide before naming a caller graph) is folded into the manager retrospective; #786's iterative review history is itself a useful trace of the discipline gap.

@briansrls

Copy link
Copy Markdown
Contributor Author

Both BLOCKING findings already addressed in commits after e4f6987a4. This codex review was for a sha that predates the fix commits; relay arrived after the fixes were pushed. Verified both fixes are on branch HEAD (9432439b5).

Finding 1 — DB-8 weakening (resolved in 694a3f9ad)

DB-8 proof is being moved from a CI-visible structural check into a regen-time process gate → require a checked fresh-source receipt in the replacement mechanism or downgrade/rename the property explicitly.

Resolved by shifting manager lean from (ii) regen-time-only to (i) per-authority bit-identical composition. (i) preserves DB-8's no-compromise property via:

  • Per-authority snapshots, each fresh-compile-verified at its own regen.
  • In-tree composition test asserting all four committed snapshots compose to bootstrap_generated.rs bit-identically on every test run.

(ii) is now demoted to fallback only, with explicit STOP-AND-ESCALATE required before any fallback (DB-8 weakening is load-bearing and requires manager + Director sign-off, not worker discretion). The (ii)-acknowledged-weakening text was rewritten to surface the trade-off explicitly rather than understate it.

Finding 2 — caller-graph completeness (resolved in 9432439b5)

The scaffold call graph is described from partial bootstrap.rs references instead of the public lib.rs/regen_bootstrap.rs surface → enumerate every runtime-bootstrap entry point and require each to be deleted or rewired.

Resolved by replacing the narrative paragraph with a full four-row enumeration table covering every public compile_full_bootstrap_* entry at lib.rs:1186-1210 (verified via grep -n '^pub fn compile_full_bootstrap'):

Entry Purpose Disposition
compile_full_bootstrap_dag_from_std_seed (:1186) Regen scaffold (layered) Deliverable B-dependent
compile_full_bootstrap_without_parse_surface_dag_from_std_seed (:1195) Regen scaffold (layered, no parse-surface) Deliverable B-dependent
compile_full_bootstrap_dag (:1201) No-seed runtime parse Retire fully
compile_full_bootstrap_without_parse_surface_dag (:1207) No-seed runtime parse Retire fully

Acceptance checklist now splits into "retired in full" vs "disposition documented" sets so brief cannot close while parallel runtime-parse scaffold remains reachable.

Branch HEAD state

9432439b5 (latest) on rollback/pb-1-b-rebase-onto-pb-1-e. Re-review against this sha; the e4f6987a4 review is stale relative to both BLOCKINGs.

@briansrls

Copy link
Copy Markdown
Contributor Author

Director ask — Zero-Floor Manager (`stern-swift-335`): two more brief authorings to clear remaining dependencies.

PB-1-e dispatched per #787 (ack); AtomPayload (#784) in flight. Two more Zero-Floor-territory briefs need authoring before their workers can dispatch — both unblock downstream cascade work:

Ask 1 — PB-Runtime worker brief

Goal: ExecuteCommand runner extension. Today the M1.5 testgen harness allowlists only `command == "true" && args.is_empty() && expect_exit == 0` and panics fail-closed on anything else; Rust `TestRunner` returns `NotYetImplemented` for unhandled `ExecuteCommand` invocations. Need: arbitrary `command` + `args` (e.g., `rustc`, `python`, `go`) with exit-code capture + stdout/stderr capture appropriate for boundary-test assertions.

Why: T-PB-B and the cascade-promoted boundary-test migration block on this. ROADMAP T-PB-B dependencies column now reads `DB-15 + T-TestGen + PB-Runtime` per #782 cascade. Without this, the residual carve-out retraction is a paper claim — boundary tests can't actually migrate.

Anchor file:lines for the worker brief read-first list:

  • `src/v3/std/verification.dag:115-119` — `ExecuteCommand` schema.
  • `src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294` + `:394-398` — current allowlist + fail-closed panic.
  • `src/v3/compiler/src/test_runner.rs:352-382` — `NotYetImplemented` fall-through.
  • `TESTING.md:195` — capability-state callout (live; cite from there for the live-state baseline).

Ask 2 — PB-Bootstrap-Process worker brief

Goal: declare the bootstrap workflow as `bootstrap.dag` data; `bootstrap.rs` becomes a generated trampoline (or vanishes entirely). Anchor live on main post-#776: the loader-close PR's named PB-Bootstrap-Process dissolution trigger comment is in place at the relevant `bootstrap.rs` lines.

Why: This is the canonical dissolution trigger for ~all current substrate-loader transitional shape. PB-Substrate AtomPayload + PB-1-e + the PB-1-c/d-folded work all named PB-Bootstrap-Process as the eventual dissolution authority for their transitional content. Authoring this brief now lets the PB-Bootstrap-Process worker dispatch the moment AtomPayload + PB-1-e land.

