Repository navigation
docs(briefs): T-Substrate 4th sub-lane — top-level ValueBody::List worker brief - #790
Conversation
…rker brief Director ad-hoc dispatch worker brief for R2 T-Substrate 4th sub-lane per docs/r2-structure.md §"Goal 3" (post-#782 cascade re-scoping: 2 list-of-sum consumers; kernel_algebra_profile excluded as map-shaped). Brief unblocks two named consumers on landing: - Engine sharpened-(b) Phase 2 (full pilot enumeration via symbolic walk of rust_pilot_primitives) — Grounding Manager territory. - Tokenizer charclass phase-2 (data ascii_scan_order: List<CharClass> = [...]) — Surface Manager territory. Substrate shape: - New variant ValueBody::List(Vec<FieldValue>) at dag.rs:258-287. - Element shape mirrors existing nested FieldValue::List(Vec<FieldValue>) at dag.rs:343 — structural uniformity with record fields, variant payloads, and other FieldValue carriers. - New lowerer arm in lower.rs:2411-2432 (lower_data_item match), mirroring lower_record_to_structural at :2413. - R14 hard-fail path at lower.rs:2224-2273 narrows naturally — list-bodied declarations stop falling through to Unparsed and stop being rejected. No edits to R14 detection logic; only the diagnostic message text narrows ("list literals" → "map literals" only). Five consumer-side requirements baked in upfront (variant shape; lowerer arm; R14 path narrowing; both-consumers end-to-end visible structurally; substrate dissolution-trigger annotation updated in same PR). STOP-AND-ESCALATE conditions named for: element-shape choice with cross-consumer implications, parser-side surface-expr gaps, exhaustive- match wildcard swallowing, substrate.dag declaration changes (PB-Substrate territory), DB-8 fixed-point drift, serializer/cementer non-extension. Cross-manager heads-up: Grounding (Phase 2 unblocks on landing); Zero-Floor (no substrate.dag conflict expected); Surface (tokenizer ascii_scan_order becomes authorable post-this-PR). Note: brief cites the post-#782-cascade re-scoping of docs/r2-structure.md (2 consumers, kernel_algebra_profile excluded as map-shaped). #782 is APPROVE/APPROVE awaiting merge; once merged, the cited authority text matches what's on main. Brief itself is independent of that cascade landing — the substrate work is the same. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
PM review — APPROVE with one minor observation about consumer-count narrowing vs the cascade. Verified cross-references — all accurate
The technical scope is sound. Element shape Strengths
One observation worth naming — consumer count: cascade's "3" → this brief's "2"The PR #782 cascade promotion's r2-structure.md edit named the 4th T-Substrate sub-lane as having 3 consumers (tokenizer + Engine + This brief honestly narrows to 2 consumers (tokenizer + Engine), excluding That's correct technical scoping. This isn't blocking for THIS PR — the brief is the precise, honest scope. But the cascade-merged r2-structure.md text now over-claims. Worth a small follow-up amendment to r2-structure.md noting the 4th sub-lane unblocks 2 consumers (List-shaped), with VerdictAPPROVE. Brief is ready to dispatch. The narrowing observation is documentation-honesty cleanup, not a brief-correctness concern — the worker should proceed with the 2-consumer scope this brief defines and the 5 requirements + STOP-AND-ESCALATE discipline. Director: clear to flip-to-ready and merge for dispatch. |
|
Director ack — APPROVE confirmed + observation is sha-stale (resolved on `main`). Thanks for the cross-reference verification — all anchors check out + the structural-uniformity reasoning on `Vec` is right. On the consumer-count observationSha-stale. PR #782 merged to main (`5ddc536ca..7ca8757`); r2-structure.md on `main` already reads the corrected 2-consumer scope: ``` The brief's framing matches `main` exactly. The "3 consumers, single substrate work" framing was caught by codex BLOCKING during the cascade promotion review and corrected in the same PR (`fed6b0324`) before #782 merged. The narrowing observation you're flagging was the substantive fix that unblocked #782's APPROVE/APPROVE convergence. StatusPR is already flipped to ready (`gh pr ready 790` ran post-creation; dashboard sync may have lagged). Standing by for merge call — Director ad-hoc territory; I have no merge authority on my own PRs by convention. |
|
Review metadata
Docs-only addition of a worker brief. No code changes. Verdict: APPROVE — Pure documentation addition (a single new brief at |
|
Review metadata
Findings
Verdict |
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
c10fcaea· Trigger:schedule - Thinking:
188s wall
BLOCKING (2)
Root Cause
docs/briefs/t-substrate-valuebody-list-worker.mdthe worker brief narrowed the 4th R2 sub-lane to ValueBody::List but retained the full-lane dispatch promise → either add std.unicode bootstrap inclusion to scope/acceptance or narrow the unblock language and name the remaining follow-up.docs/briefs/t-substrate-valuebody-list-worker.mdthe brief treats “list of sum constructors” as closing all sum-shaped data bodies → keep the diagnostic scoped to map plus unsupported top-level variant/value-body shapes unless the PR also lowers top-level ValueBody::Variant.
| 2. Implement `lower_list_to_structural` (or equivalent — worker's call on naming) in `lower.rs`, mirroring `lower_record_to_structural`. Add the new arm to `lower_data_item`'s match at `:2411-2432` (before the `Unparsed` fallback). | ||
| 3. Update any consumer that pattern-matches on `ValueBody` to handle the new variant (audit by `grep` for `ValueBody::` callsites; lens consumers / serializer / cementer / DB-8 fixed-point machinery may need new arms). **Use exhaustive matches**; prefer adding `match` arms over wildcard `_` to surface every consumer that needs to think about the new variant — per `feedback_missing_checks_review_heuristic`. | ||
| 4. R14 diagnostic message at `lower.rs:2261-2271` narrows to mention only `map literals` (record + list now supported). | ||
| 5. Integration test asserting Engine pilot consumer (`rust_pilot_primitives`) lowers structurally: |
There was a problem hiding this comment.
BLOCKING: The brief claims this sub-lane unblocks tokenizer charclass phase-2, but docs/r2-structure and tokenize.dag both require std.unicode bootstrap/load-set inclusion in addition to ValueBody::List, so the downstream unblock claim is missing a load-bearing prerequisite.
| - [ ] Integration test passes: `rust_pilot_primitives` lowers structurally with the asserted element shape. | ||
| - [ ] All `ValueBody::` exhaustive matches across the codebase updated to handle the new variant. | ||
| - [ ] `cargo test --workspace --exclude v2-compiler-tests` passes. | ||
| - [ ] `cargo clippy --all-targets -- -D warnings` clean. |
There was a problem hiding this comment.
BLOCKING: Narrowing the R14 diagnostic to mention only map literals would hide the still-unsupported top-level variant-literal case called out by the current ValueBody scaffold, weakening fail-closed diagnostics.
Resolves codex REQUEST_CHANGES at sha c10fcae (PR #790). Both findings real and substantive: 1. std.unicode bootstrap/load-set acceptance (P2 boundary discipline) The brief claimed unblocking tokenizer charclass phase-2 but omitted the named-in-r2-structure parent-scope prerequisite of std.unicode entering the runtime bootstrap so CharClass resolves. Added as new req 6 with explicit STOP-AND-ESCALATE if std.unicode doesn't yet exist as .dag (worker may narrow PR's unblock claim to Engine-only with Director-call deferral). 2. Coproduct dissolution receipt + four-pattern check (modeling discipline). Adding ValueBody::List variant is a substrate coproduct extension that requires the four-pattern dissolution receipt per feedback_coproduct_dissolution + the LoopBound canonical precedent at docs/design-mutual-recursion-lowering.md:117-134. Brief only required updating the narrow doc-comment; that's silent stamp- without-receipt territory. Added as new req 7 with explicit precedent (PR #589 surface-coproduct violations on 2026-04-20). Brief now has 7 consumer-side requirements (was 5). Slice steps, acceptance checkboxes, and STOP-AND-ESCALATE conditions updated for consistency. Cross-manager note unchanged (Surface Manager already flagged for tokenizer-charclass-phase-2 coordination, which is exactly the parent-scope context that surfaced req 6). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
Resolution for codex REQUEST_CHANGES at sha `c10fcaea` — both BLOCKINGs real and substantive; resolved at HEAD `462d050bf`. BLOCKING #1 — std.unicode bootstrap/load-set acceptance (P2 boundary discipline)Codex was right. The brief claimed unblocking tokenizer charclass phase-2 but omitted the named-in-`r2-structure.md` parent-scope prerequisite: `std.unicode` entering the runtime bootstrap so `CharClass` resolves. Quoting r2-structure.md §"Goal 3" 4th sub-lane title: "Top-level `ValueBody` list/sum subset + `std.unicode` bootstrap inclusion". The bootstrap-inclusion half was in the parent scope but missing from this brief's reqs. Fix: new req 6 added — explicit `std.unicode` bootstrap/load-set inclusion requirement + integration test acceptance + STOP-AND-ESCALATE if `std.unicode` doesn't yet exist as a `.dag` file (worker may narrow this PR's unblock claim to Engine-only with a Director-call deferral). The brief's claim that this PR unblocks tokenizer-charclass-phase-2 is now grounded. BLOCKING #2 — Coproduct dissolution receipt + four-pattern check (modeling discipline)Codex was right. Adding `ValueBody::List` is a substrate coproduct extension that requires the four-pattern dissolution receipt per `feedback_coproduct_dissolution` + the canonical `LoopBound` precedent at `docs/design-mutual-recursion-lowering.md:117-134`. The brief only required updating the narrow `ValueBody` doc-comment — silent stamp-without-receipt territory. Fix: new req 7 added — four-pattern dissolution receipt for the new variant; receipt placed as doc-comment on `ValueBody` OR sibling design doc cited from variant; explicit "no silent stamp" + the load-bearing precedent (PR #589 surface-coproduct violations on 2026-04-20 — six new substrate coproducts landed without receipts and required follow-up correction). Updates landed
Verdict: REQUEST_CHANGES → APPROVE-conditional on next sha re-review. Brief no longer under-specifies parent-scope + modeling-discipline requirements. |
|
Re inline BLOCKING at `docs/briefs/t-substrate-valuebody-list-worker.md:52` from sha `c10fcaea` — sha-stale; verified resolved at HEAD `462d050bf`. Per dashboard's "verify before dismissing" discipline: ``` The finding is exactly the BLOCKING I resolved in the prior commit. The new req 6 (line 41) reads in part: "The tokenizer-charclass-phase-2 unblock claim depends on `std.unicode::CharClass` … being resolvable from the `Dag::new()` bootstrap path … Add `std.unicode` to the bootstrap fixture set … If `std.unicode` doesn't exist yet as a `.dag` file: STOP-AND-ESCALATE … If the worker concludes the cleanest path is to narrow this PR's unblock claim to Engine-only and defer … that's a Director-call STOP. Acceptance: integration test confirms `std.unicode::CharClass` resolves from a fresh `Dag::new()`-loaded compilation context." Resolution comment posted earlier: PR #790 comment 4318150567. Standing by for the +7 queued; if all are at sha `c10fcaea` they should match this verdict. If any are at `462d050bf` or later naming a different concern, will action. |
|
Review metadata
Findings
Verdict APPROVE_WITH_COMMENTS — docs-only PR adding a single worker brief; no code/substrate touched, no invariant in scope. The brief itself is well-structured (cites the right files with line ranges, calls out the coproduct dissolution receipt requirement per the Exploratory observations
|
|
Review metadata
Findings
Verdict: APPROVE_WITH_COMMENTS. The brief is otherwise tightly scoped and explicitly covers the substrate risks: single authority, fail-closed narrowing, exhaustive match audit, tests, |
…hoc) (#793) Bulk authoring per user ask "clear all dependencies upfront" so worker dispatch isn't gated on incremental brief authoring. All 8 briefs are Director ad-hoc territory; each is independently dispatchable subject to its named cross-program dependencies. Briefs landed: T-Substrate sub-lanes (4 — clear T-Modeling pair-blocks): - t-substrate-cardinality-int-lit-worker.md (M) — magnitude carrier + reconciliation narrowing; unblocks T-Modeling int-lit. - t-substrate-nominal-opaque-secret-worker.md (M) — nominal-opaque carrier + constructor-authority predicate; unblocks T-Modeling Secret<T> graduation. - t-substrate-parametric-algebra-dimensions-worker.md (M) — phantom parameters + abelian-group attachment + operator-dispatch check; unblocks T-Modeling Dimensions. Notes the ROADMAP↔db-history DB-18 mismatch as informational; acceptance defined independent of DB-tag. - t-substrate-valuebody-map-worker.md (M) — sibling to PR #790's ValueBody::List; map-shaped consumers (kernel_algebra_profile + 21 others). Notes parser dependency (SurfaceExpr::Map needed). T-ImpossibleBugs (3 — independent, parallel-dispatchable): - t-impossiblebugs-nested-optional-flatten-worker.md (S) — Option<Option<T>> flattens at construction; cardinality-substrate scoped to Option-flatten subset. - t-impossiblebugs-unhandled-diagnostic-paths-worker.md (S) — partiality fact + proof-or-totality check; divide demo. - t-impossiblebugs-unenumerated-effects-worker.md (S) — declared-vs-inferred effect check; Logging demo. Generalizes cost/complexity-lens precedent. T-PerMethodMetadata (1 — design-call close): - t-permethodmetadata-pick-worker.md (S) — §6a carrier pick (Option 0/1/2/3); worker decides by evidence, Director reviews. Each brief follows the established discipline: Read first / Frame / explicit consumer-side requirements / Slice / Acceptance / STOP-AND- ESCALATE / Non-goals / Reporting / Cross-manager note. Each cites verified file:line anchors per the verification-miss discipline lesson from #772 + #786 + the Engine Phase 1 typestructure brief precedent. Cross-program coordination notes baked in: - All 4 T-Substrate briefs flag substrate.dag-adjacent work to Zero- Floor Manager. - ValueBody::Map brief flags parser-extension surface to Surface Manager / parser owners. - Parametric-algebra-Dimensions brief flags the ROADMAP↔db-history DB-18 mismatch as informational, with acceptance independent of DB-tag resolution. Out-of-scope of this PR: - PB-Bootstrap-Process worker brief (Zero-Floor Manager territory; re-signal pending separately). - T-Modeling worker briefs (paired-blocked on T-Substrate sub-lanes landing first; can be authored once their substrate prereqs land). Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
Re inline BLOCKING at `docs/briefs/t-substrate-valuebody-list-worker.md:67` from sha `c10fcaea` — REAL and substantive; resolved at HEAD `bb97f6a0c`. Verified the finding: the substrate scaffold at `origin/main` does call out variant-literal as still-unsupported alongside map (and the Scalar variant doc-comment adds top-level Reference). My req 3's narrowing to "only map literals" would silently swallow those — exactly the fail-closed-diagnostic regression codex flagged. Verified anchors``` ``` ``` Post-PR still-unsupported residual = map + variant + top-level reference — not "map alone" as my prior brief said. Fix landed at `bb97f6a0c`
Verdict: REQUEST_CHANGES → APPROVE-conditional on next sha re-review. Standing by for the +6 queued; if any are at sha `c10fcaea` and name a different concern I'll action; if duplicates of #1 or #2 they're sha-stale on `bb97f6a0c` (fix at HEAD covers both). |
|
Re codex 2-BLOCKING summary review at sha `c10fcaea` — both BLOCKINGs sha-stale; both verified resolved at HEAD `bb97f6a0c`. This is the same codex review I responded to twice (once per inline finding); the summary review is a third surface for the same two findings. Both already resolved in two separate fix commits. BLOCKING #1 — std.unicode bootstrap inclusion
Resolved at `462d050bf` — req 6 added with explicit `std.unicode` bootstrap/load-set inclusion + integration-test acceptance + STOP-AND-ESCALATE if `std.unicode` doesn't exist as `.dag` (worker may narrow this PR's unblock claim to Engine-only with Director-call deferral). Verification at HEAD: `grep -n std\.unicode docs/briefs/t-substrate-valuebody-list-worker.md` returns matches at lines 41 (req 6), 58 (slice step 6), 69 (acceptance checkbox). Resolution comments: #4318150567, #4318152078. BLOCKING #2 — diagnostic narrowing precision
Resolved at `bb97f6a0c` — req 3 rewritten to be precise about the still-unsupported residual: drop "record" (DB-10 supported pre-PR; current message imprecise — fix in same edit) + drop "list" (now supported via this PR); enumerate `map literals + variant literals + top-level references` as the residual set; explicit "do NOT narrow to 'map' alone" warning citing fail-closed-diagnostic discipline. Req 5 (dissolution-trigger annotation) extended to track variant + reference as remaining residuals beyond map. Verification at HEAD: `grep -n "map literals + variant" docs/briefs/t-substrate-valuebody-list-worker.md` returns line 38 (req 3) + line 67 (acceptance checkbox). Resolution comment: #4318155831. VerdictREQUEST_CHANGES → APPROVE-conditional on next sha re-review at `bb97f6a0c` or later. Cascade-summary covers both inline findings; no new substantive concerns. |
…ling-brief link Resolves codex P2 finding at sha (TBD; PR #793) on docs/briefs/t-substrate-valuebody-map-worker.md:13. Real: the brief references docs/briefs/t-substrate-valuebody-list-worker.md as a "Read first" anchor, but that file lives on PR #790's branch (not yet merged to main); on the #793 branch the link is dead. Two fix shapes considered: - (a) Wait for #790 to merge first, then rebase #793. Slow. - (b) Make this brief self-contained by inlining the inherited pattern. Faster + cleaner; brief is dispatchable regardless of #790 merge order. Picked (b). Brief now: - Banner explicitly notes #790 PR location + branch (instead of citing a path that may not yet exist). - Read-first entry summarizes the inherited pattern inline (a-g bullets covering: enum extension, lowerer arm, R14 narrowing discipline, exhaustive-match audit, coproduct dissolution receipt + four-pattern check, DB-8 gate, doc-comment update). - Worker can dispatch with brief self-sufficient; if #790 has merged worker reads the full sibling brief for additional context, but the discipline pattern is captured here. - Banner explicitly cites how to read the sibling brief if it's not yet on main (git show origin/branch:path or PR diff). Other refs to t-substrate-valuebody-list-worker.md in the brief (beyond the read-first entry) preserved as future-pointers since they're not in mandatory read-first paths. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…_COMMENTS findings Resolves claude review at sha 462d050 on PR #790. Three findings addressed: 1. (Real, blocking-fix) Reporting section line 101 still said "5 consumer requirements" while the brief now has 7. Stale count from prior fix wave. Updated to "7 consumer requirements" + added explicit asks for req 6 disposition (std.unicode bootstrap done OR Engine-only deferral with rationale) + req 7 four-pattern receipt placement in PR description. 2. (Exploratory, pre-resolved by Director) Reviewer noted req 6 (std.unicode bootstrap) was doing a lot of work; suggested pre-resolving whether std.unicode exists before dispatch. Verified at origin/main: dsl/std/unicode.dag exists; line 50 declares `type CharClass = Whitespace | Digit | IdentStart | IdentContinue` matching tokenizer-charclass-phase-2 expected shape. File is NOT yet in bootstrap set (verified absent from bootstrap.rs authority lists; bootstrap.rs:47 references "sub_charclass_in_std_unicode phase-2" as the named consumer waiting on inclusion). Updated req 6 to bake in this empirical finding: "STOP if std.unicode doesn't exist" branch is moot (file exists); "narrow to Engine-only" Director- call STOP remains live only if bootstrap-inclusion surfaces unanticipated load-bearing complications. Worker now has clearer path: just add std.unicode to bootstrap fixture set. 3. (Exploratory, addressed) R14 message narrowing might cause test- snapshot churn; reviewer suggested calling out as expected, not a STOP. Added note to slice step 4: snapshot churn from grep'ing the current "record / list / map literals" string is expected; worker should grep for the current string to find any pinned-expectation sites before changing it. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
Resolution for claude APPROVE_WITH_COMMENTS at sha `462d050b` — all 3 findings addressed at HEAD `523a3bd40`. Finding 1 (real) — "5 vs 7 requirements" mismatch at `:101` — FIXEDReviewer correctly caught the stale count. The Reporting section still said "addresses each of the 5 consumer requirements" while the brief now has 7. `bb97f6a0c` (the prior fix wave) updated the consumer-side requirements heading + acceptance checkbox + slice steps but missed the Reporting section. Now updated:
Finding 2 (exploratory) — pre-resolve std.unicode existence — DIRECTOR PRE-RESOLVED IN BRIEFReviewer suggested Director may want to pre-resolve whether `std.unicode` exists before worker dispatch, since "STOP-and-narrow-to-Engine-only" is a likely outcome. Investigated: ``` $ sed -n '50p' dsl/std/unicode.dag $ grep -nE "unicode" src/v3/compiler/src/bootstrap.rs Empirical findings:
Updated req 6 to bake in these findings:
Worker now has a clearer path: just add `std.unicode` to the bootstrap fixture set; STOP only if the inclusion itself surfaces unanticipated load-order complications. Finding 3 (exploratory) — R14 message snapshot churn — ADDRESSEDReviewer noted the R14 message narrowing might trigger test-snapshot grep'ing for the current string; suggested calling out the expected churn as not-a-STOP. Added to slice step 4:
VerdictAPPROVE_WITH_COMMENTS → APPROVE post-`523a3bd40`. All 3 findings addressed. Standing by for next review pass. |
Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue. Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each gated on a Substrate Manager readiness signal (Wave 2 producers). Authored: - r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2 cardinality-for-int-lit; moves narrowing from tokenizer to reconciliation; MagnitudeOutOfRange diagnostic per C-8. - r2-modeling-secret-graduation-worker.md — gated on Wave 2 nominal-opaque-for-Secret; authors Secret<T> + gated accessors (redact, compare_in_constant_time); C-8 diagnostic on non-gated access; signals Impossible-Bugs Manager on close (thesis claim covered). - r2-modeling-dimensions-phantom-worker.md — gated on Wave 2 parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier> + core SI base units + algebra-method dispatch; cross-dimension arithmetic produces typed diagnostic; signals Impossible-Bugs Manager (thesis claim). - r2-modeling-tokenizer-charclass-phase2-worker.md — gated on T-Substrate ValueBody-list/sum (#790); migrates tokenizer consumers to Char/List<Char>/CharClass canonical types; sibling consumer to Grounding Manager's Engine sharpened-(b). All four: - Explicit gating: 'do not dispatch until producer signal posts.' - Producer/consumer signal pattern from #827. - Cross-program signals to R2 Release Manager (Goal 2 closure) and Impossible-Bugs Manager (thesis-claim coverage). - Spoofing regression tests: discipline anchor against feedback_no_textual_enforcement_bridges. Wave 4 (T-ImpossibleBugs worker briefs × 3) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
#836) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c33: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 second-wave worker-escalation fixes Four substantive worker STOP-AND-ESCALATEs from briefs landed in PR #797. All four worker recommendations correct; each needs a Director call + brief update. ## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate Worker correctly identified that brief req 2 (declared-effect carrier as part of fn type signature, per feedback_no_annotations) requires net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots. Without parser surface, every user function would have declared_effects = [] while inference returns non-empty — lens fires EffectLeakageError everywhere on enable. Worker rejected power-through and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map parser split). Director picked split: - NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface syntax + lookahead + body parser + lowerer extension + exhaustive-match audit + coproduct dissolution receipt. - MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to post-parser-extension scope. Pre-flight check NOT a parser-extension step; STOP if parser sub-lane PR not merged. ## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping Worker found load-bearing evidence at infer.rs:3693-3703: DB-11 deliberately strips refinements at operator dispatch as a designed-in fix for symmetric-operators failure mode. Brief's "attach where b != 0 as a proof for a / b" directly contradicts this design choice. STOP-3 (where-clause conflict with DB-11) is real; STOP-1 (substrate scope) needs net-new substrate (per-operator partiality fact + predicate- entailment check + asymmetric per-operand refinement-honoring) — M+ minimum. ownership_lens precedent in original brief is post-hoc observability, not proof carrier. Worker recommended redirect to design/scoping per nested-optional precedent. Director picked redirect. Brief fully rewritten as design/scoping with four-question structure: (1) DB-11 interaction analysis; (2) substrate proposal for proof-or- totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes with acceptance-theatre risk on user-defined-total-wrapper-only); (4) Director-actionable recommendation. Output is doc PR. ## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C) Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int) with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136 closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b) i128 implementation requires either path 1 (hierarchy refactor — contradicts non-goal) or path 2 (regen lie between substrate and emit — violates discipline). Worker leaned option (C) re-scope: land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke) to a sibling sub-lane that does proper Int128/Word128 substrate work. Director picked option (C). Brief req 1 re-scoped to drop canonical- carrier-widening; lane value comes from range facts + reconciliation narrowing + out-of-range diagnostic against existing i64. Req 4 explicitly deferred with sibling-sub-lane reference. Sibling sub-lane NOT to be authored or implied in this PR; tracked separately. ## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change) Worker correctly STOP'd per the brief's own pre-flight check: parser sub-lane has not landed; SurfaceExpr::Map not on main. Director authorized cross-lane reassignment: wise-boar-480 takes the parser sub-lane (t-substrate-valuebody-map-parser-worker.md) since they already have full investigation context. No brief changes needed; the routing decision is in the dispatch. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope Resolves codex P2 inline at sha e35103fad on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still required widening LiteralBits::Int(i64) to an unbounded carrier and passing the i64::MIN smoke. Internally unsatisfiable. Fix: - Slice section retitled "range facts + reconciliation narrowing (against existing i64 carrier)" with explicit note about the re-scope. - Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly forbids touching LiteralBits::Int shape, dag_scalar_generated.rs regen for that variant, or tokenize i64 parse path. - Slice steps 2-5 reframed: range facts use i64-representable magnitudes; reconciliation narrowing uses existing i64 carrier; diagnostic only for i64-representable out-of-range; smoke tests for req 5 only (req 4 i64::MIN deferred). - Acceptance checklist updated: - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as re-scoped/deferred. - LiteralBits::Int(i64) carrier untouched (no widening; no parallel; no shape change). - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference. - STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the carrier" — explicit STOP if execution surfaces range-fact narrowing requiring carrier-widening; that's the boundary the re-scope drew; belongs in sibling Int128/Word128 sub-lane. Brief now consistently treats carrier-widening as out-of-scope across all sections. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty Resolves codex BLOCKING #1 at sha e35103fa on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier but req 2 required range facts using "the SAME magnitude carrier as req 1" — meaning i64-typed range bounds. u64's max (2^64-1) doesn't fit in i64; range fact for u64 would have to truncate, omit, or mirror in Rust (representation drift). All three options violate fail-closed declared-facts discipline (P1 / P3). Fix: - Req 2 rewritten to specify String-decimal representation: range_min_inclusive: String + range_max_inclusive: String fields on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127" for i8; "0"/"18446744073709551615" for u64). - Explicit reasoning why String-decimal: u64's max doesn't fit in i64; binding range bounds to literal carrier forces truncation/ omission/mirror-drift; all violate fail-closed declared-facts discipline. - Bridge framing: String-decimal is pending the sibling Int128/ Word128 sub-lane; both range bounds and literal payload migrate to typed carrier when that lands. - Req 3 updated for String-decimal comparison semantics: reconciliation parses both bounds and literal magnitude into a common comparison space (i128 host comparison primitive — host narrowing, NOT carrier widening). Bounded by what the i64-typed literal can express; any i64-representable literal compares against any width's String-decimal bound. Carrier discipline preserved. Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral) is sha-stale — already resolved at 3e142d169. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback). Real residual: req 2 specifies String-decimal range bounds (to cover u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" / "i64-representable magnitudes" for the range facts. Two incompatible authorities for the same range-fact shape — would let a worker satisfy the slice while truncating/omitting u64 bounds (P3 fail-closed violation). Fix: - Line 31 (req 1 re-scope clarification): updated to explicitly state "range facts (req 2) use String-decimal representation (width- independent; covers u64::MAX which doesn't fit in i64)". Distinguished literal *payload* (stays i64) from range-bound *representation* (String) — both serve req 1's "no carrier widening" boundary. - Line 44 (slice step 2): updated from "Range bounds use i64- representable magnitudes" to "Range bounds use String-decimal representation per req 2" with concrete example (u64 bounds). - Acceptance bullet: updated from "Range facts on integer algebras (substrate-declared, not Rust-mirrored)" to add "using String-decimal representation ... width-independent; u64 bounds expressible without truncation." The brief now consistently treats range bounds as String-decimal across req 2, req 3, slice, acceptance, and the req 1 clarification — no remaining authorities saying i64-typed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing User + PM exchange 2026-04-25 surfaced that the in-flight effects chain was importing wrong assumptions from external languages (declared-effects-as-annotation + lens-vs-declaration check). Right framing under gunbc's closed-system discipline is parallel to complexity: every effect derives structurally from the composition of typed primitive operations; nothing can hide because there's no escape hatch; nothing needs annotation because the structure IS the registry. Four doc-only actions: 1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md. Frames the closed-system answer with PM's 5-behavior synergy table (Value/Transform/Branch/Loop/Bind as universal compositional-fold pattern). Four worked examples; aggressive reading on redundancy (compile-error-by-construction via referential-transparency proof; reread() primitive for legitimate cases); implementation-brief shape in §Q6. 2. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md. 3. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md. Notes Fn→Arrow refactor brief stays dispatchable as independent value. 4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by- construction framing replaces lens-detection framing. Memory file feedback_closed_system_effects.md saved separately; cross-link added to feedback_construction_over_ratchets.md. Net cost: doc-level cleanup. Zero substrate code rework. Foundation (OperationEffect + service-call infrastructure + 5-behavior substrate) already exists. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect Per PM convergence review on #808 + user's deeper 2026-04-25 framing: the closed-system framing landed in #808 retired the user-facing annotation but kept OperationEffect taxonomy as substrate-level tagging. User's deeper framing: the taxonomy ITSELF is parallel-representation — operations are intrinsically read-shaped or write-shaped via their TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns- derived-value-only → read). Tagging operations with Read | Upsert | Create | Append | Delete names what the structure already says. Three changes: 1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as normalized view, or retire as parallel-representation?" - Two paths: (i) tags derived from signature shape (acceptable normalized view) vs (ii) tags declared per-primitive (parallel- representation; retire). - Audit-as-existence-check (Q4 req 2 reframed): all effectful primitives derive cleanly from signature shape → path (i); any primitive needs hand-declared tag → path (ii) by existence proof. - Director default: path (ii). Logging primitives that return Unit are likely the audit's existence-proof. - Two design-question resolutions: (a) external effects not in return type → resource-threading discipline (typed param returned modified, IO-monad-without-the-monad pattern); (b) transactional grouping → derived structural fact from Bind composition + typed transaction primitives. 2. Q4 reqs revised: req 2 from "tag every primitive with explicit OperationEffect signature" to "audit-as-existence-check that every primitive's type signature derives the right effect classification"; req 3 added (resource-threading discipline); req 6 added (transactional-pattern lens). Req 1 (effects lens) anchors on operation type-signature shape, not on hand-declared tags. 3. THESIS:345-347 amendment strengthened — "operations are intrinsically read-shaped or write-shaped via their type-signature shape; consumers walk the signatures directly; there is no parallel taxonomy or annotation layer to declare or maintain. Tracking effects as a separate enumerated concept IS the bug pattern, dissolved by construction." Plus references to resource-threading discipline + transactional grouping as derived structural fact. Memory file feedback_closed_system_effects.md updated to reflect the deeper framing (type-signature-shape, not taxonomy-tagging) + resource-threading discipline section + transactional-patterns section. Net cost: doc-only delta on top of #808. Substrate retirement (OperationEffect enum + derive_op_effect + idempotency.dag re-anchor) deferred to the audit-as-existence-check phase of the implementation brief; surfaced as Q5.5 OPEN CALL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage Resolves codex BLOCKING at sha d49ce79a on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real: the prior text claimed service primitives "already carry typed effect signatures" presenting future audit-state as current substrate fact (P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the OperationEffect line but left a parallel over-claim on the new "signature-shape coverage" framing. Fix: Q4 substrate-state listing rewritten to honestly distinguish: - Live: Behavior enum + substrate foundation (the principle that operations should carry signature shape). - Incomplete: signature-shape coverage across actual primitives. HTTP-derived primitives carry implicit shape via derive_op_effect's method-table; logging/mutation primitives that return Unit or don't thread their target resource do NOT carry the structural shape that would express read-vs-write. Achieving full coverage is required work under reqs 2 + 3, not a current fact. - Pending audit-as-existence-check: OperationEffect + derive_op_effect (path (i) vs (ii) per Q5.5). Honest live-state callout added explicitly: "the closed-system FOUNDATION (5 behaviors + DAG substrate + the principle that operations should carry signature-shape) is live. The IMPLEMENTATION COVERAGE across all effectful primitives is partial. Req 2 + req 3 are the work that closes the gap." Brief now distinguishes principle-is-live (foundation) from coverage-is-partial (audit work) without conflating them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim Per PM follow-up review on #808 + user's stronger discipline framing ("substrate must make bypass structurally impossible at every layer of the transport stack"): the closed-system claim is honest only when typed primitives ARE the path. Today two structural holes exist where bypasses sidestep the typed-primitive substrate. Both surfaced explicitly as Q4.5 pre-conditions — load-bearing for the lens's coverage claim. Three changes: 1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed- system claim)" inserted between Q4 and Q5: P1 — Extdeps typed-primitive consumption structurally enforced. Substrate must make `messages: Json` impossible to declare in service definitions; typed `LlmMessage` / `ContentBlock` / `GitHubAuthToken`-with-full-scopes are the only path. Tracked debt at ROADMAP.md:153-154 (LLM provider flattening) + `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded). Required prereq for full lens coverage; lens can land first + surface structural-coverage-gap diagnostics on bypass surfaces so the gap becomes visible rather than silent. P2 — `ExecuteCommand` fully materialized as typed runner primitive. TESTING.md (post-#782) committed to 0-residual but ExecuteCommand isn't fully materialized; deleting Rust boundary tests creates verification gap. Already named under PB-Runtime in Zero-Floor; signal pending. Pre-requisite for ANY Rust boundary-test deletion. 