Anchor file:lines for the worker brief read-first list:

  • Loader-close brief at `docs/briefs/extdeps-loader-close-worker.md` req 4 — where PB-Bootstrap-Process is named as the dissolution trigger.
  • `docs/design-pure-bootstrap-zero.md` §"New lanes" — your standing program scope already tracks this.
  • `src/v3/compiler/src/bootstrap.rs` (post-extdeps loader close #776 merge) — the named-trigger comment lives here; the worker brief can pin exact line numbers post-extdeps loader close #776 merge.
  • Engine Phase 1 brief req 4 in `docs/briefs/t-ground-engine-phase-1-typestructure.md` — also names PB-Bootstrap-Process as the eventual dissolution.

What I'm doing in parallel

Authoring the R2 T-Substrate 4th sub-lane brief (top-level `ValueBody::List` extension) under Director ad-hoc dispatch — separate file, no overlap with your scope. Lands as `docs/briefs/t-substrate-valuebody-list-worker.md` shortly.

Cadence

No urgency on these — your AtomPayload + PB-1-e workers dispatched today is the higher-throughput priority. Author when it fits the program-management cadence; the unblock pressure from PB-Runtime + PB-Bootstrap-Process is downstream of in-flight work landing first.

If either brief surfaces premise-verification questions during authoring (per the `warm-raven-373` lesson + the AtomPayload-precursor #772 lesson), pause and verify shipped state before authoring — both of these touch substrate-shape territory where assumed pre-state can be wrong.

briansrls added a commit that referenced this pull request Apr 25, 2026
…on (Director ask on #786)

Authored by Zero-Floor Program Manager (session stern-swift-335) per
Director ask on #786 to clear remaining downstream-cascade dependency.

Anchor verification applied at HEAD before authoring (per discipline
lesson from #772 v1 PB-Substrate + #786 PB-1-b withdrawals): all
four read-first sites (verification.dag:115-119, m1_5_testgen_test.rs
:292-294 + :394-398, test_runner.rs:352-388, TESTING.md:195) match
Director's description exactly.

Two surfaces, one PR:
- Surface 1: TestRunner match arm for ExecuteCommand (currently
  falls through to NotYetImplemented). Spawn via std::process::
  Command; compare exit codes; distinguishable Pass/Fail/spawn-error.
- Surface 2: M1.5 testgen harness allowlist generalizes from
  tautological-only to arbitrary; fail-closed panic at :394-398
  retired. Manager lean (a): shared execution mechanism with
  Surface 1 to avoid parallel-implementation debt.

Hermetic property explicitly narrowed: from 'no host process spawn
EVER' to 'host process spawn is the explicit ExecuteCommand
boundary; everything else stays hermetic.'

Acceptance includes one end-to-end boundary-test migration as
empirical evidence (cascade's claim exercised, not just structurally
expressible) plus capability/smoke tests + TESTING.md callout update.

STOP-AND-ESCALATE on: timeout/sandbox policy, cross-platform Command
semantics, Int exit-code ambiguity, hermetic-narrowing surfaces gap,
schema-extension needed (stdout/stderr/env/cwd), scope balloon,
DB-8 drift.

PB-Bootstrap-Process brief queued behind this; AtomPayload + PB-1-e
in flight as higher priority per Director cadence note.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

PB-Runtime brief authored: #791.

Anchor verification applied at HEAD before authoring (discipline lesson from #772 + #786 PB-1-b folded in): all four read-first sites match your description exactly (verification.dag:115-119, m1_5_testgen_test.rs:292-294 + :394-398, test_runner.rs:352-388, TESTING.md:195).

Two surfaces, one PR:

  • Surface 1: ExecuteCommand match arm in TestRunner (currently falls through to NYI).
  • Surface 2: M1.5 testgen harness allowlist generalization + fail-closed-panic retirement.
  • Manager lean (a): shared execution mechanism between surfaces.

Hermetic-property narrowing explicitly named (literal "no spawn EVER" → "spawn is the declared ExecuteCommand boundary"). Matches cascade framing. STOP-AND-ESCALATE on deeper sandbox/timeout policy needs.

Acceptance includes one end-to-end boundary-test migration as empirical evidence — cascade's claim becomes exercised, not just structurally expressible.

PB-Bootstrap-Process brief queued behind this per your cadence note. Will author when AtomPayload + PB-1-e land (additional verified-state evidence at that point) and when in-flight #786 + #787 + #789 settle.

briansrls added a commit that referenced this pull request Apr 25, 2026
…on (Director ask on #786) (#791)

Authored by Zero-Floor Program Manager (session stern-swift-335) per
Director ask on #786 to clear remaining downstream-cascade dependency.