2. Old leftover duplicate Q5 section deleted (artifact from prior Q5/Q5.5 reshape; second copy of asymmetric-tightening text was in the file alongside the earlier Q5 instance). 3. Worker-discretion-vs-Director-call section in Q4.5: lens implementation worker dispatchable now (reports gaps as findings); P1 closure is substantive substrate work touching extdeps (dedicated lane); P2 closure is PB-Runtime (signal pending). Net: design doc now honestly distinguishes principle-is-live (Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs named explicitly). The closed-system claim has explicit pre- conditions documented; implementation brief discovers them as known dependencies, not as STOP-AND-ESCALATEs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two real residuals after the Q5.5 reframe: 1. Q6's reqs/STOPs/acceptance still framed under path (i) — said "audit + tag std/ primitives — every effectful primitive carries an explicit OperationEffect signature." Directly contradicted Q4 (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment ("there is no parallel taxonomy to declare or maintain"). Worker reading Q6 in isolation would author the retracted shape. 2. Capacity / sequencing table line about "audit lane (tag std/ primitives with effect signatures)" carried the same stale framing. 3. Q6 STOP "primitive performing side effects without an OperationEffect tag" assumed tag-as-authority; under path (ii) the STOP shape is "primitive whose signature doesn't structurally reveal its effect." Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale (already fixed at f073aa95e Q4.5 commit). ## Q6 fixes - Reqs renumbered + reframed: - Req 1 anchors on operation type-signature shape (not hand-declared OperationEffect tags); composition reads from signature shape per Q2 table. - Req 2 changed from "audit + tag every primitive" to "audit-as-existence-check" — verify signature-shape coverage; ANY primitive needing a hand-declared tag IS the existence-proof for path (ii) retirement. - Req 3 added: resource-threading discipline applied to existing primitives (logging that returns Unit gets reshaped per audit). - Req 6 added: transactional-pattern lens (Bind composition + Transaction → Transaction'). - Req 7 added: asymmetric-tightening worked example in PR body (per claude review observation; the one place declaration-shaped surface re-enters). - Req 8 (was 5): tests now reference signature-shape derivation explicitly, not tag lookup. - STOPs reframed: - "OperationEffect retirement decision" — audit produces path (i) vs (ii) verdict; substrate retirement is its own dedicated sub-lane; this lane does NOT absorb it. - Pure/impure carrier STOP notes that "pure" should also derive from signature shape (pure functions don't return modified resources) — so the STOP itself may dissolve under further design. - Q4.5 P1 explicitly NOT a STOP — lens reporting structural- coverage-gap on extdeps bypass surfaces is the lens delivering its foundation-gap-visibility value. - Q4.5 P2 explicitly independent — lens doesn't depend on ExecuteCommand materialization. - Acceptance extended: lens reports gap diagnostics on P1 bypass surfaces; audit produces existence-proof verdict for Director re-decision; asymmetric-tightening worked example in PR body. ## Capacity / sequencing table Replaced "1 audit lane (tag std/ primitives with effect signatures)" with "1 audit-as-existence-check lane (verify primitives' signature- shape coverage; NOT 'tag every primitive') — produces the path (i) vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2 prereq lanes to the net summary. Closing line: "The taxonomy- retirement scope (substrate-side) is not in this lane — it's surfaced by audit and routed to dedicated retirement lane if path (ii) wins." Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity table. Worker reading Q6 in isolation now sees path-(ii)-default framing matching Q4 + Q5.5 + THESIS amendment. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792 Resolves codex inline BLOCKING at sha 191be310 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150. Real: my Q4.5 P2 framing described ExecuteCommand as still NotYetImplemented (M1.5 allowlist + Rust TestRunner returning NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand extension before this PR's authoring. TESTING.md:195 capability-state callout confirms: - Rust TestRunner + M1.5 testgen harness share one std::process path for arbitrary command + args + expect_exit_code. - M1.5 allowlist + fail-closed panic retired. - Distinguishable ClaimResult::Fail messages for spawn / timeout / policy / exit-mismatch. - Linux unshare(1) namespace isolation on host-allowing systems. - T-PB-B-1 boundary migration example landed. Fix: P2 section rewritten: - Header retitled "ExecuteCommand runner primitive: LANDED (PR #792); residual is bulk-migration." - Status update naming PR #792 + the post-#792 capability state (allowlist retired, etc.). - Honest acknowledgement: "My earlier P2 framing was stale." - Residual narrowed to bulk-migration of existing Rust Command::new boundary tests (tracked as ROADMAP residual, not lens prereq). - Sequencing reframed: P2 was always orthogonal to the effects lens itself; bulk migration proceeds at its own pace; lens not blocked. Q4.5 footer updated: - "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via #792; only consumer-side bulk migration remains)" - Worker-discretion-vs-Director-call P2 line updated: "runner primitive landed; only consumer-side bulk migration remains; tracked as ROADMAP residual, independent of the lens." Q6 STOP for P2 updated: - "the lens itself doesn't depend on P2; only TESTING.md's 0-residual claim does" → "runner primitive landed via PR #792 (post-Q4.5- authoring update). The lens itself never depended on P2; bulk consumer migration is residual ROADMAP work and remains independent of this lane." Brief now reflects live state. The closed-system claim's prereq landscape is honest: - P1 (extdeps typed-primitive consumption): real prereq, tracked debt at ROADMAP:153-154. - P2 (ExecuteCommand runner): satisfied via #792; bulk migration is consumer-side residual, not foundation work. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale Resolves codex non-blocking finding at sha bcac41bb on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real residual: capacity-table line still listed P2 as "`ExecuteCommand` materialization" prereq + framed both P1 and P2 as "pre-existing tracked-debt" — but my prior 57a9b1318 fix established that PR #792 already landed the runner primitive, so P2 is no longer a materialization prereq. Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq) from P2 (residual, not prereq): - P1: extdeps typed-primitive consumption — pre-existing tracked debt at ROADMAP:153-154; load-bearing for the lens's full-coverage claim. - P2: ExecuteCommand runner primitive landed via PR #792; only consumer-side bulk migration of existing Rust Command::new boundary tests remains (tracked as ROADMAP residual, independent of the lens; not a materialization prereq). Brief now consistently treats P2 as bulk-migration-residual across: - §Q4.5 P2 section header (LANDED via PR #792; residual is bulk-migration). - §Q4.5 footer (P2: runner primitive landed; only consumer-side bulk migration remains). - Q6 STOP for P2 (runner primitive landed; bulk migration is residual ROADMAP work). - §Capacity / sequencing impact (P2 as residual, not prereq). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349 Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated target-grounding prose; the matching extdeps typed-primitive bypass entries (LLM service flattening, GitHub auth model bypass) live at ROADMAP.md:348-349. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix third stale ROADMAP citation at line 271 Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence at line 271 in the §Q4.5 capacity table. Now consistent with lines 139 and 173 (ROADMAP.md:348-349). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity Codex flagged 'Effect-signature tagging on std/ primitives' as potentially contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240) already explicitly say 'NOT tag every primitive' — but the cross-manager line used sloppy wording. Reworded to make explicit that the audit walks signature shape; no parallel tag added. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5 - B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound - B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause - B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge - B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation) B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25): language vocabulary is primitives + namespacing only; no escape syntax; the §0 sentinels are the compiler itself failing to use primitives + namespacing internally. Eight surface sites dissolve via four substrate carriers (DeclarationRef, structural fold-shape carrier, structural emit-helper carrier, structural extdeps-fixture-set carrier). B1-B3 are independent; dispatch in parallel. B4 is sequential program work; sub-brief dispatch (B4.1-B4.12) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — drop incoherent inner-fallback non-goal Codex P2: the non-goal line excluding the inner declaration().name unwrap_or_else fallback contradicted Slice step 2, which replaces the whole chain with let-Some-else-return. Both fallbacks are in scope by construction; remove the contradictory non-goal. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives PM REQUEST_CHANGES: §Frame listed '4 type connectives (Conjunction | Disjunction | Cardinality | Bit)' which contradicted the canonical thesis source. Replaced with the canonical 6 (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary closes here'. Also removed 'typed substrate carriers' from the vocabulary list — substrate carriers are defined using the vocabulary, not part of it. Added a clarifying note that B4's carriers (DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are typed declarations composed from the vocabulary, not vocabulary extensions. Per feedback_verify_thesis_claims: brief framings citing thesis structure must ground in the canonical source. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of naming the live substrate authority. Two coordinated fixes: 1. §Read first cites src/v3/std/substrate.dag (live .dag substrate authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel meta-type — already exists with consumers in verification.dag, emit_model.dag, python.dag). 2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing DeclarationRef'. The work is consumer migration + any role-extension layer the audit reveals, NOT designing or landing the carrier. Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers) keep their 'new' framing but explicitly require sub-briefs to grep src/v3/std/ + src/v3/spec/ for existing authority before authoring 'design and land' framing — per feedback_verify_thesis_claims + feedback_emitter_workaround_is_gap_symptom. Acceptance + sub-brief dispatch order updated to reflect B4.1's consumer-migration shape. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — tighten Phase 1 umbrella sentence The umbrella 'Land the typed carriers into src/v3/std/' framing was stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced with audit-first wording that covers both the consume-existing case (#1) and the design-and-land case (#2-#4 if their audits show real gaps). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands' which conflicted with the post-reframe reality that B4.1 consumes the existing DeclarationRef. Updated to 'consumes or lands' with explicit existing-authority citation and audit-pending caveat for B4.2-B4.4. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — soften regression-test requirement (3 worker bounces) Three consecutive B1 worker dispatches (zesty-crane-890 cursor → valiant-boar-498 codex → cool-lynx-395 cursor) archived without opening a PR. Likely friction point: brief Slice step 4 asks for a unit test that constructs a Dag with an orphan variant declaration, but emit.rs has zero existing #[test] precedent — emit testing happens via integration fixtures. Workers see 'build novel test harness' inside what's billed as an S-scope fix and bounce. Per feedback_construction_over_ratchets: when a brief has friction, fix the brief, don't ratchet the worker. Softened step 4 + acceptance: regression test stays optional. If test setup requires novel scaffolding, route the gap to follow-up. The structural fail-closed at step 2 is the load-bearing change. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description' is too weak; PR descriptions don't survive squash-merge cleanly. Two coordinated edits: 1. Slice step 4 — explicit substrate-signal framing: skipped test means emit-side hermetic-unit-test infrastructure is the missing substrate (feedback_emitter_workaround_is_gap_symptom). 2. Acceptance — require ROADMAP debt row (new or existing) with named dissolution trigger, referenced in PR body. Converts the skip from PR-local note (transient) into tracked debt (durable, dispatchable). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124 Codex BLOCKING: my earlier softening claimed emit.rs had no #[test] precedent — wrong. The module has #[cfg(test)] mod tests at line 3124 with 12+ tests using compile_to_dag(source, filename) as harness (e.g., go_struct_fields_render_with_separators :3143, shared_walk_to_disj_finds_match_scrutinee_sum_type :3195). This is a feedback_verify_thesis_claims violation on Director-side brief authoring — claim made without grep verification. Fix: restore step 4 as required, with explicit precedent citation. Worker constructs the failure case via the existing harness (direct Dag, fixture string, or BranchPattern exercise; worker's call on cleanest path). STOP-AND-ESCALATE only if construction proves materially harder than precedent suggests, in which case that escalation surfaces a real substrate gap and warrants ROADMAP debt — but the default is 'add the test.' Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites) Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded to 'several using compile_to_dag'. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this is Wave 1 of Director's 14-brief authoring queue, covering B4 program internals. Authored: - b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) — replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag") fold-skip with structural template-formal carrier; mandatory authority audit per feedback_audit_adjacent_authority_first. - b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) — replaces §0.6 emit.rs bind/branch.span.file equality with typed BindEmitParticipation/BranchEmitParticipation roles populated at lowering; aligned with #824 worker's in-flight implementation shape. - b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4 of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with typed substrate authority; explicit pre-promotion-constraint disposition (single-authority vs authority+tracked-debt) addresses parallel-representation risk surfaced on #825. - b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) — names B4.5-B4.12 Phase 2 sites with carrier dependencies, cross-program coordination notes, and skeleton-brief template; full per-site briefs author at dispatch time per #827's Substrate Manager ownership. Cross-cutting discipline applied per inbox #828 reply: - feedback_audit_adjacent_authority_first (mandatory grep before design) - feedback_no_textual_enforcement_bridges (no replacement sentinels) - feedback_parallel_representation_debt (explicit if shape (b)) - feedback_construction_over_ratchets (no parity-by-runtime as primary) - feedback_coproduct_dissolution (receipts for new variants) Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3) Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue. Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by Modeling Manager's Wave 3 worker briefs (gated on these landing). Authored: - r2-substrate-cardinality-for-int-lit-subset.md (M) — produces magnitude carrier consumed by T-Modeling int-lit. Coordinates with PR #806's prior cardinality work; mandatory authority audit guards against #796's rejected IntLiteralMagnitude shape resurfacing. Open design questions: magnitude representation, reconciliation narrowing point, i64::MIN representability. - r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces nominal-opacity carrier consumed by T-Modeling Secret<T>. Open design questions: carrier shape (flag/connective/sealed-accessor), generic-walk discipline, accessor gating. - r2-substrate-parametric-algebra-for-dimensions-subset.md (M) — produces phantom-parameter carrier consumed by T-Modeling Dimension<Carrier>. Open design questions: carrier shape, type-equivalence rule, algebra-method dispatch, lifting/coercion. All three: - Scoped narrowly to their paired R2 consumer; not full substrate-capability lanes. - Mandatory pre-author authority audit per feedback_audit_adjacent_authority_first. - Cross-program readiness signal pattern from #827's manager rework. - Coproduct dissolution receipts required for any new variants. - Open design questions surfaced explicitly so Substrate Manager (or Director pre-spin-up) can resolve at dispatch time. Wave 3 (T-Modeling worker briefs × 4) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4) Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue. Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each gated on a Substrate Manager readiness signal (Wave 2 producers). Authored: - r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2 cardinality-for-int-lit; moves narrowing from tokenizer to reconciliation; MagnitudeOutOfRange diagnostic per C-8. - r2-modeling-secret-graduation-worker.md — gated on Wave 2 nominal-opaque-for-Secret; authors Secret<T> + gated accessors (redact, compare_in_constant_time); C-8 diagnostic on non-gated access; signals Impossible-Bugs Manager on close (thesis claim covered). - r2-modeling-dimensions-phantom-worker.md — gated on Wave 2 parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier> + core SI base units + algebra-method dispatch; cross-dimension arithmetic produces typed diagnostic; signals Impossible-Bugs Manager (thesis claim). - r2-modeling-tokenizer-charclass-phase2-worker.md — gated on T-Substrate ValueBody-list/sum (#790); migrates tokenizer consumers to Char/List<Char>/CharClass canonical types; sibling consumer to Grounding Manager's Engine sharpened-(b). All four: - Explicit gating: 'do not dispatch until producer signal posts.' - Producer/consumer signal pattern from #827. - Cross-program signals to R2 Release Manager (Goal 2 closure) and Impossible-Bugs Manager (thesis-claim coverage). - Spoofing regression tests: discipline anchor against feedback_no_textual_enforcement_bridges. Wave 4 (T-ImpossibleBugs worker briefs × 3) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3) Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue. Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes, consuming the existing design/scoping briefs as authority. Authored: - r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on cardinality refinement substrate (T-Substrate territory adjacent to int-lit / DB-11 alias-where). Implementation: structural normalize of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T?? worker decision (reject vs normalize). Cites t-impossiblebugs-nested-optional-flatten-design.md as authority. - r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated on Tier 2 substrate (predicate-entailment infrastructure; distinct from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes predicate entailment, (b) feedback_totality_by_omission dissolves partial primitives, (c) park. Worker decides at audit time. Cites t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority. - r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate prerequisite per closed-system framing in design doc (#808). Audit- as-existence-check + lens implementation as compositional fold over 5 behaviors; redundancy detection compile-error via referential transparency + reread() escape hatch; path (i/ii) decision on OperationEffect taxonomy retain-vs-retire (default retire). Cites design doc #808 as authority. Cross-cutting: - Each cites prior design/scoping brief as authority (the existing *-design.md / *-worker.md REFRAMED files). - Explicit gating per #827 producer/consumer signal pattern; two briefs gated on substrate, one NOT gated (closed-system). - STOP-AND-ESCALATE includes 'design brief assumptions don't hold' surfacing per feedback_thesis_gate_state_drift. Wave 4 complete. Director's 14-brief queue done; awaiting PM portion (6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4.4 — tighten Slice §3 per PM review on #836 PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b) (authority + tracked debt parallel-rep) as autonomously acceptable contradicts feedback_construction_over_ratchets + feedback_parallel_representation_debt. Tightened: - Shape (a) is the only autonomous worker path. - Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a regen-host-loader sub-lane decision; not authorable without explicit Substrate Manager approval citation in the PR body. - Acceptance bullet requires the approval citation when shape (b) lands. - STOP-AND-ESCALATE rephrased to make this explicit; permanent parallel-representation re-escalates even with manager approval. This preserves shape (a) as autonomous; shape (b) becomes a cross-manager design escalation, not a B4.4 implementation call. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief Cursor review on #836 flagged the Read-first reference to .claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md as machine-specific (outside the repo, not resolvable from a normal clone). Replaced with in-repo prose pointing at the design doc's §Q1-Q3 as canonical authority — the discipline lives there in-repo. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs) Codex flagged: src/v3/std/types.dag does not exist; the canonical authority is at dsl/std/types.dag. Affected briefs (all from R2 spin-up Wave 2 + Wave 3): - r2-substrate-cardinality-for-int-lit-subset.md - r2-substrate-nominal-opaque-for-secret-subset.md - r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs) - r2-modeling-dimensions-phantom-worker.md - r2-modeling-secret-graduation-worker.md feedback_verify_thesis_claims violation on Director-side brief authoring — assumed path without grep. Same family of error as the earlier emit.rs precedent claim. Mass-replaced via perl; verified no remaining stale refs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant Codex BLOCKING on #836: my R2 worker brief gated nested-optional on cardinality refinement substrate, but the design doc verifies v3 is ALREADY past the cardinality bridge — TypeConnective::Cardinality is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is the carrier for Option. The dissolution is an UNGATED implementation via substrate-constructor invariant. feedback_verify_thesis_claims violation again — should have read the design doc fully before assuming the substrate gate. Rewrote brief to match design doc canonical sketch: - Single predicate (cardinality_idempotent_target) owns the rule - Single allocator (alloc_cardinality_decl) is THE substrate-constructor - API closure on TypeConnective::Cardinality payload (modeling-discipline practice 6) — variant cannot be struct-init'd outside the allocator - 3 hand-Rust + ~22 codegen call sites enumerated per design audit - infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as the killer case for generic-instantiation paths - Surface-syntax T?? decision left to worker (Director-lean: silent normalize) Brief now dispatchable immediately, no producer signal needed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment substrate path, but the design doc §4 explicitly recommends totality-by- omission as the Director-actionable path. Predicate-entailment is M+ scope that reopens DB-11's explicitly-closed asymmetric-strip design — design doc explicitly discards it. feedback_verify_thesis_claims violation again — same family as nested- optional reframe. Should have read design doc §4 in full before assuming the path ordering. Rewrote brief to match design doc §4 follow-on shape: - Primary path: per-class totality-by-omission (algebra retype + per- target realization migration). For Int/Int: OrderedRing.div retype at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 / python:486 + python_target.rs:680 helper). - NOT predicate-entailment (out of scope; M+ + DB-11 reopen). - NOT NonZero-typed-input (deferred to separate per-operand-variance substrate brief; STOP-AND-ESCALATE if chosen). - Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i] indexing, quotient, remainder) queue separately per design doc audit. - feedback_totality_by_omission discipline anchor explicit. Brief now matches feedback_totality_by_omission discipline + design doc recommendation. No substrate prerequisite; dispatchable immediately. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a pattern: I authored R2 worker briefs without fully reading each design doc's Director-actionable recommendation. Pre-emptively re-verified unenumerated-effects against design doc §Q6 to catch the same family of error before reviewers do. Findings: brief was substantively close but missing 3 of 8 design-doc reqs: - Req 3: Resource-threading discipline applied to existing primitives - Req 5: reread(key) primitive in std/ as explicit Slice item (was only mentioned in tests) - Req 7: Asymmetric-tightening worked example in PR body Plus: Slice didn't cite the canonical lens path src/v3/lenses/effect_enumeration.dag from design doc. Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6 specifies 4 specific STOPs (path-decision-escalation, pure: Bool carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP) that I had elided. Reframed Slice as 8 numbered reqs matching design doc verbatim; STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs; Acceptance enumerated per req. This is the third reframe in the unhandled-bugs series — same feedback_verify_thesis_claims violation each time. The pattern suggests Director-side R2 brief authoring should ALWAYS read each design doc's §Director-actionable / §Q-recommendation in full first, not assume. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)" listed as a worker-pick option violates THESIS.md substrate-shape lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) are canonical (per #811 thesis additions and #827 PM review); a 7th is a C1 stop signal requiring failed-dissolution evidence + Director substrate-design call, not autonomous worker pick. Removed the "new TypeConnective variant" option; replaced with `inhabits`-edge-shape carrier as third option (audit-time check). The explicit STOP-AND-ESCALATE clause now states: 7th connective is the precondition for failed-dissolution-evidence + Director substrate-design call, not a worker path. feedback_verify_thesis_claims still in play — should have grounded substrate-shape options against the THESIS lock before listing Opaque(T) as worker-autonomous. Pattern continues; reading source-of-truth before authoring options is the discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place) Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter already exist at dag.rs:186, :217 — explicitly authored for the R2 Dimensions consumer per the doc comment at dag.rs:148-160. phantom_unit_mismatch already wired at infer.rs:1057, :1132. The substrate is fully landed; my brief framing it as 'producer sub-lane to land carrier' is wrong on the same feedback_audit_adjacent_authority_first violation that hit nested-optional / unhandled-diagnostic / unenumerated- effects. Reframed the substrate-side brief as no-op / closed-by-audit: - Documents the audit receipt (5 sites confirming substrate exists) - States the lane is closed - Routes T-Modeling Dimensions consumer to dispatch immediately against the existing carrier - Records the lesson: 'always grep substrate before authoring producer briefs' — discipline doesn't end at brief boundaries. Updated r2-modeling-dimensions-phantom-worker.md correspondingly: - Changed gating from 'do not dispatch until producer signal' to 'NOT GATED — dispatch immediately' - Read-first updated with concrete dag.rs/infer.rs cites - Slice §1 changed from 'confirm producer signal' to 'verify substrate at HEAD' - STOP reframed: existing carrier extension would need Substrate Manager call, not autonomous worker pick Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit both verified — no existing substrate (no is_nominal_opaque / MagnitudeBound patterns in dag.rs); both still legitimately producer-side work. Pattern is now four reframes deep on the R2 spin-up wave. The lesson saved is structural: read source-of-truth before authoring options. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority Codex BLOCKING on #836: my new R2 spin-up brief duplicates the existing t-substrate-cardinality-int-lit-worker.md, which carries the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64) stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane). Single-authority violation per INVARIANTS P2. Same feedback_audit_adjacent_authority_first failure as parametric- algebra-for-Dimensions reframe (4 hours ago): assumed substrate authority didn't exist; should have grepped docs/briefs/ before authoring. This is the SECOND R2 spin-up substrate brief closed as redundant — the discipline lesson is structural. Reframed brief as no-op routing doc (documents the audit receipt; routes consumers to the existing authority); updated r2-modeling-int-lit-magnitude-worker.md to cite t-substrate-cardinality-int-lit-worker.md instead. Pattern across the R2 spin-up wave reframes (5 now): 1. nested-optional gating-on-substrate (substrate already past cardinality bridge) 2. unhandled-diagnostic predicate-entailment default (design doc recommends totality-by-omission) 3. unenumerated-effects 8-req design-doc elision 4. parametric-algebra Producer (Declaration.phantom_params already authored explicitly for this consumer) 5. cardinality-for-int-lit Producer (existing brief is authority) All five are 'as…
…er briefs) Per user direction "lets keep going here until we have full dispatch/briefing for both with thorough review please" — authored the two non-trivial R1 Closure Manager lane worker briefs deferred earlier per "do the trivial ones" direction. R1 Closure Manager lane queue now fully authored. ## R1C-A — T-TestGen schema extensions (M-L; was M before audit) Pre-author audit at main HEAD 407a8bc (per matrix verification invariant) revealed three coupled sub-deliverables, sized M-L total: - **Sub-deliverable A — M1(2.8) list-body lowering for `data` declarations.** Compiler work in lower.rs:2446 (currently rejects `data: List<T> = [...]` as ValueBody::Unparsed). Predecessor for MockBackedInvariant fixture authoring + 6 PB-census predicate authoring. Substrate dependency: T-Substrate ValueBody-list/sum (PR #790; R2 sub-lane) — verify substrate state at brief- dispatch time per feedback_thesis_gate_state_drift. - **Sub-deliverable B — Predicate-shape scoping for 6 PB-census gates.** No `.dag` predicate shape exists for any of the 6 census gates today; ROADMAP line 65 names T-TestGen as scoping authority. R1C-A authors them from scratch. Proposed shapes: CensusBoundCheck / CensusSubsetCount / FixedPointConverges / RatchetZero / GeneratedFromDag (per gate). Audit-first: grep dsl/std/ test_infrastructure.dag for existing predicate-variant pattern; mirror schema discipline. - **Sub-deliverable C — MockBackedInvariant minimal-demo fixture.** Closes testgen_mock_backed_integration_safe gate. Depends on Sub-deliverable A (fixture body uses list literal). 5-10 lines `.dag`. Slice: A → B → C, sequential. STOP-AND-ESCALATE if substrate variant absent, predicate shapes need substrate work, or DB-8 drifts. ## R1C-D — T-PB census-as-`.dag` (M-L) Pre-author audit established census authority at sg0_census_test.rs:166-297 (EXPECTED_HAND_AUTHORED_NON_TEST 41 entries; EXPECTED_HAND_AUTHORED_TEST 77 entries; EXPECTED_HAND_AUTHORED_FRAGMENTS 1 entry). Drift test sg0_v3_hand _authored_census at :387-451 panics with narrative on mismatch. 6 fixtures, one per census gate, each consuming an R1C-A Sub-deliverable B predicate shape: - D.1 pb_hand_rust_at_shim_floor (CensusBoundCheck on NON_TEST list) - D.2 lens_producer_files_remaining (CensusSubsetCount on lens-producer pattern) - D.3 pb_self_compile_fixed_point (FixedPointConverges on bootstrap snapshot) - D.4 pb_compiler_std_ratchet_zero (RatchetZero on consolidation ratchet) - D.5 pb_test_file_generated_from_dag (GeneratedFromDag on test partition) - D.6 pb_rust_tests_outside_residual_zero (CensusBoundCheck on TEST list) Dispatch gated on R1C-A Sub-deliverable B landing. STOP-AND-ESCALATE if predicate shapes don't capture gate semantics (back-pressure to R1C-A); or if cascade-promotion 0-floor work hasn't reduced census to 0 by R1 close declaration time (gates D.1/D.2/D.6 stay RED; Director arbitration). ## R1 Closure Manager status sync Updated r1-closure-manager.md deliverables table + Sub-briefs section to reflect all 6 lane worker briefs as AUTHORED (per matrix's status-consistency rule — table cannot say NOT YET AUTHORED while worker briefs are landed). R1C-A row sized up from M to M-L per audit revealing Sub-deliverable A is compiler work. ## Matrix invariants applied Both new briefs follow the matrix's local checklist: - Categorization: Category 1 (worker brief) — explicit in Cross-refs - Owner / artifact type / status — consistent across deliverables, slice, acceptance, STOP-AND-ESCALATE sections - Pre-author verification — explicit audit receipt section at top of each brief with file:line citations to runner / lowering / schema / census - Discipline anchors named (feedback_construction_over_ratchets, feedback_audit_adjacent_authority_first, feedback_thesis_gate_state_drift, feedback_verify_thesis_claims, feedback_compiler_is_dag_processor, feedback_foundation_over_speed) ## What this PR (#847) now contains (final state expected) - R1 Closure Manager brief + ROADMAP registration + 6 lane worker briefs (R1C-A through R1C-F) — full R1 closure dispatch surface - §6a follow-through worker brief - B5 / B6 / B7 (worker briefs + signal doc) - Escalation-paths union map (45 clauses) - Thesis-claim coverage map (74 claims, 0 GAPs) - Authority matrix (5 categories + per-manager inventory + status-consistency + pre-author verification invariants) - ROADMAP + r2-structure.md + design-substrate-carrier-port-program.md edits R2 spin-up brief queue: complete. R1 closure brief queue: complete. PM inbox #828 fully delivered. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs: PM bundle — R1 Closure Manager + escalation-paths union map
Two PM-portion deliverables, bundled per the user-preferred bundling cadence
for multiple workstreams.
## R1 Closure Manager (new) — docs/briefs/r1-closure-manager.md
Strict-interpretation gate-close authority. Per-HEAD gate audit against
ROADMAP.md §"Lane acceptance — .dag gates" surfaced 12+ unwired gates
under strict reading ("the release gate IS a .dag program" per THESIS):
- T-P0 (3): repeat_string_correct / no_fabrication_sentinel /
rest_ops_aligned — features work, no .dag TestClaim wrappers
- T-Sub (1): sub_type_alias_where_lowers — PR #703 landed feature,
no fixture wrapper
- T-TestGen (1 compiles-only): testgen_mock_backed_integration_safe —
runner returns NotYetImplemented; M1(2.8) data body blocker
- T-PB census (6): hand_rust_at_shim_floor / lens_producer_files_remaining
/ self_compile_fixed_point / compiler_std_ratchet_zero (T-PB-A) +
test_file_generated_from_dag / rust_tests_outside_residual_zero
(T-PB-B) — enforced as Rust ratchets, not .dag TestClaims
- T-Emit (3): rust_fixtures_rustc_green / generic_bounds_survive /
omni_demo_fixtures_green — host-harness only, no .dag wrappers
- T-Demo (1): demo_user_authored_lens_rejects_violating_program —
no fixture
Six mutually-exclusive lanes (R1C-A through R1C-F) at the
fixture-file / runner-dispatch-arm level. R1C-A (T-TestGen schema
extensions) unblocks R1C-D (T-PB census-as-.dag); other 4 lanes
parallel-dispatchable Day-1.
Lane variants per user direction: T-PB-A and T-PB-B merged into R1C-D
(single predicate-shape work); T-Emit kept (no host-harness pragmatic
acceptance).
Manager dissolves on R1 all-gates-green declaration; R2 managers spawn
post-dissolution per docs/r2-structure.md transition mechanics. No
overlap with R2 managers (R2 spawn gated on this manager's close).
## Escalation paths union map (new) — docs/escalation-paths.md
Sweep against main HEAD 407a8bc cataloged 45 "if X happens, escalate"
clauses across INVARIANTS / ROADMAP / THESIS / r2-structure.md / all
docs/briefs / docs/design-*.md / docs/thesis.
- 73% GROUNDED (32 clauses): trigger condition is concrete +
measurable (specific gate names, file:line citations, mechanical
search verifiable)
- 27% SOFT (13 clauses): trigger requires human judgment to fire
No significant authority conflicts. Three minor naming-tightening
opportunities surfaced as Fix 1 / Fix 2 / Fix 3 (applied below). One
near-orphan (DB-revision target unattested on main) — resolved by R2
promotion housekeeping; not load-bearing now.
Sweep boundary: main only. PR #835 (PM portion) and PR #836 (Director
portion) are NOT in this map's current sweep — second-pass sweep
planned on those PRs' merge to main.
## Three surgical fixes to source authority docs
Each fix is a 1-2 line edit closing an open-resolution-path gap the
sweep surfaced:
### Fix 1 — Signal channel naming (docs/r2-structure.md)
New paragraph in §"Manager structure" preamble naming the escalation
signal channel: GitHub session-inbox issue comment for human-target
escalations; cross-manager queue (per R1 "Cross-manager notifications
queued" pattern) for inter-manager signals. Worker-brief STOP-AND-
ESCALATE clauses no longer need to restate the channel.
### Fix 2 — Director decision-artifact format (docs/r2-structure.md)
Extended the "Scope-change escalation" bullet in §"Director" to name
where Director's adjudication decision lands: (a) amendment PR to the
originating brief OR (b) sibling brief if scope creates new program.
Closes the escalation cycle explicitly — originating brief stays open
until artifact lands.
### Fix 3 — C1 lane explicit owner (docs/design-substrate-carrier-port-program.md)
Two STOP-AND-ESCALATE clauses (Lane E-T :120 and Lane E-P :148)
rewritten from "→ C1 lane" to "→ escalate to Director (Director opens
a C1 substrate-capability lane if escalation requires substrate work)."
Director becomes the explicit receiver; C1 lane becomes the optional
dispatch outcome.
## Out of scope for this PR
- §6a follow-through brief authoring (next PM deliverable per inbox #828
PM portion; tracked in r2-release-manager.md per PR #835)
- B5 / B6 / B7 brief authoring (next PM deliverables per inbox #828 PM
portion)
- Thesis-claim coverage mapping table (lands at R1 close → R2 promotion
transition per r2-structure.md)
- Authority matrix structural normalization (per openai-pro PAUSE_AND_REGROUP
meta-review on PR #835; deferred — escalation-paths.md provides initial
evidence base for any future matrix authoring)
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs: add R1 Closure Manager ROADMAP registration + §6a follow-through worker brief
Two additions to the PM bundle.
## ROADMAP §"R1 Closure Manager" section (new)
Small registration section between §"Lane acceptance — .dag gates" and
§"Scheduled cleanups". Names the manager + lane structure (R1C-A through
R1C-F) + critical-path edge (R1C-A → R1C-D); points at the brief at
docs/briefs/r1-closure-manager.md as authority for the per-lane scope.
Parallel registration shape to docs/r2-structure.md's §"Manager structure"
treatment for R2 managers — short authoritative pointer in ROADMAP, full
manager scope in the brief. Manager dissolves on R1 all-gates-green; R2
spawn gated on this dissolution.
## §6a follow-through worker brief (new)
Per inbox #828 PM-portion split, this is the next PM deliverable in the
queue. Anchored against the existing pick-worker brief at
docs/briefs/t-permethodmetadata-pick-worker.md (landed PR #794) so there's
no duplicate decision authority — pick is closed; this brief is post-pick
scope only.
Three consumer-side requirements:
1. Inventory current consumption sites in cost.dag / complexity.dag for
the three carrier fields (size_effect / cost_shape / callback_element_position).
2. Bulk-migrate to MethodContract-keyed lookup; retire lens-local reads
of *_templates() result fields.
3. Track field-by-field dissolution triggers as named ROADMAP debt rows
per §6a:175 (each field has a named upstream-fact landing condition
that retires the carrier; when all three trigger conditions fire,
MethodContract retires).
Slice: inventory → migrate → track. 1-3 PRs at worker discretion.
STOP-AND-ESCALATE clauses cite the new escalation channel discipline from
docs/escalation-paths.md (channel: GitHub session-inbox; Director decision
artifact = amendment PR or sibling brief). Behavioral-regression on R1
gates is non-negotiable STOP; DB-8 drift is STOP; carrier-shape gap
discovery is STOP (the pick may need amending).
## What this PR now contains (cumulative)
- docs/briefs/r1-closure-manager.md (new) — R1 Closure Manager brief
- docs/escalation-paths.md (new) — 45-clause union map
- docs/briefs/r2-release-6a-follow-through-worker.md (new) — post-pick worker brief
- ROADMAP.md edit — R1 Closure Manager registration section
- docs/r2-structure.md edits — signal channel + Director decision-artifact format (Fixes 1+2)
- docs/design-substrate-carrier-port-program.md edits — C1 lane explicit owner (Fix 3)
## Out of scope
Still-pending PM deliverables per inbox #828: B5 Loop construction-closure
audit brief; B6 file-preference rank checklist completion; B7 priority-hint
relay (cross-manager signal); thesis-claim coverage mapping table (lands
at R1 close → R2 promotion).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix(escalation-paths): resolve P2 single-authority wording ambiguity
Codex on #847 sha 265d97f flagged that line 3's "Authoritative single
source for ... escalation clauses" contradicts line 18's "descriptive,
not prescriptive ... source briefs remain authoritative" — direct P2
single-authority ambiguity per INVARIANTS.md.
Fix: line 3 now reads "Authoritative union receipt + conflict map ...
The source briefs remain authoritative on their own escalation clauses
(per §How to use below); this doc owns the union view + cross-brief
consistency surfacing."
Surface change only; the doc's actual authority scope is unchanged
from the §"How to use" semantics — clauses live in source briefs;
this doc surfaces the union + conflicts. The status line now matches
the body.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs: B5 / B6 / B7 — R2 Release Manager B-wave Tier 2 (PM portion)
Per inbox #828 PM portion, three deliverables completing the B-wave
Tier 2 PM authoring queue per docs/briefs/debt-paydown-synthesis-
2026-04-25.md §5 (lines 526-528). All three target R2 Release Manager
ownership (post-spawn).
## B5 — Loop construction-closure audit (worker brief)
S, R2-coupled. Audit-FIRST per parent scope statement (lines 300-314).
Step 1: enumerate every Behavior::Loop construction site in lower.rs
+ anywhere; trace caller path. Step 2 (conditional on audit):
- Closure-holds (preferred per feedback_construction_over_ratchets):
deliverable is structural integration test asserting closure;
speculative LoopKind marker retired.
- Closure-fails: marker spec authored as separate brief; escalates
to substrate-amendment per synthesis-doc STOP discipline.
STOP-AND-ESCALATE clauses cover: (a) ambiguous construction-site
origin; (b) marker spec requiring new substrate connective (C1-class
escalation per feedback_compiler_is_dag_processor); (c) self-fulfilling
closure if audit's own scaffold triggers.
## B6 — file-preference rank checklist completion (worker brief)
XS-trivial. Audit-first per feedback_audit_adjacent_authority_first.
Two paths: (a) add the three missing modules (computation/induction/
termination) to dag.rs:2735-2764 checklist; (b) document exemption
in source if the modules are intentionally exempt.
Single-PR deliverable; either +3 line addition or +1 line comment cite.
STOP if rank-function semantics are genuinely ambiguous, or if "fix"
turns out to require substrate work (don't ratchet on a scaffold
already named for dissolution).
## B7 — priority-hint relay to Pure Bootstrap Manager (signal doc, NOT worker brief)
Cross-manager signal content snapshot. NOT a worker brief — documents
the signal R2 Release Manager queues to R2 Pure Bootstrap Manager
once both spawn at R1 close.
Payload: lift patch_lower_helpers_generated_type_alias_refinement
retirement to PB-Tier1-Sweep priority within R2 Pure Bootstrap
Manager's owned-deliverable queue.
Pre-spawn: this file documents content. Post-spawn: R2 Release
Manager queues the signal as one of its first dispatch actions; R2
PB Manager acks + adjusts priority. Closure trigger: signal delivered
+ consumed (or dissolution already fired pre-R1); file marks RESOLVED
in follow-up cleanup.
Distinguished from B5 / B6 worker briefs by the explicit "NOT a worker
brief" framing in the synthesis doc; preserves single-authority discipline
(deliverables vs signals do not blur).
## Cumulative PR contents (PR #847)
- docs/briefs/r1-closure-manager.md
- docs/briefs/r2-release-6a-follow-through-worker.md
- docs/briefs/r2-release-b5-loop-construction-closure-audit-worker.md (this commit)
- docs/briefs/r2-release-b6-file-preference-rank-checklist-worker.md (this commit)
- docs/briefs/r2-release-b7-priority-hint-relay-to-pure-bootstrap.md (this commit)
- docs/escalation-paths.md
- ROADMAP.md (R1 Closure Manager registration section)
- docs/r2-structure.md (Fixes 1+2 + earlier signal-channel section)
- docs/design-substrate-carrier-port-program.md (Fix 3 — C1 lane explicit owner)
## What's left in PM inbox-#828 queue
- Thesis-claim coverage mapping table — gated on R1 close → R2 promotion
per docs/r2-structure.md Open call 1; not in this PR.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs: R1 Closure Manager — 4 trivial-to-small lane worker briefs (R1C-B / -C / -E / -F)
Per user direction "lets do the trivial ones" — authoring the four
R1 Closure Manager lanes that don't depend on R1C-A (T-TestGen schema
extensions). All four are parallel-dispatchable Day-1 once R1 Closure
Manager spawns; sized S or smaller per the manager brief.
## R1C-B — T-P0 fixtures (S; 3 gates)
- p0_repeat_string_correct (Day-1, DB-15 schema): authored immediately
- p0_no_fabrication_sentinel (ext): audit predicate shape; possibly blocks on R1C-A
- p0_rest_ops_aligned (ext): audit predicate shape; possibly blocks on R1C-A
Branch on audit per gate; bundle PRs if all DB-15-suffices, split if any
blocks on R1C-A schema landing.
## R1C-C — T-Sub sub_type_alias_where_lowers fixture (XS; 1 gate)
PR #703 already landed the feature with test_db11_type_alias_where_*
integration receipts. Brief authors the .dag wrapper; predicate likely
Compiles on a fixture program exercising type-alias where lowering.
Single PR; dispatchable Day-1.
## R1C-E — T-Emit .dag TestClaim wrappers (S; 3 gates)
PB-Runtime ExecuteCommand (PR #792) is the runner enabler. Three gates:
- emit_rust_fixtures_rustc_green: ExecuteCommand running rustc on emitted output
- emit_generic_bounds_survive: audit-decided shape (ExecuteCommand+grep or structural)
- emit_omni_demo_fixtures_green: multi-target; ForAllTargets quantifier may need
R1C-A schema, OR can be expressed as 3 ExecuteCommand claims (1 per target)
STOP if ForAllTargets needed and not in scope; STOP if PR #792 ExecuteCommand
runner doesn't cover the bounded-execution shape.
## R1C-F — T-Demo demo_user_authored_lens_rejects_violating_program (S; 1 gate)
Built on T-LensAPI user_authored_lens_compiles (GREEN). Three components:
- ~20-line user-authored lens in .dag (e.g., "max external HTTP calls per workflow"
per THESIS canonical example)
- Violating program (~10-20 lines)
- TestClaim with FailsWithDiagnostic predicate (asserts lens rejects violator)
Demo artifact also authored per docs/r2-structure.md §"Demo discipline".
## Discipline anchors applied
- feedback_construction_over_ratchets — fixtures ground in observable
behavior (compiles / output / exit-code), not parallel asserts
- feedback_audit_adjacent_authority_first — every brief mandates audit
step before authoring (pick predicate / pick lens example / pick path)
- All four briefs cite docs/escalation-paths.md as escalation discipline
authority
## Out of scope
- R1C-A T-TestGen schema extensions worker brief (M; meatier; authored separately)
- R1C-D T-PB census-as-.dag worker brief (M-L; meatier; gated on R1C-A; authored separately)
- Implementation of any of these briefs (worker dispatch happens at R1
Closure Manager spawn)
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs: thesis-claim coverage map (R2 promotion Open call 1 deliverable)
Per docs/r2-structure.md §"Open calls" item 1 — required pre-promotion
audit table mapping every THESIS claim to R1-closed / R2-gated /
post-R2-external disposition with gate name + evidence + status.
## Sweep result
74 claims cataloged across THESIS.md §"Thesis claims — complete list"
(Tier 1 / Tier 2 / Tier 3 + categorical claims under Concept unifications,
Epistemic stacking, Substrate shape, Free consequences, Omni-emission,
Meta-process modeling, Self-hosting, Audience duality, Adoption model,
Tests-as-data, Enumerable impossible-bug classes, Modeling discipline).
## Coverage statistics
- R1-closed: 52
- R2-gated: 18
- post-R2-external: 4
- GAP (no disposition): 0
**Pre-promotion blocker count: 0.** Open call 1's gate is satisfied —
every thesis claim has a named disposition + documented evidence.
## Coverage anomalies (partial-status, NOT blockers)
Four claims have partial-status notes:
1. Ownership (Tier 1) — full infrastructure may have post-R1 tail
2. Shape A omni-emission — R1 demonstrates 3 of 6+ targets (TS/Swift/HDL post-R1)
3. Self-hosting fixed-point + tests-as-data — [ext] gates pending T-TestGen
runner closure; structural commitment R1
4. Grounding completeness — Tier 1 but R2-gated (intentional, single co-anchor
claim per docs/r2-structure.md)
## Doc shape (mirrors escalation-paths.md authority pattern)
- Status: PROPOSAL pre-R1-close; promotes to ACTIVE on R1 close → R2 promotion
- Authority: descriptive (union receipt + GAP-surfacing); THESIS + ROADMAP
+ r2-structure.md remain authoritative on claim text + dispositions
- Refresh discipline: every release transition; rebuild on new claims
## What this PR (#847) now contains
Cumulative deliverables:
- docs/briefs/r1-closure-manager.md (R1 Closure Manager brief, 6 lanes)
- docs/briefs/r1c-b/c/e/f-*.md (4 trivial R1C lane worker briefs)
- docs/briefs/r2-release-6a-follow-through-worker.md
- docs/briefs/r2-release-b5-loop-construction-closure-audit-worker.md
- docs/briefs/r2-release-b6-file-preference-rank-checklist-worker.md
- docs/briefs/r2-release-b7-priority-hint-relay-to-pure-bootstrap.md
- docs/escalation-paths.md (45-clause union map)
- docs/thesis-claim-coverage.md (74-claim coverage map; this commit)
- ROADMAP.md edit — R1 Closure Manager registration section
- docs/r2-structure.md edits — Fix 1+2 (signal channel + Director decision artifact)
- docs/design-substrate-carrier-port-program.md edits — Fix 3 (C1 lane explicit owner)
## Out of scope
- R1C-A (M) and R1C-D (M-L) worker briefs — meatier; defer to next PM iteration
- Implementation of any worker brief (R1 Closure Manager dispatches at spawn)
- Authority matrix structural normalization per openai-pro PAUSE_AND_REGROUP
meta-review — escalation-paths.md + thesis-claim-coverage.md provide
evidence base; matrix authoring optional next iteration
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs: R2 manager-brief authority matrix (resolves PAUSE_AND_REGROUP meta-review)
Per openai-pro PAUSE_AND_REGROUP meta-review on PR #835 sha bfaab66, the
recurring "authority ambiguity at stage boundaries" pattern (B7 dual-contract,
Grounding pending unbounded, §6a stale framing, B4.1 stale BLOCKING) was being
fixed instance-by-instance via wording sweeps. The structural fix is a shared
authority matrix that makes the categories disjoint at brief-authoring time.
This commit graduates the recurring class out of per-instance review.
## docs/briefs/r2-manager-brief-authority-matrix.md (new)
5 disjoint artifact categories with explicit invariants:
1. Worker brief — dispatchable authoring task; produces concrete deliverable
2. Decision brief — scoped design call (pick + lock); follow-through is
distinct Category 1 worker brief (resolves §6a anti-pattern)
3. Cross-manager signal — routes priority/scope info; NOT a worker brief
(resolves B7 anti-pattern)
4. Standing reporting duty — continuous-state ledger / monitor; activates
on spawn, dissolves on manager dissolution
5. Pre-spawn placeholder — skeleton authored before spawn; graduates into
1-4 OR dissolves at spawn
Per-manager deliverable inventory tags every owned deliverable from all 6 R2
managers (Grounding / Substrate / Modeling / Impossible-Bugs / Pure Bootstrap /
Release) with category. Inventory references PR #835 (manager briefs), PR #836
(14 Director worker briefs), and PR #847 (this PR's worker briefs + signal doc).
Local review checklist (per meta-review recommendation #3): Owned deliverables
+ Pre-spawn vs post-spawn authority + Autonomous dispatch authority + Sub-briefs
sections must agree on owner + artifact type per matrix categorization. Doesn't
need new top-level INVARIANTS rule; P2 + P5 already cover; this is the local
invariant for the manager-brief family.
## Sweep verification — current state of 6 R2 manager briefs (PR #835 sha 3260d71)
All 6 manager briefs verified consistent with matrix:
- Grounding: ✅ no category conflicts (Pending bounds fixed in f916fba)
- Substrate: ✅ no category conflicts (B4.1 staleness fixed in 74b679b)
- Modeling: ✅ no category conflicts
- Impossible-Bugs: ✅ no category conflicts (filenames fixed 70df547)
- Pure Bootstrap: ✅ no category conflicts
- Release: ✅ no category conflicts (B7 dual-contract fixed f916fba; §6a
stale framing fixed 74b679b + 3260d71)
No additional fix-pushes needed on PR #835 from this matrix introduction.
## docs/r2-structure.md (edit)
Added "Manager-brief authority matrix" paragraph in §"Manager structure"
preamble, citing the matrix doc as authority. Manager briefs now cite the
matrix and stop self-categorizing.
## What this PR (#847) now contains
Cumulative deliverables:
- docs/briefs/r1-closure-manager.md (R1 Closure Manager brief, 6 lanes)
- docs/briefs/r1c-b/c/e/f-*.md (4 trivial R1C lane worker briefs)
- docs/briefs/r2-release-6a-follow-through-worker.md
- docs/briefs/r2-release-b5-loop-construction-closure-audit-worker.md
- docs/briefs/r2-release-b6-file-preference-rank-checklist-worker.md
- docs/briefs/r2-release-b7-priority-hint-relay-to-pure-bootstrap.md
- docs/briefs/r2-manager-brief-authority-matrix.md (this commit)
- docs/escalation-paths.md (45-clause union map)
- docs/thesis-claim-coverage.md (74-claim coverage map; 0 GAPs)
- ROADMAP.md edit — R1 Closure Manager registration section
- docs/r2-structure.md edits — signal channel + Director decision artifact
+ authority matrix reference (this commit)
- docs/design-substrate-carrier-port-program.md edits — Fix 3 (C1 lane
explicit owner)
## What's outstanding (out of scope for this PR)
- R1C-A and R1C-D worker briefs (M and M-L; meatier; deferred per user's
"trivial ones" direction)
- Sweep of PR #836's 14 worker briefs against the matrix at PR #836 merge
(current sweep is main-only)
- Authority matrix becomes ACTIVE on R1 closure → R2 promotion transition
per the matrix's status; PROPOSAL until then
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(matrix): add status-consistency + pre-author verification invariants
Two additions to the local review checklist on the R2 manager-brief
authority matrix, both surfaced by review activity since the matrix's
initial landing:
## Status-consistency rule
openai-pro APPROVE_WITH_COMMENTS on PR #835 sha 3260d71 found T-Ground-Rust
in two contradictory states: deliverables table said DISPATCHED, but
Sub-briefs Pending list said "T-Ground-Rust full implementation" pending.
Same lane, two authoritative states — the matrix's existing checklist
covered owner + artifact type but not status, leaving room for this class.
Added rule: a single deliverable cannot be both DISPATCHED/AUTHORED in the
deliverables table AND Pending/NOT YET AUTHORED in the Sub-briefs section.
Partial-state lanes must scope the partial explicitly in the table (e.g.,
"PARTIAL — Pilot PR #X done; full implementation pending"). Sub-briefs
section is single authority for authored-vs-pending; deliverables table
cites that authority without duplicating ambiguously.
Fixed in 3ef1509 on PR #835 (T-Ground-Rust row scoped to NOT YET AUTHORED).
## Pre-author verification invariant
Director's PR #836 hit feedback_verify_thesis_claims 7 times in one PR
authoring cycle (consistently: brief authored without grepping
source-of-truth before slicing). The pattern is a separate failure class
from categorization — not what the matrix's prior checklist addressed.
Added invariant: before authoring a brief that references substrate state,
gate condition, existing brief, or design-doc disposition, grep
src/v3/std/ + src/v3/spec/ + src/v3/compiler/src/ for state cited; grep
docs/briefs/ for existing canonical briefs; read the design doc's
§Director-actionable / §Q-recommendation / §Decision in full. Cite
specific file:line / brief filename / §ref in Read first. State audit
receipt before slicing.
This operationalizes feedback_verify_thesis_claims for the brief-authoring
family. Doesn't need a new INVARIANTS rule; cited existing P2 + P5 +
feedback_verify_thesis_claims as authority. Local invariant collected
here as a single review checkpoint.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs: R1 Closure Manager — full lane brief queue (R1C-A + R1C-D meatier briefs)
Per user direction "lets keep going here until we have full dispatch/briefing
for both with thorough review please" — authored the two non-trivial R1
Closure Manager lane worker briefs deferred earlier per "do the trivial ones"
direction. R1 Closure Manager lane queue now fully authored.
## R1C-A — T-TestGen schema extensions (M-L; was M before audit)
Pre-author audit at main HEAD 407a8bc (per matrix verification invariant)
revealed three coupled sub-deliverables, sized M-L total:
- **Sub-deliverable A — M1(2.8) list-body lowering for `data` declarations.**
Compiler work in lower.rs:2446 (currently rejects `data: List<T> = [...]`
as ValueBody::Unparsed). Predecessor for MockBackedInvariant fixture
authoring + 6 PB-census predicate authoring. Substrate dependency: T-Substrate
ValueBody-list/sum (PR #790; R2 sub-lane) — verify substrate state at brief-
dispatch time per feedback_thesis_gate_state_drift.
- **Sub-deliverable B — Predicate-shape scoping for 6 PB-census gates.**
No `.dag` predicate shape exists for any of the 6 census gates today; ROADMAP
line 65 names T-TestGen as scoping authority. R1C-A authors them from scratch.
Proposed shapes: CensusBoundCheck / CensusSubsetCount / FixedPointConverges /
RatchetZero / GeneratedFromDag (per gate). Audit-first: grep dsl/std/
test_infrastructure.dag for existing predicate-variant pattern; mirror
schema discipline.
- **Sub-deliverable C — MockBackedInvariant minimal-demo fixture.**
Closes testgen_mock_backed_integration_safe gate. Depends on Sub-deliverable
A (fixture body uses list literal). 5-10 lines `.dag`.
Slice: A → B → C, sequential. STOP-AND-ESCALATE if substrate variant absent,
predicate shapes need substrate work, or DB-8 drifts.
## R1C-D — T-PB census-as-`.dag` (M-L)
Pre-author audit established census authority at sg0_census_test.rs:166-297
(EXPECTED_HAND_AUTHORED_NON_TEST 41 entries; EXPECTED_HAND_AUTHORED_TEST 77
entries; EXPECTED_HAND_AUTHORED_FRAGMENTS 1 entry). Drift test sg0_v3_hand
_authored_census at :387-451 panics with narrative on mismatch.
6 fixtures, one per census gate, each consuming an R1C-A Sub-deliverable B
predicate shape:
- D.1 pb_hand_rust_at_shim_floor (CensusBoundCheck on NON_TEST list)
- D.2 lens_producer_files_remaining (CensusSubsetCount on lens-producer pattern)
- D.3 pb_self_compile_fixed_point (FixedPointConverges on bootstrap snapshot)
- D.4 pb_compiler_std_ratchet_zero (RatchetZero on consolidation ratchet)
- D.5 pb_test_file_generated_from_dag (GeneratedFromDag on test partition)
- D.6 pb_rust_tests_outside_residual_zero (CensusBoundCheck on TEST list)
Dispatch gated on R1C-A Sub-deliverable B landing. STOP-AND-ESCALATE if
predicate shapes don't capture gate semantics (back-pressure to R1C-A);
or if cascade-promotion 0-floor work hasn't reduced census to 0 by R1 close
declaration time (gates D.1/D.2/D.6 stay RED; Director arbitration).
## R1 Closure Manager status sync
Updated r1-closure-manager.md deliverables table + Sub-briefs section to
reflect all 6 lane worker briefs as AUTHORED (per matrix's status-consistency
rule — table cannot say NOT YET AUTHORED while worker briefs are landed).
R1C-A row sized up from M to M-L per audit revealing Sub-deliverable A is
compiler work.
## Matrix invariants applied
Both new briefs follow the matrix's local checklist:
- Categorization: Category 1 (worker brief) — explicit in Cross-refs
- Owner / artifact type / status — consistent across deliverables, slice,
acceptance, STOP-AND-ESCALATE sections
- Pre-author verification — explicit audit receipt section at top of each
brief with file:line citations to runner / lowering / schema / census
- Discipline anchors named (feedback_construction_over_ratchets,
feedback_audit_adjacent_authority_first, feedback_thesis_gate_state_drift,
feedback_verify_thesis_claims, feedback_compiler_is_dag_processor,
feedback_foundation_over_speed)
## What this PR (#847) now contains (final state expected)
- R1 Closure Manager brief + ROADMAP registration + 6 lane worker briefs
(R1C-A through R1C-F) — full R1 closure dispatch surface
- §6a follow-through worker brief
- B5 / B6 / B7 (worker briefs + signal doc)
- Escalation-paths union map (45 clauses)
- Thesis-claim coverage map (74 claims, 0 GAPs)
- Authority matrix (5 categories + per-manager inventory + status-consistency
+ pre-author verification invariants)
- ROADMAP + r2-structure.md + design-substrate-carrier-port-program.md edits
R2 spin-up brief queue: complete. R1 closure brief queue: complete. PM inbox
#828 fully delivered.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix(briefs): correct R1C-A citations from self-review pass
Self-review pass against the matrix's pre-author verification invariant
caught two factual citation misses in r1c-a-t-testgen-schema-extensions-worker.md:
## BLOCKING — wrong file path for TestClaim schema (4 occurrences)
Brief cited `dsl/std/test_infrastructure.dag` and `src/v3/std/test_infrastructure.dag`
in 4 places (audit receipt at :17 + Sub-deliverable B framing at :61, :66 +
Slice PR-B at :87 + Cross-refs Schema authority at :119). That file does NOT
exist on main HEAD 407a8bc.
The actual TestClaim schema authority lives at:
- DSL-side: `dsl/std/verification.dag` (TestClaim at :36; full schema)
- v3-mirror: `src/v3/std/verification.dag` (TestClaim.requires at :187)
All 4 occurrences corrected to point at the real file. Schema authority
line in Cross-refs now also explicitly cites `dsl/std/verification.dag:36`
(DSL-side type declaration) for completeness.
## MINOR — predicate dispatch line range was off
Brief cited "Predicate dispatch inventory at test_runner.rs:1423-1431 has
all 10 predicates wired" — but lines 1423-1431 only contain 9 predicates
(Compiles through ExecuteCommand); MockBackedInvariant arm starts at
line 1432 and runs through 1448.
Corrected to: "in the match block at test_runner.rs:1424-1448 has all 10
predicates wired (Compiles / FailsWithDiagnostic / OutputEquals / PortHasState
/ CostBounded / LensOutputEquals / DifferentialEquals / AlgebraicLaw /
ExecuteCommand wired across :1424-1431; MockBackedInvariant arm at :1432-1448)."
## MINOR — ResourceReference line range corrected
Brief cited `src/v3/std/resources.dag:25-27` — actual range is :25-26 (the
type spans 2 lines, not 3). Corrected.
## Discipline note
Both misses were exactly the failure mode `feedback_verify_thesis_claims`
names: state cited from memory rather than grepped at brief-authoring time.
The pre-author audit was largely accurate (runner :1432-1448 quote was
exact; lower.rs:2446 diagnostic was exact; census line ranges all correct),
but two slips made it through. The matrix's pre-author verification invariant
worked at the self-review pass level — caught before automated reviewers.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation)
Director-authored amendment following the 2026-04-24 escalation from PR
#693 (sub-child sharp-bear-829 under Surface Manager).
Two edits:
1. New "Class 5 Gap 3 — port-carried field values in data bodies"
row in the 2026-04-21 post-merge-debt section. The substrate gap was
documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP
ledger row for cross-lane visibility. PR #693's execution surfaced it
as the blocker on sub_charclass_in_std_unicode phase-2.
2. Retract the "ready-to-dispatch (no substrate capability gap)" claim
on the Character-level row, annotate phase-1 landed via PR #693
(CharClass vocabulary + Rust-mirror structural scanner path), and
point phase-2 at the new Class 5 Gap 3 row.
Codifies the audit pattern: "this consumption gap has no substrate
capability gap" claims must be verified by attempting the retype before
the claim lands.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main
* docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review)
* docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review)
Row title still said 'consumption gap, not substrate gap' while the
body block retracted that claim and cited Class 5 Gap 3 as a substrate
dependency for phase-2. Title now matches body: mixed classification,
consumption for steps 1+3, substrate for step 2.
* docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit)
gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining
gap" description was wrong: field-level shapes (nested records, list
literals, declaration refs, Var refs, sum-variant literals) are
supported today via FieldValue variants + lower_structural_field_value
(dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the
top-level ValueBody boundary (non-scalar, non-record top-level bodies).
The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself
stale: it describes the pre-PR-B-unwind shape where FieldValue was
LiteralBits-only. PR-B's unwind extended FieldValue to carry
Reference / Record / List / Variant, moving the gap to ValueBody.
Two fixes:
1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody
boundary, point at code paths (dag.rs, lower.rs) as live authority,
flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass
blocker classification to "provisional pending reproduction."
2. Update the Character-level row's phase-2 block to name that the
specific shape of the CharClass failure needs concrete reproduction
from the escalating sub-child before the blocker is finalized.
Recursive audit-pattern instance: the row I wrote to codify "verify
live state before claiming substrate gap" itself failed to verify live
state. Both incidents (2026-04-23 original row + 2026-04-24 my
retraction row) are now cited in the audit-pattern sub-note as
examples of the same discipline.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* WIP: gunbc Director
* docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33
Three substantive fixes addressing internal-consistency gaps in the cascade
promotion PR caught by codex review at sha 0d6e7c33:
1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane
acceptance bullets and Hand-Rust census paragraph in line with the
updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero
(LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is
retracted under 0-floor with explicit migration to ExecuteCommand-based
.dag TestClaim declarations.
2. docs/design-pure-bootstrap-zero.md promotion section — converted from
future-tense ("This doc is PROPOSAL until promoted… promotion is a
single Director-authored cascade PR…") to historical past-tense
promotion-receipt framing ("This doc was PROPOSAL until promoted;
promotion was a single Director-authored cascade PR that did all of the
following atomically…"); blocking-clause struck through and resolved
inline. Banner cites PR #782 explicitly.
3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_
profile excluded (Map<String, AlgebraProfile> body, not list-of-sum;
needs distinct ValueBody::Map substrate work, tracked separately as a
future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass
phase-2 + Engine sharpened-(b) pilot enumeration), both sharing
list-of-sum substrate work. Lane table, dependency DAG, and capacity
summary updated for consistency (slot count 9-13, was 10-14).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities
Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade
self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22
explicitly names THESIS.md and "any other authority docs" as required
retraction targets; the prior diff updated ROADMAP + r2-structure + design
docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting-
manager.md pointing at the now-SUPERSEDED ≤5-floor framing.
Files:
- THESIS.md (5 prose blocks updated):
- :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests
migrate to ExecuteCommand-based .dag TestClaim declarations.
- :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag.
- :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor
target citing design-pure-bootstrap-zero.md as live authority;
hand_maintained_src list shrinks to empty set.
- :301-318 — Tests-are-structural-data block: residual carve-out retracted;
predicate name pb_rust_tests_outside_residual_zero retained as
housekeeping (semantically the residual is empty under cascade).
- docs/thesis/compiler-std-consolidation.md (5 references):
- Header link to design-pure-bootstrap-zero.md (LIVE) supersedes
design-pure-bootstrap.md (SUPERSEDED).
- :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process
lane named as the dissolution trigger for bootstrap.rs itself.
- :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md.
- :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority
re-cited.
- :185 Related docs link.
- docs/briefs/r1-selfhosting-manager.md (active dispatch brief):
- SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5);
T-PB-B residual carve-out retracted; predicate names retained for
housekeeping; cascade-promoted authorities are source of truth.
- Slice descriptions for T-PB-A / T-PB-B updated inline.
- Framing-question + ask updated to 0-floor / no-residual framing.
- Day-1 + up-to-director hand-off bullets updated.
- Working-state checklist :111 ≤5 → 0 with cite.
- Decisions log :164 ≤5 → 0-floor target updated.
- docs/r2-structure.md §2 design call (RETRACTED block):
- "Pre-promotion ≤5 irreducible-shim gate-name review" struck through
in entirety (both Option A sharpen-and-keep and Option B rename are
moot under 0-floor). Section preserved as audit-trail historical
context.
- Background-doc index: self-hosting anchor updated to
design-pure-bootstrap-zero.md as live authority.
- docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per
non-blocking suggestion):
- Banner cites cascade promotion PR #782 explicitly.
- New paragraph: "Treat all numeric floors below as retracted" with
explicit lines named that quote in isolation (table row, body prose
references). Prevents re-quoting from this doc as live authority.
Cascade is now atomically consistent across:
THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔
docs/thesis/compiler-std-consolidation.md ↔
docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔
docs/design-pure-bootstrap-zero.md (LIVE) ↔
docs/design-pure-bootstrap.md (SUPERSEDED).
The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds
genuinely.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(cascade-promotion): correct ExecuteCommand runner-capability claim
Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation):
TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138
overstated live runner capability — claimed runner support landed in
PR #688/#741 with "emit Rust, invoke rustc on output, check exit code"
as a structurally-equivalent migration path. Verified against live
sources:
- src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema
exists (declared via PR #678).
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5
testgen harness allowlists ONLY `command == "true" && args.is_empty()
&& expect_exit == 0`.
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 —
panics fail-closed on any other shape with explicit "ExecuteCommand
shell shape is not supported here (runner-owned — do not treat as
ordinary false)".
- src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no
match arm for ExecuteCommand; falls through to ClaimResult::
NotYetImplemented.
Reality: a TestClaim declaring rustc/python/go invocation is
structurally expressible as data today, but executing it is blocked.
Full arbitrary-command runner support is the PB-Runtime lane's
deliverable.
Files updated:
- TESTING.md:195 — capability state callout with file:line citations;
"Full runner support — arbitrary command + args (rustc/python/go) with
exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor
program)." Bullet about migration shape preserved as the cascade-named
successor pattern, not as a live capability.
- TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane
lands the ExecuteCommand runner extension" as an explicit precondition.
- docs/design-pure-bootstrap-zero.md:138 — same correction for the
matching prose, with PB-Runtime named as the runner-extension
dependency for boundary-test migration.
- ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner
foundation in #688/#741 with `true`-no-args allowlist only — full
arbitrary-command runner support deferred to PB-Runtime lane,
blocking the actual boundary-test migration." Dependencies column
extended to "DB-15 + T-TestGen + PB-Runtime".
The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still
holds for atomic-cascade-across-authority-docs; this commit closes the
remaining capability/claim mismatch flagged by codex.
(Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still
SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.)
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief
Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation).
The prior banner contained:
> "Operationally R1 closure may still ship before the 0-floor is reached
> — the ratchet ensures the trajectory; the gate's acceptance number is
> what shifts."
This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0.
Two competing gate semantics in the cascade is exactly what the
atomic-cascade clause forbids.
Replaced with single-authority-honest framing:
> "R1 closure now requires the 0-floor target by gate semantics: T-PB-A
> and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade
> promotion changed their acceptance numbers to 0; R1 cannot close
> while the SG-0 census carries non-zero hand-Rust."
Plus minor sharpening:
- "T-PB-A's non-test target is 0" → "non-test acceptance target is 0
per ROADMAP.md:67" (cite the authority).
- T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep
the capability-state honesty consistent with the recent fix wave.
- Predicate-rename housekeeping line moved into banner ("post-cascade
housekeeping, not a pre-promotion blocker") — was implicit before.
The brief now genuinely inherits the cascade-promoted gate; no
competing release authority.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): R2 second-wave worker-escalation fixes
Four substantive worker STOP-AND-ESCALATEs from briefs landed in
PR #797. All four worker recommendations correct; each needs a
Director call + brief update.
## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate
Worker correctly identified that brief req 2 (declared-effect carrier
as part of fn type signature, per feedback_no_annotations) requires
net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at
src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots.
Without parser surface, every user function would have
declared_effects = [] while inference returns non-empty — lens fires
EffectLeakageError everywhere on enable. Worker rejected power-through
and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map
parser split).
Director picked split:
- NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md
Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface
syntax + lookahead + body parser + lowerer extension + exhaustive-match
audit + coproduct dissolution receipt.
- MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to
post-parser-extension scope. Pre-flight check NOT a parser-extension
step; STOP if parser sub-lane PR not merged.
## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping
Worker found load-bearing evidence at infer.rs:3693-3703: DB-11
deliberately strips refinements at operator dispatch as a designed-in
fix for symmetric-operators failure mode. Brief's "attach where b != 0
as a proof for a / b" directly contradicts this design choice. STOP-3
(where-clause conflict with DB-11) is real; STOP-1 (substrate scope)
needs net-new substrate (per-operator partiality fact + predicate-
entailment check + asymmetric per-operand refinement-honoring) — M+
minimum. ownership_lens precedent in original brief is post-hoc
observability, not proof carrier.
Worker recommended redirect to design/scoping per nested-optional
precedent. Director picked redirect.
Brief fully rewritten as design/scoping with four-question structure:
(1) DB-11 interaction analysis; (2) substrate proposal for proof-or-
totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes
with acceptance-theatre risk on user-defined-total-wrapper-only);
(4) Director-actionable recommendation. Output is doc PR.
## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C)
Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int)
with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136
closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b)
i128 implementation requires either path 1 (hierarchy refactor —
contradicts non-goal) or path 2 (regen lie between substrate and
emit — violates discipline). Worker leaned option (C) re-scope:
land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke)
to a sibling sub-lane that does proper Int128/Word128 substrate work.
Director picked option (C). Brief req 1 re-scoped to drop canonical-
carrier-widening; lane value comes from range facts + reconciliation
narrowing + out-of-range diagnostic against existing i64. Req 4
explicitly deferred with sibling-sub-lane reference. Sibling sub-lane
NOT to be authored or implied in this PR; tracked separately.
## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change)
Worker correctly STOP'd per the brief's own pre-flight check: parser
sub-lane has not landed; SurfaceExpr::Map not on main. Director
authorized cross-lane reassignment: wise-boar-480 takes the parser
sub-lane (t-substrate-valuebody-map-parser-worker.md) since they
already have full investigation context. No brief changes needed; the
routing decision is in the dispatch.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope
Resolves codex P2 inline at sha e35103fad on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer
carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still
required widening LiteralBits::Int(i64) to an unbounded carrier and
passing the i64::MIN smoke. Internally unsatisfiable.
Fix:
- Slice section retitled "range facts + reconciliation narrowing
(against existing i64 carrier)" with explicit note about the
re-scope.
- Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly
forbids touching LiteralBits::Int shape, dag_scalar_generated.rs
regen for that variant, or tokenize i64 parse path.
- Slice steps 2-5 reframed: range facts use i64-representable
magnitudes; reconciliation narrowing uses existing i64 carrier;
diagnostic only for i64-representable out-of-range; smoke tests
for req 5 only (req 4 i64::MIN deferred).
- Acceptance checklist updated:
- Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as
re-scoped/deferred.
- LiteralBits::Int(i64) carrier untouched (no widening; no
parallel; no shape change).
- i64::MIN smoke marked DEFERRED with sibling-sub-lane reference.
- STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the
carrier" — explicit STOP if execution surfaces range-fact narrowing
requiring carrier-widening; that's the boundary the re-scope drew;
belongs in sibling Int128/Word128 sub-lane.
Brief now consistently treats carrier-widening as out-of-scope across
all sections.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty
Resolves codex BLOCKING #1 at sha e35103fa on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier
but req 2 required range facts using "the SAME magnitude carrier
as req 1" — meaning i64-typed range bounds. u64's max (2^64-1)
doesn't fit in i64; range fact for u64 would have to truncate,
omit, or mirror in Rust (representation drift). All three options
violate fail-closed declared-facts discipline (P1 / P3).
Fix:
- Req 2 rewritten to specify String-decimal representation:
range_min_inclusive: String + range_max_inclusive: String fields
on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127"
for i8; "0"/"18446744073709551615" for u64).
- Explicit reasoning why String-decimal: u64's max doesn't fit in
i64; binding range bounds to literal carrier forces truncation/
omission/mirror-drift; all violate fail-closed declared-facts
discipline.
- Bridge framing: String-decimal is pending the sibling Int128/
Word128 sub-lane; both range bounds and literal payload migrate
to typed carrier when that lands.
- Req 3 updated for String-decimal comparison semantics:
reconciliation parses both bounds and literal magnitude into a
common comparison space (i128 host comparison primitive — host
narrowing, NOT carrier widening). Bounded by what the i64-typed
literal can express; any i64-representable literal compares
against any width's String-decimal bound. Carrier discipline
preserved.
Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral)
is sha-stale — already resolved at 3e142d169.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed
Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback).
Real residual: req 2 specifies String-decimal range bounds (to cover
u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance
bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" /
"i64-representable magnitudes" for the range facts. Two incompatible
authorities for the same range-fact shape — would let a worker satisfy
the slice while truncating/omitting u64 bounds (P3 fail-closed
violation).
Fix:
- Line 31 (req 1 re-scope clarification): updated to explicitly state
"range facts (req 2) use String-decimal representation (width-
independent; covers u64::MAX which doesn't fit in i64)". Distinguished
literal *payload* (stays i64) from range-bound *representation*
(String) — both serve req 1's "no carrier widening" boundary.
- Line 44 (slice step 2): updated from "Range bounds use i64-
representable magnitudes" to "Range bounds use String-decimal
representation per req 2" with concrete example (u64 bounds).
- Acceptance bullet: updated from "Range facts on integer algebras
(substrate-declared, not Rust-mirrored)" to add "using String-decimal
representation ... width-independent; u64 bounds expressible without
truncation."
The brief now consistently treats range bounds as String-decimal
across req 2, req 3, slice, acceptance, and the req 1 clarification —
no remaining authorities saying i64-typed.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing
User + PM exchange 2026-04-25 surfaced that the in-flight effects
chain was importing wrong assumptions from external languages
(declared-effects-as-annotation + lens-vs-declaration check). Right
framing under gunbc's closed-system discipline is parallel to
complexity: every effect derives structurally from the composition
of typed primitive operations; nothing can hide because there's no
escape hatch; nothing needs annotation because the structure IS the
registry.
Four doc-only actions:
1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md.
Frames the closed-system answer with PM's 5-behavior synergy
table (Value/Transform/Branch/Loop/Bind as universal
compositional-fold pattern). Four worked examples; aggressive
reading on redundancy (compile-error-by-construction via
referential-transparency proof; reread() primitive for legitimate
cases); implementation-brief shape in §Q6.
2. SUPERSEDED banner on
docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md.
3. SUPERSEDED banner on
docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md.
Notes Fn→Arrow refactor brief stays dispatchable as independent
value.
4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by-
construction framing replaces lens-detection framing.
Memory file feedback_closed_system_effects.md saved separately;
cross-link added to feedback_construction_over_ratchets.md.
Net cost: doc-level cleanup. Zero substrate code rework. Foundation
(OperationEffect + service-call infrastructure + 5-behavior
substrate) already exists.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect
Per PM convergence review on #808 + user's deeper 2026-04-25 framing:
the closed-system framing landed in #808 retired the user-facing
annotation but kept OperationEffect taxonomy as substrate-level tagging.
User's deeper framing: the taxonomy ITSELF is parallel-representation —
operations are intrinsically read-shaped or write-shaped via their
TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns-
derived-value-only → read). Tagging operations with Read | Upsert |
Create | Append | Delete names what the structure already says.
Three changes:
1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as
normalized view, or retire as parallel-representation?"
- Two paths: (i) tags derived from signature shape (acceptable
normalized view) vs (ii) tags declared per-primitive (parallel-
representation; retire).
- Audit-as-existence-check (Q4 req 2 reframed): all effectful
primitives derive cleanly from signature shape → path (i); any
primitive needs hand-declared tag → path (ii) by existence proof.
- Director default: path (ii). Logging primitives that return Unit
are likely the audit's existence-proof.
- Two design-question resolutions: (a) external effects not in
return type → resource-threading discipline (typed param returned
modified, IO-monad-without-the-monad pattern); (b) transactional
grouping → derived structural fact from Bind composition + typed
transaction primitives.
2. Q4 reqs revised: req 2 from "tag every primitive with explicit
OperationEffect signature" to "audit-as-existence-check that every
primitive's type signature derives the right effect classification";
req 3 added (resource-threading discipline); req 6 added
(transactional-pattern lens). Req 1 (effects lens) anchors on
operation type-signature shape, not on hand-declared tags.
3. THESIS:345-347 amendment strengthened — "operations are
intrinsically read-shaped or write-shaped via their type-signature
shape; consumers walk the signatures directly; there is no parallel
taxonomy or annotation layer to declare or maintain. Tracking
effects as a separate enumerated concept IS the bug pattern,
dissolved by construction." Plus references to resource-threading
discipline + transactional grouping as derived structural fact.
Memory file feedback_closed_system_effects.md updated to reflect the
deeper framing (type-signature-shape, not taxonomy-tagging) +
resource-threading discipline section + transactional-patterns
section.
Net cost: doc-only delta on top of #808. Substrate retirement
(OperationEffect enum + derive_op_effect + idempotency.dag re-anchor)
deferred to the audit-as-existence-check phase of the implementation
brief; surfaced as Q5.5 OPEN CALL.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage
Resolves codex BLOCKING at sha d49ce79a on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real:
the prior text claimed service primitives "already carry typed effect
signatures" presenting future audit-state as current substrate fact
(P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the
OperationEffect line but left a parallel over-claim on the new
"signature-shape coverage" framing.
Fix: Q4 substrate-state listing rewritten to honestly distinguish:
- Live: Behavior enum + substrate foundation (the principle that
operations should carry signature shape).
- Incomplete: signature-shape coverage across actual primitives.
HTTP-derived primitives carry implicit shape via derive_op_effect's
method-table; logging/mutation primitives that return Unit or don't
thread their target resource do NOT carry the structural shape that
would express read-vs-write. Achieving full coverage is required
work under reqs 2 + 3, not a current fact.
- Pending audit-as-existence-check: OperationEffect + derive_op_effect
(path (i) vs (ii) per Q5.5).
Honest live-state callout added explicitly: "the closed-system
FOUNDATION (5 behaviors + DAG substrate + the principle that
operations should carry signature-shape) is live. The IMPLEMENTATION
COVERAGE across all effectful primitives is partial. Req 2 + req 3
are the work that closes the gap."
Brief now distinguishes principle-is-live (foundation) from
coverage-is-partial (audit work) without conflating them.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* WIP: gunbc Director
* docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim
Per PM follow-up review on #808 + user's stronger discipline framing
("substrate must make bypass structurally impossible at every layer
of the transport stack"): the closed-system claim is honest only when
typed primitives ARE the path. Today two structural holes exist where
bypasses sidestep the typed-primitive substrate. Both surfaced
explicitly as Q4.5 pre-conditions — load-bearing for the lens's
coverage claim.
Three changes:
1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed-
system claim)" inserted between Q4 and Q5:
P1 — Extdeps typed-primitive consumption structurally enforced.
Substrate must make `messages: Json` impossible to declare in
service definitions; typed `LlmMessage` / `ContentBlock` /
`GitHubAuthToken`-with-full-scopes are the only path. Tracked
debt at ROADMAP.md:153-154 (LLM provider flattening) +
`dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded).
Required prereq for full lens coverage; lens can land first +
surface structural-coverage-gap diagnostics on bypass surfaces
so the gap becomes visible rather than silent.
P2 — `ExecuteCommand` fully materialized as typed runner
primitive. TESTING.md (post-#782) committed to 0-residual but
ExecuteCommand isn't fully materialized; deleting Rust boundary
tests creates verification gap. Already named under PB-Runtime
in Zero-Floor; signal pending. Pre-requisite for ANY Rust
boundary-test deletion.
2. Old leftover duplicate Q5 section deleted (artifact from prior
Q5/Q5.5 reshape; second copy of asymmetric-tightening text was
in the file alongside the earlier Q5 instance).
3. Worker-discretion-vs-Director-call section in Q4.5: lens
implementation worker dispatchable now (reports gaps as
findings); P1 closure is substantive substrate work touching
extdeps (dedicated lane); P2 closure is PB-Runtime (signal
pending).
Net: design doc now honestly distinguishes principle-is-live
(Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs
named explicitly). The closed-system claim has explicit pre-
conditions documented; implementation brief discovers them as
known dependencies, not as STOP-AND-ESCALATEs.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default
Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two
real residuals after the Q5.5 reframe:
1. Q6's reqs/STOPs/acceptance still framed under path (i) — said
"audit + tag std/ primitives — every effectful primitive carries
an explicit OperationEffect signature." Directly contradicted Q4
(post-191be310b) + Q5.5's path (ii) default + the THESIS amendment
("there is no parallel taxonomy to declare or maintain"). Worker
reading Q6 in isolation would author the retracted shape.
2. Capacity / sequencing table line about "audit lane (tag std/
primitives with effect signatures)" carried the same stale
framing.
3. Q6 STOP "primitive performing side effects without an
OperationEffect tag" assumed tag-as-authority; under path (ii)
the STOP shape is "primitive whose signature doesn't structurally
reveal its effect."
Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale
(already fixed at f073aa95e Q4.5 commit).
## Q6 fixes
- Reqs renumbered + reframed:
- Req 1 anchors on operation type-signature shape (not hand-declared
OperationEffect tags); composition reads from signature shape per
Q2 table.
- Req 2 changed from "audit + tag every primitive" to
"audit-as-existence-check" — verify signature-shape coverage; ANY
primitive needing a hand-declared tag IS the existence-proof for
path (ii) retirement.
- Req 3 added: resource-threading discipline applied to existing
primitives (logging that returns Unit gets reshaped per audit).
- Req 6 added: transactional-pattern lens (Bind composition +
Transaction → Transaction').
- Req 7 added: asymmetric-tightening worked example in PR body
(per claude review observation; the one place declaration-shaped
surface re-enters).
- Req 8 (was 5): tests now reference signature-shape derivation
explicitly, not tag lookup.
- STOPs reframed:
- "OperationEffect retirement decision" — audit produces path (i)
vs (ii) verdict; substrate retirement is its own dedicated
sub-lane; this lane does NOT absorb it.
- Pure/impure carrier STOP notes that "pure" should also derive
from signature shape (pure functions don't return modified
resources) — so the STOP itself may dissolve under further design.
- Q4.5 P1 explicitly NOT a STOP — lens reporting structural-
coverage-gap on extdeps bypass surfaces is the lens delivering
its foundation-gap-visibility value.
- Q4.5 P2 explicitly independent — lens doesn't depend on
ExecuteCommand materialization.
- Acceptance extended: lens reports gap diagnostics on P1 bypass
surfaces; audit produces existence-proof verdict for Director
re-decision; asymmetric-tightening worked example in PR body.
## Capacity / sequencing table
Replaced "1 audit lane (tag std/ primitives with effect signatures)"
with "1 audit-as-existence-check lane (verify primitives' signature-
shape coverage; NOT 'tag every primitive') — produces the path (i)
vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2
prereq lanes to the net summary. Closing line: "The taxonomy-
retirement scope (substrate-side) is not in this lane — it's
surfaced by audit and routed to dedicated retirement lane if path
(ii) wins."
Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity
table. Worker reading Q6 in isolation now sees path-(ii)-default
framing matching Q4 + Q5.5 + THESIS amendment.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792
Resolves codex inline BLOCKING at sha 191be310 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150.
Real: my Q4.5 P2 framing described ExecuteCommand as still
NotYetImplemented (M1.5 allowlist + Rust TestRunner returning
NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand
extension before this PR's authoring. TESTING.md:195 capability-state
callout confirms:
- Rust TestRunner + M1.5 testgen harness share one std::process path
for arbitrary command + args + expect_exit_code.
- M1.5 allowlist + fail-closed panic retired.
- Distinguishable ClaimResult::Fail messages for spawn / timeout /
policy / exit-mismatch.
- Linux unshare(1) namespace isolation on host-allowing systems.
- T-PB-B-1 boundary migration example landed.
Fix:
P2 section rewritten:
- Header retitled "ExecuteCommand runner primitive: LANDED (PR #792);
residual is bulk-migration."
- Status update naming PR #792 + the post-#792 capability state
(allowlist retired, etc.).
- Honest acknowledgement: "My earlier P2 framing was stale."
- Residual narrowed to bulk-migration of existing Rust Command::new
boundary tests (tracked as ROADMAP residual, not lens prereq).
- Sequencing reframed: P2 was always orthogonal to the effects lens
itself; bulk migration proceeds at its own pace; lens not blocked.
Q4.5 footer updated:
- "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via
#792; only consumer-side bulk migration remains)"
- Worker-discretion-vs-Director-call P2 line updated: "runner
primitive landed; only consumer-side bulk migration remains;
tracked as ROADMAP residual, independent of the lens."
Q6 STOP for P2 updated:
- "the lens itself doesn't depend on P2; only TESTING.md's 0-residual
claim does" → "runner primitive landed via PR #792 (post-Q4.5-
authoring update). The lens itself never depended on P2; bulk
consumer migration is residual ROADMAP work and remains independent
of this lane."
Brief now reflects live state. The closed-system claim's prereq
landscape is honest:
- P1 (extdeps typed-primitive consumption): real prereq, tracked
debt at ROADMAP:153-154.
- P2 (ExecuteCommand runner): satisfied via #792; bulk migration is
consumer-side residual, not foundation work.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale
Resolves codex non-blocking finding at sha bcac41bb on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real
residual: capacity-table line still listed P2 as "`ExecuteCommand`
materialization" prereq + framed both P1 and P2 as "pre-existing
tracked-debt" — but my prior 57a9b1318 fix established that PR #792
already landed the runner primitive, so P2 is no longer a
materialization prereq.
Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq)
from P2 (residual, not prereq):
- P1: extdeps typed-primitive consumption — pre-existing tracked
debt at ROADMAP:153-154; load-bearing for the lens's full-coverage
claim.
- P2: ExecuteCommand runner primitive landed via PR #792; only
consumer-side bulk migration of existing Rust Command::new
boundary tests remains (tracked as ROADMAP residual, independent
of the lens; not a materialization prereq).
Brief now consistently treats P2 as bulk-migration-residual across:
- §Q4.5 P2 section header (LANDED via PR #792; residual is
bulk-migration).
- §Q4.5 footer (P2: runner primitive landed; only consumer-side
bulk migration remains).
- Q6 STOP for P2 (runner primitive landed; bulk migration is
residual ROADMAP work).
- §Capacity / sequencing impact (P2 as residual, not prereq).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349
Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated
target-grounding prose; the matching extdeps typed-primitive bypass
entries (LLM service flattening, GitHub auth model bypass) live at
ROADMAP.md:348-349.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(effects-design): fix third stale ROADMAP citation at line 271
Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence
at line 271 in the §Q4.5 capacity table. Now consistent with lines
139 and 173 (ROADMAP.md:348-349).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity
Codex flagged 'Effect-signature tagging on std/ primitives' as potentially
contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240)
already explicitly say 'NOT tag every primitive' — but the cross-manager
line used sloppy wording. Reworded to make explicit that the audit walks
signature shape; no parallel tag added.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5
- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)
B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).
B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B1 — drop incoherent inner-fallback non-goal
Codex P2: the non-goal line excluding the inner declaration().name
unwrap_or_else fallback contradicted Slice step 2, which replaces the
whole chain with let-Some-else-return. Both fallbacks are in scope by
construction; remove the contradictory non-goal.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives
PM REQUEST_CHANGES: §Frame listed '4 type connectives
(Conjunction | Disjunction | Cardinality | Bit)' which contradicted
the canonical thesis source. Replaced with the canonical 6
(Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per
docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary
closes here'. Also removed 'typed substrate carriers' from the
vocabulary list — substrate carriers are defined using the vocabulary,
not part of it. Added a clarifying note that B4's carriers
(DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are
typed declarations composed from the vocabulary, not vocabulary
extensions.
Per feedback_verify_thesis_claims: brief framings citing thesis
structure must ground in the canonical source.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority
Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of
naming the live substrate authority. Two coordinated fixes:
1. §Read first cites src/v3/std/substrate.dag (live .dag substrate
authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel
meta-type — already exists with consumers in verification.dag,
emit_model.dag, python.dag).
2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing
DeclarationRef'. The work is consumer migration + any role-extension
layer the audit reveals, NOT designing or landing the carrier.
Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers)
keep their 'new' framing but explicitly require sub-briefs to grep
src/v3/std/ + src/v3/spec/ for existing authority before authoring
'design and land' framing — per feedback_verify_thesis_claims +
feedback_emitter_workaround_is_gap_symptom.
Acceptance + sub-brief dispatch order updated to reflect B4.1's
consumer-migration shape.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B4 — tighten Phase 1 umbrella sentence
The umbrella 'Land the typed carriers into src/v3/std/' framing was
stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced
with audit-first wording that covers both the consume-existing case (#1)
and the design-and-land case (#2-#4 if their audits show real gaps).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording
Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands'
which conflicted with the post-reframe reality that B4.1 consumes the
existing DeclarationRef. Updated to 'consumes or lands' with explicit
existing-authority citation and audit-pending caveat for B4.2-B4.4.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B1 — soften regression-test requirement (3 worker bounces)
Three consecutive B1 worker dispatches (zesty-crane-890 cursor →
valiant-boar-498 codex → cool-lynx-395 cursor) archived without
opening a PR. Likely friction point: brief Slice step 4 asks for a
unit test that constructs a Dag with an orphan variant declaration,
but emit.rs has zero existing #[test] precedent — emit testing
happens via integration fixtures. Workers see 'build novel test
harness' inside what's billed as an S-scope fix and bounce.
Per feedback_construction_over_ratchets: when a brief has friction,
fix the brief, don't ratchet the worker.
Softened step 4 + acceptance: regression test stays optional. If
test setup requires novel scaffolding, route the gap to follow-up.
The structural fail-closed at step 2 is the load-bearing change.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt
PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description'
is too weak; PR descriptions don't survive squash-merge cleanly.
Two coordinated edits:
1. Slice step 4 — explicit substrate-signal framing: skipped test
means emit-side hermetic-unit-test infrastructure is the missing
substrate (feedback_emitter_workaround_is_gap_symptom).
2. Acceptance — require ROADMAP debt row (new or existing) with
named dissolution trigger, referenced in PR body. Converts the
skip from PR-local note (transient) into tracked debt (durable,
dispatchable).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124
Codex BLOCKING: my earlier softening claimed emit.rs had no #[test]
precedent — wrong. The module has #[cfg(test)] mod tests at line 3124
with 12+ tests using compile_to_dag(source, filename) as harness
(e.g., go_struct_fields_render_with_separators :3143,
shared_walk_to_disj_finds_match_scrutinee_sum_type :3195).
This is a feedback_verify_thesis_claims violation on Director-side
brief authoring — claim made without grep verification.
Fix: restore step 4 as required, with explicit precedent citation.
Worker constructs the failure case via the existing harness
(direct Dag, fixture string, or BranchPattern exercise; worker's
call on cleanest path). STOP-AND-ESCALATE only if construction
proves materially harder than precedent suggests, in which case
that escalation surfaces a real substrate gap and warrants ROADMAP
debt — but the default is 'add the test.'
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites)
Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but
emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded
to 'several using compile_to_dag'.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue
Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this
is Wave 1 of Director's 14-brief authoring queue, covering B4 program
internals.
Authored:
- b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) —
replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag")
fold-skip with structural template-formal carrier; mandatory
authority audit per feedback_audit_adjacent_authority_first.
- b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) —
replaces §0.6 emit.rs bind/branch.span.file equality with typed
BindEmitParticipation/BranchEmitParticipation roles populated at
lowering; aligned with #824 worker's in-flight implementation shape.
- b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4
of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with
typed substrate authority; explicit pre-promotion-constraint
disposition (single-authority vs authority+tracked-debt) addresses
parallel-representation risk surfaced on #825.
- b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) —
names B4.5-B4.12 Phase 2 sites with carrier dependencies,
cross-program coordination notes, and skeleton-brief template;
full per-site briefs author at dispatch time per #827's
Substrate Manager ownership.
Cross-cutting discipline applied per inbox #828 reply:
- feedback_audit_adjacent_authority_first (mandatory grep before design)
- feedback_no_textual_enforcement_bridges (no replacement sentinels)
- feedback_parallel_representation_debt (explicit if shape (b))
- feedback_construction_over_ratchets (no parity-by-runtime as primary)
- feedback_coproduct_dissolution (receipts for new variants)
Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling
worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* WIP: gunbc Director
* docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3)
Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue.
Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by
Modeling Manager's Wave 3 worker briefs (gated on these landing).
Authored:
- r2-substrate-cardinality-for-int-lit-subset.md (M) — produces
magnitude carrier consumed by T-Modeling int-lit. Coordinates with
PR #806's prior cardinality work; mandatory authority audit guards
against #796's rejected IntLiteralMagnitude shape resurfacing.
Open design questions: magnitude representation, reconciliation
narrowing point, i64::MIN representability.
- r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces
nominal-opacity carrier consumed by T-Modeling Secret<T>. Open
design questions: carrier shape (flag/connective/sealed-accessor),
generic-walk discipline, accessor gating.
- r2-substrate-parametric-algebra-for-dimensions-subset.md (M) —
produces phantom-parameter carrier consumed by T-Modeling
Dimension<Carrier>. Open design questions: carrier shape,
type-equivalence rule, algebra-method dispatch, lifting/coercion.
All three:
- Scoped narrowly to their paired R2 consumer; not full
substrate-capability lanes.
- Mandatory pre-author authority audit per
feedback_audit_adjacent_authority_first.
- Cross-program readiness signal pattern from #827's manager rework.
- Coproduct dissolution receipts required for any new variants.
- Open design questions surfaced explicitly so Substrate Manager
(or Director pre-spin-up) can resolve at dispatch time.
Wave 3 (T-Modeling worker briefs × 4) follows.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4)
Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue.
Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each
gated on a Substrate Manager readiness signal (Wave 2 producers).
Authored:
- r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2
cardinality-for-int-lit; moves narrowing from tokenizer to
reconciliation; MagnitudeOutOfRange diagnostic per C-8.
- r2-modeling-secret-graduation-worker.md — gated on Wave 2
nominal-opaque-for-Secret; authors Secret<T> + gated accessors
(redact, compare_in_constant_time); C-8 diagnostic on non-gated
access; signals Impossible-Bugs Manager on close (thesis claim
covered).
- r2-modeling-dimensions-phantom-worker.md — gated on Wave 2
parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier>
+ core SI base units + algebra-method dispatch; cross-dimension
arithmetic produces typed diagnostic; signals Impossible-Bugs
Manager (thesis claim).
- r2-modeling-tokenizer-charclass-phase2-worker.md — gated on
T-Substrate ValueBody-list/sum (#790); migrates tokenizer
consumers to Char/List<Char>/CharClass canonical types; sibling
consumer to Grounding Manager's Engine sharpened-(b).
All four:
- Explicit gating: 'do not dispatch until producer signal posts.'
- Producer/consumer signal pattern from #827.
- Cross-program signals to R2 Release Manager (Goal 2 closure)
and Impossible-Bugs Manager (thesis-claim coverage).
- Spoofing regression tests: discipline anchor against
feedback_no_textual_enforcement_bridges.
Wave 4 (T-ImpossibleBugs worker briefs × 3) follows.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3)
Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue.
Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes,
consuming the existing design/scoping briefs as authority.
Authored:
- r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on
cardinality refinement substrate (T-Substrate territory adjacent
to int-lit / DB-11 alias-where). Implementation: structural normalize
of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T??
worker decision (reject vs normalize). Cites
t-impossiblebugs-nested-optional-flatten-design.md as authority.
- r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated
on Tier 2 substrate (predicate-entailment infrastructure; distinct
from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes
predicate entailment, (b) feedback_totality_by_omission dissolves
partial primitives, (c) park. Worker decides at audit time. Cites
t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority.
- r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate
prerequisite per closed-system framing in design doc (#808). Audit-
as-existence-check + lens implementation as compositional fold over
5 behaviors; redundancy detection compile-error via referential
transparency + reread() escape hatch; path (i/ii) decision on
OperationEffect taxonomy retain-vs-retire (default retire). Cites
design doc #808 as authority.
Cross-cutting:
- Each cites prior design/scoping brief as authority (the existing
*-design.md / *-worker.md REFRAMED files).
- Explicit gating per #827 producer/consumer signal pattern; two
briefs gated on substrate, one NOT gated (closed-system).
- STOP-AND-ESCALATE includes 'design brief assumptions don't hold'
surfacing per feedback_thesis_gate_state_drift.
Wave 4 complete. Director's 14-brief queue done; awaiting PM portion
(6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): B4.4 — tighten Slice §3 per PM review on #836
PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b)
(authority + tracked debt parallel-rep) as autonomously acceptable
contradicts feedback_construction_over_ratchets +
feedback_parallel_representation_debt.
Tightened:
- Shape (a) is the only autonomous worker path.
- Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a
regen-host-loader sub-lane decision; not authorable without explicit
Substrate Manager approval citation in the PR body.
- Acceptance bullet requires the approval citation when shape (b)
lands.
- STOP-AND-ESCALATE rephrased to make this explicit; permanent
parallel-representation re-escalates even with manager approval.
This preserves shape (a) as autonomous; shape (b) becomes a
cross-manager design escalation, not a B4.4 implementation call.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief
Cursor review on #836 flagged the Read-first reference to
.claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md
as machine-specific (outside the repo, not resolvable from a normal
clone). Replaced with in-repo prose pointing at the design doc's
§Q1-Q3 as canonical authority — the discipline lives there in-repo.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs)
Codex flagged: src/v3/std/types.dag does not exist; the canonical
authority is at dsl/std/types.dag. Affected briefs (all from R2
spin-up Wave 2 + Wave 3):
- r2-substrate-cardinality-for-int-lit-subset.md
- r2-substrate-nominal-opaque-for-secret-subset.md
- r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs)
- r2-modeling-dimensions-phantom-worker.md
- r2-modeling-secret-graduation-worker.md
feedback_verify_thesis_claims violation on Director-side brief
authoring — assumed path without grep. Same family of error as
the earlier emit.rs precedent claim. Mass-replaced via perl;
verified no remaining stale refs.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant
Codex BLOCKING on #836: my R2 worker brief gated nested-optional on
cardinality refinement substrate, but the design doc verifies v3 is
ALREADY past the cardinality bridge — TypeConnective::Cardinality
is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is
the carrier for Option. The dissolution is an UNGATED implementation
via substrate-constructor invariant.
feedback_verify_thesis_claims violation again — should have read the
design doc fully before assuming the substrate gate.
Rewrote brief to match design doc canonical sketch:
- Single predicate (cardinality_idempotent_target) owns the rule
- Single allocator (alloc_cardinality_decl) is THE substrate-constructor
- API closure on TypeConnective::Cardinality payload (modeling-discipline
practice 6) — variant cannot be struct-init'd outside the allocator
- 3 hand-Rust + ~22 codegen call sites enumerated per design audit
- infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as
the killer case for generic-instantiation paths
- Surface-syntax T?? decision left to worker (Director-lean: silent
normalize)
Brief now dispatchable immediately, no producer signal needed.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation
Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment
substrate path, but the design doc §4 explicitly recommends totality-by-
omission as the Director-actionable path. Predicate-entailment is M+ scope
that reopens DB-11's explicitly-closed asymmetric-strip design — design
doc explicitly discards it.
feedback_verify_thesis_claims violation again — same family as nested-
optional reframe. Should have read design doc §4 in full before assuming
the path ordering.
Rewrote brief to match design doc §4 follow-on shape:
- Primary path: per-class totality-by-omission (algebra retype + per-
target realization migration). For Int/Int: OrderedRing.div retype
at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 /
python:486 + python_target.rs:680 helper).
- NOT predicate-entailment (out of scope; M+ + DB-11 reopen).
- NOT NonZero-typed-input (deferred to separate per-operand-variance
substrate brief; STOP-AND-ESCALATE if chosen).
- Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i]
indexing, quotient, remainder) queue separately per design doc audit.
- feedback_totality_by_omission discipline anchor explicit.
Brief now matches feedback_totality_by_omission discipline + design doc
recommendation. No substrate prerequisite; dispatchable immediately.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure
Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a
pattern: I authored R2 worker briefs without fully reading each design
doc's Director-actionable recommendation. Pre-emptively re-verified
unenumerated-effects against design doc §Q6 to catch the same family
of error before reviewers do.
Findings: brief was substantively close but missing 3 of 8 design-doc
reqs:
- Req 3: Resource-threading discipline applied to existing primitives
- Req 5: reread(key) primitive in std/ as explicit Slice item (was
only mentioned in tests)
- Req 7: Asymmetric-tightening worked example in PR body
Plus: Slice didn't cite the canonical lens path
src/v3/lenses/effect_enumeration.dag from design doc.
Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6
specifies 4 specific STOPs (path-decision-escalation, pure: Bool
carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP)
that I had elided.
Reframed Slice as 8 numbered reqs matching design doc verbatim;
STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs;
Acceptance enumerated per req.
This is the third reframe in the unhandled-bugs series — same
feedback_verify_thesis_claims violation each time. The pattern
suggests Director-side R2 brief authoring should ALWAYS read each
design doc's §Director-actionable / §Q-recommendation in full first,
not assume.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options
Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)"
listed as a worker-pick option violates THESIS.md substrate-shape
lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality |
Instantiation) are canonical (per #811 thesis additions and #827 PM
review); a 7th is a C1 stop signal requiring failed-dissolution
evidence + Director substrate-design call, not autonomous worker pick.
Removed the "new TypeConnective variant" option; replaced with
`inhabits`-edge-shape carrier as third option (audit-time check). The
explicit STOP-AND-ESCALATE clause now states: 7th connective is the
precondition for failed-dissolution-evidence + Director substrate-design
call, not a worker path.
feedback_verify_thesis_claims still in play — should have grounded
substrate-shape options against the THESIS lock before listing Opaque(T)
as worker-autonomous. Pattern continues; reading source-of-truth before
authoring options is the discipline.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place)
Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter
already exist at dag.rs:186, :217 — explicitly authored for the
R2 Dimensions consumer per the doc comment at dag.rs:148-160.
phantom_unit_mismatch already wired at infer.rs:1057, :1132. The
substrate is fully landed; my brief framing it as 'producer sub-lane
to land carrier' is wrong on the same feedback_audit_adjacent_authority_first
violation that hit nested-optional / unhandled-diagnostic / unenumerated-
effects.
Reframed the substrate-side brief as no-op / closed-by-audit:
- Documents the audit receipt (5 sites confirming substrate exists)
- States the lane is closed
- Routes T-Modeling Dimensions consumer to dispatch immediately
against the existing carrier
- Records the lesson: 'always grep substrate before authoring
producer briefs' — discipline doesn't end at brief boundaries.
Updated r2-modeling-dimensions-phantom-worker.md correspondingly:
- Changed gating from 'do not dispatch until producer signal' to
'NOT GATED — dispatch immediately'
- Read-first updated with concrete dag.rs/infer.rs cites
- Slice §1 changed from 'confirm producer signal' to 'verify
substrate at HEAD'
- STOP reframed: existing carrier extension would need Substrate
Manager call, not autonomous worker pick
Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit
both verified — no existing substrate (no is_nominal_opaque /
MagnitudeBound patterns in dag.rs); both still legitimately
producer-side work.
Pattern is now four reframes deep on the R2 spin-up wave. The lesson
saved is structural: read source-of-truth before authoring options.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority
Codex BLOCKING on #836: my new R2 spin-up brief duplicates the
existing t-substrate-cardinality-int-lit-worker.md, which carries
the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64)
stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane).
Single-authority violation per INVARIANTS P2.
Same feedback_audit_adjacent_authority_first failure as parametric-
algebra-for-Dimensions reframe (4 hours ago): assumed substrate
authority didn't exist; should have grepped docs/briefs/ before
authoring. This is the SECOND R2 spin-up substrate brief closed
as redundant — the discipline lesson is structural.
Reframed brief as no-op routing doc (documents the audit receipt;
routes consumers to the existing authority); updated
r2-modeling-int-lit-magnitude-worker.md to cite
t-substrate-cardinality-int-lit-worker.md instead.
Pattern across the R2 spin-up wave reframes (5 now):
1. nested-optional gating-on-substrate (substrate already past
cardinality bridge)
2. unhandled-diagnostic predicate-entailment default (design doc
recommends totality-by-omission)
3. unenumerated-effects 8-req design-doc elision
4. parametric-algebra Producer (Declaration.phantom_params already
authored explicitly for this consumer)
5. cardinality-for-int-lit Producer (existing brief is authority)
All five are 'assumed state without grep before authoring'. Future
R2 subs…
…+ reflection completeness + Q6.5 two-layer diagnostic-kind) (#1129) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c33: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 second-wave worker-escalation fixes Four substantive worker STOP-AND-ESCALATEs from briefs landed in PR #797. All four worker recommendations correct; each needs a Director call + brief update. ## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate Worker correctly identified that brief req 2 (declared-effect carrier as part of fn type signature, per feedback_no_annotations) requires net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots. Without parser surface, every user function would have declared_effects = [] while inference returns non-empty — lens fires EffectLeakageError everywhere on enable. Worker rejected power-through and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map parser split). Director picked split: - NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface syntax + lookahead + body parser + lowerer extension + exhaustive-match audit + coproduct dissolution receipt. - MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to post-parser-extension scope. Pre-flight check NOT a parser-extension step; STOP if parser sub-lane PR not merged. ## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping Worker found load-bearing evidence at infer.rs:3693-3703: DB-11 deliberately strips refinements at operator dispatch as a designed-in fix for symmetric-operators failure mode. Brief's "attach where b != 0 as a proof for a / b" directly contradicts this design choice. STOP-3 (where-clause conflict with DB-11) is real; STOP-1 (substrate scope) needs net-new substrate (per-operator partiality fact + predicate- entailment check + asymmetric per-operand refinement-honoring) — M+ minimum. ownership_lens precedent in original brief is post-hoc observability, not proof carrier. Worker recommended redirect to design/scoping per nested-optional precedent. Director picked redirect. Brief fully rewritten as design/scoping with four-question structure: (1) DB-11 interaction analysis; (2) substrate proposal for proof-or- totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes with acceptance-theatre risk on user-defined-total-wrapper-only); (4) Director-actionable recommendation. Output is doc PR. ## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C) Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int) with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136 closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b) i128 implementation requires either path 1 (hierarchy refactor — contradicts non-goal) or path 2 (regen lie between substrate and emit — violates discipline). Worker leaned option (C) re-scope: land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke) to a sibling sub-lane that does proper Int128/Word128 substrate work. Director picked option (C). Brief req 1 re-scoped to drop canonical- carrier-widening; lane value comes from range facts + reconciliation narrowing + out-of-range diagnostic against existing i64. Req 4 explicitly deferred with sibling-sub-lane reference. Sibling sub-lane NOT to be authored or implied in this PR; tracked separately. ## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change) Worker correctly STOP'd per the brief's own pre-flight check: parser sub-lane has not landed; SurfaceExpr::Map not on main. Director authorized cross-lane reassignment: wise-boar-480 takes the parser sub-lane (t-substrate-valuebody-map-parser-worker.md) since they already have full investigation context. No brief changes needed; the routing decision is in the dispatch. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope Resolves codex P2 inline at sha e35103fad on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still required widening LiteralBits::Int(i64) to an unbounded carrier and passing the i64::MIN smoke. Internally unsatisfiable. Fix: - Slice section retitled "range facts + reconciliation narrowing (against existing i64 carrier)" with explicit note about the re-scope. - Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly forbids touching LiteralBits::Int shape, dag_scalar_generated.rs regen for that variant, or tokenize i64 parse path. - Slice steps 2-5 reframed: range facts use i64-representable magnitudes; reconciliation narrowing uses existing i64 carrier; diagnostic only for i64-representable out-of-range; smoke tests for req 5 only (req 4 i64::MIN deferred). - Acceptance checklist updated: - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as re-scoped/deferred. - LiteralBits::Int(i64) carrier untouched (no widening; no parallel; no shape change). - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference. - STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the carrier" — explicit STOP if execution surfaces range-fact narrowing requiring carrier-widening; that's the boundary the re-scope drew; belongs in sibling Int128/Word128 sub-lane. Brief now consistently treats carrier-widening as out-of-scope across all sections. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty Resolves codex BLOCKING #1 at sha e35103fa on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier but req 2 required range facts using "the SAME magnitude carrier as req 1" — meaning i64-typed range bounds. u64's max (2^64-1) doesn't fit in i64; range fact for u64 would have to truncate, omit, or mirror in Rust (representation drift). All three options violate fail-closed declared-facts discipline (P1 / P3). Fix: - Req 2 rewritten to specify String-decimal representation: range_min_inclusive: String + range_max_inclusive: String fields on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127" for i8; "0"/"18446744073709551615" for u64). - Explicit reasoning why String-decimal: u64's max doesn't fit in i64; binding range bounds to literal carrier forces truncation/ omission/mirror-drift; all violate fail-closed declared-facts discipline. - Bridge framing: String-decimal is pending the sibling Int128/ Word128 sub-lane; both range bounds and literal payload migrate to typed carrier when that lands. - Req 3 updated for String-decimal comparison semantics: reconciliation parses both bounds and literal magnitude into a common comparison space (i128 host comparison primitive — host narrowing, NOT carrier widening). Bounded by what the i64-typed literal can express; any i64-representable literal compares against any width's String-decimal bound. Carrier discipline preserved. Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral) is sha-stale — already resolved at 3e142d169. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback). Real residual: req 2 specifies String-decimal range bounds (to cover u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" / "i64-representable magnitudes" for the range facts. Two incompatible authorities for the same range-fact shape — would let a worker satisfy the slice while truncating/omitting u64 bounds (P3 fail-closed violation). Fix: - Line 31 (req 1 re-scope clarification): updated to explicitly state "range facts (req 2) use String-decimal representation (width- independent; covers u64::MAX which doesn't fit in i64)". Distinguished literal *payload* (stays i64) from range-bound *representation* (String) — both serve req 1's "no carrier widening" boundary. - Line 44 (slice step 2): updated from "Range bounds use i64- representable magnitudes" to "Range bounds use String-decimal representation per req 2" with concrete example (u64 bounds). - Acceptance bullet: updated from "Range facts on integer algebras (substrate-declared, not Rust-mirrored)" to add "using String-decimal representation ... width-independent; u64 bounds expressible without truncation." The brief now consistently treats range bounds as String-decimal across req 2, req 3, slice, acceptance, and the req 1 clarification — no remaining authorities saying i64-typed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing User + PM exchange 2026-04-25 surfaced that the in-flight effects chain was importing wrong assumptions from external languages (declared-effects-as-annotation + lens-vs-declaration check). Right framing under gunbc's closed-system discipline is parallel to complexity: every effect derives structurally from the composition of typed primitive operations; nothing can hide because there's no escape hatch; nothing needs annotation because the structure IS the registry. Four doc-only actions: 1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md. Frames the closed-system answer with PM's 5-behavior synergy table (Value/Transform/Branch/Loop/Bind as universal compositional-fold pattern). Four worked examples; aggressive reading on redundancy (compile-error-by-construction via referential-transparency proof; reread() primitive for legitimate cases); implementation-brief shape in §Q6. 2. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md. 3. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md. Notes Fn→Arrow refactor brief stays dispatchable as independent value. 4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by- construction framing replaces lens-detection framing. Memory file feedback_closed_system_effects.md saved separately; cross-link added to feedback_construction_over_ratchets.md. Net cost: doc-level cleanup. Zero substrate code rework. Foundation (OperationEffect + service-call infrastructure + 5-behavior substrate) already exists. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect Per PM convergence review on #808 + user's deeper 2026-04-25 framing: the closed-system framing landed in #808 retired the user-facing annotation but kept OperationEffect taxonomy as substrate-level tagging. User's deeper framing: the taxonomy ITSELF is parallel-representation — operations are intrinsically read-shaped or write-shaped via their TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns- derived-value-only → read). Tagging operations with Read | Upsert | Create | Append | Delete names what the structure already says. Three changes: 1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as normalized view, or retire as parallel-representation?" - Two paths: (i) tags derived from signature shape (acceptable normalized view) vs (ii) tags declared per-primitive (parallel- representation; retire). - Audit-as-existence-check (Q4 req 2 reframed): all effectful primitives derive cleanly from signature shape → path (i); any primitive needs hand-declared tag → path (ii) by existence proof. - Director default: path (ii). Logging primitives that return Unit are likely the audit's existence-proof. - Two design-question resolutions: (a) external effects not in return type → resource-threading discipline (typed param returned modified, IO-monad-without-the-monad pattern); (b) transactional grouping → derived structural fact from Bind composition + typed transaction primitives. 2. Q4 reqs revised: req 2 from "tag every primitive with explicit OperationEffect signature" to "audit-as-existence-check that every primitive's type signature derives the right effect classification"; req 3 added (resource-threading discipline); req 6 added (transactional-pattern lens). Req 1 (effects lens) anchors on operation type-signature shape, not on hand-declared tags. 3. THESIS:345-347 amendment strengthened — "operations are intrinsically read-shaped or write-shaped via their type-signature shape; consumers walk the signatures directly; there is no parallel taxonomy or annotation layer to declare or maintain. Tracking effects as a separate enumerated concept IS the bug pattern, dissolved by construction." Plus references to resource-threading discipline + transactional grouping as derived structural fact. Memory file feedback_closed_system_effects.md updated to reflect the deeper framing (type-signature-shape, not taxonomy-tagging) + resource-threading discipline section + transactional-patterns section. Net cost: doc-only delta on top of #808. Substrate retirement (OperationEffect enum + derive_op_effect + idempotency.dag re-anchor) deferred to the audit-as-existence-check phase of the implementation brief; surfaced as Q5.5 OPEN CALL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage Resolves codex BLOCKING at sha d49ce79a on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real: the prior text claimed service primitives "already carry typed effect signatures" presenting future audit-state as current substrate fact (P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the OperationEffect line but left a parallel over-claim on the new "signature-shape coverage" framing. Fix: Q4 substrate-state listing rewritten to honestly distinguish: - Live: Behavior enum + substrate foundation (the principle that operations should carry signature shape). - Incomplete: signature-shape coverage across actual primitives. HTTP-derived primitives carry implicit shape via derive_op_effect's method-table; logging/mutation primitives that return Unit or don't thread their target resource do NOT carry the structural shape that would express read-vs-write. Achieving full coverage is required work under reqs 2 + 3, not a current fact. - Pending audit-as-existence-check: OperationEffect + derive_op_effect (path (i) vs (ii) per Q5.5). Honest live-state callout added explicitly: "the closed-system FOUNDATION (5 behaviors + DAG substrate + the principle that operations should carry signature-shape) is live. The IMPLEMENTATION COVERAGE across all effectful primitives is partial. Req 2 + req 3 are the work that closes the gap." Brief now distinguishes principle-is-live (foundation) from coverage-is-partial (audit work) without conflating them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim Per PM follow-up review on #808 + user's stronger discipline framing ("substrate must make bypass structurally impossible at every layer of the transport stack"): the closed-system claim is honest only when typed primitives ARE the path. Today two structural holes exist where bypasses sidestep the typed-primitive substrate. Both surfaced explicitly as Q4.5 pre-conditions — load-bearing for the lens's coverage claim. Three changes: 1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed- system claim)" inserted between Q4 and Q5: P1 — Extdeps typed-primitive consumption structurally enforced. Substrate must make `messages: Json` impossible to declare in service definitions; typed `LlmMessage` / `ContentBlock` / `GitHubAuthToken`-with-full-scopes are the only path. Tracked debt at ROADMAP.md:153-154 (LLM provider flattening) + `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded). Required prereq for full lens coverage; lens can land first + surface structural-coverage-gap diagnostics on bypass surfaces so the gap becomes visible rather than silent. P2 — `ExecuteCommand` fully materialized as typed runner primitive. TESTING.md (post-#782) committed to 0-residual but ExecuteCommand isn't fully materialized; deleting Rust boundary tests creates verification gap. Already named under PB-Runtime in Zero-Floor; signal pending. Pre-requisite for ANY Rust boundary-test deletion. 2. Old leftover duplicate Q5 section deleted (artifact from prior Q5/Q5.5 reshape; second copy of asymmetric-tightening text was in the file alongside the earlier Q5 instance). 3. Worker-discretion-vs-Director-call section in Q4.5: lens implementation worker dispatchable now (reports gaps as findings); P1 closure is substantive substrate work touching extdeps (dedicated lane); P2 closure is PB-Runtime (signal pending). Net: design doc now honestly distinguishes principle-is-live (Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs named explicitly). The closed-system claim has explicit pre- conditions documented; implementation brief discovers them as known dependencies, not as STOP-AND-ESCALATEs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two real residuals after the Q5.5 reframe: 1. Q6's reqs/STOPs/acceptance still framed under path (i) — said "audit + tag std/ primitives — every effectful primitive carries an explicit OperationEffect signature." Directly contradicted Q4 (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment ("there is no parallel taxonomy to declare or maintain"). Worker reading Q6 in isolation would author the retracted shape. 2. Capacity / sequencing table line about "audit lane (tag std/ primitives with effect signatures)" carried the same stale framing. 3. Q6 STOP "primitive performing side effects without an OperationEffect tag" assumed tag-as-authority; under path (ii) the STOP shape is "primitive whose signature doesn't structurally reveal its effect." Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale (already fixed at f073aa95e Q4.5 commit). ## Q6 fixes - Reqs renumbered + reframed: - Req 1 anchors on operation type-signature shape (not hand-declared OperationEffect tags); composition reads from signature shape per Q2 table. - Req 2 changed from "audit + tag every primitive" to "audit-as-existence-check" — verify signature-shape coverage; ANY primitive needing a hand-declared tag IS the existence-proof for path (ii) retirement. - Req 3 added: resource-threading discipline applied to existing primitives (logging that returns Unit gets reshaped per audit). - Req 6 added: transactional-pattern lens (Bind composition + Transaction → Transaction'). - Req 7 added: asymmetric-tightening worked example in PR body (per claude review observation; the one place declaration-shaped surface re-enters). - Req 8 (was 5): tests now reference signature-shape derivation explicitly, not tag lookup. - STOPs reframed: - "OperationEffect retirement decision" — audit produces path (i) vs (ii) verdict; substrate retirement is its own dedicated sub-lane; this lane does NOT absorb it. - Pure/impure carrier STOP notes that "pure" should also derive from signature shape (pure functions don't return modified resources) — so the STOP itself may dissolve under further design. - Q4.5 P1 explicitly NOT a STOP — lens reporting structural- coverage-gap on extdeps bypass surfaces is the lens delivering its foundation-gap-visibility value. - Q4.5 P2 explicitly independent — lens doesn't depend on ExecuteCommand materialization. - Acceptance extended: lens reports gap diagnostics on P1 bypass surfaces; audit produces existence-proof verdict for Director re-decision; asymmetric-tightening worked example in PR body. ## Capacity / sequencing table Replaced "1 audit lane (tag std/ primitives with effect signatures)" with "1 audit-as-existence-check lane (verify primitives' signature- shape coverage; NOT 'tag every primitive') — produces the path (i) vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2 prereq lanes to the net summary. Closing line: "The taxonomy- retirement scope (substrate-side) is not in this lane — it's surfaced by audit and routed to dedicated retirement lane if path (ii) wins." Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity table. Worker reading Q6 in isolation now sees path-(ii)-default framing matching Q4 + Q5.5 + THESIS amendment. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792 Resolves codex inline BLOCKING at sha 191be310 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150. Real: my Q4.5 P2 framing described ExecuteCommand as still NotYetImplemented (M1.5 allowlist + Rust TestRunner returning NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand extension before this PR's authoring. TESTING.md:195 capability-state callout confirms: - Rust TestRunner + M1.5 testgen harness share one std::process path for arbitrary command + args + expect_exit_code. - M1.5 allowlist + fail-closed panic retired. - Distinguishable ClaimResult::Fail messages for spawn / timeout / policy / exit-mismatch. - Linux unshare(1) namespace isolation on host-allowing systems. - T-PB-B-1 boundary migration example landed. Fix: P2 section rewritten: - Header retitled "ExecuteCommand runner primitive: LANDED (PR #792); residual is bulk-migration." - Status update naming PR #792 + the post-#792 capability state (allowlist retired, etc.). - Honest acknowledgement: "My earlier P2 framing was stale." - Residual narrowed to bulk-migration of existing Rust Command::new boundary tests (tracked as ROADMAP residual, not lens prereq). - Sequencing reframed: P2 was always orthogonal to the effects lens itself; bulk migration proceeds at its own pace; lens not blocked. Q4.5 footer updated: - "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via #792; only consumer-side bulk migration remains)" - Worker-discretion-vs-Director-call P2 line updated: "runner primitive landed; only consumer-side bulk migration remains; tracked as ROADMAP residual, independent of the lens." Q6 STOP for P2 updated: - "the lens itself doesn't depend on P2; only TESTING.md's 0-residual claim does" → "runner primitive landed via PR #792 (post-Q4.5- authoring update). The lens itself never depended on P2; bulk consumer migration is residual ROADMAP work and remains independent of this lane." Brief now reflects live state. The closed-system claim's prereq landscape is honest: - P1 (extdeps typed-primitive consumption): real prereq, tracked debt at ROADMAP:153-154. - P2 (ExecuteCommand runner): satisfied via #792; bulk migration is consumer-side residual, not foundation work. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale Resolves codex non-blocking finding at sha bcac41bb on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real residual: capacity-table line still listed P2 as "`ExecuteCommand` materialization" prereq + framed both P1 and P2 as "pre-existing tracked-debt" — but my prior 57a9b1318 fix established that PR #792 already landed the runner primitive, so P2 is no longer a materialization prereq. Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq) from P2 (residual, not prereq): - P1: extdeps typed-primitive consumption — pre-existing tracked debt at ROADMAP:153-154; load-bearing for the lens's full-coverage claim. - P2: ExecuteCommand runner primitive landed via PR #792; only consumer-side bulk migration of existing Rust Command::new boundary tests remains (tracked as ROADMAP residual, independent of the lens; not a materialization prereq). Brief now consistently treats P2 as bulk-migration-residual across: - §Q4.5 P2 section header (LANDED via PR #792; residual is bulk-migration). - §Q4.5 footer (P2: runner primitive landed; only consumer-side bulk migration remains). - Q6 STOP for P2 (runner primitive landed; bulk migration is residual ROADMAP work). - §Capacity / sequencing impact (P2 as residual, not prereq). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349 Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated target-grounding prose; the matching extdeps typed-primitive bypass entries (LLM service flattening, GitHub auth model bypass) live at ROADMAP.md:348-349. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix third stale ROADMAP citation at line 271 Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence at line 271 in the §Q4.5 capacity table. Now consistent with lines 139 and 173 (ROADMAP.md:348-349). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity Codex flagged 'Effect-signature tagging on std/ primitives' as potentially contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240) already explicitly say 'NOT tag every primitive' — but the cross-manager line used sloppy wording. Reworded to make explicit that the audit walks signature shape; no parallel tag added. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5 - B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound - B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause - B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge - B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation) B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25): language vocabulary is primitives + namespacing only; no escape syntax; the §0 sentinels are the compiler itself failing to use primitives + namespacing internally. Eight surface sites dissolve via four substrate carriers (DeclarationRef, structural fold-shape carrier, structural emit-helper carrier, structural extdeps-fixture-set carrier). B1-B3 are independent; dispatch in parallel. B4 is sequential program work; sub-brief dispatch (B4.1-B4.12) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — drop incoherent inner-fallback non-goal Codex P2: the non-goal line excluding the inner declaration().name unwrap_or_else fallback contradicted Slice step 2, which replaces the whole chain with let-Some-else-return. Both fallbacks are in scope by construction; remove the contradictory non-goal. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives PM REQUEST_CHANGES: §Frame listed '4 type connectives (Conjunction | Disjunction | Cardinality | Bit)' which contradicted the canonical thesis source. Replaced with the canonical 6 (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary closes here'. Also removed 'typed substrate carriers' from the vocabulary list — substrate carriers are defined using the vocabulary, not part of it. Added a clarifying note that B4's carriers (DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are typed declarations composed from the vocabulary, not vocabulary extensions. Per feedback_verify_thesis_claims: brief framings citing thesis structure must ground in the canonical source. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of naming the live substrate authority. Two coordinated fixes: 1. §Read first cites src/v3/std/substrate.dag (live .dag substrate authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel meta-type — already exists with consumers in verification.dag, emit_model.dag, python.dag). 2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing DeclarationRef'. The work is consumer migration + any role-extension layer the audit reveals, NOT designing or landing the carrier. Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers) keep their 'new' framing but explicitly require sub-briefs to grep src/v3/std/ + src/v3/spec/ for existing authority before authoring 'design and land' framing — per feedback_verify_thesis_claims + feedback_emitter_workaround_is_gap_symptom. Acceptance + sub-brief dispatch order updated to reflect B4.1's consumer-migration shape. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — tighten Phase 1 umbrella sentence The umbrella 'Land the typed carriers into src/v3/std/' framing was stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced with audit-first wording that covers both the consume-existing case (#1) and the design-and-land case (#2-#4 if their audits show real gaps). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands' which conflicted with the post-reframe reality that B4.1 consumes the existing DeclarationRef. Updated to 'consumes or lands' with explicit existing-authority citation and audit-pending caveat for B4.2-B4.4. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — soften regression-test requirement (3 worker bounces) Three consecutive B1 worker dispatches (zesty-crane-890 cursor → valiant-boar-498 codex → cool-lynx-395 cursor) archived without opening a PR. Likely friction point: brief Slice step 4 asks for a unit test that constructs a Dag with an orphan variant declaration, but emit.rs has zero existing #[test] precedent — emit testing happens via integration fixtures. Workers see 'build novel test harness' inside what's billed as an S-scope fix and bounce. Per feedback_construction_over_ratchets: when a brief has friction, fix the brief, don't ratchet the worker. Softened step 4 + acceptance: regression test stays optional. If test setup requires novel scaffolding, route the gap to follow-up. The structural fail-closed at step 2 is the load-bearing change. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description' is too weak; PR descriptions don't survive squash-merge cleanly. Two coordinated edits: 1. Slice step 4 — explicit substrate-signal framing: skipped test means emit-side hermetic-unit-test infrastructure is the missing substrate (feedback_emitter_workaround_is_gap_symptom). 2. Acceptance — require ROADMAP debt row (new or existing) with named dissolution trigger, referenced in PR body. Converts the skip from PR-local note (transient) into tracked debt (durable, dispatchable). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124 Codex BLOCKING: my earlier softening claimed emit.rs had no #[test] precedent — wrong. The module has #[cfg(test)] mod tests at line 3124 with 12+ tests using compile_to_dag(source, filename) as harness (e.g., go_struct_fields_render_with_separators :3143, shared_walk_to_disj_finds_match_scrutinee_sum_type :3195). This is a feedback_verify_thesis_claims violation on Director-side brief authoring — claim made without grep verification. Fix: restore step 4 as required, with explicit precedent citation. Worker constructs the failure case via the existing harness (direct Dag, fixture string, or BranchPattern exercise; worker's call on cleanest path). STOP-AND-ESCALATE only if construction proves materially harder than precedent suggests, in which case that escalation surfaces a real substrate gap and warrants ROADMAP debt — but the default is 'add the test.' Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites) Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded to 'several using compile_to_dag'. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this is Wave 1 of Director's 14-brief authoring queue, covering B4 program internals. Authored: - b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) — replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag") fold-skip with structural template-formal carrier; mandatory authority audit per feedback_audit_adjacent_authority_first. - b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) — replaces §0.6 emit.rs bind/branch.span.file equality with typed BindEmitParticipation/BranchEmitParticipation roles populated at lowering; aligned with #824 worker's in-flight implementation shape. - b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4 of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with typed substrate authority; explicit pre-promotion-constraint disposition (single-authority vs authority+tracked-debt) addresses parallel-representation risk surfaced on #825. - b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) — names B4.5-B4.12 Phase 2 sites with carrier dependencies, cross-program coordination notes, and skeleton-brief template; full per-site briefs author at dispatch time per #827's Substrate Manager ownership. Cross-cutting discipline applied per inbox #828 reply: - feedback_audit_adjacent_authority_first (mandatory grep before design) - feedback_no_textual_enforcement_bridges (no replacement sentinels) - feedback_parallel_representation_debt (explicit if shape (b)) - feedback_construction_over_ratchets (no parity-by-runtime as primary) - feedback_coproduct_dissolution (receipts for new variants) Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3) Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue. Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by Modeling Manager's Wave 3 worker briefs (gated on these landing). Authored: - r2-substrate-cardinality-for-int-lit-subset.md (M) — produces magnitude carrier consumed by T-Modeling int-lit. Coordinates with PR #806's prior cardinality work; mandatory authority audit guards against #796's rejected IntLiteralMagnitude shape resurfacing. Open design questions: magnitude representation, reconciliation narrowing point, i64::MIN representability. - r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces nominal-opacity carrier consumed by T-Modeling Secret<T>. Open design questions: carrier shape (flag/connective/sealed-accessor), generic-walk discipline, accessor gating. - r2-substrate-parametric-algebra-for-dimensions-subset.md (M) — produces phantom-parameter carrier consumed by T-Modeling Dimension<Carrier>. Open design questions: carrier shape, type-equivalence rule, algebra-method dispatch, lifting/coercion. All three: - Scoped narrowly to their paired R2 consumer; not full substrate-capability lanes. - Mandatory pre-author authority audit per feedback_audit_adjacent_authority_first. - Cross-program readiness signal pattern from #827's manager rework. - Coproduct dissolution receipts required for any new variants. - Open design questions surfaced explicitly so Substrate Manager (or Director pre-spin-up) can resolve at dispatch time. Wave 3 (T-Modeling worker briefs × 4) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4) Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue. Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each gated on a Substrate Manager readiness signal (Wave 2 producers). Authored: - r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2 cardinality-for-int-lit; moves narrowing from tokenizer to reconciliation; MagnitudeOutOfRange diagnostic per C-8. - r2-modeling-secret-graduation-worker.md — gated on Wave 2 nominal-opaque-for-Secret; authors Secret<T> + gated accessors (redact, compare_in_constant_time); C-8 diagnostic on non-gated access; signals Impossible-Bugs Manager on close (thesis claim covered). - r2-modeling-dimensions-phantom-worker.md — gated on Wave 2 parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier> + core SI base units + algebra-method dispatch; cross-dimension arithmetic produces typed diagnostic; signals Impossible-Bugs Manager (thesis claim). - r2-modeling-tokenizer-charclass-phase2-worker.md — gated on T-Substrate ValueBody-list/sum (#790); migrates tokenizer consumers to Char/List<Char>/CharClass canonical types; sibling consumer to Grounding Manager's Engine sharpened-(b). All four: - Explicit gating: 'do not dispatch until producer signal posts.' - Producer/consumer signal pattern from #827. - Cross-program signals to R2 Release Manager (Goal 2 closure) and Impossible-Bugs Manager (thesis-claim coverage). - Spoofing regression tests: discipline anchor against feedback_no_textual_enforcement_bridges. Wave 4 (T-ImpossibleBugs worker briefs × 3) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3) Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue. Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes, consuming the existing design/scoping briefs as authority. Authored: - r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on cardinality refinement substrate (T-Substrate territory adjacent to int-lit / DB-11 alias-where). Implementation: structural normalize of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T?? worker decision (reject vs normalize). Cites t-impossiblebugs-nested-optional-flatten-design.md as authority. - r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated on Tier 2 substrate (predicate-entailment infrastructure; distinct from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes predicate entailment, (b) feedback_totality_by_omission dissolves partial primitives, (c) park. Worker decides at audit time. Cites t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority. - r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate prerequisite per closed-system framing in design doc (#808). Audit- as-existence-check + lens implementation as compositional fold over 5 behaviors; redundancy detection compile-error via referential transparency + reread() escape hatch; path (i/ii) decision on OperationEffect taxonomy retain-vs-retire (default retire). Cites design doc #808 as authority. Cross-cutting: - Each cites prior design/scoping brief as authority (the existing *-design.md / *-worker.md REFRAMED files). - Explicit gating per #827 producer/consumer signal pattern; two briefs gated on substrate, one NOT gated (closed-system). - STOP-AND-ESCALATE includes 'design brief assumptions don't hold' surfacing per feedback_thesis_gate_state_drift. Wave 4 complete. Director's 14-brief queue done; awaiting PM portion (6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4.4 — tighten Slice §3 per PM review on #836 PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b) (authority + tracked debt parallel-rep) as autonomously acceptable contradicts feedback_construction_over_ratchets + feedback_parallel_representation_debt. Tightened: - Shape (a) is the only autonomous worker path. - Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a regen-host-loader sub-lane decision; not authorable without explicit Substrate Manager approval citation in the PR body. - Acceptance bullet requires the approval citation when shape (b) lands. - STOP-AND-ESCALATE rephrased to make this explicit; permanent parallel-representation re-escalates even with manager approval. This preserves shape (a) as autonomous; shape (b) becomes a cross-manager design escalation, not a B4.4 implementation call. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief Cursor review on #836 flagged the Read-first reference to .claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md as machine-specific (outside the repo, not resolvable from a normal clone). Replaced with in-repo prose pointing at the design doc's §Q1-Q3 as canonical authority — the discipline lives there in-repo. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs) Codex flagged: src/v3/std/types.dag does not exist; the canonical authority is at dsl/std/types.dag. Affected briefs (all from R2 spin-up Wave 2 + Wave 3): - r2-substrate-cardinality-for-int-lit-subset.md - r2-substrate-nominal-opaque-for-secret-subset.md - r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs) - r2-modeling-dimensions-phantom-worker.md - r2-modeling-secret-graduation-worker.md feedback_verify_thesis_claims violation on Director-side brief authoring — assumed path without grep. Same family of error as the earlier emit.rs precedent claim. Mass-replaced via perl; verified no remaining stale refs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant Codex BLOCKING on #836: my R2 worker brief gated nested-optional on cardinality refinement substrate, but the design doc verifies v3 is ALREADY past the cardinality bridge — TypeConnective::Cardinality is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is the carrier for Option. The dissolution is an UNGATED implementation via substrate-constructor invariant. feedback_verify_thesis_claims violation again — should have read the design doc fully before assuming the substrate gate. Rewrote brief to match design doc canonical sketch: - Single predicate (cardinality_idempotent_target) owns the rule - Single allocator (alloc_cardinality_decl) is THE substrate-constructor - API closure on TypeConnective::Cardinality payload (modeling-discipline practice 6) — variant cannot be struct-init'd outside the allocator - 3 hand-Rust + ~22 codegen call sites enumerated per design audit - infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as the killer case for generic-instantiation paths - Surface-syntax T?? decision left to worker (Director-lean: silent normalize) Brief now dispatchable immediately, no producer signal needed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment substrate path, but the design doc §4 explicitly recommends totality-by- omission as the Director-actionable path. Predicate-entailment is M+ scope that reopens DB-11's explicitly-closed asymmetric-strip design — design doc explicitly discards it. feedback_verify_thesis_claims violation again — same family as nested- optional reframe. Should have read design doc §4 in full before assuming the path ordering. Rewrote brief to match design doc §4 follow-on shape: - Primary path: per-class totality-by-omission (algebra retype + per- target realization migration). For Int/Int: OrderedRing.div retype at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 / python:486 + python_target.rs:680 helper). - NOT predicate-entailment (out of scope; M+ + DB-11 reopen). - NOT NonZero-typed-input (deferred to separate per-operand-variance substrate brief; STOP-AND-ESCALATE if chosen). - Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i] indexing, quotient, remainder) queue separately per design doc audit. - feedback_totality_by_omission discipline anchor explicit. Brief now matches feedback_totality_by_omission discipline + design doc recommendation. No substrate prerequisite; dispatchable immediately. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a pattern: I authored R2 worker briefs without fully reading each design doc's Director-actionable recommendation. Pre-emptively re-verified unenumerated-effects against design doc §Q6 to catch the same family of error before reviewers do. Findings: brief was substantively close but missing 3 of 8 design-doc reqs: - Req 3: Resource-threading discipline applied to existing primitives - Req 5: reread(key) primitive in std/ as explicit Slice item (was only mentioned in tests) - Req 7: Asymmetric-tightening worked example in PR body Plus: Slice didn't cite the canonical lens path src/v3/lenses/effect_enumeration.dag from design doc. Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6 specifies 4 specific STOPs (path-decision-escalation, pure: Bool carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP) that I had elided. Reframed Slice as 8 numbered reqs matching design doc verbatim; STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs; Acceptance enumerated per req. This is the third reframe in the unhandled-bugs series — same feedback_verify_thesis_claims violation each time. The pattern suggests Director-side R2 brief authoring should ALWAYS read each design doc's §Director-actionable / §Q-recommendation in full first, not assume. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)" listed as a worker-pick option violates THESIS.md substrate-shape lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) are canonical (per #811 thesis additions and #827 PM review); a 7th is a C1 stop signal requiring failed-dissolution evidence + Director substrate-design call, not autonomous worker pick. Removed the "new TypeConnective variant" option; replaced with `inhabits`-edge-shape carrier as third option (audit-time check). The explicit STOP-AND-ESCALATE clause now states: 7th connective is the precondition for failed-dissolution-evidence + Director substrate-design call, not a worker path. feedback_verify_thesis_claims still in play — should have grounded substrate-shape options against the THESIS lock before listing Opaque(T) as worker-autonomous. Pattern continues; reading source-of-truth before authoring options is the discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place) Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter already exist at dag.rs:186, :217 — explicitly authored for the R2 Dimensions consumer per the doc comment at dag.rs:148-160. phantom_unit_mismatch already wired at infer.rs:1057, :1132. The substrate is fully landed; my brief framing it as 'producer sub-lane to land carrier' is wrong on the same feedback_audit_adjacent_authority_first violation that hit nested-optional / unhandled-diagnostic / unenumerated- effects. Reframed the substrate-side brief as no-op / closed-by-audit: - Documents the audit receipt (5 sites confirming substrate exists) - States the lane is closed - Routes T-Modeling Dimensions consumer to dispatch immediately against the existing carrier - Records the lesson: 'always grep substrate before authoring producer briefs' — discipline doesn't end at brief boundaries. Updated r2-modeling-dimensions-phantom-worker.md correspondingly: - Changed gating from 'do not dispatch until producer signal' to 'NOT GATED — dispatch immediately' - Read-first updated with concrete dag.rs/infer.rs cites - Slice §1 changed from 'confirm producer signal' to 'verify substrate at HEAD' - STOP reframed: existing carrier extension would need Substrate Manager call, not autonomous worker pick Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit both verified — no existing substrate (no is_nominal_opaque / MagnitudeBound patterns in dag.rs); both still legitimately producer-side work. Pattern is now four reframes deep on the R2 spin-up wave. The lesson saved is structural: read source-of-truth before authoring options. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority Codex BLOCKING on #836: my new R2 spin-up brief duplicates the existing t-substrate-cardinality-int-lit-worker.md, which carries the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64) stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane). Single-authority violation per INVARIANTS P2. Same feedback_audit_adjacent_authority_first failure as parametric- algebra-for-Dimensions reframe (4 hours ago): assumed substrate authority didn't exist; should have grepped docs/briefs/ before authoring. This is the SECOND R2 spin-up substrate brief closed as redundant — the discipline lesson is structural. Reframed brief as no-op routing doc (documents the audit receipt; routes consumers to the existing authority); updated r2-modeling-int-lit-magnitude-worker.md to cite t-substrate-cardinality-int-lit-worker.md instead. Pattern across the R2 spin-up wave reframes (5 now): 1. nested-optional gating-on-substrate (substrate already past cardinality bridge) 2. unhandled-diagnostic predicate-entailment default (design doc recommends totality-by-omission) 3. unenumerated-effects 8-req design-doc elision 4. parametric-algebra Producer (Declaration.phantom_params already authored explicitly for this consumer) 5. cardinality-for-int-lit…
…gpt-5-5-pro post-merge follow-up) (#1162) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c33: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 second-wave worker-escalation fixes Four substantive worker STOP-AND-ESCALATEs from briefs landed in PR #797. All four worker recommendations correct; each needs a Director call + brief update. ## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate Worker correctly identified that brief req 2 (declared-effect carrier as part of fn type signature, per feedback_no_annotations) requires net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots. Without parser surface, every user function would have declared_effects = [] while inference returns non-empty — lens fires EffectLeakageError everywhere on enable. Worker rejected power-through and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map parser split). Director picked split: - NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface syntax + lookahead + body parser + lowerer extension + exhaustive-match audit + coproduct dissolution receipt. - MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to post-parser-extension scope. Pre-flight check NOT a parser-extension step; STOP if parser sub-lane PR not merged. ## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping Worker found load-bearing evidence at infer.rs:3693-3703: DB-11 deliberately strips refinements at operator dispatch as a designed-in fix for symmetric-operators failure mode. Brief's "attach where b != 0 as a proof for a / b" directly contradicts this design choice. STOP-3 (where-clause conflict with DB-11) is real; STOP-1 (substrate scope) needs net-new substrate (per-operator partiality fact + predicate- entailment check + asymmetric per-operand refinement-honoring) — M+ minimum. ownership_lens precedent in original brief is post-hoc observability, not proof carrier. Worker recommended redirect to design/scoping per nested-optional precedent. Director picked redirect. Brief fully rewritten as design/scoping with four-question structure: (1) DB-11 interaction analysis; (2) substrate proposal for proof-or- totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes with acceptance-theatre risk on user-defined-total-wrapper-only); (4) Director-actionable recommendation. Output is doc PR. ## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C) Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int) with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136 closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b) i128 implementation requires either path 1 (hierarchy refactor — contradicts non-goal) or path 2 (regen lie between substrate and emit — violates discipline). Worker leaned option (C) re-scope: land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke) to a sibling sub-lane that does proper Int128/Word128 substrate work. Director picked option (C). Brief req 1 re-scoped to drop canonical- carrier-widening; lane value comes from range facts + reconciliation narrowing + out-of-range diagnostic against existing i64. Req 4 explicitly deferred with sibling-sub-lane reference. Sibling sub-lane NOT to be authored or implied in this PR; tracked separately. ## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change) Worker correctly STOP'd per the brief's own pre-flight check: parser sub-lane has not landed; SurfaceExpr::Map not on main. Director authorized cross-lane reassignment: wise-boar-480 takes the parser sub-lane (t-substrate-valuebody-map-parser-worker.md) since they already have full investigation context. No brief changes needed; the routing decision is in the dispatch. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope Resolves codex P2 inline at sha e35103fad on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still required widening LiteralBits::Int(i64) to an unbounded carrier and passing the i64::MIN smoke. Internally unsatisfiable. Fix: - Slice section retitled "range facts + reconciliation narrowing (against existing i64 carrier)" with explicit note about the re-scope. - Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly forbids touching LiteralBits::Int shape, dag_scalar_generated.rs regen for that variant, or tokenize i64 parse path. - Slice steps 2-5 reframed: range facts use i64-representable magnitudes; reconciliation narrowing uses existing i64 carrier; diagnostic only for i64-representable out-of-range; smoke tests for req 5 only (req 4 i64::MIN deferred). - Acceptance checklist updated: - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as re-scoped/deferred. - LiteralBits::Int(i64) carrier untouched (no widening; no parallel; no shape change). - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference. - STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the carrier" — explicit STOP if execution surfaces range-fact narrowing requiring carrier-widening; that's the boundary the re-scope drew; belongs in sibling Int128/Word128 sub-lane. Brief now consistently treats carrier-widening as out-of-scope across all sections. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty Resolves codex BLOCKING #1 at sha e35103fa on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier but req 2 required range facts using "the SAME magnitude carrier as req 1" — meaning i64-typed range bounds. u64's max (2^64-1) doesn't fit in i64; range fact for u64 would have to truncate, omit, or mirror in Rust (representation drift). All three options violate fail-closed declared-facts discipline (P1 / P3). Fix: - Req 2 rewritten to specify String-decimal representation: range_min_inclusive: String + range_max_inclusive: String fields on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127" for i8; "0"/"18446744073709551615" for u64). - Explicit reasoning why String-decimal: u64's max doesn't fit in i64; binding range bounds to literal carrier forces truncation/ omission/mirror-drift; all violate fail-closed declared-facts discipline. - Bridge framing: String-decimal is pending the sibling Int128/ Word128 sub-lane; both range bounds and literal payload migrate to typed carrier when that lands. - Req 3 updated for String-decimal comparison semantics: reconciliation parses both bounds and literal magnitude into a common comparison space (i128 host comparison primitive — host narrowing, NOT carrier widening). Bounded by what the i64-typed literal can express; any i64-representable literal compares against any width's String-decimal bound. Carrier discipline preserved. Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral) is sha-stale — already resolved at 3e142d169. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback). Real residual: req 2 specifies String-decimal range bounds (to cover u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" / "i64-representable magnitudes" for the range facts. Two incompatible authorities for the same range-fact shape — would let a worker satisfy the slice while truncating/omitting u64 bounds (P3 fail-closed violation). Fix: - Line 31 (req 1 re-scope clarification): updated to explicitly state "range facts (req 2) use String-decimal representation (width- independent; covers u64::MAX which doesn't fit in i64)". Distinguished literal *payload* (stays i64) from range-bound *representation* (String) — both serve req 1's "no carrier widening" boundary. - Line 44 (slice step 2): updated from "Range bounds use i64- representable magnitudes" to "Range bounds use String-decimal representation per req 2" with concrete example (u64 bounds). - Acceptance bullet: updated from "Range facts on integer algebras (substrate-declared, not Rust-mirrored)" to add "using String-decimal representation ... width-independent; u64 bounds expressible without truncation." The brief now consistently treats range bounds as String-decimal across req 2, req 3, slice, acceptance, and the req 1 clarification — no remaining authorities saying i64-typed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing User + PM exchange 2026-04-25 surfaced that the in-flight effects chain was importing wrong assumptions from external languages (declared-effects-as-annotation + lens-vs-declaration check). Right framing under gunbc's closed-system discipline is parallel to complexity: every effect derives structurally from the composition of typed primitive operations; nothing can hide because there's no escape hatch; nothing needs annotation because the structure IS the registry. Four doc-only actions: 1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md. Frames the closed-system answer with PM's 5-behavior synergy table (Value/Transform/Branch/Loop/Bind as universal compositional-fold pattern). Four worked examples; aggressive reading on redundancy (compile-error-by-construction via referential-transparency proof; reread() primitive for legitimate cases); implementation-brief shape in §Q6. 2. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md. 3. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md. Notes Fn→Arrow refactor brief stays dispatchable as independent value. 4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by- construction framing replaces lens-detection framing. Memory file feedback_closed_system_effects.md saved separately; cross-link added to feedback_construction_over_ratchets.md. Net cost: doc-level cleanup. Zero substrate code rework. Foundation (OperationEffect + service-call infrastructure + 5-behavior substrate) already exists. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect Per PM convergence review on #808 + user's deeper 2026-04-25 framing: the closed-system framing landed in #808 retired the user-facing annotation but kept OperationEffect taxonomy as substrate-level tagging. User's deeper framing: the taxonomy ITSELF is parallel-representation — operations are intrinsically read-shaped or write-shaped via their TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns- derived-value-only → read). Tagging operations with Read | Upsert | Create | Append | Delete names what the structure already says. Three changes: 1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as normalized view, or retire as parallel-representation?" - Two paths: (i) tags derived from signature shape (acceptable normalized view) vs (ii) tags declared per-primitive (parallel- representation; retire). - Audit-as-existence-check (Q4 req 2 reframed): all effectful primitives derive cleanly from signature shape → path (i); any primitive needs hand-declared tag → path (ii) by existence proof. - Director default: path (ii). Logging primitives that return Unit are likely the audit's existence-proof. - Two design-question resolutions: (a) external effects not in return type → resource-threading discipline (typed param returned modified, IO-monad-without-the-monad pattern); (b) transactional grouping → derived structural fact from Bind composition + typed transaction primitives. 2. Q4 reqs revised: req 2 from "tag every primitive with explicit OperationEffect signature" to "audit-as-existence-check that every primitive's type signature derives the right effect classification"; req 3 added (resource-threading discipline); req 6 added (transactional-pattern lens). Req 1 (effects lens) anchors on operation type-signature shape, not on hand-declared tags. 3. THESIS:345-347 amendment strengthened — "operations are intrinsically read-shaped or write-shaped via their type-signature shape; consumers walk the signatures directly; there is no parallel taxonomy or annotation layer to declare or maintain. Tracking effects as a separate enumerated concept IS the bug pattern, dissolved by construction." Plus references to resource-threading discipline + transactional grouping as derived structural fact. Memory file feedback_closed_system_effects.md updated to reflect the deeper framing (type-signature-shape, not taxonomy-tagging) + resource-threading discipline section + transactional-patterns section. Net cost: doc-only delta on top of #808. Substrate retirement (OperationEffect enum + derive_op_effect + idempotency.dag re-anchor) deferred to the audit-as-existence-check phase of the implementation brief; surfaced as Q5.5 OPEN CALL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage Resolves codex BLOCKING at sha d49ce79a on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real: the prior text claimed service primitives "already carry typed effect signatures" presenting future audit-state as current substrate fact (P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the OperationEffect line but left a parallel over-claim on the new "signature-shape coverage" framing. Fix: Q4 substrate-state listing rewritten to honestly distinguish: - Live: Behavior enum + substrate foundation (the principle that operations should carry signature shape). - Incomplete: signature-shape coverage across actual primitives. HTTP-derived primitives carry implicit shape via derive_op_effect's method-table; logging/mutation primitives that return Unit or don't thread their target resource do NOT carry the structural shape that would express read-vs-write. Achieving full coverage is required work under reqs 2 + 3, not a current fact. - Pending audit-as-existence-check: OperationEffect + derive_op_effect (path (i) vs (ii) per Q5.5). Honest live-state callout added explicitly: "the closed-system FOUNDATION (5 behaviors + DAG substrate + the principle that operations should carry signature-shape) is live. The IMPLEMENTATION COVERAGE across all effectful primitives is partial. Req 2 + req 3 are the work that closes the gap." Brief now distinguishes principle-is-live (foundation) from coverage-is-partial (audit work) without conflating them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim Per PM follow-up review on #808 + user's stronger discipline framing ("substrate must make bypass structurally impossible at every layer of the transport stack"): the closed-system claim is honest only when typed primitives ARE the path. Today two structural holes exist where bypasses sidestep the typed-primitive substrate. Both surfaced explicitly as Q4.5 pre-conditions — load-bearing for the lens's coverage claim. Three changes: 1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed- system claim)" inserted between Q4 and Q5: P1 — Extdeps typed-primitive consumption structurally enforced. Substrate must make `messages: Json` impossible to declare in service definitions; typed `LlmMessage` / `ContentBlock` / `GitHubAuthToken`-with-full-scopes are the only path. Tracked debt at ROADMAP.md:153-154 (LLM provider flattening) + `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded). Required prereq for full lens coverage; lens can land first + surface structural-coverage-gap diagnostics on bypass surfaces so the gap becomes visible rather than silent. P2 — `ExecuteCommand` fully materialized as typed runner primitive. TESTING.md (post-#782) committed to 0-residual but ExecuteCommand isn't fully materialized; deleting Rust boundary tests creates verification gap. Already named under PB-Runtime in Zero-Floor; signal pending. Pre-requisite for ANY Rust boundary-test deletion. 2. Old leftover duplicate Q5 section deleted (artifact from prior Q5/Q5.5 reshape; second copy of asymmetric-tightening text was in the file alongside the earlier Q5 instance). 3. Worker-discretion-vs-Director-call section in Q4.5: lens implementation worker dispatchable now (reports gaps as findings); P1 closure is substantive substrate work touching extdeps (dedicated lane); P2 closure is PB-Runtime (signal pending). Net: design doc now honestly distinguishes principle-is-live (Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs named explicitly). The closed-system claim has explicit pre- conditions documented; implementation brief discovers them as known dependencies, not as STOP-AND-ESCALATEs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two real residuals after the Q5.5 reframe: 1. Q6's reqs/STOPs/acceptance still framed under path (i) — said "audit + tag std/ primitives — every effectful primitive carries an explicit OperationEffect signature." Directly contradicted Q4 (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment ("there is no parallel taxonomy to declare or maintain"). Worker reading Q6 in isolation would author the retracted shape. 2. Capacity / sequencing table line about "audit lane (tag std/ primitives with effect signatures)" carried the same stale framing. 3. Q6 STOP "primitive performing side effects without an OperationEffect tag" assumed tag-as-authority; under path (ii) the STOP shape is "primitive whose signature doesn't structurally reveal its effect." Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale (already fixed at f073aa95e Q4.5 commit). ## Q6 fixes - Reqs renumbered + reframed: - Req 1 anchors on operation type-signature shape (not hand-declared OperationEffect tags); composition reads from signature shape per Q2 table. - Req 2 changed from "audit + tag every primitive" to "audit-as-existence-check" — verify signature-shape coverage; ANY primitive needing a hand-declared tag IS the existence-proof for path (ii) retirement. - Req 3 added: resource-threading discipline applied to existing primitives (logging that returns Unit gets reshaped per audit). - Req 6 added: transactional-pattern lens (Bind composition + Transaction → Transaction'). - Req 7 added: asymmetric-tightening worked example in PR body (per claude review observation; the one place declaration-shaped surface re-enters). - Req 8 (was 5): tests now reference signature-shape derivation explicitly, not tag lookup. - STOPs reframed: - "OperationEffect retirement decision" — audit produces path (i) vs (ii) verdict; substrate retirement is its own dedicated sub-lane; this lane does NOT absorb it. - Pure/impure carrier STOP notes that "pure" should also derive from signature shape (pure functions don't return modified resources) — so the STOP itself may dissolve under further design. - Q4.5 P1 explicitly NOT a STOP — lens reporting structural- coverage-gap on extdeps bypass surfaces is the lens delivering its foundation-gap-visibility value. - Q4.5 P2 explicitly independent — lens doesn't depend on ExecuteCommand materialization. - Acceptance extended: lens reports gap diagnostics on P1 bypass surfaces; audit produces existence-proof verdict for Director re-decision; asymmetric-tightening worked example in PR body. ## Capacity / sequencing table Replaced "1 audit lane (tag std/ primitives with effect signatures)" with "1 audit-as-existence-check lane (verify primitives' signature- shape coverage; NOT 'tag every primitive') — produces the path (i) vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2 prereq lanes to the net summary. Closing line: "The taxonomy- retirement scope (substrate-side) is not in this lane — it's surfaced by audit and routed to dedicated retirement lane if path (ii) wins." Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity table. Worker reading Q6 in isolation now sees path-(ii)-default framing matching Q4 + Q5.5 + THESIS amendment. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792 Resolves codex inline BLOCKING at sha 191be310 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150. Real: my Q4.5 P2 framing described ExecuteCommand as still NotYetImplemented (M1.5 allowlist + Rust TestRunner returning NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand extension before this PR's authoring. TESTING.md:195 capability-state callout confirms: - Rust TestRunner + M1.5 testgen harness share one std::process path for arbitrary command + args + expect_exit_code. - M1.5 allowlist + fail-closed panic retired. - Distinguishable ClaimResult::Fail messages for spawn / timeout / policy / exit-mismatch. - Linux unshare(1) namespace isolation on host-allowing systems. - T-PB-B-1 boundary migration example landed. Fix: P2 section rewritten: - Header retitled "ExecuteCommand runner primitive: LANDED (PR #792); residual is bulk-migration." - Status update naming PR #792 + the post-#792 capability state (allowlist retired, etc.). - Honest acknowledgement: "My earlier P2 framing was stale." - Residual narrowed to bulk-migration of existing Rust Command::new boundary tests (tracked as ROADMAP residual, not lens prereq). - Sequencing reframed: P2 was always orthogonal to the effects lens itself; bulk migration proceeds at its own pace; lens not blocked. Q4.5 footer updated: - "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via #792; only consumer-side bulk migration remains)" - Worker-discretion-vs-Director-call P2 line updated: "runner primitive landed; only consumer-side bulk migration remains; tracked as ROADMAP residual, independent of the lens." Q6 STOP for P2 updated: - "the lens itself doesn't depend on P2; only TESTING.md's 0-residual claim does" → "runner primitive landed via PR #792 (post-Q4.5- authoring update). The lens itself never depended on P2; bulk consumer migration is residual ROADMAP work and remains independent of this lane." Brief now reflects live state. The closed-system claim's prereq landscape is honest: - P1 (extdeps typed-primitive consumption): real prereq, tracked debt at ROADMAP:153-154. - P2 (ExecuteCommand runner): satisfied via #792; bulk migration is consumer-side residual, not foundation work. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale Resolves codex non-blocking finding at sha bcac41bb on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real residual: capacity-table line still listed P2 as "`ExecuteCommand` materialization" prereq + framed both P1 and P2 as "pre-existing tracked-debt" — but my prior 57a9b1318 fix established that PR #792 already landed the runner primitive, so P2 is no longer a materialization prereq. Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq) from P2 (residual, not prereq): - P1: extdeps typed-primitive consumption — pre-existing tracked debt at ROADMAP:153-154; load-bearing for the lens's full-coverage claim. - P2: ExecuteCommand runner primitive landed via PR #792; only consumer-side bulk migration of existing Rust Command::new boundary tests remains (tracked as ROADMAP residual, independent of the lens; not a materialization prereq). Brief now consistently treats P2 as bulk-migration-residual across: - §Q4.5 P2 section header (LANDED via PR #792; residual is bulk-migration). - §Q4.5 footer (P2: runner primitive landed; only consumer-side bulk migration remains). - Q6 STOP for P2 (runner primitive landed; bulk migration is residual ROADMAP work). - §Capacity / sequencing impact (P2 as residual, not prereq). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349 Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated target-grounding prose; the matching extdeps typed-primitive bypass entries (LLM service flattening, GitHub auth model bypass) live at ROADMAP.md:348-349. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix third stale ROADMAP citation at line 271 Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence at line 271 in the §Q4.5 capacity table. Now consistent with lines 139 and 173 (ROADMAP.md:348-349). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity Codex flagged 'Effect-signature tagging on std/ primitives' as potentially contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240) already explicitly say 'NOT tag every primitive' — but the cross-manager line used sloppy wording. Reworded to make explicit that the audit walks signature shape; no parallel tag added. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5 - B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound - B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause - B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge - B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation) B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25): language vocabulary is primitives + namespacing only; no escape syntax; the §0 sentinels are the compiler itself failing to use primitives + namespacing internally. Eight surface sites dissolve via four substrate carriers (DeclarationRef, structural fold-shape carrier, structural emit-helper carrier, structural extdeps-fixture-set carrier). B1-B3 are independent; dispatch in parallel. B4 is sequential program work; sub-brief dispatch (B4.1-B4.12) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — drop incoherent inner-fallback non-goal Codex P2: the non-goal line excluding the inner declaration().name unwrap_or_else fallback contradicted Slice step 2, which replaces the whole chain with let-Some-else-return. Both fallbacks are in scope by construction; remove the contradictory non-goal. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives PM REQUEST_CHANGES: §Frame listed '4 type connectives (Conjunction | Disjunction | Cardinality | Bit)' which contradicted the canonical thesis source. Replaced with the canonical 6 (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary closes here'. Also removed 'typed substrate carriers' from the vocabulary list — substrate carriers are defined using the vocabulary, not part of it. Added a clarifying note that B4's carriers (DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are typed declarations composed from the vocabulary, not vocabulary extensions. Per feedback_verify_thesis_claims: brief framings citing thesis structure must ground in the canonical source. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of naming the live substrate authority. Two coordinated fixes: 1. §Read first cites src/v3/std/substrate.dag (live .dag substrate authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel meta-type — already exists with consumers in verification.dag, emit_model.dag, python.dag). 2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing DeclarationRef'. The work is consumer migration + any role-extension layer the audit reveals, NOT designing or landing the carrier. Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers) keep their 'new' framing but explicitly require sub-briefs to grep src/v3/std/ + src/v3/spec/ for existing authority before authoring 'design and land' framing — per feedback_verify_thesis_claims + feedback_emitter_workaround_is_gap_symptom. Acceptance + sub-brief dispatch order updated to reflect B4.1's consumer-migration shape. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — tighten Phase 1 umbrella sentence The umbrella 'Land the typed carriers into src/v3/std/' framing was stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced with audit-first wording that covers both the consume-existing case (#1) and the design-and-land case (#2-#4 if their audits show real gaps). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands' which conflicted with the post-reframe reality that B4.1 consumes the existing DeclarationRef. Updated to 'consumes or lands' with explicit existing-authority citation and audit-pending caveat for B4.2-B4.4. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — soften regression-test requirement (3 worker bounces) Three consecutive B1 worker dispatches (zesty-crane-890 cursor → valiant-boar-498 codex → cool-lynx-395 cursor) archived without opening a PR. Likely friction point: brief Slice step 4 asks for a unit test that constructs a Dag with an orphan variant declaration, but emit.rs has zero existing #[test] precedent — emit testing happens via integration fixtures. Workers see 'build novel test harness' inside what's billed as an S-scope fix and bounce. Per feedback_construction_over_ratchets: when a brief has friction, fix the brief, don't ratchet the worker. Softened step 4 + acceptance: regression test stays optional. If test setup requires novel scaffolding, route the gap to follow-up. The structural fail-closed at step 2 is the load-bearing change. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description' is too weak; PR descriptions don't survive squash-merge cleanly. Two coordinated edits: 1. Slice step 4 — explicit substrate-signal framing: skipped test means emit-side hermetic-unit-test infrastructure is the missing substrate (feedback_emitter_workaround_is_gap_symptom). 2. Acceptance — require ROADMAP debt row (new or existing) with named dissolution trigger, referenced in PR body. Converts the skip from PR-local note (transient) into tracked debt (durable, dispatchable). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124 Codex BLOCKING: my earlier softening claimed emit.rs had no #[test] precedent — wrong. The module has #[cfg(test)] mod tests at line 3124 with 12+ tests using compile_to_dag(source, filename) as harness (e.g., go_struct_fields_render_with_separators :3143, shared_walk_to_disj_finds_match_scrutinee_sum_type :3195). This is a feedback_verify_thesis_claims violation on Director-side brief authoring — claim made without grep verification. Fix: restore step 4 as required, with explicit precedent citation. Worker constructs the failure case via the existing harness (direct Dag, fixture string, or BranchPattern exercise; worker's call on cleanest path). STOP-AND-ESCALATE only if construction proves materially harder than precedent suggests, in which case that escalation surfaces a real substrate gap and warrants ROADMAP debt — but the default is 'add the test.' Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites) Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded to 'several using compile_to_dag'. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this is Wave 1 of Director's 14-brief authoring queue, covering B4 program internals. Authored: - b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) — replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag") fold-skip with structural template-formal carrier; mandatory authority audit per feedback_audit_adjacent_authority_first. - b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) — replaces §0.6 emit.rs bind/branch.span.file equality with typed BindEmitParticipation/BranchEmitParticipation roles populated at lowering; aligned with #824 worker's in-flight implementation shape. - b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4 of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with typed substrate authority; explicit pre-promotion-constraint disposition (single-authority vs authority+tracked-debt) addresses parallel-representation risk surfaced on #825. - b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) — names B4.5-B4.12 Phase 2 sites with carrier dependencies, cross-program coordination notes, and skeleton-brief template; full per-site briefs author at dispatch time per #827's Substrate Manager ownership. Cross-cutting discipline applied per inbox #828 reply: - feedback_audit_adjacent_authority_first (mandatory grep before design) - feedback_no_textual_enforcement_bridges (no replacement sentinels) - feedback_parallel_representation_debt (explicit if shape (b)) - feedback_construction_over_ratchets (no parity-by-runtime as primary) - feedback_coproduct_dissolution (receipts for new variants) Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3) Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue. Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by Modeling Manager's Wave 3 worker briefs (gated on these landing). Authored: - r2-substrate-cardinality-for-int-lit-subset.md (M) — produces magnitude carrier consumed by T-Modeling int-lit. Coordinates with PR #806's prior cardinality work; mandatory authority audit guards against #796's rejected IntLiteralMagnitude shape resurfacing. Open design questions: magnitude representation, reconciliation narrowing point, i64::MIN representability. - r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces nominal-opacity carrier consumed by T-Modeling Secret<T>. Open design questions: carrier shape (flag/connective/sealed-accessor), generic-walk discipline, accessor gating. - r2-substrate-parametric-algebra-for-dimensions-subset.md (M) — produces phantom-parameter carrier consumed by T-Modeling Dimension<Carrier>. Open design questions: carrier shape, type-equivalence rule, algebra-method dispatch, lifting/coercion. All three: - Scoped narrowly to their paired R2 consumer; not full substrate-capability lanes. - Mandatory pre-author authority audit per feedback_audit_adjacent_authority_first. - Cross-program readiness signal pattern from #827's manager rework. - Coproduct dissolution receipts required for any new variants. - Open design questions surfaced explicitly so Substrate Manager (or Director pre-spin-up) can resolve at dispatch time. Wave 3 (T-Modeling worker briefs × 4) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4) Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue. Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each gated on a Substrate Manager readiness signal (Wave 2 producers). Authored: - r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2 cardinality-for-int-lit; moves narrowing from tokenizer to reconciliation; MagnitudeOutOfRange diagnostic per C-8. - r2-modeling-secret-graduation-worker.md — gated on Wave 2 nominal-opaque-for-Secret; authors Secret<T> + gated accessors (redact, compare_in_constant_time); C-8 diagnostic on non-gated access; signals Impossible-Bugs Manager on close (thesis claim covered). - r2-modeling-dimensions-phantom-worker.md — gated on Wave 2 parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier> + core SI base units + algebra-method dispatch; cross-dimension arithmetic produces typed diagnostic; signals Impossible-Bugs Manager (thesis claim). - r2-modeling-tokenizer-charclass-phase2-worker.md — gated on T-Substrate ValueBody-list/sum (#790); migrates tokenizer consumers to Char/List<Char>/CharClass canonical types; sibling consumer to Grounding Manager's Engine sharpened-(b). All four: - Explicit gating: 'do not dispatch until producer signal posts.' - Producer/consumer signal pattern from #827. - Cross-program signals to R2 Release Manager (Goal 2 closure) and Impossible-Bugs Manager (thesis-claim coverage). - Spoofing regression tests: discipline anchor against feedback_no_textual_enforcement_bridges. Wave 4 (T-ImpossibleBugs worker briefs × 3) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3) Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue. Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes, consuming the existing design/scoping briefs as authority. Authored: - r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on cardinality refinement substrate (T-Substrate territory adjacent to int-lit / DB-11 alias-where). Implementation: structural normalize of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T?? worker decision (reject vs normalize). Cites t-impossiblebugs-nested-optional-flatten-design.md as authority. - r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated on Tier 2 substrate (predicate-entailment infrastructure; distinct from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes predicate entailment, (b) feedback_totality_by_omission dissolves partial primitives, (c) park. Worker decides at audit time. Cites t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority. - r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate prerequisite per closed-system framing in design doc (#808). Audit- as-existence-check + lens implementation as compositional fold over 5 behaviors; redundancy detection compile-error via referential transparency + reread() escape hatch; path (i/ii) decision on OperationEffect taxonomy retain-vs-retire (default retire). Cites design doc #808 as authority. Cross-cutting: - Each cites prior design/scoping brief as authority (the existing *-design.md / *-worker.md REFRAMED files). - Explicit gating per #827 producer/consumer signal pattern; two briefs gated on substrate, one NOT gated (closed-system). - STOP-AND-ESCALATE includes 'design brief assumptions don't hold' surfacing per feedback_thesis_gate_state_drift. Wave 4 complete. Director's 14-brief queue done; awaiting PM portion (6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4.4 — tighten Slice §3 per PM review on #836 PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b) (authority + tracked debt parallel-rep) as autonomously acceptable contradicts feedback_construction_over_ratchets + feedback_parallel_representation_debt. Tightened: - Shape (a) is the only autonomous worker path. - Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a regen-host-loader sub-lane decision; not authorable without explicit Substrate Manager approval citation in the PR body. - Acceptance bullet requires the approval citation when shape (b) lands. - STOP-AND-ESCALATE rephrased to make this explicit; permanent parallel-representation re-escalates even with manager approval. This preserves shape (a) as autonomous; shape (b) becomes a cross-manager design escalation, not a B4.4 implementation call. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief Cursor review on #836 flagged the Read-first reference to .claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md as machine-specific (outside the repo, not resolvable from a normal clone). Replaced with in-repo prose pointing at the design doc's §Q1-Q3 as canonical authority — the discipline lives there in-repo. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs) Codex flagged: src/v3/std/types.dag does not exist; the canonical authority is at dsl/std/types.dag. Affected briefs (all from R2 spin-up Wave 2 + Wave 3): - r2-substrate-cardinality-for-int-lit-subset.md - r2-substrate-nominal-opaque-for-secret-subset.md - r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs) - r2-modeling-dimensions-phantom-worker.md - r2-modeling-secret-graduation-worker.md feedback_verify_thesis_claims violation on Director-side brief authoring — assumed path without grep. Same family of error as the earlier emit.rs precedent claim. Mass-replaced via perl; verified no remaining stale refs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant Codex BLOCKING on #836: my R2 worker brief gated nested-optional on cardinality refinement substrate, but the design doc verifies v3 is ALREADY past the cardinality bridge — TypeConnective::Cardinality is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is the carrier for Option. The dissolution is an UNGATED implementation via substrate-constructor invariant. feedback_verify_thesis_claims violation again — should have read the design doc fully before assuming the substrate gate. Rewrote brief to match design doc canonical sketch: - Single predicate (cardinality_idempotent_target) owns the rule - Single allocator (alloc_cardinality_decl) is THE substrate-constructor - API closure on TypeConnective::Cardinality payload (modeling-discipline practice 6) — variant cannot be struct-init'd outside the allocator - 3 hand-Rust + ~22 codegen call sites enumerated per design audit - infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as the killer case for generic-instantiation paths - Surface-syntax T?? decision left to worker (Director-lean: silent normalize) Brief now dispatchable immediately, no producer signal needed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment substrate path, but the design doc §4 explicitly recommends totality-by- omission as the Director-actionable path. Predicate-entailment is M+ scope that reopens DB-11's explicitly-closed asymmetric-strip design — design doc explicitly discards it. feedback_verify_thesis_claims violation again — same family as nested- optional reframe. Should have read design doc §4 in full before assuming the path ordering. Rewrote brief to match design doc §4 follow-on shape: - Primary path: per-class totality-by-omission (algebra retype + per- target realization migration). For Int/Int: OrderedRing.div retype at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 / python:486 + python_target.rs:680 helper). - NOT predicate-entailment (out of scope; M+ + DB-11 reopen). - NOT NonZero-typed-input (deferred to separate per-operand-variance substrate brief; STOP-AND-ESCALATE if chosen). - Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i] indexing, quotient, remainder) queue separately per design doc audit. - feedback_totality_by_omission discipline anchor explicit. Brief now matches feedback_totality_by_omission discipline + design doc recommendation. No substrate prerequisite; dispatchable immediately. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a pattern: I authored R2 worker briefs without fully reading each design doc's Director-actionable recommendation. Pre-emptively re-verified unenumerated-effects against design doc §Q6 to catch the same family of error before reviewers do. Findings: brief was substantively close but missing 3 of 8 design-doc reqs: - Req 3: Resource-threading discipline applied to existing primitives - Req 5: reread(key) primitive in std/ as explicit Slice item (was only mentioned in tests) - Req 7: Asymmetric-tightening worked example in PR body Plus: Slice didn't cite the canonical lens path src/v3/lenses/effect_enumeration.dag from design doc. Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6 specifies 4 specific STOPs (path-decision-escalation, pure: Bool carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP) that I had elided. Reframed Slice as 8 numbered reqs matching design doc verbatim; STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs; Acceptance enumerated per req. This is the third reframe in the unhandled-bugs series — same feedback_verify_thesis_claims violation each time. The pattern suggests Director-side R2 brief authoring should ALWAYS read each design doc's §Director-actionable / §Q-recommendation in full first, not assume. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)" listed as a worker-pick option violates THESIS.md substrate-shape lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) are canonical (per #811 thesis additions and #827 PM review); a 7th is a C1 stop signal requiring failed-dissolution evidence + Director substrate-design call, not autonomous worker pick. Removed the "new TypeConnective variant" option; replaced with `inhabits`-edge-shape carrier as third option (audit-time check). The explicit STOP-AND-ESCALATE clause now states: 7th connective is the precondition for failed-dissolution-evidence + Director substrate-design call, not a worker path. feedback_verify_thesis_claims still in play — should have grounded substrate-shape options against the THESIS lock before listing Opaque(T) as worker-autonomous. Pattern continues; reading source-of-truth before authoring options is the discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place) Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter already exist at dag.rs:186, :217 — explicitly authored for the R2 Dimensions consumer per the doc comment at dag.rs:148-160. phantom_unit_mismatch already wired at infer.rs:1057, :1132. The substrate is fully landed; my brief framing it as 'producer sub-lane to land carrier' is wrong on the same feedback_audit_adjacent_authority_first violation that hit nested-optional / unhandled-diagnostic / unenumerated- effects. Reframed the substrate-side brief as no-op / closed-by-audit: - Documents the audit receipt (5 sites confirming substrate exists) - States the lane is closed - Routes T-Modeling Dimensions consumer to dispatch immediately against the existing carrier - Records the lesson: 'always grep substrate before authoring producer briefs' — discipline doesn't end at brief boundaries. Updated r2-modeling-dimensions-phantom-worker.md correspondingly: - Changed gating from 'do not dispatch until producer signal' to 'NOT GATED — dispatch immediately' - Read-first updated with concrete dag.rs/infer.rs cites - Slice §1 changed from 'confirm producer signal' to 'verify substrate at HEAD' - STOP reframed: existing carrier extension would need Substrate Manager call, not autonomous worker pick Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit both verified — no existing substrate (no is_nominal_opaque / MagnitudeBound patterns in dag.rs); both still legitimately producer-side work. Pattern is now four reframes deep on the R2 spin-up wave. The lesson saved is structural: read source-of-truth before authoring options. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority Codex BLOCKING on #836: my new R2 spin-up brief duplicates the existing t-substrate-cardinality-int-lit-worker.md, which carries the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64) stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane). Single-authority violation per INVARIANTS P2. Same feedback_audit_adjacent_authority_first failure as parametric- algebra-for-Dimensions reframe (4 hours ago): assumed substrate authority didn't exist; should have grepped docs/briefs/ before authoring. This is the SECOND R2 spin-up substrate brief closed as redundant — the discipline lesson is structural. Reframed brief as no-op routing doc (documents the audit receipt; routes consumers to the existing authority); updated r2-modeling-int-lit-magnitude-worker.md to cite t-substrate-cardinality-int-lit-worker.md instead. Pattern across the R2 spin-up wave reframes (5 now): 1. nested-optional gating-on-substrate (substrate already past cardinality bridge) 2. unhandled-diagnostic predicate-entailment default (design doc recommends totality-by-omission) 3. unenumerated-effects 8-req design-doc elision 4. parametric-algebra Producer (Declaration.phantom_params already authored explicitly for this consumer) 5. cardinality-for-int-lit Producer (existing brief …
… + bin-shim emit pattern) (#1176) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c33: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 second-wave worker-escalation fixes Four substantive worker STOP-AND-ESCALATEs from briefs landed in PR #797. All four worker recommendations correct; each needs a Director call + brief update. ## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate Worker correctly identified that brief req 2 (declared-effect carrier as part of fn type signature, per feedback_no_annotations) requires net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots. Without parser surface, every user function would have declared_effects = [] while inference returns non-empty — lens fires EffectLeakageError everywhere on enable. Worker rejected power-through and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map parser split). Director picked split: - NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface syntax + lookahead + body parser + lowerer extension + exhaustive-match audit + coproduct dissolution receipt. - MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to post-parser-extension scope. Pre-flight check NOT a parser-extension step; STOP if parser sub-lane PR not merged. ## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping Worker found load-bearing evidence at infer.rs:3693-3703: DB-11 deliberately strips refinements at operator dispatch as a designed-in fix for symmetric-operators failure mode. Brief's "attach where b != 0 as a proof for a / b" directly contradicts this design choice. STOP-3 (where-clause conflict with DB-11) is real; STOP-1 (substrate scope) needs net-new substrate (per-operator partiality fact + predicate- entailment check + asymmetric per-operand refinement-honoring) — M+ minimum. ownership_lens precedent in original brief is post-hoc observability, not proof carrier. Worker recommended redirect to design/scoping per nested-optional precedent. Director picked redirect. Brief fully rewritten as design/scoping with four-question structure: (1) DB-11 interaction analysis; (2) substrate proposal for proof-or- totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes with acceptance-theatre risk on user-defined-total-wrapper-only); (4) Director-actionable recommendation. Output is doc PR. ## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C) Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int) with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136 closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b) i128 implementation requires either path 1 (hierarchy refactor — contradicts non-goal) or path 2 (regen lie between substrate and emit — violates discipline). Worker leaned option (C) re-scope: land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke) to a sibling sub-lane that does proper Int128/Word128 substrate work. Director picked option (C). Brief req 1 re-scoped to drop canonical- carrier-widening; lane value comes from range facts + reconciliation narrowing + out-of-range diagnostic against existing i64. Req 4 explicitly deferred with sibling-sub-lane reference. Sibling sub-lane NOT to be authored or implied in this PR; tracked separately. ## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change) Worker correctly STOP'd per the brief's own pre-flight check: parser sub-lane has not landed; SurfaceExpr::Map not on main. Director authorized cross-lane reassignment: wise-boar-480 takes the parser sub-lane (t-substrate-valuebody-map-parser-worker.md) since they already have full investigation context. No brief changes needed; the routing decision is in the dispatch. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope Resolves codex P2 inline at sha e35103fad on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still required widening LiteralBits::Int(i64) to an unbounded carrier and passing the i64::MIN smoke. Internally unsatisfiable. Fix: - Slice section retitled "range facts + reconciliation narrowing (against existing i64 carrier)" with explicit note about the re-scope. - Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly forbids touching LiteralBits::Int shape, dag_scalar_generated.rs regen for that variant, or tokenize i64 parse path. - Slice steps 2-5 reframed: range facts use i64-representable magnitudes; reconciliation narrowing uses existing i64 carrier; diagnostic only for i64-representable out-of-range; smoke tests for req 5 only (req 4 i64::MIN deferred). - Acceptance checklist updated: - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as re-scoped/deferred. - LiteralBits::Int(i64) carrier untouched (no widening; no parallel; no shape change). - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference. - STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the carrier" — explicit STOP if execution surfaces range-fact narrowing requiring carrier-widening; that's the boundary the re-scope drew; belongs in sibling Int128/Word128 sub-lane. Brief now consistently treats carrier-widening as out-of-scope across all sections. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty Resolves codex BLOCKING #1 at sha e35103fa on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier but req 2 required range facts using "the SAME magnitude carrier as req 1" — meaning i64-typed range bounds. u64's max (2^64-1) doesn't fit in i64; range fact for u64 would have to truncate, omit, or mirror in Rust (representation drift). All three options violate fail-closed declared-facts discipline (P1 / P3). Fix: - Req 2 rewritten to specify String-decimal representation: range_min_inclusive: String + range_max_inclusive: String fields on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127" for i8; "0"/"18446744073709551615" for u64). - Explicit reasoning why String-decimal: u64's max doesn't fit in i64; binding range bounds to literal carrier forces truncation/ omission/mirror-drift; all violate fail-closed declared-facts discipline. - Bridge framing: String-decimal is pending the sibling Int128/ Word128 sub-lane; both range bounds and literal payload migrate to typed carrier when that lands. - Req 3 updated for String-decimal comparison semantics: reconciliation parses both bounds and literal magnitude into a common comparison space (i128 host comparison primitive — host narrowing, NOT carrier widening). Bounded by what the i64-typed literal can express; any i64-representable literal compares against any width's String-decimal bound. Carrier discipline preserved. Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral) is sha-stale — already resolved at 3e142d169. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback). Real residual: req 2 specifies String-decimal range bounds (to cover u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" / "i64-representable magnitudes" for the range facts. Two incompatible authorities for the same range-fact shape — would let a worker satisfy the slice while truncating/omitting u64 bounds (P3 fail-closed violation). Fix: - Line 31 (req 1 re-scope clarification): updated to explicitly state "range facts (req 2) use String-decimal representation (width- independent; covers u64::MAX which doesn't fit in i64)". Distinguished literal *payload* (stays i64) from range-bound *representation* (String) — both serve req 1's "no carrier widening" boundary. - Line 44 (slice step 2): updated from "Range bounds use i64- representable magnitudes" to "Range bounds use String-decimal representation per req 2" with concrete example (u64 bounds). - Acceptance bullet: updated from "Range facts on integer algebras (substrate-declared, not Rust-mirrored)" to add "using String-decimal representation ... width-independent; u64 bounds expressible without truncation." The brief now consistently treats range bounds as String-decimal across req 2, req 3, slice, acceptance, and the req 1 clarification — no remaining authorities saying i64-typed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing User + PM exchange 2026-04-25 surfaced that the in-flight effects chain was importing wrong assumptions from external languages (declared-effects-as-annotation + lens-vs-declaration check). Right framing under gunbc's closed-system discipline is parallel to complexity: every effect derives structurally from the composition of typed primitive operations; nothing can hide because there's no escape hatch; nothing needs annotation because the structure IS the registry. Four doc-only actions: 1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md. Frames the closed-system answer with PM's 5-behavior synergy table (Value/Transform/Branch/Loop/Bind as universal compositional-fold pattern). Four worked examples; aggressive reading on redundancy (compile-error-by-construction via referential-transparency proof; reread() primitive for legitimate cases); implementation-brief shape in §Q6. 2. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md. 3. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md. Notes Fn→Arrow refactor brief stays dispatchable as independent value. 4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by- construction framing replaces lens-detection framing. Memory file feedback_closed_system_effects.md saved separately; cross-link added to feedback_construction_over_ratchets.md. Net cost: doc-level cleanup. Zero substrate code rework. Foundation (OperationEffect + service-call infrastructure + 5-behavior substrate) already exists. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect Per PM convergence review on #808 + user's deeper 2026-04-25 framing: the closed-system framing landed in #808 retired the user-facing annotation but kept OperationEffect taxonomy as substrate-level tagging. User's deeper framing: the taxonomy ITSELF is parallel-representation — operations are intrinsically read-shaped or write-shaped via their TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns- derived-value-only → read). Tagging operations with Read | Upsert | Create | Append | Delete names what the structure already says. Three changes: 1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as normalized view, or retire as parallel-representation?" - Two paths: (i) tags derived from signature shape (acceptable normalized view) vs (ii) tags declared per-primitive (parallel- representation; retire). - Audit-as-existence-check (Q4 req 2 reframed): all effectful primitives derive cleanly from signature shape → path (i); any primitive needs hand-declared tag → path (ii) by existence proof. - Director default: path (ii). Logging primitives that return Unit are likely the audit's existence-proof. - Two design-question resolutions: (a) external effects not in return type → resource-threading discipline (typed param returned modified, IO-monad-without-the-monad pattern); (b) transactional grouping → derived structural fact from Bind composition + typed transaction primitives. 2. Q4 reqs revised: req 2 from "tag every primitive with explicit OperationEffect signature" to "audit-as-existence-check that every primitive's type signature derives the right effect classification"; req 3 added (resource-threading discipline); req 6 added (transactional-pattern lens). Req 1 (effects lens) anchors on operation type-signature shape, not on hand-declared tags. 3. THESIS:345-347 amendment strengthened — "operations are intrinsically read-shaped or write-shaped via their type-signature shape; consumers walk the signatures directly; there is no parallel taxonomy or annotation layer to declare or maintain. Tracking effects as a separate enumerated concept IS the bug pattern, dissolved by construction." Plus references to resource-threading discipline + transactional grouping as derived structural fact. Memory file feedback_closed_system_effects.md updated to reflect the deeper framing (type-signature-shape, not taxonomy-tagging) + resource-threading discipline section + transactional-patterns section. Net cost: doc-only delta on top of #808. Substrate retirement (OperationEffect enum + derive_op_effect + idempotency.dag re-anchor) deferred to the audit-as-existence-check phase of the implementation brief; surfaced as Q5.5 OPEN CALL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage Resolves codex BLOCKING at sha d49ce79a on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real: the prior text claimed service primitives "already carry typed effect signatures" presenting future audit-state as current substrate fact (P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the OperationEffect line but left a parallel over-claim on the new "signature-shape coverage" framing. Fix: Q4 substrate-state listing rewritten to honestly distinguish: - Live: Behavior enum + substrate foundation (the principle that operations should carry signature shape). - Incomplete: signature-shape coverage across actual primitives. HTTP-derived primitives carry implicit shape via derive_op_effect's method-table; logging/mutation primitives that return Unit or don't thread their target resource do NOT carry the structural shape that would express read-vs-write. Achieving full coverage is required work under reqs 2 + 3, not a current fact. - Pending audit-as-existence-check: OperationEffect + derive_op_effect (path (i) vs (ii) per Q5.5). Honest live-state callout added explicitly: "the closed-system FOUNDATION (5 behaviors + DAG substrate + the principle that operations should carry signature-shape) is live. The IMPLEMENTATION COVERAGE across all effectful primitives is partial. Req 2 + req 3 are the work that closes the gap." Brief now distinguishes principle-is-live (foundation) from coverage-is-partial (audit work) without conflating them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim Per PM follow-up review on #808 + user's stronger discipline framing ("substrate must make bypass structurally impossible at every layer of the transport stack"): the closed-system claim is honest only when typed primitives ARE the path. Today two structural holes exist where bypasses sidestep the typed-primitive substrate. Both surfaced explicitly as Q4.5 pre-conditions — load-bearing for the lens's coverage claim. Three changes: 1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed- system claim)" inserted between Q4 and Q5: P1 — Extdeps typed-primitive consumption structurally enforced. Substrate must make `messages: Json` impossible to declare in service definitions; typed `LlmMessage` / `ContentBlock` / `GitHubAuthToken`-with-full-scopes are the only path. Tracked debt at ROADMAP.md:153-154 (LLM provider flattening) + `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded). Required prereq for full lens coverage; lens can land first + surface structural-coverage-gap diagnostics on bypass surfaces so the gap becomes visible rather than silent. P2 — `ExecuteCommand` fully materialized as typed runner primitive. TESTING.md (post-#782) committed to 0-residual but ExecuteCommand isn't fully materialized; deleting Rust boundary tests creates verification gap. Already named under PB-Runtime in Zero-Floor; signal pending. Pre-requisite for ANY Rust boundary-test deletion. 2. Old leftover duplicate Q5 section deleted (artifact from prior Q5/Q5.5 reshape; second copy of asymmetric-tightening text was in the file alongside the earlier Q5 instance). 3. Worker-discretion-vs-Director-call section in Q4.5: lens implementation worker dispatchable now (reports gaps as findings); P1 closure is substantive substrate work touching extdeps (dedicated lane); P2 closure is PB-Runtime (signal pending). Net: design doc now honestly distinguishes principle-is-live (Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs named explicitly). The closed-system claim has explicit pre- conditions documented; implementation brief discovers them as known dependencies, not as STOP-AND-ESCALATEs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two real residuals after the Q5.5 reframe: 1. Q6's reqs/STOPs/acceptance still framed under path (i) — said "audit + tag std/ primitives — every effectful primitive carries an explicit OperationEffect signature." Directly contradicted Q4 (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment ("there is no parallel taxonomy to declare or maintain"). Worker reading Q6 in isolation would author the retracted shape. 2. Capacity / sequencing table line about "audit lane (tag std/ primitives with effect signatures)" carried the same stale framing. 3. Q6 STOP "primitive performing side effects without an OperationEffect tag" assumed tag-as-authority; under path (ii) the STOP shape is "primitive whose signature doesn't structurally reveal its effect." Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale (already fixed at f073aa95e Q4.5 commit). ## Q6 fixes - Reqs renumbered + reframed: - Req 1 anchors on operation type-signature shape (not hand-declared OperationEffect tags); composition reads from signature shape per Q2 table. - Req 2 changed from "audit + tag every primitive" to "audit-as-existence-check" — verify signature-shape coverage; ANY primitive needing a hand-declared tag IS the existence-proof for path (ii) retirement. - Req 3 added: resource-threading discipline applied to existing primitives (logging that returns Unit gets reshaped per audit). - Req 6 added: transactional-pattern lens (Bind composition + Transaction → Transaction'). - Req 7 added: asymmetric-tightening worked example in PR body (per claude review observation; the one place declaration-shaped surface re-enters). - Req 8 (was 5): tests now reference signature-shape derivation explicitly, not tag lookup. - STOPs reframed: - "OperationEffect retirement decision" — audit produces path (i) vs (ii) verdict; substrate retirement is its own dedicated sub-lane; this lane does NOT absorb it. - Pure/impure carrier STOP notes that "pure" should also derive from signature shape (pure functions don't return modified resources) — so the STOP itself may dissolve under further design. - Q4.5 P1 explicitly NOT a STOP — lens reporting structural- coverage-gap on extdeps bypass surfaces is the lens delivering its foundation-gap-visibility value. - Q4.5 P2 explicitly independent — lens doesn't depend on ExecuteCommand materialization. - Acceptance extended: lens reports gap diagnostics on P1 bypass surfaces; audit produces existence-proof verdict for Director re-decision; asymmetric-tightening worked example in PR body. ## Capacity / sequencing table Replaced "1 audit lane (tag std/ primitives with effect signatures)" with "1 audit-as-existence-check lane (verify primitives' signature- shape coverage; NOT 'tag every primitive') — produces the path (i) vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2 prereq lanes to the net summary. Closing line: "The taxonomy- retirement scope (substrate-side) is not in this lane — it's surfaced by audit and routed to dedicated retirement lane if path (ii) wins." Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity table. Worker reading Q6 in isolation now sees path-(ii)-default framing matching Q4 + Q5.5 + THESIS amendment. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792 Resolves codex inline BLOCKING at sha 191be310 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150. Real: my Q4.5 P2 framing described ExecuteCommand as still NotYetImplemented (M1.5 allowlist + Rust TestRunner returning NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand extension before this PR's authoring. TESTING.md:195 capability-state callout confirms: - Rust TestRunner + M1.5 testgen harness share one std::process path for arbitrary command + args + expect_exit_code. - M1.5 allowlist + fail-closed panic retired. - Distinguishable ClaimResult::Fail messages for spawn / timeout / policy / exit-mismatch. - Linux unshare(1) namespace isolation on host-allowing systems. - T-PB-B-1 boundary migration example landed. Fix: P2 section rewritten: - Header retitled "ExecuteCommand runner primitive: LANDED (PR #792); residual is bulk-migration." - Status update naming PR #792 + the post-#792 capability state (allowlist retired, etc.). - Honest acknowledgement: "My earlier P2 framing was stale." - Residual narrowed to bulk-migration of existing Rust Command::new boundary tests (tracked as ROADMAP residual, not lens prereq). - Sequencing reframed: P2 was always orthogonal to the effects lens itself; bulk migration proceeds at its own pace; lens not blocked. Q4.5 footer updated: - "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via #792; only consumer-side bulk migration remains)" - Worker-discretion-vs-Director-call P2 line updated: "runner primitive landed; only consumer-side bulk migration remains; tracked as ROADMAP residual, independent of the lens." Q6 STOP for P2 updated: - "the lens itself doesn't depend on P2; only TESTING.md's 0-residual claim does" → "runner primitive landed via PR #792 (post-Q4.5- authoring update). The lens itself never depended on P2; bulk consumer migration is residual ROADMAP work and remains independent of this lane." Brief now reflects live state. The closed-system claim's prereq landscape is honest: - P1 (extdeps typed-primitive consumption): real prereq, tracked debt at ROADMAP:153-154. - P2 (ExecuteCommand runner): satisfied via #792; bulk migration is consumer-side residual, not foundation work. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale Resolves codex non-blocking finding at sha bcac41bb on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real residual: capacity-table line still listed P2 as "`ExecuteCommand` materialization" prereq + framed both P1 and P2 as "pre-existing tracked-debt" — but my prior 57a9b1318 fix established that PR #792 already landed the runner primitive, so P2 is no longer a materialization prereq. Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq) from P2 (residual, not prereq): - P1: extdeps typed-primitive consumption — pre-existing tracked debt at ROADMAP:153-154; load-bearing for the lens's full-coverage claim. - P2: ExecuteCommand runner primitive landed via PR #792; only consumer-side bulk migration of existing Rust Command::new boundary tests remains (tracked as ROADMAP residual, independent of the lens; not a materialization prereq). Brief now consistently treats P2 as bulk-migration-residual across: - §Q4.5 P2 section header (LANDED via PR #792; residual is bulk-migration). - §Q4.5 footer (P2: runner primitive landed; only consumer-side bulk migration remains). - Q6 STOP for P2 (runner primitive landed; bulk migration is residual ROADMAP work). - §Capacity / sequencing impact (P2 as residual, not prereq). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349 Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated target-grounding prose; the matching extdeps typed-primitive bypass entries (LLM service flattening, GitHub auth model bypass) live at ROADMAP.md:348-349. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix third stale ROADMAP citation at line 271 Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence at line 271 in the §Q4.5 capacity table. Now consistent with lines 139 and 173 (ROADMAP.md:348-349). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity Codex flagged 'Effect-signature tagging on std/ primitives' as potentially contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240) already explicitly say 'NOT tag every primitive' — but the cross-manager line used sloppy wording. Reworded to make explicit that the audit walks signature shape; no parallel tag added. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5 - B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound - B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause - B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge - B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation) B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25): language vocabulary is primitives + namespacing only; no escape syntax; the §0 sentinels are the compiler itself failing to use primitives + namespacing internally. Eight surface sites dissolve via four substrate carriers (DeclarationRef, structural fold-shape carrier, structural emit-helper carrier, structural extdeps-fixture-set carrier). B1-B3 are independent; dispatch in parallel. B4 is sequential program work; sub-brief dispatch (B4.1-B4.12) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — drop incoherent inner-fallback non-goal Codex P2: the non-goal line excluding the inner declaration().name unwrap_or_else fallback contradicted Slice step 2, which replaces the whole chain with let-Some-else-return. Both fallbacks are in scope by construction; remove the contradictory non-goal. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives PM REQUEST_CHANGES: §Frame listed '4 type connectives (Conjunction | Disjunction | Cardinality | Bit)' which contradicted the canonical thesis source. Replaced with the canonical 6 (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary closes here'. Also removed 'typed substrate carriers' from the vocabulary list — substrate carriers are defined using the vocabulary, not part of it. Added a clarifying note that B4's carriers (DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are typed declarations composed from the vocabulary, not vocabulary extensions. Per feedback_verify_thesis_claims: brief framings citing thesis structure must ground in the canonical source. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of naming the live substrate authority. Two coordinated fixes: 1. §Read first cites src/v3/std/substrate.dag (live .dag substrate authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel meta-type — already exists with consumers in verification.dag, emit_model.dag, python.dag). 2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing DeclarationRef'. The work is consumer migration + any role-extension layer the audit reveals, NOT designing or landing the carrier. Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers) keep their 'new' framing but explicitly require sub-briefs to grep src/v3/std/ + src/v3/spec/ for existing authority before authoring 'design and land' framing — per feedback_verify_thesis_claims + feedback_emitter_workaround_is_gap_symptom. Acceptance + sub-brief dispatch order updated to reflect B4.1's consumer-migration shape. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — tighten Phase 1 umbrella sentence The umbrella 'Land the typed carriers into src/v3/std/' framing was stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced with audit-first wording that covers both the consume-existing case (#1) and the design-and-land case (#2-#4 if their audits show real gaps). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands' which conflicted with the post-reframe reality that B4.1 consumes the existing DeclarationRef. Updated to 'consumes or lands' with explicit existing-authority citation and audit-pending caveat for B4.2-B4.4. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — soften regression-test requirement (3 worker bounces) Three consecutive B1 worker dispatches (zesty-crane-890 cursor → valiant-boar-498 codex → cool-lynx-395 cursor) archived without opening a PR. Likely friction point: brief Slice step 4 asks for a unit test that constructs a Dag with an orphan variant declaration, but emit.rs has zero existing #[test] precedent — emit testing happens via integration fixtures. Workers see 'build novel test harness' inside what's billed as an S-scope fix and bounce. Per feedback_construction_over_ratchets: when a brief has friction, fix the brief, don't ratchet the worker. Softened step 4 + acceptance: regression test stays optional. If test setup requires novel scaffolding, route the gap to follow-up. The structural fail-closed at step 2 is the load-bearing change. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description' is too weak; PR descriptions don't survive squash-merge cleanly. Two coordinated edits: 1. Slice step 4 — explicit substrate-signal framing: skipped test means emit-side hermetic-unit-test infrastructure is the missing substrate (feedback_emitter_workaround_is_gap_symptom). 2. Acceptance — require ROADMAP debt row (new or existing) with named dissolution trigger, referenced in PR body. Converts the skip from PR-local note (transient) into tracked debt (durable, dispatchable). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124 Codex BLOCKING: my earlier softening claimed emit.rs had no #[test] precedent — wrong. The module has #[cfg(test)] mod tests at line 3124 with 12+ tests using compile_to_dag(source, filename) as harness (e.g., go_struct_fields_render_with_separators :3143, shared_walk_to_disj_finds_match_scrutinee_sum_type :3195). This is a feedback_verify_thesis_claims violation on Director-side brief authoring — claim made without grep verification. Fix: restore step 4 as required, with explicit precedent citation. Worker constructs the failure case via the existing harness (direct Dag, fixture string, or BranchPattern exercise; worker's call on cleanest path). STOP-AND-ESCALATE only if construction proves materially harder than precedent suggests, in which case that escalation surfaces a real substrate gap and warrants ROADMAP debt — but the default is 'add the test.' Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites) Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded to 'several using compile_to_dag'. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this is Wave 1 of Director's 14-brief authoring queue, covering B4 program internals. Authored: - b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) — replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag") fold-skip with structural template-formal carrier; mandatory authority audit per feedback_audit_adjacent_authority_first. - b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) — replaces §0.6 emit.rs bind/branch.span.file equality with typed BindEmitParticipation/BranchEmitParticipation roles populated at lowering; aligned with #824 worker's in-flight implementation shape. - b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4 of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with typed substrate authority; explicit pre-promotion-constraint disposition (single-authority vs authority+tracked-debt) addresses parallel-representation risk surfaced on #825. - b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) — names B4.5-B4.12 Phase 2 sites with carrier dependencies, cross-program coordination notes, and skeleton-brief template; full per-site briefs author at dispatch time per #827's Substrate Manager ownership. Cross-cutting discipline applied per inbox #828 reply: - feedback_audit_adjacent_authority_first (mandatory grep before design) - feedback_no_textual_enforcement_bridges (no replacement sentinels) - feedback_parallel_representation_debt (explicit if shape (b)) - feedback_construction_over_ratchets (no parity-by-runtime as primary) - feedback_coproduct_dissolution (receipts for new variants) Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3) Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue. Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by Modeling Manager's Wave 3 worker briefs (gated on these landing). Authored: - r2-substrate-cardinality-for-int-lit-subset.md (M) — produces magnitude carrier consumed by T-Modeling int-lit. Coordinates with PR #806's prior cardinality work; mandatory authority audit guards against #796's rejected IntLiteralMagnitude shape resurfacing. Open design questions: magnitude representation, reconciliation narrowing point, i64::MIN representability. - r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces nominal-opacity carrier consumed by T-Modeling Secret<T>. Open design questions: carrier shape (flag/connective/sealed-accessor), generic-walk discipline, accessor gating. - r2-substrate-parametric-algebra-for-dimensions-subset.md (M) — produces phantom-parameter carrier consumed by T-Modeling Dimension<Carrier>. Open design questions: carrier shape, type-equivalence rule, algebra-method dispatch, lifting/coercion. All three: - Scoped narrowly to their paired R2 consumer; not full substrate-capability lanes. - Mandatory pre-author authority audit per feedback_audit_adjacent_authority_first. - Cross-program readiness signal pattern from #827's manager rework. - Coproduct dissolution receipts required for any new variants. - Open design questions surfaced explicitly so Substrate Manager (or Director pre-spin-up) can resolve at dispatch time. Wave 3 (T-Modeling worker briefs × 4) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4) Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue. Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each gated on a Substrate Manager readiness signal (Wave 2 producers). Authored: - r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2 cardinality-for-int-lit; moves narrowing from tokenizer to reconciliation; MagnitudeOutOfRange diagnostic per C-8. - r2-modeling-secret-graduation-worker.md — gated on Wave 2 nominal-opaque-for-Secret; authors Secret<T> + gated accessors (redact, compare_in_constant_time); C-8 diagnostic on non-gated access; signals Impossible-Bugs Manager on close (thesis claim covered). - r2-modeling-dimensions-phantom-worker.md — gated on Wave 2 parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier> + core SI base units + algebra-method dispatch; cross-dimension arithmetic produces typed diagnostic; signals Impossible-Bugs Manager (thesis claim). - r2-modeling-tokenizer-charclass-phase2-worker.md — gated on T-Substrate ValueBody-list/sum (#790); migrates tokenizer consumers to Char/List<Char>/CharClass canonical types; sibling consumer to Grounding Manager's Engine sharpened-(b). All four: - Explicit gating: 'do not dispatch until producer signal posts.' - Producer/consumer signal pattern from #827. - Cross-program signals to R2 Release Manager (Goal 2 closure) and Impossible-Bugs Manager (thesis-claim coverage). - Spoofing regression tests: discipline anchor against feedback_no_textual_enforcement_bridges. Wave 4 (T-ImpossibleBugs worker briefs × 3) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3) Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue. Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes, consuming the existing design/scoping briefs as authority. Authored: - r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on cardinality refinement substrate (T-Substrate territory adjacent to int-lit / DB-11 alias-where). Implementation: structural normalize of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T?? worker decision (reject vs normalize). Cites t-impossiblebugs-nested-optional-flatten-design.md as authority. - r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated on Tier 2 substrate (predicate-entailment infrastructure; distinct from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes predicate entailment, (b) feedback_totality_by_omission dissolves partial primitives, (c) park. Worker decides at audit time. Cites t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority. - r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate prerequisite per closed-system framing in design doc (#808). Audit- as-existence-check + lens implementation as compositional fold over 5 behaviors; redundancy detection compile-error via referential transparency + reread() escape hatch; path (i/ii) decision on OperationEffect taxonomy retain-vs-retire (default retire). Cites design doc #808 as authority. Cross-cutting: - Each cites prior design/scoping brief as authority (the existing *-design.md / *-worker.md REFRAMED files). - Explicit gating per #827 producer/consumer signal pattern; two briefs gated on substrate, one NOT gated (closed-system). - STOP-AND-ESCALATE includes 'design brief assumptions don't hold' surfacing per feedback_thesis_gate_state_drift. Wave 4 complete. Director's 14-brief queue done; awaiting PM portion (6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4.4 — tighten Slice §3 per PM review on #836 PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b) (authority + tracked debt parallel-rep) as autonomously acceptable contradicts feedback_construction_over_ratchets + feedback_parallel_representation_debt. Tightened: - Shape (a) is the only autonomous worker path. - Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a regen-host-loader sub-lane decision; not authorable without explicit Substrate Manager approval citation in the PR body. - Acceptance bullet requires the approval citation when shape (b) lands. - STOP-AND-ESCALATE rephrased to make this explicit; permanent parallel-representation re-escalates even with manager approval. This preserves shape (a) as autonomous; shape (b) becomes a cross-manager design escalation, not a B4.4 implementation call. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief Cursor review on #836 flagged the Read-first reference to .claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md as machine-specific (outside the repo, not resolvable from a normal clone). Replaced with in-repo prose pointing at the design doc's §Q1-Q3 as canonical authority — the discipline lives there in-repo. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs) Codex flagged: src/v3/std/types.dag does not exist; the canonical authority is at dsl/std/types.dag. Affected briefs (all from R2 spin-up Wave 2 + Wave 3): - r2-substrate-cardinality-for-int-lit-subset.md - r2-substrate-nominal-opaque-for-secret-subset.md - r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs) - r2-modeling-dimensions-phantom-worker.md - r2-modeling-secret-graduation-worker.md feedback_verify_thesis_claims violation on Director-side brief authoring — assumed path without grep. Same family of error as the earlier emit.rs precedent claim. Mass-replaced via perl; verified no remaining stale refs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant Codex BLOCKING on #836: my R2 worker brief gated nested-optional on cardinality refinement substrate, but the design doc verifies v3 is ALREADY past the cardinality bridge — TypeConnective::Cardinality is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is the carrier for Option. The dissolution is an UNGATED implementation via substrate-constructor invariant. feedback_verify_thesis_claims violation again — should have read the design doc fully before assuming the substrate gate. Rewrote brief to match design doc canonical sketch: - Single predicate (cardinality_idempotent_target) owns the rule - Single allocator (alloc_cardinality_decl) is THE substrate-constructor - API closure on TypeConnective::Cardinality payload (modeling-discipline practice 6) — variant cannot be struct-init'd outside the allocator - 3 hand-Rust + ~22 codegen call sites enumerated per design audit - infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as the killer case for generic-instantiation paths - Surface-syntax T?? decision left to worker (Director-lean: silent normalize) Brief now dispatchable immediately, no producer signal needed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment substrate path, but the design doc §4 explicitly recommends totality-by- omission as the Director-actionable path. Predicate-entailment is M+ scope that reopens DB-11's explicitly-closed asymmetric-strip design — design doc explicitly discards it. feedback_verify_thesis_claims violation again — same family as nested- optional reframe. Should have read design doc §4 in full before assuming the path ordering. Rewrote brief to match design doc §4 follow-on shape: - Primary path: per-class totality-by-omission (algebra retype + per- target realization migration). For Int/Int: OrderedRing.div retype at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 / python:486 + python_target.rs:680 helper). - NOT predicate-entailment (out of scope; M+ + DB-11 reopen). - NOT NonZero-typed-input (deferred to separate per-operand-variance substrate brief; STOP-AND-ESCALATE if chosen). - Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i] indexing, quotient, remainder) queue separately per design doc audit. - feedback_totality_by_omission discipline anchor explicit. Brief now matches feedback_totality_by_omission discipline + design doc recommendation. No substrate prerequisite; dispatchable immediately. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a pattern: I authored R2 worker briefs without fully reading each design doc's Director-actionable recommendation. Pre-emptively re-verified unenumerated-effects against design doc §Q6 to catch the same family of error before reviewers do. Findings: brief was substantively close but missing 3 of 8 design-doc reqs: - Req 3: Resource-threading discipline applied to existing primitives - Req 5: reread(key) primitive in std/ as explicit Slice item (was only mentioned in tests) - Req 7: Asymmetric-tightening worked example in PR body Plus: Slice didn't cite the canonical lens path src/v3/lenses/effect_enumeration.dag from design doc. Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6 specifies 4 specific STOPs (path-decision-escalation, pure: Bool carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP) that I had elided. Reframed Slice as 8 numbered reqs matching design doc verbatim; STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs; Acceptance enumerated per req. This is the third reframe in the unhandled-bugs series — same feedback_verify_thesis_claims violation each time. The pattern suggests Director-side R2 brief authoring should ALWAYS read each design doc's §Director-actionable / §Q-recommendation in full first, not assume. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)" listed as a worker-pick option violates THESIS.md substrate-shape lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) are canonical (per #811 thesis additions and #827 PM review); a 7th is a C1 stop signal requiring failed-dissolution evidence + Director substrate-design call, not autonomous worker pick. Removed the "new TypeConnective variant" option; replaced with `inhabits`-edge-shape carrier as third option (audit-time check). The explicit STOP-AND-ESCALATE clause now states: 7th connective is the precondition for failed-dissolution-evidence + Director substrate-design call, not a worker path. feedback_verify_thesis_claims still in play — should have grounded substrate-shape options against the THESIS lock before listing Opaque(T) as worker-autonomous. Pattern continues; reading source-of-truth before authoring options is the discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place) Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter already exist at dag.rs:186, :217 — explicitly authored for the R2 Dimensions consumer per the doc comment at dag.rs:148-160. phantom_unit_mismatch already wired at infer.rs:1057, :1132. The substrate is fully landed; my brief framing it as 'producer sub-lane to land carrier' is wrong on the same feedback_audit_adjacent_authority_first violation that hit nested-optional / unhandled-diagnostic / unenumerated- effects. Reframed the substrate-side brief as no-op / closed-by-audit: - Documents the audit receipt (5 sites confirming substrate exists) - States the lane is closed - Routes T-Modeling Dimensions consumer to dispatch immediately against the existing carrier - Records the lesson: 'always grep substrate before authoring producer briefs' — discipline doesn't end at brief boundaries. Updated r2-modeling-dimensions-phantom-worker.md correspondingly: - Changed gating from 'do not dispatch until producer signal' to 'NOT GATED — dispatch immediately' - Read-first updated with concrete dag.rs/infer.rs cites - Slice §1 changed from 'confirm producer signal' to 'verify substrate at HEAD' - STOP reframed: existing carrier extension would need Substrate Manager call, not autonomous worker pick Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit both verified — no existing substrate (no is_nominal_opaque / MagnitudeBound patterns in dag.rs); both still legitimately producer-side work. Pattern is now four reframes deep on the R2 spin-up wave. The lesson saved is structural: read source-of-truth before authoring options. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority Codex BLOCKING on #836: my new R2 spin-up brief duplicates the existing t-substrate-cardinality-int-lit-worker.md, which carries the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64) stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane). Single-authority violation per INVARIANTS P2. Same feedback_audit_adjacent_authority_first failure as parametric- algebra-for-Dimensions reframe (4 hours ago): assumed substrate authority didn't exist; should have grepped docs/briefs/ before authoring. This is the SECOND R2 spin-up substrate brief closed as redundant — the discipline lesson is structural. Reframed brief as no-op routing doc (documents the audit receipt; routes consumers to the existing authority); updated r2-modeling-int-lit-magnitude-worker.md to cite t-substrate-cardinality-int-lit-worker.md instead. Pattern across the R2 spin-up wave reframes (5 now): 1. nested-optional gating-on-substrate (substrate already past cardinality bridge) 2. unhandled-diagnostic predicate-entailment default (design doc recommends totality-by-omission) 3. unenumerated-effects 8-req design-doc elision 4. parametric-algebra Producer (Declaration.phantom_params already authored explicitly for this consumer) 5. cardinality-for-int-lit Producer (existing brief is autho…
Summary
Director ad-hoc dispatch worker brief for the R2 T-Substrate 4th sub-lane: extending v3's
ValueBodyenum with aList(Vec<FieldValue>)variant so top-leveldata X: List<T> = [...]declarations stop falling through toValueBody::Unparsed(SourceSpan)and triggering R14 hard-fail.Single new file:
docs/briefs/t-substrate-valuebody-list-worker.md.Why
Loader-close worker (PR #776) discovered
rust_pilot_primitives: List<RustPrimitive> = [...]lowers asValueBody::Unparsedbecause v3 lacks a top-level list variant. Two named consumers share this substrate work (both list-of-sum):rust_pilot_primitives.data ascii_scan_order: List<CharClass> = [...](per PR docs: charclass phase-2 → R2 T-Substrate (4th sub-lane) + 0-floor self-hosting design proposal (supersedes ≤5-floor framing) #762 reclassification).kernel_algebra_profile(Map<String, AlgebraProfile>) is excluded — different substrate shape, tracked separately as a sibling future T-Substrate sub-lane needingValueBody::Mapwork.What lands when this brief's worker dispatches
src/v3/compiler/src/dag.rs:258-287ValueBody::List(Vec<FieldValue>)variant; doc-comment updated per req 5src/v3/compiler/src/lower.rs:2378-2436lower_data_itemmatch producingValueBody::List, mirroringlower_record_to_structuralat :2413src/v3/compiler/src/lower.rs:2224-2273rust_pilot_primitiveslowers structurally with 10FieldValue::VariantelementsValueBodyexhaustive-match call sitesgrep)Element shape
Vec<FieldValue>mirrors the existing nestedFieldValue::List(Vec<FieldValue>)atdag.rs:343for structural uniformity.Five consumer-side requirements baked in
ValueBody::List(Vec<FieldValue>)variant added.lower_data_itemproduces it for list-shaped surface expressions.dag.rs:259-262updated in same PR.STOP-AND-ESCALATE conditions
Named for: element-shape choice with cross-consumer implications, parser-side surface-expr gaps, exhaustive-match wildcard swallowing, substrate.dag declaration changes (PB-Substrate territory), DB-8 fixed-point drift, serializer/cementer non-extension.
Cross-manager note
crisp-seal-366): Phase 2 brief att-ground-engine-phase-2-enumeration.md(forward-planned, not yet authored per PR R2 Grounding Manager — pre-author Engine Phase 1 typestructure brief + Phase 1/2 split working state #785) becomes authorable against the live shape after this PR lands.stern-swift-335): this PR doesn't touch substrate.dag declarations, so no PB-Substrate conflict expected.ascii_scan_orderdeclaration becomes authorable post-this-PR.Soft dependency on #782
Brief cites the post-cascade re-scoping in
docs/r2-structure.md(2 consumers;kernel_algebra_profileexcluded). PR #782 is APPROVE/APPROVE awaiting merge; once it merges, the cited authority text matches what's on main. The substrate work itself is independent of #782 landing.Test plan