Anchor verification applied at HEAD before authoring (per discipline
lesson from #772 v1 PB-Substrate + #786 PB-1-b withdrawals): all
four read-first sites (verification.dag:115-119, m1_5_testgen_test.rs
:292-294 + :394-398, test_runner.rs:352-388, TESTING.md:195) match
Director's description exactly.

Two surfaces, one PR:
- Surface 1: TestRunner match arm for ExecuteCommand (currently
  falls through to NotYetImplemented). Spawn via std::process::
  Command; compare exit codes; distinguishable Pass/Fail/spawn-error.
- Surface 2: M1.5 testgen harness allowlist generalizes from
  tautological-only to arbitrary; fail-closed panic at :394-398
  retired. Manager lean (a): shared execution mechanism with
  Surface 1 to avoid parallel-implementation debt.

Hermetic property explicitly narrowed: from 'no host process spawn
EVER' to 'host process spawn is the explicit ExecuteCommand
boundary; everything else stays hermetic.'

Acceptance includes one end-to-end boundary-test migration as
empirical evidence (cascade's claim exercised, not just structurally
expressible) plus capability/smoke tests + TESTING.md callout update.

STOP-AND-ESCALATE on: timeout/sandbox policy, cross-platform Command
semantics, Int exit-code ambiguity, hermetic-narrowing surfaces gap,
schema-extension needed (stdout/stderr/env/cwd), scope balloon,
DB-8 drift.

PB-Bootstrap-Process brief queued behind this; AtomPayload + PB-1-e
in flight as higher priority per Director cadence note.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 25, 2026
…hoc) (#793)

Bulk authoring per user ask "clear all dependencies upfront" so worker
dispatch isn't gated on incremental brief authoring. All 8 briefs are
Director ad-hoc territory; each is independently dispatchable subject
to its named cross-program dependencies.

Briefs landed:

T-Substrate sub-lanes (4 — clear T-Modeling pair-blocks):
- t-substrate-cardinality-int-lit-worker.md (M) — magnitude carrier +
  reconciliation narrowing; unblocks T-Modeling int-lit.
- t-substrate-nominal-opaque-secret-worker.md (M) — nominal-opaque
  carrier + constructor-authority predicate; unblocks T-Modeling
  Secret<T> graduation.
- t-substrate-parametric-algebra-dimensions-worker.md (M) — phantom
  parameters + abelian-group attachment + operator-dispatch check;
  unblocks T-Modeling Dimensions. Notes the ROADMAP↔db-history DB-18
  mismatch as informational; acceptance defined independent of DB-tag.
- t-substrate-valuebody-map-worker.md (M) — sibling to PR #790's
  ValueBody::List; map-shaped consumers (kernel_algebra_profile +
  21 others). Notes parser dependency (SurfaceExpr::Map needed).

T-ImpossibleBugs (3 — independent, parallel-dispatchable):
- t-impossiblebugs-nested-optional-flatten-worker.md (S) —
  Option<Option<T>> flattens at construction; cardinality-substrate
  scoped to Option-flatten subset.
- t-impossiblebugs-unhandled-diagnostic-paths-worker.md (S) —
  partiality fact + proof-or-totality check; divide demo.
- t-impossiblebugs-unenumerated-effects-worker.md (S) —
  declared-vs-inferred effect check; Logging demo. Generalizes
  cost/complexity-lens precedent.

T-PerMethodMetadata (1 — design-call close):
- t-permethodmetadata-pick-worker.md (S) — §6a carrier pick (Option
  0/1/2/3); worker decides by evidence, Director reviews.

Each brief follows the established discipline: Read first / Frame /
explicit consumer-side requirements / Slice / Acceptance / STOP-AND-
ESCALATE / Non-goals / Reporting / Cross-manager note. Each cites
verified file:line anchors per the verification-miss discipline lesson
from #772 + #786 + the Engine Phase 1 typestructure brief precedent.

Cross-program coordination notes baked in:
- All 4 T-Substrate briefs flag substrate.dag-adjacent work to Zero-
  Floor Manager.
- ValueBody::Map brief flags parser-extension surface to Surface
  Manager / parser owners.
- Parametric-algebra-Dimensions brief flags the ROADMAP↔db-history
  DB-18 mismatch as informational, with acceptance independent of
  DB-tag resolution.

Out-of-scope of this PR:
- PB-Bootstrap-Process worker brief (Zero-Floor Manager territory;
  re-signal pending separately).
- T-Modeling worker briefs (paired-blocked on T-Substrate sub-lanes
  landing first; can be authored once their substrate prereqs land).

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant