Skip to content

t-substrate cardinality int - #806

Merged
briansrls merged 41 commits into
mainfrom
session/royal-badger-316
Apr 25, 2026
Merged

briansrls merged 41 commits into
mainfrom
session/royal-badger-316

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Opened from session-dashboard for session royal-badger-316.

@briansrls

Copy link
Copy Markdown
Contributor Author

Director review — APPROVE on substance. Re-scope honored cleanly; this is what the brief asked for.

Worker correctly read the re-scoped brief (which the prior worker on #796 did not). Verified at HEAD:

Re-scope discipline preserved

  • ✅ LiteralBits::Int(i64) untouched — diff reads LiteralBits::Int(*n) and LiteralBits::Int(value) as i64 throughout; no widening.
  • ✅ No new substrate types — no Int128, UInt128, Word128Carrier, or parallel magnitude carrier added.
  • ✅ No regen-explosion — diff is +307/-15 (vs feat(v3): T-Substrate int-literal magnitude — i128 carrier, range facts, infer narrowing, MagnitudeOutOfRange #796's +5308/-13034); proportional to the actual scope.
  • ✅ String-decimal range facts on IntegerPrimitive — all 8 integer primitives (i8/i16/i32/i64/u8/u16/u32/u64) get range_min_inclusive: String + range_max_inclusive: String per req 2; u64's "18446744073709551615" representable without truncation.
  • ✅ Host-narrowing-time comparison via i128 parse — new int_literal_ranges.rs (158 lines) provides IntegerRange::min(self) -> i128 / max(self) -> i128 parsing String-decimal bounds; contains_i64(self, value: i64) -> bool does the i128 host comparison per req 3. Literal payload stays i64; comparison space is i128 host primitive — exactly the brief's framing.

Implementation surfaces touched (per req coverage)

Req File Status
2 (range facts) dsl/extdeps/languages/rust/primitives.dag ✓ all 8 entries populated
3 (reconciliation narrowing) src/v3/compiler/src/infer.rs (+24), int_literal_ranges.rs (+158), lower.rs (+46) ✓ via contains_i64 host comparison
5 (MagnitudeOutOfRange diagnostic) src/v3/compiler/src/diagnostics.rs (+22) ✓ new variant
Tests extdeps_rust_primitives_loader_test.rs (+9) ✓
Pilot mirror coordination grounding_pilot/src/lib.rs (+18), grounding_engine/src/lib.rs (+4) ✓
Regen regen_bootstrap_emit.rs (+14) ✓

Diff stats are honest (small substrate addition; range-fact populations; bounded reconciliation logic + diagnostic).

What's not in the diff (per re-scoped brief — NOT scope violations)

  • ❌ Carrier widening (deferred req 1; sibling Int128/Word128 sub-lane handles).
  • ❌ i64::MIN smoke test (deferred req 4; sibling sub-lane).

Both are per the re-scope; absence is correct.

Verdict

APPROVE pending CI green + ready-flip. This is exactly the lane the brief specifies. Diff scope is bounded, re-scope discipline preserved, host-vs-substrate comparison-vs-carrier separation honored.

Worker can flip to ready when comfortable; merge enables T-Modeling int-lit follow-on brief authoring (paired-blocked on this lane landing).

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 370f7c0e · Trigger: schedule
  • Thinking: 361s wall

BLOCKING (2)

Root Cause

  • src/v3/compiler/src/int_literal_ranges.rs source integer cardinality is introduced at the consumer instead of being carried from std.integer/std.bit or the new RustPrimitive facts → move the range fact into substrate authority and make this helper a structural lookup.
  • src/v3/compiler/src/int_literal_ranges.rs the diagnostic can compute advice but not a source rewrite → leave fixes empty or add a non-applyable diagnostic hint carrier instead of encoding it as Correction.

⚠️ The range check is directionally right, but the production path needs one substrate authority for bounds and must not publish fake correction edits.

}
}

pub(crate) fn integer_range_for_decl(dag: &Dag, decl: DeclarationId) -> Option<IntegerRange> {

This comment was marked as resolved.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified against current PR head e1358bf6a6882656580b1871f03501d23ce692a8: this is addressed there. integer_range_for_decl no longer uses the hard-coded declaration-name bounds table; it derives a routing key from the expected DAG type shape and then reads IntegerRangeFact structural data declarations from dsl/extdeps/languages/rust/primitives.dag for range_min_inclusive / range_max_inclusive. No LiteralBits::Int(i64) widening or parallel magnitude carrier was introduced.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-verified against current PR head 4cff3279a118dd2406d834d74966246b82258963: still addressed. integer_range_for_decl reads structural IntegerRangeFact declarations from dsl/extdeps/languages/rust/primitives.dag; it no longer carries a hard-coded declaration-name bounds table. The current head also includes 4cff3279a, which makes the routing walk follow zero-argument alias instantiations before matching the underlying integer substrate shape, with regression coverage for type ByteAlias = UInt8.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-verified against current PR head 26ec5a1a4e648ad85c9ec1db9f963a3855cd4142: still addressed. integer_range_for_decl reads structural IntegerRangeFact declarations from dsl/extdeps/languages/rust/primitives.dag and has no hard-coded integer bounds table. The alias behavior is covered at current head as well: integer_routing_key_for_decl walks zero-argument alias instantiations, with tests for type ByteAlias = UInt8 accepting 255 and rejecting 256 via MagnitudeOutOfRange.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-verified against current PR head 8d6f307d0c721bd918c8ff5b1f6f9d55e5d0c3e4: this remains addressed. integer_range_for_decl derives an IntegerRoutingKey from the expected DAG type shape, then scans structural IntegerRangeFact data declarations (is_integer_range_fact + integer_range_fact) for the matching (algebra, carrier) range. There is no hard-coded integer bounds table in src/v3/compiler/src/int_literal_ranges.rs, and no LiteralBits::Int(i64) widening or parallel magnitude carrier was introduced.

span,
fixes: vec![Correction {
description: hint,
span: SourceSpan::new("<int-literal-range-hint>", 0, 0),

This comment was marked as resolved.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified against current PR head e1358bf6a6882656580b1871f03501d23ce692a8: this is addressed there. magnitude_out_of_range now returns fixes: Vec::new() and no longer fabricates a Correction with a synthetic span or empty replacement.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-verified against current PR head b0bb3b27e67326abd4ba4f7c405bbca20850fd96: still addressed. magnitude_out_of_range constructs Diagnostic::MagnitudeOutOfRange with fixes: Vec::new() and there is no remaining Correction, synthetic SourceSpan::new, or <int-literal-range-hint> path in src/v3/compiler/src/int_literal_ranges.rs.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-verified against current PR head 26ec5a1a4e648ad85c9ec1db9f963a3855cd4142: still addressed. magnitude_out_of_range constructs Diagnostic::MagnitudeOutOfRange with fixes: Vec::new(), and src/v3/compiler/src/int_literal_ranges.rs contains no Correction, synthetic SourceSpan::new, or <int-literal-range-hint> path.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-verified against current PR head 8d6f307d0c721bd918c8ff5b1f6f9d55e5d0c3e4: this remains addressed. magnitude_out_of_range now constructs Diagnostic::MagnitudeOutOfRange with fixes: Vec::new(). src/v3/compiler/src/int_literal_ranges.rs contains no Correction, no synthetic SourceSpan::new, and no <int-literal-range-hint> path, so apply-fix consumers receive no fabricated edit data.

@briansrls
briansrls marked this pull request as ready for review April 25, 2026 17:08
@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: b048360c · Trigger: schedule
  • Thinking: 78s wall

Findings

  • Duplicate diagnostic emission for out-of-range literals at top-level data items. In src/v3/compiler/src/lower.rs lines 412-425 (the lower_data_item Err branch), when lower_scalar_literal_for_type returns a magnitude diagnostic, the new code emits diag and then unconditionally emits a follow-up Diagnostic::ResolveError. Compare the parallel lower_structural_field_value site at lines 435-441, which correctly suppresses the redundant ResolveError via Err(Diagnostic::ResolveError { .. }) => {}. Both call sites should filter the same way; otherwise data x: UInt8 = 256 will produce two diagnostics for one root cause. The new test uses messages.iter().any(...) so this duplication slips past — worth either filtering as the structural site does, or asserting exactly one diagnostic in the test. (NON-BLOCKING — diagnostic UX, not substrate integrity, but a clear bug.)

Tracked-bridge acknowledgement (not a finding)

The hardcoded range table in int_literal_ranges.rs is parallel to the freshly-declared range_min_inclusive / range_max_inclusive facts on IntegerPrimitive, AND keyed by DSL type names (Int8, UInt8, …) rather than the target_name used in primitives.dag (i8, u8, …). Normally that would be a single-authority concern, but the sg0_census comment (lines 686-694) documents it, bounds it (host-side reconciliation glue), and names a concrete dissolution trigger ("R2 T-Substrate's top-level aggregate ValueBody sub-lane makes rust_pilot_primitives row values structurally walkable"). All three properties present — accept as a tracked bridge per the rubric.

Verdict

APPROVE_WITH_COMMENTS — the substrate addition (range facts on IntegerPrimitive) and the fail-closed MagnitudeOutOfRange diagnostic are clean and well-scoped, with proper bootstrap regeneration, mirror updates in grounding_engine/grounding_pilot, hermetic behavior receipts, and an explicit dissolution path documented in the census. The one real issue is the inconsistent duplicate-diagnostic handling in lower_data_item vs lower_structural_field_value; worth fixing before this lands but doesn't block in principle.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: codex / codex-default
  • Commit: b048360c · Trigger: schedule
  • Thinking: 353s wall

Findings

  • src/v3/compiler/src/int_literal_ranges.rs:83 returns the first declaration name before walking alias/connective edges. That makes the new range check work for direct UInt8/Int8 declarations but fail for aliases like type Byte = UInt8; data x: Byte = 255, even though aliases should preserve the underlying substrate fact. This violates Boundary Discipline / facts-flow-forward and CODING’s “names are namespaces, not aliases” guidance. I verified direct UInt8 succeeds while the alias form fails semantically.

Verdict: REQUEST_CHANGES
The main range path is close, and the targeted tests pass: cargo test -p v3-compiler int_literal_cardinality_test -- --nocapture. The alias handling needs fixing before merge because it commits the new substrate-cardinality behavior to name-keyed builtin cases instead of following the declared type structure.

Copy link
Copy Markdown
Contributor Author

Verified the blocking review from 2026-04-25T17:06:04Z against current PR head e1358bf6a6882656580b1871f03501d23ce692a8.

Both findings are addressed in the current code:

  • integer_range_for_decl no longer introduces source integer cardinality at the consumer with a hard-coded bounds table. It derives the expected integer routing key from the DAG type structure and reads structural IntegerRangeFact declarations from dsl/extdeps/languages/rust/primitives.dag, where the string-decimal range_min_inclusive / range_max_inclusive facts live.
  • magnitude_out_of_range now emits fixes: Vec::new() and no longer creates a Correction with a synthetic span or empty replacement.

No new substrate carrier, LiteralBits::Int widening, or parallel magnitude carrier was introduced.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b048360c41

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +83 to +84
if let Some(name) = declaration.name.as_deref() {
return Some(name);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Resolve alias chains before matching integer ranges

integer_decl_name returns the first declaration name it sees, so aliases like type Tiny = UInt8 stop at Tiny and never reach the canonical integer names handled in integer_range_for_decl. As a result, in-range literals for aliased bounded integers still fail with scalar literal does not match declared type instead of being accepted (and out-of-range literals miss the new magnitude diagnostic path), which breaks the new narrowing behavior for any user-defined integer alias.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified valid against the reviewed commit and fixed in current PR head b0bb3b27e67326abd4ba4f7c405bbca20850fd96 via 4cff3279a (fix(v3): follow aliases for int literal ranges). integer_routing_key_for_decl now walks zero-argument alias instantiations before matching the underlying integer substrate shape, and int_literal_cardinality_test covers both type ByteAlias = UInt8; data alias_u8_max: ByteAlias = 255 and the aliased out-of-range 256 case producing MagnitudeOutOfRange.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-verified against current PR head 26ec5a1a4e648ad85c9ec1db9f963a3855cd4142: still fixed. integer_routing_key_for_decl walks zero-argument alias instantiations before matching the underlying integer substrate shape, and int_literal_cardinality_test covers type ByteAlias = UInt8 for both in-range 255 and out-of-range 256 producing MagnitudeOutOfRange.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: f5a71d20 · Trigger: schedule
  • Thinking: 70s wall

Review

No blocking findings. This is a clean, well-scoped substrate addition. The diff:

  • Adds IntegerRangeFact substrate declarations in primitives.dag whose ranges are read by a host-side helper (int_literal_ranges.rs) to narrow scalar-literal reconciliation against expected target type, and emits a new MagnitudeOutOfRange diagnostic.
  • Tests cover the three behaviors that matter: in-range types compile, unconstrained literals keep the Int64 default (so the existing aliasing isn't disturbed), and out-of-range emits exactly one root-cause diagnostic with no fabricated fixes (int_literal_cardinality_test.rs:31-92).
  • Census/allowlist (sg0_census_test.rs:152-186, 232-237) updates EXPECTED_HAND_AUTHORED_* with a paragraph that names the dissolution trigger ("R2 T-Substrate's top-level aggregate ValueBody sub-lane"). That satisfies the tracked-debt criteria (documented + bounded + named trigger).
  • Fail-closed: out-of-range literals are rejected at lower (lower.rs:3204-3215) and at transform reconciliation (infer.rs:1066-1082).
  • Diagnostic plumbing is consistent: span(), fixes(), message(), diagnostic_kind, and the regen emitter (regen_bootstrap_emit.rs:655-668) are all updated together — no half-wired variant.

Verdict

APPROVE — substrate change is small, fail-closed, behavior-tested, and the host-side shim has an explicit, named dissolution trigger.

Exploratory observations (non-blocking)

  • Three parallel representations of the integer ranges: IntegerPrimitive rows inside rust_pilot_primitives (unparsed list, primitives.dag:281-318), the new IntegerRangeFact data decls (primitives.dag:197-269), and the Rust mirror in grounding_pilot/src/lib.rs:103-243. The dissolution comment in sg0_census_test.rs:152-160 covers the first two; you may want a parallel note for the grounding_pilot mirror so the R2 trigger collapses all three together.
  • Result<LiteralBits, Diagnostic> as control flow (lower.rs:3171-3220): Err(Diagnostic::ResolveError { .. }) is overloaded to mean "this literal isn't applicable, fall through to other paths," while other Err variants mean "report me." Works, but the contract reads cleaner as a dedicated three-state enum (Match / NotApplicable / Reject(diag)); the variant-as-sentinel is easy to break later if anyone starts emitting ResolveError for a real reason. Worth a follow-up if/when this helper grows another caller.
  • IntegerRange::contains_i64 vs u64 max: range_max_inclusive for u64 is 18446744073709551615, which i128::parse handles fine — but any literal that big can never reach contains_i64 because LiteralBits::Int is i64. So u64 overflow at the upper end fails earlier in the parser, not here. Not a bug, just worth knowing the helper can't ever assert "256 fits u8" symmetrically with "2^63 fits u64" today.

Copy link
Copy Markdown
Contributor Author

Re-verified the 2026-04-25T17:06:04Z blocking review against current PR head b0bb3b27e67326abd4ba4f7c405bbca20850fd96.

Both findings remain addressed:

  • integer_range_for_decl reads structural IntegerRangeFact declarations from dsl/extdeps/languages/rust/primitives.dag for string-decimal bounds, rather than using a hard-coded bounds table. Current head also follows zero-argument alias instantiations before matching the underlying integer substrate shape.
  • magnitude_out_of_range emits fixes: Vec::new() and no longer constructs a Correction with synthetic edit data.

No LiteralBits::Int(i64) widening, new substrate carrier, or parallel magnitude carrier was introduced.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: codex / codex-default
  • Commit: f5a71d20 · Trigger: schedule
  • Thinking: 242s wall

Verdict: APPROVE

Diff is small in intent and the temporary duplicated range facts are documented, bounded, and have a named dissolution trigger. I did not see a concrete violation of the pinned invariants/modeling/testing guidance.

Verified:
cargo test -p v3-compiler --test integration int_literal_cardinality_test
cargo test -p v3-compiler --test integration extdeps_rust_primitives_loader_test
cargo test -p v3-grounding-engine

Copy link
Copy Markdown
Contributor Author

Re-verified the 2026-04-25T17:06:04Z blocking review against current PR head 26ec5a1a4e648ad85c9ec1db9f963a3855cd4142.

Both findings remain addressed:

  • integer_range_for_decl reads structural IntegerRangeFact declarations from dsl/extdeps/languages/rust/primitives.dag for string-decimal bounds rather than using a hard-coded bounds table, and current head follows zero-argument alias instantiations before matching the underlying integer substrate shape.
  • magnitude_out_of_range emits fixes: Vec::new() and no longer constructs a Correction with synthetic edit data.

No LiteralBits::Int(i64) widening, new substrate carrier, or parallel magnitude carrier was introduced.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: openai-pro / gpt-5-5-pro
  • Commit: f5a71d20 · Trigger: manual
  • Conversation: View conversation

1. Story of the diff

This PR moves integer literal cardinality from an implicit Rust-side assumption into declared extdeps data. RustPrimitive::IntegerPrimitive now carries inclusive decimal range fields, and the PR adds structurally walkable IntegerRangeFact declarations for each Rust integer primitive while rust_pilot_primitives remains unparsed as a top-level aggregate (dsl/extdeps/languages/rust/primitives.dag:178-201, dsl/extdeps/languages/rust/primitives.dag:204-266). The compiler then consumes those facts through a new int_literal_ranges helper, using algebra+carrier routing to find the declared range for an expected integer type and to decide whether an i64 literal can narrow into that expected type (src/v3/compiler/src/int_literal_ranges.rs:34-41, src/v3/compiler/src/int_literal_ranges.rs:56-91, src/v3/compiler/src/lower.rs:3191-3215, src/v3/compiler/src/infer.rs:1066-1083).

The user-visible behavior is fail-closed: in-range literals can inhabit narrower integer types, unconstrained integer literals still default to Int/Int64, and out-of-range literals produce a typed MagnitudeOutOfRange diagnostic instead of falling through to a generic mismatch or fabricating a value (src/v3/compiler/src/diagnostics.rs:188-196, src/v3/compiler/tests/integration/int_literal_cardinality_test.rs:7-31, src/v3/compiler/tests/integration/int_literal_cardinality_test.rs:33-55, src/v3/compiler/tests/integration/int_literal_cardinality_test.rs:57-93). The generated bootstrap/mirror/grounding changes are the receipts that the new extdeps shape is reflected through the existing bootstrap and grounding surfaces.

2. Invariant categories

  1. LAYER MODEL — Finding, BLOCKING. The diff does touch substrate: it declares range facts as substrate/extdeps data (dsl/extdeps/languages/rust/primitives.dag:196-201) and then makes compiler behavior depend on them (src/v3/compiler/src/int_literal_ranges.rs:34-41). The substrate fields are only Strings, and the host consumer stores them as raw strings (src/v3/compiler/src/int_literal_ranges.rs:9-12) before parsing with panicking expect calls (src/v3/compiler/src/int_literal_ranges.rs:16-25). That leaves malformed declared range data as a runtime panic rather than an unrepresentable state or typed fail-closed outcome. I would make IntegerRange hold parsed numeric bounds, or make parsing return a typed/optional failure at integer_range_fact construction time so invalid declared facts cannot reach contains_i64.
  2. INVARIANTS.md + modeling-discipline.md — Finding, BLOCKING. Specific principle: fail-closed + illegal states unrepresentable. The new diagnostic path itself is good — MagnitudeOutOfRange is a typed carrier with literal, target, bounds, expected type, span, and fixes (src/v3/compiler/src/diagnostics.rs:188-196), and lowering/inference use it instead of accepting out-of-range values (src/v3/compiler/src/lower.rs:3207-3215, src/v3/compiler/src/infer.rs:1072-1081). The gap is the same malformed-range path above: range_min_inclusive / range_max_inclusive are accepted as arbitrary strings in the substrate (dsl/extdeps/languages/rust/primitives.dag:200-201) and only validated by expect (src/v3/compiler/src/int_literal_ranges.rs:19, src/v3/compiler/src/int_literal_ranges.rs:25), so the model permits invalid range facts and discovers them by panic.
  3. CODING.md — Finding, BLOCKING because this is substrate-consuming library code. The new helper is otherwise shaped as data + functions, and the module boundary is explicit via mod int_literal_ranges (src/v3/compiler/src/lib.rs:37). The concrete deviation is hidden panic surface in library code: IntegerRange::min and IntegerRange::max call .expect(...) while consuming declared .dag facts (src/v3/compiler/src/int_literal_ranges.rs:16-25). This should be a Result/Option-shaped parse boundary or a parsed carrier constructed only after validation, not a panic behind contains_i64.
  4. TESTING.md — Compliant with one style note. The PR adds a focused behavior receipt covering the three important contracts: in-range narrowing to scalar value bodies (src/v3/compiler/tests/integration/int_literal_cardinality_test.rs:7-31), unconstrained defaulting to Int (src/v3/compiler/tests/integration/int_literal_cardinality_test.rs:33-55), and out-of-range fail-closed diagnostics with no fabricated correction (src/v3/compiler/tests/integration/int_literal_cardinality_test.rs:57-93). Minor non-blocking note: the OOB test checks message substrings (src/v3/compiler/tests/integration/int_literal_cardinality_test.rs:74-81) even though the typed diagnostic is available; matching the MagnitudeOutOfRange fields directly would better preserve the typed-carrier discipline.
  5. LOCKED DESIGN DECISIONS — N/A. I do not see this PR altering a locked thesis/design decision; the R2/top-level aggregate references are used as a dissolution target for the temporary range-fact exposure, not as a divergence from a locked rule (dsl/extdeps/languages/rust/primitives.dag:190-195, src/v3/compiler/tests/integration/sg0_census_test.rs:153-160).
  6. TRACKED vs UNTRACKED DEBT — Compliant. The duplicate range exposure is explicitly documented as a bridge over the current unparsed rust_pilot_primitives aggregate: the .dag comment explains why separate IntegerRangeFact rows exist and that consumers should not mirror bounds in Rust (dsl/extdeps/languages/rust/primitives.dag:190-195). The census entry bounds the scaffold to int_literal_ranges.rs and names the dissolution trigger: once R2 top-level aggregate ValueBody makes the primitive rows structurally walkable, the helper should consume those rows directly or move behind generated substrate accessors (src/v3/compiler/tests/integration/sg0_census_test.rs:153-160, src/v3/compiler/tests/integration/sg0_census_test.rs:232-236).

3. Verdict

REQUEST_CHANGES. The feature direction is right and the behavior tests are meaningful, but the new substrate-consuming range path still admits invalid declared range facts and handles them by panic. That is small to fix now and much cheaper than normalizing a panic-shaped substrate boundary after more consumers depend on it.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: effc3cd5 · Trigger: schedule
  • Thinking: 90s wall

Review

The diff adds a fail-closed cardinality check for integer literals against integer-range facts declared in dsl/extdeps/languages/rust/primitives.dag, with a new MagnitudeOutOfRange diagnostic and an alias-walking range lookup. The bridge in int_literal_ranges.rs and the parallel range list in grounding_pilot are both registered in the SG0 census with a named dissolution trigger (R2 top-level aggregate ValueBody sub-lane).

Findings: none blocking.

Exploratory observations

  • Diagnostic-as-sentinel control flow in src/v3/compiler/src/lower.rs:3174-3220. lower_scalar_literal_for_type now signals three different conditions through Result<_, Diagnostic>: "not a literal expression at all", "type mismatch with no range fact", and "out-of-range int". Call sites discriminate by matching Err(Diagnostic::ResolveError { .. }) => {} (lower.rs:2851, 2434) to mean "fall through / try the next strategy", while Err(other) => report. That couples flow control to diagnostic-variant identity — if a future producer in this function emits a ResolveError it actually wants surfaced, it'll be silently swallowed by lower_structural_field_value. Consider an explicit enum LowerLiteralOutcome { Lit(LiteralBits), NotALiteral, Mismatch(Diagnostic) }. CODING.md style — illegal states unrepresentable, and the synthetic "expected scalar literal" ResolveError at line 3176 only exists to be matched-and-discarded.
  • lower_data_item rewrites the inner diagnostic (lower.rs:2436-2450): when lower_scalar_literal_for_type returns its own ResolveError ("scalar literal does not match declared type"), the outer code throws it away and reports a synthetic ResolveError { name: "scalar literal ... in declaration body" }. Minor — the inner reason is more informative.
  • O(N·declarations) range lookup: integer_range_for_decl scans dag.declarations() linearly per call, called per literal-typed reconciliation site. Fine today; if int-literal density grows, a one-time index keyed by (algebra, carrier) would be straightforward. NON-BLOCKING.
  • The range mirror in grounding_pilot is documented as a tracked bridge, but it's a third copy of the same bounds (alongside the RustPrimitive rows and the new IntegerRangeFact rows in primitives.dag). The dissolution comment correctly names that the pilot mirror falls when the substrate accessors land. Worth noting that the dag now contains the same bounds twice: once on rust_pilot_primitives rows (currently Unparsed) and once on IntegerRangeFact rows (structurally walkable). The PR is explicit about this being a temporary bridge until the top-level aggregate sub-lane lands.

Verdict: APPROVE_WITH_COMMENTS — fail-closed semantics are correct, the tests cover the alias-walking and "explicit Int64 default" cases, and both bridges are tracked with bounded dissolution triggers. Main feedback is stylistic: the Result<_, Diagnostic> sentinel pattern in lower.rs is fragile and worth replacing with an explicit outcome enum.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: codex / codex-default
  • Commit: effc3cd5 · Trigger: schedule
  • Thinking: 240s wall

Verdict: APPROVE

Reviewed effc3cd5 against origin/main. This looks clean: the range bridge is documented with a dissolution trigger, diagnostics fail closed, and the new tests cover the main behavior/alias paths.

Verification: cargo test -p v3-compiler int_literal_cardinality_test --test integration passed.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: 73543f60 · Trigger: schedule
  • Thinking: 74s wall

Findings

  • NON-BLOCKING — coproduct classification annotation missing. src/v3/compiler/src/lower.rs:3161 introduces enum LowerScalarLiteralOutcome with three variants (Literal, NotApplicable, Reject) and no 🟢/🟡/🔴 ledger/trigger comment per docs/modeling-discipline.md §4. It is implementation-layer (file-scoped, doesn't appear on the Dag), so this is a practice-hygiene nit rather than substrate damage — but the rule is explicit that any new N≥2 enum gets a classification. Would read as 🟢 terminal: each variant maps to a different downstream control-flow branch (lower it / skip / report) and is a textbook Pattern-1 (fact placement) endpoint.

  • NON-BLOCKING observation — three-way range duplication is tracked, but watch the inline IntegerPrimitive fields. dsl/extdeps/languages/rust/primitives.dag:178-179 adds range_min_inclusive / range_max_inclusive to the IntegerPrimitive record and introduces parallel IntegerRangeFact records (lines 199-265), and src/v3/grounding_pilot/src/lib.rs:108-109 mirrors the same strings into the Rust pilot const. The compiler reads exclusively from IntegerRangeFact (the single structural authority), and the dissolution trigger ("R2 top-level aggregate ValueBody sub-lane lands") is documented at the IntegerRangeFact block, in grounding_pilot/src/lib.rs:171-176, and in sg0_census_test.rs:152-160. That satisfies the tracked-bridge criteria (documented + bounded + named trigger), so this is acceptable. The one place it is not documented is the inline IntegerPrimitive { range_min_inclusive, ... } fields themselves — those are purely declarative-future duplication today (consumers can't read them until R2). Worth a one-line // scaffold: next to the new fields so a future reader doesn't wire a second consumer to them.

  • NON-BLOCKING — silent None fall-through in integer_routing_key_for_decl. src/v3/compiler/src/int_literal_ranges.rs:48-50 bails with None once recursion depth >= 32. Practically unreachable (declaration alias chains aren't 32 deep), but per docs/modeling-discipline.md §1 (fail-closed) this is an Option-on-error path where the caller can't tell "no range fact for this type" from "I gave up walking." Today both legitimately mean "fall through to existing diagnostics," so behavior is correct. Worth a comment justifying the silent return.

Verdict

APPROVE_WITH_COMMENTS. The core shape is right: IntegerRangeFact is the single structural authority, the inline pilot list and the Rust mirror are tracked bridges with a named R2 dissolution trigger and a census-test pin, the new MagnitudeOutOfRange diagnostic is fail-closed with structured bounds and no fabricated fixes, and the LowerScalarLiteralOutcome refactor correctly threads the typed reject through lower_data_item and lower_structural_field_value instead of swallowing into Unparsed. Tests exercise narrowing, alias-chain narrowing, the explicit Int64 default, and the OOB diagnostic shape (including the "one root-cause" assertion). The findings above are all polish.

Copy link
Copy Markdown
Contributor Author

Addressed the 2026-04-25T20:04:15Z inline blocking comment on src/v3/compiler/src/int_literal_ranges.rs:36 at current PR head 78b603e58bcde76a1aa1800a1e455cb1b09a4759.

The finding was valid. The range lookup no longer represents malformed/duplicate substrate facts as plain absence:

  • integer_range_for_decl now returns an explicit IntegerRangeLookup::{Found, Missing, Invalid}.
  • malformed IntegerRangeFact rows and duplicate matching (algebra, carrier) rows produce Invalid(Diagnostic::MalformedIntegerRangeFact { .. }).
  • lower/infer callers propagate that diagnostic instead of falling through to generic scalar mismatch.
  • the malformed and duplicate range fact tests now assert the typed diagnostic carrier.

Verified locally:

  • cargo test -p v3-compiler malformed_integer_range_fact_fails_closed --test integration
  • cargo test -p v3-compiler duplicate_integer_range_fact_fails_closed --test integration
  • cargo test -p v3-compiler int_literal_cardinality --test integration
  • cargo test -p v3-compiler m1_5_testgen --test integration
  • cargo run -p v3-compiler --features bootstrap-regen-fresh --bin regen_bootstrap -- --verify
  • cargo fmt --all --check
  • git diff --check

No LiteralBits::Int(i64) widening, new substrate carrier, or parallel magnitude carrier was introduced.

Copy link
Copy Markdown
Contributor Author

Verified the 2026-04-25T20:04:15Z top-level blocking review against current PR head 78b603e58bcde76a1aa1800a1e455cb1b09a4759.

This is addressed at current head:

  • integer_range_for_decl now returns IntegerRangeLookup::{Found, Missing, Invalid} instead of Option.
  • duplicate matching facts and malformed matching facts return Invalid(Diagnostic::MalformedIntegerRangeFact { .. }).
  • lower/infer callers propagate that diagnostic instead of treating invalid facts as absence.
  • regression tests cover both malformed and duplicate matching facts.

Verified locally:

  • cargo test -p v3-compiler malformed_integer_range_fact_fails_closed --test integration
  • cargo test -p v3-compiler duplicate_integer_range_fact_fails_closed --test integration

Both pass. Current GitHub fmt is green; ci and v3 are still running on head 78b603e58.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 78b603e5 · Trigger: schedule
  • Thinking: 508s wall

BLOCKING (1)

Root Cause

  • src/v3/compiler/src/lower.rs data bodies are structurally lowered before type-alias refinements are attached → either attach refinements before scalar field lowering or recursively revalidate ValueBody::Structural fields after refinement lowering.

⚠️ One refinement-discharge gap remains for structural data literals.

Comment thread src/v3/compiler/src/lower.rs

Copy link
Copy Markdown
Contributor Author

Verified the 2026-04-25T21:08:35Z inline blocking comment on src/v3/compiler/src/int_literal_ranges.rs:36 against current PR head 78b603e58bcde76a1aa1800a1e455cb1b09a4759.

This is already addressed at current head. integer_range_for_decl no longer uses filter_map(...ok()) or returns Option. It returns IntegerRangeLookup::{Found, Missing, Invalid}, with malformed and duplicate matching IntegerRangeFact rows represented as Invalid(Diagnostic::MalformedIntegerRangeFact { .. }). lower/infer propagate that diagnostic rather than treating invalid facts as absence.

Verified locally:

  • cargo test -p v3-compiler malformed_integer_range_fact_fails_closed --test integration
  • cargo test -p v3-compiler duplicate_integer_range_fact_fails_closed --test integration

Both pass. Current GitHub checks (fmt, v3, ci, self_host_ratchet) are green at head 78b603e58.

Copy link
Copy Markdown
Contributor Author

Verified the 2026-04-25T21:08:35 blocking review against current PR head 2c8bffaebdb3fd1fd9bf61ef8a2e53b7f8a5792d.

The finding was valid at reviewed commit 78b603e5 and is addressed at current head:

  • validate_scalar_data_refinements_phase no longer checks only top-level ValueBody::Scalar; it now recursively revalidates scalar literals inside ValueBody::Structural records, lists, and variant payloads after type-alias refinements have been attached.
  • Structural scalar fields whose expected type carries a non-placeholder refinement are cleared and diagnosed instead of remaining accepted as base scalar evidence.
  • Added regression coverage for type PositiveInt = Int where PositiveInt > 0; type Box { value: PositiveInt }; data x: Box = { value: 1 }.

Verified locally:

  • cargo test -p v3-compiler structural_data_scalar_fields_do_not_bypass_refinement --test integration
  • cargo test -p v3-compiler int_literal_cardinality --test integration
  • cargo test -p v3-compiler test_3a3 --test integration
  • cargo run -p v3-compiler --features bootstrap-regen-fresh --bin regen_bootstrap -- --verify
  • cargo fmt --all --check
  • git diff --check

No LiteralBits::Int(i64) widening, new substrate carrier, or parallel magnitude carrier was introduced.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 2c8bffae · Trigger: schedule
  • Thinking: 340s wall

Non-blocking — Strengths

  • dsl/extdeps/languages/rust/primitives.dag The temporary duplicated range facts are documented, bounded to the top-level aggregate ValueBody gap, and have named dissolution triggers.
  • src/v3/compiler/tests/integration/int_literal_cardinality_test.rs The tests cover range acceptance, out-of-range diagnostics, alias following, malformed facts, and the refinement-discharge regressions from prior review rounds.

✅ No blocking concerns in the current mixed .dag/code/test diff.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 48370dfc · Trigger: schedule
  • Thinking: 281s wall

✅ Mixed .dag/code/test PR; the prior blocking issues are addressed and I found no new blocking concerns.

@briansrls
briansrls merged commit eefd1ca into main Apr 25, 2026
4 checks passed
briansrls added a commit that referenced this pull request Apr 26, 2026
… (3)

Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue.
Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by
Modeling Manager's Wave 3 worker briefs (gated on these landing).

Authored:
- r2-substrate-cardinality-for-int-lit-subset.md (M) — produces
  magnitude carrier consumed by T-Modeling int-lit. Coordinates with
  PR #806's prior cardinality work; mandatory authority audit guards
  against #796's rejected IntLiteralMagnitude shape resurfacing.
  Open design questions: magnitude representation, reconciliation
  narrowing point, i64::MIN representability.
- r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces
  nominal-opacity carrier consumed by T-Modeling Secret<T>. Open
  design questions: carrier shape (flag/connective/sealed-accessor),
  generic-walk discipline, accessor gating.
- r2-substrate-parametric-algebra-for-dimensions-subset.md (M) —
  produces phantom-parameter carrier consumed by T-Modeling
  Dimension<Carrier>. Open design questions: carrier shape,
  type-equivalence rule, algebra-method dispatch, lifting/coercion.

All three:
- Scoped narrowly to their paired R2 consumer; not full
  substrate-capability lanes.
- Mandatory pre-author authority audit per
  feedback_audit_adjacent_authority_first.
- Cross-program readiness signal pattern from #827's manager rework.
- Coproduct dissolution receipts required for any new variants.
- Open design questions surfaced explicitly so Substrate Manager
  (or Director pre-spin-up) can resolve at dispatch time.

Wave 3 (T-Modeling worker briefs × 4) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 26, 2026
#836)

* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation)

Director-authored amendment following the 2026-04-24 escalation from PR
#693 (sub-child sharp-bear-829 under Surface Manager).

Two edits:

1. New "Class 5 Gap 3 — port-carried field values in data bodies"
   row in the 2026-04-21 post-merge-debt section. The substrate gap was
   documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP
   ledger row for cross-lane visibility. PR #693's execution surfaced it
   as the blocker on sub_charclass_in_std_unicode phase-2.

2. Retract the "ready-to-dispatch (no substrate capability gap)" claim
   on the Character-level row, annotate phase-1 landed via PR #693
   (CharClass vocabulary + Rust-mirror structural scanner path), and
   point phase-2 at the new Class 5 Gap 3 row.

Codifies the audit pattern: "this consumption gap has no substrate
capability gap" claims must be verified by attempting the retype before
the claim lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main

* docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review)

* docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review)

Row title still said 'consumption gap, not substrate gap' while the
body block retracted that claim and cited Class 5 Gap 3 as a substrate
dependency for phase-2. Title now matches body: mixed classification,
consumption for steps 1+3, substrate for step 2.

* docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit)

gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining
gap" description was wrong: field-level shapes (nested records, list
literals, declaration refs, Var refs, sum-variant literals) are
supported today via FieldValue variants + lower_structural_field_value
(dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the
top-level ValueBody boundary (non-scalar, non-record top-level bodies).

The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself
stale: it describes the pre-PR-B-unwind shape where FieldValue was
LiteralBits-only. PR-B's unwind extended FieldValue to carry
Reference / Record / List / Variant, moving the gap to ValueBody.

Two fixes:

1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody
   boundary, point at code paths (dag.rs, lower.rs) as live authority,
   flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass
   blocker classification to "provisional pending reproduction."

2. Update the Character-level row's phase-2 block to name that the
   specific shape of the CharClass failure needs concrete reproduction
   from the escalating sub-child before the blocker is finalized.

Recursive audit-pattern instance: the row I wrote to codify "verify
live state before claiming substrate gap" itself failed to verify live
state. Both incidents (2026-04-23 original row + 2026-04-24 my
retraction row) are now cited in the audit-pattern sub-note as
examples of the same discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33

Three substantive fixes addressing internal-consistency gaps in the cascade
promotion PR caught by codex review at sha 0d6e7c33:

1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane
   acceptance bullets and Hand-Rust census paragraph in line with the
   updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero
   (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is
   retracted under 0-floor with explicit migration to ExecuteCommand-based
   .dag TestClaim declarations.

2. docs/design-pure-bootstrap-zero.md promotion section — converted from
   future-tense ("This doc is PROPOSAL until promoted… promotion is a
   single Director-authored cascade PR…") to historical past-tense
   promotion-receipt framing ("This doc was PROPOSAL until promoted;
   promotion was a single Director-authored cascade PR that did all of the
   following atomically…"); blocking-clause struck through and resolved
   inline. Banner cites PR #782 explicitly.

3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_
   profile excluded (Map<String, AlgebraProfile> body, not list-of-sum;
   needs distinct ValueBody::Map substrate work, tracked separately as a
   future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass
   phase-2 + Engine sharpened-(b) pilot enumeration), both sharing
   list-of-sum substrate work. Lane table, dependency DAG, and capacity
   summary updated for consistency (slot count 9-13, was 10-14).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities

Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade
self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22
explicitly names THESIS.md and "any other authority docs" as required
retraction targets; the prior diff updated ROADMAP + r2-structure + design
docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting-
manager.md pointing at the now-SUPERSEDED ≤5-floor framing.

Files:

- THESIS.md (5 prose blocks updated):
  - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests
    migrate to ExecuteCommand-based .dag TestClaim declarations.
  - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag.
  - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor
    target citing design-pure-bootstrap-zero.md as live authority;
    hand_maintained_src list shrinks to empty set.
  - :301-318 — Tests-are-structural-data block: residual carve-out retracted;
    predicate name pb_rust_tests_outside_residual_zero retained as
    housekeeping (semantically the residual is empty under cascade).

- docs/thesis/compiler-std-consolidation.md (5 references):
  - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes
    design-pure-bootstrap.md (SUPERSEDED).
  - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process
    lane named as the dissolution trigger for bootstrap.rs itself.
  - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md.
  - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority
    re-cited.
  - :185 Related docs link.

- docs/briefs/r1-selfhosting-manager.md (active dispatch brief):
  - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5);
    T-PB-B residual carve-out retracted; predicate names retained for
    housekeeping; cascade-promoted authorities are source of truth.
  - Slice descriptions for T-PB-A / T-PB-B updated inline.
  - Framing-question + ask updated to 0-floor / no-residual framing.
  - Day-1 + up-to-director hand-off bullets updated.
  - Working-state checklist :111 ≤5 → 0 with cite.
  - Decisions log :164 ≤5 → 0-floor target updated.

- docs/r2-structure.md §2 design call (RETRACTED block):
  - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through
    in entirety (both Option A sharpen-and-keep and Option B rename are
    moot under 0-floor). Section preserved as audit-trail historical
    context.
  - Background-doc index: self-hosting anchor updated to
    design-pure-bootstrap-zero.md as live authority.

- docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per
  non-blocking suggestion):
  - Banner cites cascade promotion PR #782 explicitly.
  - New paragraph: "Treat all numeric floors below as retracted" with
    explicit lines named that quote in isolation (table row, body prose
    references). Prevents re-quoting from this doc as live authority.

Cascade is now atomically consistent across:
  THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔
  docs/thesis/compiler-std-consolidation.md ↔
  docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔
  docs/design-pure-bootstrap-zero.md (LIVE) ↔
  docs/design-pure-bootstrap.md (SUPERSEDED).

The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds
genuinely.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): correct ExecuteCommand runner-capability claim

Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation):
TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138
overstated live runner capability — claimed runner support landed in
PR #688/#741 with "emit Rust, invoke rustc on output, check exit code"
as a structurally-equivalent migration path. Verified against live
sources:

- src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema
  exists (declared via PR #678).
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5
  testgen harness allowlists ONLY `command == "true" && args.is_empty()
  && expect_exit == 0`.
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 —
  panics fail-closed on any other shape with explicit "ExecuteCommand
  shell shape is not supported here (runner-owned — do not treat as
  ordinary false)".
- src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no
  match arm for ExecuteCommand; falls through to ClaimResult::
  NotYetImplemented.

Reality: a TestClaim declaring rustc/python/go invocation is
structurally expressible as data today, but executing it is blocked.
Full arbitrary-command runner support is the PB-Runtime lane's
deliverable.

Files updated:

- TESTING.md:195 — capability state callout with file:line citations;
  "Full runner support — arbitrary command + args (rustc/python/go) with
  exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor
  program)." Bullet about migration shape preserved as the cascade-named
  successor pattern, not as a live capability.
- TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane
  lands the ExecuteCommand runner extension" as an explicit precondition.
- docs/design-pure-bootstrap-zero.md:138 — same correction for the
  matching prose, with PB-Runtime named as the runner-extension
  dependency for boundary-test migration.
- ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner
  foundation in #688/#741 with `true`-no-args allowlist only — full
  arbitrary-command runner support deferred to PB-Runtime lane,
  blocking the actual boundary-test migration." Dependencies column
  extended to "DB-15 + T-TestGen + PB-Runtime".

The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still
holds for atomic-cascade-across-authority-docs; this commit closes the
remaining capability/claim mismatch flagged by codex.

(Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still
SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief

Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation).
The prior banner contained:

> "Operationally R1 closure may still ship before the 0-floor is reached
>  — the ratchet ensures the trajectory; the gate's acceptance number is
>  what shifts."

This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0.
Two competing gate semantics in the cascade is exactly what the
atomic-cascade clause forbids.

Replaced with single-authority-honest framing:

> "R1 closure now requires the 0-floor target by gate semantics: T-PB-A
>  and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade
>  promotion changed their acceptance numbers to 0; R1 cannot close
>  while the SG-0 census carries non-zero hand-Rust."

Plus minor sharpening:
- "T-PB-A's non-test target is 0" → "non-test acceptance target is 0
  per ROADMAP.md:67" (cite the authority).
- T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep
  the capability-state honesty consistent with the recent fix wave.
- Predicate-rename housekeeping line moved into banner ("post-cascade
  housekeeping, not a pre-promotion blocker") — was implicit before.

The brief now genuinely inherits the cascade-promoted gate; no
competing release authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 second-wave worker-escalation fixes

Four substantive worker STOP-AND-ESCALATEs from briefs landed in
PR #797. All four worker recommendations correct; each needs a
Director call + brief update.

## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate

Worker correctly identified that brief req 2 (declared-effect carrier
as part of fn type signature, per feedback_no_annotations) requires
net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at
src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots.
Without parser surface, every user function would have
declared_effects = [] while inference returns non-empty — lens fires
EffectLeakageError everywhere on enable. Worker rejected power-through
and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map
parser split).

Director picked split:
- NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md
  Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface
  syntax + lookahead + body parser + lowerer extension + exhaustive-match
  audit + coproduct dissolution receipt.
- MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to
  post-parser-extension scope. Pre-flight check NOT a parser-extension
  step; STOP if parser sub-lane PR not merged.

## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping

Worker found load-bearing evidence at infer.rs:3693-3703: DB-11
deliberately strips refinements at operator dispatch as a designed-in
fix for symmetric-operators failure mode. Brief's "attach where b != 0
as a proof for a / b" directly contradicts this design choice. STOP-3
(where-clause conflict with DB-11) is real; STOP-1 (substrate scope)
needs net-new substrate (per-operator partiality fact + predicate-
entailment check + asymmetric per-operand refinement-honoring) — M+
minimum. ownership_lens precedent in original brief is post-hoc
observability, not proof carrier.

Worker recommended redirect to design/scoping per nested-optional
precedent. Director picked redirect.

Brief fully rewritten as design/scoping with four-question structure:
(1) DB-11 interaction analysis; (2) substrate proposal for proof-or-
totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes
with acceptance-theatre risk on user-defined-total-wrapper-only);
(4) Director-actionable recommendation. Output is doc PR.

## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C)

Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int)
with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136
closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b)
i128 implementation requires either path 1 (hierarchy refactor —
contradicts non-goal) or path 2 (regen lie between substrate and
emit — violates discipline). Worker leaned option (C) re-scope:
land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke)
to a sibling sub-lane that does proper Int128/Word128 substrate work.

Director picked option (C). Brief req 1 re-scoped to drop canonical-
carrier-widening; lane value comes from range facts + reconciliation
narrowing + out-of-range diagnostic against existing i64. Req 4
explicitly deferred with sibling-sub-lane reference. Sibling sub-lane
NOT to be authored or implied in this PR; tracked separately.

## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change)

Worker correctly STOP'd per the brief's own pre-flight check: parser
sub-lane has not landed; SurfaceExpr::Map not on main. Director
authorized cross-lane reassignment: wise-boar-480 takes the parser
sub-lane (t-substrate-valuebody-map-parser-worker.md) since they
already have full investigation context. No brief changes needed; the
routing decision is in the dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope

Resolves codex P2 inline at sha e35103fad on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer
carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still
required widening LiteralBits::Int(i64) to an unbounded carrier and
passing the i64::MIN smoke. Internally unsatisfiable.

Fix:

- Slice section retitled "range facts + reconciliation narrowing
  (against existing i64 carrier)" with explicit note about the
  re-scope.
- Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly
  forbids touching LiteralBits::Int shape, dag_scalar_generated.rs
  regen for that variant, or tokenize i64 parse path.
- Slice steps 2-5 reframed: range facts use i64-representable
  magnitudes; reconciliation narrowing uses existing i64 carrier;
  diagnostic only for i64-representable out-of-range; smoke tests
  for req 5 only (req 4 i64::MIN deferred).
- Acceptance checklist updated:
  - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as
    re-scoped/deferred.
  - LiteralBits::Int(i64) carrier untouched (no widening; no
    parallel; no shape change).
  - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference.
- STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the
  carrier" — explicit STOP if execution surfaces range-fact narrowing
  requiring carrier-widening; that's the boundary the re-scope drew;
  belongs in sibling Int128/Word128 sub-lane.

Brief now consistently treats carrier-widening as out-of-scope across
all sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty

Resolves codex BLOCKING #1 at sha e35103fa on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier
but req 2 required range facts using "the SAME magnitude carrier
as req 1" — meaning i64-typed range bounds. u64's max (2^64-1)
doesn't fit in i64; range fact for u64 would have to truncate,
omit, or mirror in Rust (representation drift). All three options
violate fail-closed declared-facts discipline (P1 / P3).

Fix:

- Req 2 rewritten to specify String-decimal representation:
  range_min_inclusive: String + range_max_inclusive: String fields
  on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127"
  for i8; "0"/"18446744073709551615" for u64).
- Explicit reasoning why String-decimal: u64's max doesn't fit in
  i64; binding range bounds to literal carrier forces truncation/
  omission/mirror-drift; all violate fail-closed declared-facts
  discipline.
- Bridge framing: String-decimal is pending the sibling Int128/
  Word128 sub-lane; both range bounds and literal payload migrate
  to typed carrier when that lands.

- Req 3 updated for String-decimal comparison semantics:
  reconciliation parses both bounds and literal magnitude into a
  common comparison space (i128 host comparison primitive — host
  narrowing, NOT carrier widening). Bounded by what the i64-typed
  literal can express; any i64-representable literal compares
  against any width's String-decimal bound. Carrier discipline
  preserved.

Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral)
is sha-stale — already resolved at 3e142d169.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed

Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback).
Real residual: req 2 specifies String-decimal range bounds (to cover
u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance
bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" /
"i64-representable magnitudes" for the range facts. Two incompatible
authorities for the same range-fact shape — would let a worker satisfy
the slice while truncating/omitting u64 bounds (P3 fail-closed
violation).

Fix:

- Line 31 (req 1 re-scope clarification): updated to explicitly state
  "range facts (req 2) use String-decimal representation (width-
  independent; covers u64::MAX which doesn't fit in i64)". Distinguished
  literal *payload* (stays i64) from range-bound *representation*
  (String) — both serve req 1's "no carrier widening" boundary.
- Line 44 (slice step 2): updated from "Range bounds use i64-
  representable magnitudes" to "Range bounds use String-decimal
  representation per req 2" with concrete example (u64 bounds).
- Acceptance bullet: updated from "Range facts on integer algebras
  (substrate-declared, not Rust-mirrored)" to add "using String-decimal
  representation ... width-independent; u64 bounds expressible without
  truncation."

The brief now consistently treats range bounds as String-decimal
across req 2, req 3, slice, acceptance, and the req 1 clarification —
no remaining authorities saying i64-typed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing

User + PM exchange 2026-04-25 surfaced that the in-flight effects
chain was importing wrong assumptions from external languages
(declared-effects-as-annotation + lens-vs-declaration check). Right
framing under gunbc's closed-system discipline is parallel to
complexity: every effect derives structurally from the composition
of typed primitive operations; nothing can hide because there's no
escape hatch; nothing needs annotation because the structure IS the
registry.

Four doc-only actions:

1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md.
   Frames the closed-system answer with PM's 5-behavior synergy
   table (Value/Transform/Branch/Loop/Bind as universal
   compositional-fold pattern). Four worked examples; aggressive
   reading on redundancy (compile-error-by-construction via
   referential-transparency proof; reread() primitive for legitimate
   cases); implementation-brief shape in §Q6.

2. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md.

3. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md.
   Notes Fn→Arrow refactor brief stays dispatchable as independent
   value.

4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by-
   construction framing replaces lens-detection framing.

Memory file feedback_closed_system_effects.md saved separately;
cross-link added to feedback_construction_over_ratchets.md.

Net cost: doc-level cleanup. Zero substrate code rework. Foundation
(OperationEffect + service-call infrastructure + 5-behavior
substrate) already exists.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect

Per PM convergence review on #808 + user's deeper 2026-04-25 framing:
the closed-system framing landed in #808 retired the user-facing
annotation but kept OperationEffect taxonomy as substrate-level tagging.
User's deeper framing: the taxonomy ITSELF is parallel-representation —
operations are intrinsically read-shaped or write-shaped via their
TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns-
derived-value-only → read). Tagging operations with Read | Upsert |
Create | Append | Delete names what the structure already says.

Three changes:

1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as
   normalized view, or retire as parallel-representation?"
   - Two paths: (i) tags derived from signature shape (acceptable
     normalized view) vs (ii) tags declared per-primitive (parallel-
     representation; retire).
   - Audit-as-existence-check (Q4 req 2 reframed): all effectful
     primitives derive cleanly from signature shape → path (i); any
     primitive needs hand-declared tag → path (ii) by existence proof.
   - Director default: path (ii). Logging primitives that return Unit
     are likely the audit's existence-proof.
   - Two design-question resolutions: (a) external effects not in
     return type → resource-threading discipline (typed param returned
     modified, IO-monad-without-the-monad pattern); (b) transactional
     grouping → derived structural fact from Bind composition + typed
     transaction primitives.

2. Q4 reqs revised: req 2 from "tag every primitive with explicit
   OperationEffect signature" to "audit-as-existence-check that every
   primitive's type signature derives the right effect classification";
   req 3 added (resource-threading discipline); req 6 added
   (transactional-pattern lens). Req 1 (effects lens) anchors on
   operation type-signature shape, not on hand-declared tags.

3. THESIS:345-347 amendment strengthened — "operations are
   intrinsically read-shaped or write-shaped via their type-signature
   shape; consumers walk the signatures directly; there is no parallel
   taxonomy or annotation layer to declare or maintain. Tracking
   effects as a separate enumerated concept IS the bug pattern,
   dissolved by construction." Plus references to resource-threading
   discipline + transactional grouping as derived structural fact.

Memory file feedback_closed_system_effects.md updated to reflect the
deeper framing (type-signature-shape, not taxonomy-tagging) +
resource-threading discipline section + transactional-patterns
section.

Net cost: doc-only delta on top of #808. Substrate retirement
(OperationEffect enum + derive_op_effect + idempotency.dag re-anchor)
deferred to the audit-as-existence-check phase of the implementation
brief; surfaced as Q5.5 OPEN CALL.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage

Resolves codex BLOCKING at sha d49ce79a on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real:
the prior text claimed service primitives "already carry typed effect
signatures" presenting future audit-state as current substrate fact
(P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the
OperationEffect line but left a parallel over-claim on the new
"signature-shape coverage" framing.

Fix: Q4 substrate-state listing rewritten to honestly distinguish:

- Live: Behavior enum + substrate foundation (the principle that
  operations should carry signature shape).
- Incomplete: signature-shape coverage across actual primitives.
  HTTP-derived primitives carry implicit shape via derive_op_effect's
  method-table; logging/mutation primitives that return Unit or don't
  thread their target resource do NOT carry the structural shape that
  would express read-vs-write. Achieving full coverage is required
  work under reqs 2 + 3, not a current fact.
- Pending audit-as-existence-check: OperationEffect + derive_op_effect
  (path (i) vs (ii) per Q5.5).

Honest live-state callout added explicitly: "the closed-system
FOUNDATION (5 behaviors + DAG substrate + the principle that
operations should carry signature-shape) is live. The IMPLEMENTATION
COVERAGE across all effectful primitives is partial. Req 2 + req 3
are the work that closes the gap."

Brief now distinguishes principle-is-live (foundation) from
coverage-is-partial (audit work) without conflating them.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim

Per PM follow-up review on #808 + user's stronger discipline framing
("substrate must make bypass structurally impossible at every layer
of the transport stack"): the closed-system claim is honest only when
typed primitives ARE the path. Today two structural holes exist where
bypasses sidestep the typed-primitive substrate. Both surfaced
explicitly as Q4.5 pre-conditions — load-bearing for the lens's
coverage claim.

Three changes:

1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed-
   system claim)" inserted between Q4 and Q5:

   P1 — Extdeps typed-primitive consumption structurally enforced.
   Substrate must make `messages: Json` impossible to declare in
   service definitions; typed `LlmMessage` / `ContentBlock` /
   `GitHubAuthToken`-with-full-scopes are the only path. Tracked
   debt at ROADMAP.md:153-154 (LLM provider flattening) +
   `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded).
   Required prereq for full lens coverage; lens can land first +
   surface structural-coverage-gap diagnostics on bypass surfaces
   so the gap becomes visible rather than silent.

   P2 — `ExecuteCommand` fully materialized as typed runner
   primitive. TESTING.md (post-#782) committed to 0-residual but
   ExecuteCommand isn't fully materialized; deleting Rust boundary
   tests creates verification gap. Already named under PB-Runtime
   in Zero-Floor; signal pending. Pre-requisite for ANY Rust
   boundary-test deletion.

2. Old leftover duplicate Q5 section deleted (artifact from prior
   Q5/Q5.5 reshape; second copy of asymmetric-tightening text was
   in the file alongside the earlier Q5 instance).

3. Worker-discretion-vs-Director-call section in Q4.5: lens
   implementation worker dispatchable now (reports gaps as
   findings); P1 closure is substantive substrate work touching
   extdeps (dedicated lane); P2 closure is PB-Runtime (signal
   pending).

Net: design doc now honestly distinguishes principle-is-live
(Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs
named explicitly). The closed-system claim has explicit pre-
conditions documented; implementation brief discovers them as
known dependencies, not as STOP-AND-ESCALATEs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default

Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two
real residuals after the Q5.5 reframe:

1. Q6's reqs/STOPs/acceptance still framed under path (i) — said
   "audit + tag std/ primitives — every effectful primitive carries
   an explicit OperationEffect signature." Directly contradicted Q4
   (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment
   ("there is no parallel taxonomy to declare or maintain"). Worker
   reading Q6 in isolation would author the retracted shape.

2. Capacity / sequencing table line about "audit lane (tag std/
   primitives with effect signatures)" carried the same stale
   framing.

3. Q6 STOP "primitive performing side effects without an
   OperationEffect tag" assumed tag-as-authority; under path (ii)
   the STOP shape is "primitive whose signature doesn't structurally
   reveal its effect."

Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale
(already fixed at f073aa95e Q4.5 commit).

## Q6 fixes

- Reqs renumbered + reframed:
  - Req 1 anchors on operation type-signature shape (not hand-declared
    OperationEffect tags); composition reads from signature shape per
    Q2 table.
  - Req 2 changed from "audit + tag every primitive" to
    "audit-as-existence-check" — verify signature-shape coverage; ANY
    primitive needing a hand-declared tag IS the existence-proof for
    path (ii) retirement.
  - Req 3 added: resource-threading discipline applied to existing
    primitives (logging that returns Unit gets reshaped per audit).
  - Req 6 added: transactional-pattern lens (Bind composition +
    Transaction → Transaction').
  - Req 7 added: asymmetric-tightening worked example in PR body
    (per claude review observation; the one place declaration-shaped
    surface re-enters).
  - Req 8 (was 5): tests now reference signature-shape derivation
    explicitly, not tag lookup.
- STOPs reframed:
  - "OperationEffect retirement decision" — audit produces path (i)
    vs (ii) verdict; substrate retirement is its own dedicated
    sub-lane; this lane does NOT absorb it.
  - Pure/impure carrier STOP notes that "pure" should also derive
    from signature shape (pure functions don't return modified
    resources) — so the STOP itself may dissolve under further design.
  - Q4.5 P1 explicitly NOT a STOP — lens reporting structural-
    coverage-gap on extdeps bypass surfaces is the lens delivering
    its foundation-gap-visibility value.
  - Q4.5 P2 explicitly independent — lens doesn't depend on
    ExecuteCommand materialization.
- Acceptance extended: lens reports gap diagnostics on P1 bypass
  surfaces; audit produces existence-proof verdict for Director
  re-decision; asymmetric-tightening worked example in PR body.

## Capacity / sequencing table

Replaced "1 audit lane (tag std/ primitives with effect signatures)"
with "1 audit-as-existence-check lane (verify primitives' signature-
shape coverage; NOT 'tag every primitive') — produces the path (i)
vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2
prereq lanes to the net summary. Closing line: "The taxonomy-
retirement scope (substrate-side) is not in this lane — it's
surfaced by audit and routed to dedicated retirement lane if path
(ii) wins."

Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity
table. Worker reading Q6 in isolation now sees path-(ii)-default
framing matching Q4 + Q5.5 + THESIS amendment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792

Resolves codex inline BLOCKING at sha 191be310 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150.
Real: my Q4.5 P2 framing described ExecuteCommand as still
NotYetImplemented (M1.5 allowlist + Rust TestRunner returning
NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand
extension before this PR's authoring. TESTING.md:195 capability-state
callout confirms:
- Rust TestRunner + M1.5 testgen harness share one std::process path
  for arbitrary command + args + expect_exit_code.
- M1.5 allowlist + fail-closed panic retired.
- Distinguishable ClaimResult::Fail messages for spawn / timeout /
  policy / exit-mismatch.
- Linux unshare(1) namespace isolation on host-allowing systems.
- T-PB-B-1 boundary migration example landed.

Fix:

P2 section rewritten:
- Header retitled "ExecuteCommand runner primitive: LANDED (PR #792);
  residual is bulk-migration."
- Status update naming PR #792 + the post-#792 capability state
  (allowlist retired, etc.).
- Honest acknowledgement: "My earlier P2 framing was stale."
- Residual narrowed to bulk-migration of existing Rust Command::new
  boundary tests (tracked as ROADMAP residual, not lens prereq).
- Sequencing reframed: P2 was always orthogonal to the effects lens
  itself; bulk migration proceeds at its own pace; lens not blocked.

Q4.5 footer updated:
- "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via
  #792; only consumer-side bulk migration remains)"
- Worker-discretion-vs-Director-call P2 line updated: "runner
  primitive landed; only consumer-side bulk migration remains;
  tracked as ROADMAP residual, independent of the lens."

Q6 STOP for P2 updated:
- "the lens itself doesn't depend on P2; only TESTING.md's 0-residual
  claim does" → "runner primitive landed via PR #792 (post-Q4.5-
  authoring update). The lens itself never depended on P2; bulk
  consumer migration is residual ROADMAP work and remains independent
  of this lane."

Brief now reflects live state. The closed-system claim's prereq
landscape is honest:
- P1 (extdeps typed-primitive consumption): real prereq, tracked
  debt at ROADMAP:153-154.
- P2 (ExecuteCommand runner): satisfied via #792; bulk migration is
  consumer-side residual, not foundation work.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale

Resolves codex non-blocking finding at sha bcac41bb on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real
residual: capacity-table line still listed P2 as "`ExecuteCommand`
materialization" prereq + framed both P1 and P2 as "pre-existing
tracked-debt" — but my prior 57a9b1318 fix established that PR #792
already landed the runner primitive, so P2 is no longer a
materialization prereq.

Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq)
from P2 (residual, not prereq):

  - P1: extdeps typed-primitive consumption — pre-existing tracked
    debt at ROADMAP:153-154; load-bearing for the lens's full-coverage
    claim.
  - P2: ExecuteCommand runner primitive landed via PR #792; only
    consumer-side bulk migration of existing Rust Command::new
    boundary tests remains (tracked as ROADMAP residual, independent
    of the lens; not a materialization prereq).

Brief now consistently treats P2 as bulk-migration-residual across:
- §Q4.5 P2 section header (LANDED via PR #792; residual is
  bulk-migration).
- §Q4.5 footer (P2: runner primitive landed; only consumer-side
  bulk migration remains).
- Q6 STOP for P2 (runner primitive landed; bulk migration is
  residual ROADMAP work).
- §Capacity / sequencing impact (P2 as residual, not prereq).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349

Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated
target-grounding prose; the matching extdeps typed-primitive bypass
entries (LLM service flattening, GitHub auth model bypass) live at
ROADMAP.md:348-349.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix third stale ROADMAP citation at line 271

Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence
at line 271 in the §Q4.5 capacity table. Now consistent with lines
139 and 173 (ROADMAP.md:348-349).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity

Codex flagged 'Effect-signature tagging on std/ primitives' as potentially
contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240)
already explicitly say 'NOT tag every primitive' — but the cross-manager
line used sloppy wording. Reworded to make explicit that the audit walks
signature shape; no parallel tag added.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5

- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)

B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).

B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — drop incoherent inner-fallback non-goal

Codex P2: the non-goal line excluding the inner declaration().name
unwrap_or_else fallback contradicted Slice step 2, which replaces the
whole chain with let-Some-else-return. Both fallbacks are in scope by
construction; remove the contradictory non-goal.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives

PM REQUEST_CHANGES: §Frame listed '4 type connectives
(Conjunction | Disjunction | Cardinality | Bit)' which contradicted
the canonical thesis source. Replaced with the canonical 6
(Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per
docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary
closes here'. Also removed 'typed substrate carriers' from the
vocabulary list — substrate carriers are defined using the vocabulary,
not part of it. Added a clarifying note that B4's carriers
(DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are
typed declarations composed from the vocabulary, not vocabulary
extensions.

Per feedback_verify_thesis_claims: brief framings citing thesis
structure must ground in the canonical source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority

Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of
naming the live substrate authority. Two coordinated fixes:

1. §Read first cites src/v3/std/substrate.dag (live .dag substrate
authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel
meta-type — already exists with consumers in verification.dag,
emit_model.dag, python.dag).

2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing
DeclarationRef'. The work is consumer migration + any role-extension
layer the audit reveals, NOT designing or landing the carrier.

Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers)
keep their 'new' framing but explicitly require sub-briefs to grep
src/v3/std/ + src/v3/spec/ for existing authority before authoring
'design and land' framing — per feedback_verify_thesis_claims +
feedback_emitter_workaround_is_gap_symptom.

Acceptance + sub-brief dispatch order updated to reflect B4.1's
consumer-migration shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — tighten Phase 1 umbrella sentence

The umbrella 'Land the typed carriers into src/v3/std/' framing was
stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced
with audit-first wording that covers both the consume-existing case (#1)
and the design-and-land case (#2-#4 if their audits show real gaps).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording

Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands'
which conflicted with the post-reframe reality that B4.1 consumes the
existing DeclarationRef. Updated to 'consumes or lands' with explicit
existing-authority citation and audit-pending caveat for B4.2-B4.4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — soften regression-test requirement (3 worker bounces)

Three consecutive B1 worker dispatches (zesty-crane-890 cursor →
valiant-boar-498 codex → cool-lynx-395 cursor) archived without
opening a PR. Likely friction point: brief Slice step 4 asks for a
unit test that constructs a Dag with an orphan variant declaration,
but emit.rs has zero existing #[test] precedent — emit testing
happens via integration fixtures. Workers see 'build novel test
harness' inside what's billed as an S-scope fix and bounce.

Per feedback_construction_over_ratchets: when a brief has friction,
fix the brief, don't ratchet the worker.

Softened step 4 + acceptance: regression test stays optional. If
test setup requires novel scaffolding, route the gap to follow-up.
The structural fail-closed at step 2 is the load-bearing change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt

PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description'
is too weak; PR descriptions don't survive squash-merge cleanly.

Two coordinated edits:
1. Slice step 4 — explicit substrate-signal framing: skipped test
   means emit-side hermetic-unit-test infrastructure is the missing
   substrate (feedback_emitter_workaround_is_gap_symptom).
2. Acceptance — require ROADMAP debt row (new or existing) with
   named dissolution trigger, referenced in PR body. Converts the
   skip from PR-local note (transient) into tracked debt (durable,
   dispatchable).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124

Codex BLOCKING: my earlier softening claimed emit.rs had no #[test]
precedent — wrong. The module has #[cfg(test)] mod tests at line 3124
with 12+ tests using compile_to_dag(source, filename) as harness
(e.g., go_struct_fields_render_with_separators :3143,
shared_walk_to_disj_finds_match_scrutinee_sum_type :3195).

This is a feedback_verify_thesis_claims violation on Director-side
brief authoring — claim made without grep verification.

Fix: restore step 4 as required, with explicit precedent citation.
Worker constructs the failure case via the existing harness
(direct Dag, fixture string, or BranchPattern exercise; worker's
call on cleanest path). STOP-AND-ESCALATE only if construction
proves materially harder than precedent suggests, in which case
that escalation surfaces a real substrate gap and warrants ROADMAP
debt — but the default is 'add the test.'

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites)

Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but
emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded
to 'several using compile_to_dag'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue

Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this
is Wave 1 of Director's 14-brief authoring queue, covering B4 program
internals.

Authored:
- b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) —
  replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag")
  fold-skip with structural template-formal carrier; mandatory
  authority audit per feedback_audit_adjacent_authority_first.
- b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) —
  replaces §0.6 emit.rs bind/branch.span.file equality with typed
  BindEmitParticipation/BranchEmitParticipation roles populated at
  lowering; aligned with #824 worker's in-flight implementation shape.
- b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4
  of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with
  typed substrate authority; explicit pre-promotion-constraint
  disposition (single-authority vs authority+tracked-debt) addresses
  parallel-representation risk surfaced on #825.
- b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) —
  names B4.5-B4.12 Phase 2 sites with carrier dependencies,
  cross-program coordination notes, and skeleton-brief template;
  full per-site briefs author at dispatch time per #827's
  Substrate Manager ownership.

Cross-cutting discipline applied per inbox #828 reply:
- feedback_audit_adjacent_authority_first (mandatory grep before design)
- feedback_no_textual_enforcement_bridges (no replacement sentinels)
- feedback_parallel_representation_debt (explicit if shape (b))
- feedback_construction_over_ratchets (no parity-by-runtime as primary)
- feedback_coproduct_dissolution (receipts for new variants)

Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling
worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3)

Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue.
Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by
Modeling Manager's Wave 3 worker briefs (gated on these landing).

Authored:
- r2-substrate-cardinality-for-int-lit-subset.md (M) — produces
  magnitude carrier consumed by T-Modeling int-lit. Coordinates with
  PR #806's prior cardinality work; mandatory authority audit guards
  against #796's rejected IntLiteralMagnitude shape resurfacing.
  Open design questions: magnitude representation, reconciliation
  narrowing point, i64::MIN representability.
- r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces
  nominal-opacity carrier consumed by T-Modeling Secret<T>. Open
  design questions: carrier shape (flag/connective/sealed-accessor),
  generic-walk discipline, accessor gating.
- r2-substrate-parametric-algebra-for-dimensions-subset.md (M) —
  produces phantom-parameter carrier consumed by T-Modeling
  Dimension<Carrier>. Open design questions: carrier shape,
  type-equivalence rule, algebra-method dispatch, lifting/coercion.

All three:
- Scoped narrowly to their paired R2 consumer; not full
  substrate-capability lanes.
- Mandatory pre-author authority audit per
  feedback_audit_adjacent_authority_first.
- Cross-program readiness signal pattern from #827's manager rework.
- Coproduct dissolution receipts required for any new variants.
- Open design questions surfaced explicitly so Substrate Manager
  (or Director pre-spin-up) can resolve at dispatch time.

Wave 3 (T-Modeling worker briefs × 4) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4)

Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue.
Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each
gated on a Substrate Manager readiness signal (Wave 2 producers).

Authored:
- r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2
  cardinality-for-int-lit; moves narrowing from tokenizer to
  reconciliation; MagnitudeOutOfRange diagnostic per C-8.
- r2-modeling-secret-graduation-worker.md — gated on Wave 2
  nominal-opaque-for-Secret; authors Secret<T> + gated accessors
  (redact, compare_in_constant_time); C-8 diagnostic on non-gated
  access; signals Impossible-Bugs Manager on close (thesis claim
  covered).
- r2-modeling-dimensions-phantom-worker.md — gated on Wave 2
  parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier>
  + core SI base units + algebra-method dispatch; cross-dimension
  arithmetic produces typed diagnostic; signals Impossible-Bugs
  Manager (thesis claim).
- r2-modeling-tokenizer-charclass-phase2-worker.md — gated on
  T-Substrate ValueBody-list/sum (#790); migrates tokenizer
  consumers to Char/List<Char>/CharClass canonical types; sibling
  consumer to Grounding Manager's Engine sharpened-(b).

All four:
- Explicit gating: 'do not dispatch until producer signal posts.'
- Producer/consumer signal pattern from #827.
- Cross-program signals to R2 Release Manager (Goal 2 closure)
  and Impossible-Bugs Manager (thesis-claim coverage).
- Spoofing regression tests: discipline anchor against
  feedback_no_textual_enforcement_bridges.

Wave 4 (T-ImpossibleBugs worker briefs × 3) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3)

Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue.
Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes,
consuming the existing design/scoping briefs as authority.

Authored:
- r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on
  cardinality refinement substrate (T-Substrate territory adjacent
  to int-lit / DB-11 alias-where). Implementation: structural normalize
  of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T??
  worker decision (reject vs normalize). Cites
  t-impossiblebugs-nested-optional-flatten-design.md as authority.
- r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated
  on Tier 2 substrate (predicate-entailment infrastructure; distinct
  from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes
  predicate entailment, (b) feedback_totality_by_omission dissolves
  partial primitives, (c) park. Worker decides at audit time. Cites
  t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority.
- r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate
  prerequisite per closed-system framing in design doc (#808). Audit-
  as-existence-check + lens implementation as compositional fold over
  5 behaviors; redundancy detection compile-error via referential
  transparency + reread() escape hatch; path (i/ii) decision on
  OperationEffect taxonomy retain-vs-retire (default retire). Cites
  design doc #808 as authority.

Cross-cutting:
- Each cites prior design/scoping brief as authority (the existing
  *-design.md / *-worker.md REFRAMED files).
- Explicit gating per #827 producer/consumer signal pattern; two
  briefs gated on substrate, one NOT gated (closed-system).
- STOP-AND-ESCALATE includes 'design brief assumptions don't hold'
  surfacing per feedback_thesis_gate_state_drift.

Wave 4 complete. Director's 14-brief queue done; awaiting PM portion
(6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4.4 — tighten Slice §3 per PM review on #836

PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b)
(authority + tracked debt parallel-rep) as autonomously acceptable
contradicts feedback_construction_over_ratchets +
feedback_parallel_representation_debt.

Tightened:
- Shape (a) is the only autonomous worker path.
- Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a
  regen-host-loader sub-lane decision; not authorable without explicit
  Substrate Manager approval citation in the PR body.
- Acceptance bullet requires the approval citation when shape (b)
  lands.
- STOP-AND-ESCALATE rephrased to make this explicit; permanent
  parallel-representation re-escalates even with manager approval.

This preserves shape (a) as autonomous; shape (b) becomes a
cross-manager design escalation, not a B4.4 implementation call.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief

Cursor review on #836 flagged the Read-first reference to
.claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md
as machine-specific (outside the repo, not resolvable from a normal
clone). Replaced with in-repo prose pointing at the design doc's
§Q1-Q3 as canonical authority — the discipline lives there in-repo.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs)

Codex flagged: src/v3/std/types.dag does not exist; the canonical
authority is at dsl/std/types.dag. Affected briefs (all from R2
spin-up Wave 2 + Wave 3):

- r2-substrate-cardinality-for-int-lit-subset.md
- r2-substrate-nominal-opaque-for-secret-subset.md
- r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs)
- r2-modeling-dimensions-phantom-worker.md
- r2-modeling-secret-graduation-worker.md

feedback_verify_thesis_claims violation on Director-side brief
authoring — assumed path without grep. Same family of error as
the earlier emit.rs precedent claim. Mass-replaced via perl;
verified no remaining stale refs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant

Codex BLOCKING on #836: my R2 worker brief gated nested-optional on
cardinality refinement substrate, but the design doc verifies v3 is
ALREADY past the cardinality bridge — TypeConnective::Cardinality
is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is
the carrier for Option. The dissolution is an UNGATED implementation
via substrate-constructor invariant.

feedback_verify_thesis_claims violation again — should have read the
design doc fully before assuming the substrate gate.

Rewrote brief to match design doc canonical sketch:
- Single predicate (cardinality_idempotent_target) owns the rule
- Single allocator (alloc_cardinality_decl) is THE substrate-constructor
- API closure on TypeConnective::Cardinality payload (modeling-discipline
  practice 6) — variant cannot be struct-init'd outside the allocator
- 3 hand-Rust + ~22 codegen call sites enumerated per design audit
- infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as
  the killer case for generic-instantiation paths
- Surface-syntax T?? decision left to worker (Director-lean: silent
  normalize)

Brief now dispatchable immediately, no producer signal needed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation

Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment
substrate path, but the design doc §4 explicitly recommends totality-by-
omission as the Director-actionable path. Predicate-entailment is M+ scope
that reopens DB-11's explicitly-closed asymmetric-strip design — design
doc explicitly discards it.

feedback_verify_thesis_claims violation again — same family as nested-
optional reframe. Should have read design doc §4 in full before assuming
the path ordering.

Rewrote brief to match design doc §4 follow-on shape:
- Primary path: per-class totality-by-omission (algebra retype + per-
  target realization migration). For Int/Int: OrderedRing.div retype
  at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 /
  python:486 + python_target.rs:680 helper).
- NOT predicate-entailment (out of scope; M+ + DB-11 reopen).
- NOT NonZero-typed-input (deferred to separate per-operand-variance
  substrate brief; STOP-AND-ESCALATE if chosen).
- Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i]
  indexing, quotient, remainder) queue separately per design doc audit.
- feedback_totality_by_omission discipline anchor explicit.

Brief now matches feedback_totality_by_omission discipline + design doc
recommendation. No substrate prerequisite; dispatchable immediately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure

Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a
pattern: I authored R2 worker briefs without fully reading each design
doc's Director-actionable recommendation. Pre-emptively re-verified
unenumerated-effects against design doc §Q6 to catch the same family
of error before reviewers do.

Findings: brief was substantively close but missing 3 of 8 design-doc
reqs:
- Req 3: Resource-threading discipline applied to existing primitives
- Req 5: reread(key) primitive in std/ as explicit Slice item (was
  only mentioned in tests)
- Req 7: Asymmetric-tightening worked example in PR body

Plus: Slice didn't cite the canonical lens path
src/v3/lenses/effect_enumeration.dag from design doc.

Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6
specifies 4 specific STOPs (path-decision-escalation, pure: Bool
carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP)
that I had elided.

Reframed Slice as 8 numbered reqs matching design doc verbatim;
STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs;
Acceptance enumerated per req.

This is the third reframe in the unhandled-bugs series — same
feedback_verify_thesis_claims violation each time. The pattern
suggests Director-side R2 brief authoring should ALWAYS read each
design doc's §Director-actionable / §Q-recommendation in full first,
not assume.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options

Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)"
listed as a worker-pick option violates THESIS.md substrate-shape
lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality |
Instantiation) are canonical (per #811 thesis additions and #827 PM
review); a 7th is a C1 stop signal requiring failed-dissolution
evidence + Director substrate-design call, not autonomous worker pick.

Removed the "new TypeConnective variant" option; replaced with
`inhabits`-edge-shape carrier as third option (audit-time check). The
explicit STOP-AND-ESCALATE clause now states: 7th connective is the
precondition for failed-dissolution-evidence + Director substrate-design
call, not a worker path.

feedback_verify_thesis_claims still in play — should have grounded
substrate-shape options against the THESIS lock before listing Opaque(T)
as worker-autonomous. Pattern continues; reading source-of-truth before
authoring options is the discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place)

Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter
already exist at dag.rs:186, :217 — explicitly authored for the
R2 Dimensions consumer per the doc comment at dag.rs:148-160.
phantom_unit_mismatch already wired at infer.rs:1057, :1132. The
substrate is fully landed; my brief framing it as 'producer sub-lane
to land carrier' is wrong on the same feedback_audit_adjacent_authority_first
violation that hit nested-optional / unhandled-diagnostic / unenumerated-
effects.

Reframed the substrate-side brief as no-op / closed-by-audit:
- Documents the audit receipt (5 sites confirming substrate exists)
- States the lane is closed
- Routes T-Modeling Dimensions consumer to dispatch immediately
  against the existing carrier
- Records the lesson: 'always grep substrate before authoring
  producer briefs' — discipline doesn't end at brief boundaries.

Updated r2-modeling-dimensions-phantom-worker.md correspondingly:
- Changed gating from 'do not dispatch until producer signal' to
  'NOT GATED — dispatch immediately'
- Read-first updated with concrete dag.rs/infer.rs cites
- Slice §1 changed from 'confirm producer signal' to 'verify
  substrate at HEAD'
- STOP reframed: existing carrier extension would need Substrate
  Manager call, not autonomous worker pick

Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit
both verified — no existing substrate (no is_nominal_opaque /
MagnitudeBound patterns in dag.rs); both still legitimately
producer-side work.

Pattern is now four reframes deep on the R2 spin-up wave. The lesson
saved is structural: read source-of-truth before authoring options.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority

Codex BLOCKING on #836: my new R2 spin-up brief duplicates the
existing t-substrate-cardinality-int-lit-worker.md, which carries
the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64)
stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane).
Single-authority violation per INVARIANTS P2.

Same feedback_audit_adjacent_authority_first failure as parametric-
algebra-for-Dimensions reframe (4 hours ago): assumed substrate
authority didn't exist; should have grepped docs/briefs/ before
authoring. This is the SECOND R2 spin-up substrate brief closed
as redundant — the discipline lesson is structural.

Reframed brief as no-op routing doc (documents the audit receipt;
routes consumers to the existing authority); updated
r2-modeling-int-lit-magnitude-worker.md to cite
t-substrate-cardinality-int-lit-worker.md instead.

Pattern across the R2 spin-up wave reframes (5 now):
1. nested-optional gating-on-substrate (substrate already past
   cardinality bridge)
2. unhandled-diagnostic predicate-entailment default (design doc
   recommends totality-by-omission)
3. unenumerated-effects 8-req design-doc elision
4. parametric-algebra Producer (Declaration.phantom_params already
   authored explicitly for this consumer)
5. cardinality-for-int-lit Producer (existing brief is authority)

All five are 'as…
briansrls added a commit that referenced this pull request Apr 26, 2026
* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation)

Director-authored amendment following the 2026-04-24 escalation from PR
#693 (sub-child sharp-bear-829 under Surface Manager).

Two edits:

1. New "Class 5 Gap 3 — port-carried field values in data bodies"
   row in the 2026-04-21 post-merge-debt section. The substrate gap was
   documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP
   ledger row for cross-lane visibility. PR #693's execution surfaced it
   as the blocker on sub_charclass_in_std_unicode phase-2.

2. Retract the "ready-to-dispatch (no substrate capability gap)" claim
   on the Character-level row, annotate phase-1 landed via PR #693
   (CharClass vocabulary + Rust-mirror structural scanner path), and
   point phase-2 at the new Class 5 Gap 3 row.

Codifies the audit pattern: "this consumption gap has no substrate
capability gap" claims must be verified by attempting the retype before
the claim lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main

* docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review)

* docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review)

Row title still said 'consumption gap, not substrate gap' while the
body block retracted that claim and cited Class 5 Gap 3 as a substrate
dependency for phase-2. Title now matches body: mixed classification,
consumption for steps 1+3, substrate for step 2.

* docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit)

gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining
gap" description was wrong: field-level shapes (nested records, list
literals, declaration refs, Var refs, sum-variant literals) are
supported today via FieldValue variants + lower_structural_field_value
(dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the
top-level ValueBody boundary (non-scalar, non-record top-level bodies).

The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself
stale: it describes the pre-PR-B-unwind shape where FieldValue was
LiteralBits-only. PR-B's unwind extended FieldValue to carry
Reference / Record / List / Variant, moving the gap to ValueBody.

Two fixes:

1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody
   boundary, point at code paths (dag.rs, lower.rs) as live authority,
   flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass
   blocker classification to "provisional pending reproduction."

2. Update the Character-level row's phase-2 block to name that the
   specific shape of the CharClass failure needs concrete reproduction
   from the escalating sub-child before the blocker is finalized.

Recursive audit-pattern instance: the row I wrote to codify "verify
live state before claiming substrate gap" itself failed to verify live
state. Both incidents (2026-04-23 original row + 2026-04-24 my
retraction row) are now cited in the audit-pattern sub-note as
examples of the same discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33

Three substantive fixes addressing internal-consistency gaps in the cascade
promotion PR caught by codex review at sha 0d6e7c33:

1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane
   acceptance bullets and Hand-Rust census paragraph in line with the
   updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero
   (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is
   retracted under 0-floor with explicit migration to ExecuteCommand-based
   .dag TestClaim declarations.

2. docs/design-pure-bootstrap-zero.md promotion section — converted from
   future-tense ("This doc is PROPOSAL until promoted… promotion is a
   single Director-authored cascade PR…") to historical past-tense
   promotion-receipt framing ("This doc was PROPOSAL until promoted;
   promotion was a single Director-authored cascade PR that did all of the
   following atomically…"); blocking-clause struck through and resolved
   inline. Banner cites PR #782 explicitly.

3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_
   profile excluded (Map<String, AlgebraProfile> body, not list-of-sum;
   needs distinct ValueBody::Map substrate work, tracked separately as a
   future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass
   phase-2 + Engine sharpened-(b) pilot enumeration), both sharing
   list-of-sum substrate work. Lane table, dependency DAG, and capacity
   summary updated for consistency (slot count 9-13, was 10-14).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities

Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade
self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22
explicitly names THESIS.md and "any other authority docs" as required
retraction targets; the prior diff updated ROADMAP + r2-structure + design
docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting-
manager.md pointing at the now-SUPERSEDED ≤5-floor framing.

Files:

- THESIS.md (5 prose blocks updated):
  - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests
    migrate to ExecuteCommand-based .dag TestClaim declarations.
  - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag.
  - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor
    target citing design-pure-bootstrap-zero.md as live authority;
    hand_maintained_src list shrinks to empty set.
  - :301-318 — Tests-are-structural-data block: residual carve-out retracted;
    predicate name pb_rust_tests_outside_residual_zero retained as
    housekeeping (semantically the residual is empty under cascade).

- docs/thesis/compiler-std-consolidation.md (5 references):
  - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes
    design-pure-bootstrap.md (SUPERSEDED).
  - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process
    lane named as the dissolution trigger for bootstrap.rs itself.
  - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md.
  - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority
    re-cited.
  - :185 Related docs link.

- docs/briefs/r1-selfhosting-manager.md (active dispatch brief):
  - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5);
    T-PB-B residual carve-out retracted; predicate names retained for
    housekeeping; cascade-promoted authorities are source of truth.
  - Slice descriptions for T-PB-A / T-PB-B updated inline.
  - Framing-question + ask updated to 0-floor / no-residual framing.
  - Day-1 + up-to-director hand-off bullets updated.
  - Working-state checklist :111 ≤5 → 0 with cite.
  - Decisions log :164 ≤5 → 0-floor target updated.

- docs/r2-structure.md §2 design call (RETRACTED block):
  - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through
    in entirety (both Option A sharpen-and-keep and Option B rename are
    moot under 0-floor). Section preserved as audit-trail historical
    context.
  - Background-doc index: self-hosting anchor updated to
    design-pure-bootstrap-zero.md as live authority.

- docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per
  non-blocking suggestion):
  - Banner cites cascade promotion PR #782 explicitly.
  - New paragraph: "Treat all numeric floors below as retracted" with
    explicit lines named that quote in isolation (table row, body prose
    references). Prevents re-quoting from this doc as live authority.

Cascade is now atomically consistent across:
  THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔
  docs/thesis/compiler-std-consolidation.md ↔
  docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔
  docs/design-pure-bootstrap-zero.md (LIVE) ↔
  docs/design-pure-bootstrap.md (SUPERSEDED).

The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds
genuinely.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): correct ExecuteCommand runner-capability claim

Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation):
TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138
overstated live runner capability — claimed runner support landed in
PR #688/#741 with "emit Rust, invoke rustc on output, check exit code"
as a structurally-equivalent migration path. Verified against live
sources:

- src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema
  exists (declared via PR #678).
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5
  testgen harness allowlists ONLY `command == "true" && args.is_empty()
  && expect_exit == 0`.
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 —
  panics fail-closed on any other shape with explicit "ExecuteCommand
  shell shape is not supported here (runner-owned — do not treat as
  ordinary false)".
- src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no
  match arm for ExecuteCommand; falls through to ClaimResult::
  NotYetImplemented.

Reality: a TestClaim declaring rustc/python/go invocation is
structurally expressible as data today, but executing it is blocked.
Full arbitrary-command runner support is the PB-Runtime lane's
deliverable.

Files updated:

- TESTING.md:195 — capability state callout with file:line citations;
  "Full runner support — arbitrary command + args (rustc/python/go) with
  exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor
  program)." Bullet about migration shape preserved as the cascade-named
  successor pattern, not as a live capability.
- TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane
  lands the ExecuteCommand runner extension" as an explicit precondition.
- docs/design-pure-bootstrap-zero.md:138 — same correction for the
  matching prose, with PB-Runtime named as the runner-extension
  dependency for boundary-test migration.
- ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner
  foundation in #688/#741 with `true`-no-args allowlist only — full
  arbitrary-command runner support deferred to PB-Runtime lane,
  blocking the actual boundary-test migration." Dependencies column
  extended to "DB-15 + T-TestGen + PB-Runtime".

The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still
holds for atomic-cascade-across-authority-docs; this commit closes the
remaining capability/claim mismatch flagged by codex.

(Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still
SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief

Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation).
The prior banner contained:

> "Operationally R1 closure may still ship before the 0-floor is reached
>  — the ratchet ensures the trajectory; the gate's acceptance number is
>  what shifts."

This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0.
Two competing gate semantics in the cascade is exactly what the
atomic-cascade clause forbids.

Replaced with single-authority-honest framing:

> "R1 closure now requires the 0-floor target by gate semantics: T-PB-A
>  and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade
>  promotion changed their acceptance numbers to 0; R1 cannot close
>  while the SG-0 census carries non-zero hand-Rust."

Plus minor sharpening:
- "T-PB-A's non-test target is 0" → "non-test acceptance target is 0
  per ROADMAP.md:67" (cite the authority).
- T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep
  the capability-state honesty consistent with the recent fix wave.
- Predicate-rename housekeeping line moved into banner ("post-cascade
  housekeeping, not a pre-promotion blocker") — was implicit before.

The brief now genuinely inherits the cascade-promoted gate; no
competing release authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 second-wave worker-escalation fixes

Four substantive worker STOP-AND-ESCALATEs from briefs landed in
PR #797. All four worker recommendations correct; each needs a
Director call + brief update.

## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate

Worker correctly identified that brief req 2 (declared-effect carrier
as part of fn type signature, per feedback_no_annotations) requires
net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at
src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots.
Without parser surface, every user function would have
declared_effects = [] while inference returns non-empty — lens fires
EffectLeakageError everywhere on enable. Worker rejected power-through
and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map
parser split).

Director picked split:
- NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md
  Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface
  syntax + lookahead + body parser + lowerer extension + exhaustive-match
  audit + coproduct dissolution receipt.
- MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to
  post-parser-extension scope. Pre-flight check NOT a parser-extension
  step; STOP if parser sub-lane PR not merged.

## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping

Worker found load-bearing evidence at infer.rs:3693-3703: DB-11
deliberately strips refinements at operator dispatch as a designed-in
fix for symmetric-operators failure mode. Brief's "attach where b != 0
as a proof for a / b" directly contradicts this design choice. STOP-3
(where-clause conflict with DB-11) is real; STOP-1 (substrate scope)
needs net-new substrate (per-operator partiality fact + predicate-
entailment check + asymmetric per-operand refinement-honoring) — M+
minimum. ownership_lens precedent in original brief is post-hoc
observability, not proof carrier.

Worker recommended redirect to design/scoping per nested-optional
precedent. Director picked redirect.

Brief fully rewritten as design/scoping with four-question structure:
(1) DB-11 interaction analysis; (2) substrate proposal for proof-or-
totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes
with acceptance-theatre risk on user-defined-total-wrapper-only);
(4) Director-actionable recommendation. Output is doc PR.

## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C)

Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int)
with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136
closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b)
i128 implementation requires either path 1 (hierarchy refactor —
contradicts non-goal) or path 2 (regen lie between substrate and
emit — violates discipline). Worker leaned option (C) re-scope:
land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke)
to a sibling sub-lane that does proper Int128/Word128 substrate work.

Director picked option (C). Brief req 1 re-scoped to drop canonical-
carrier-widening; lane value comes from range facts + reconciliation
narrowing + out-of-range diagnostic against existing i64. Req 4
explicitly deferred with sibling-sub-lane reference. Sibling sub-lane
NOT to be authored or implied in this PR; tracked separately.

## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change)

Worker correctly STOP'd per the brief's own pre-flight check: parser
sub-lane has not landed; SurfaceExpr::Map not on main. Director
authorized cross-lane reassignment: wise-boar-480 takes the parser
sub-lane (t-substrate-valuebody-map-parser-worker.md) since they
already have full investigation context. No brief changes needed; the
routing decision is in the dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope

Resolves codex P2 inline at sha e35103fad on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer
carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still
required widening LiteralBits::Int(i64) to an unbounded carrier and
passing the i64::MIN smoke. Internally unsatisfiable.

Fix:

- Slice section retitled "range facts + reconciliation narrowing
  (against existing i64 carrier)" with explicit note about the
  re-scope.
- Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly
  forbids touching LiteralBits::Int shape, dag_scalar_generated.rs
  regen for that variant, or tokenize i64 parse path.
- Slice steps 2-5 reframed: range facts use i64-representable
  magnitudes; reconciliation narrowing uses existing i64 carrier;
  diagnostic only for i64-representable out-of-range; smoke tests
  for req 5 only (req 4 i64::MIN deferred).
- Acceptance checklist updated:
  - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as
    re-scoped/deferred.
  - LiteralBits::Int(i64) carrier untouched (no widening; no
    parallel; no shape change).
  - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference.
- STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the
  carrier" — explicit STOP if execution surfaces range-fact narrowing
  requiring carrier-widening; that's the boundary the re-scope drew;
  belongs in sibling Int128/Word128 sub-lane.

Brief now consistently treats carrier-widening as out-of-scope across
all sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty

Resolves codex BLOCKING #1 at sha e35103fa on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier
but req 2 required range facts using "the SAME magnitude carrier
as req 1" — meaning i64-typed range bounds. u64's max (2^64-1)
doesn't fit in i64; range fact for u64 would have to truncate,
omit, or mirror in Rust (representation drift). All three options
violate fail-closed declared-facts discipline (P1 / P3).

Fix:

- Req 2 rewritten to specify String-decimal representation:
  range_min_inclusive: String + range_max_inclusive: String fields
  on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127"
  for i8; "0"/"18446744073709551615" for u64).
- Explicit reasoning why String-decimal: u64's max doesn't fit in
  i64; binding range bounds to literal carrier forces truncation/
  omission/mirror-drift; all violate fail-closed declared-facts
  discipline.
- Bridge framing: String-decimal is pending the sibling Int128/
  Word128 sub-lane; both range bounds and literal payload migrate
  to typed carrier when that lands.

- Req 3 updated for String-decimal comparison semantics:
  reconciliation parses both bounds and literal magnitude into a
  common comparison space (i128 host comparison primitive — host
  narrowing, NOT carrier widening). Bounded by what the i64-typed
  literal can express; any i64-representable literal compares
  against any width's String-decimal bound. Carrier discipline
  preserved.

Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral)
is sha-stale — already resolved at 3e142d169.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed

Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback).
Real residual: req 2 specifies String-decimal range bounds (to cover
u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance
bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" /
"i64-representable magnitudes" for the range facts. Two incompatible
authorities for the same range-fact shape — would let a worker satisfy
the slice while truncating/omitting u64 bounds (P3 fail-closed
violation).

Fix:

- Line 31 (req 1 re-scope clarification): updated to explicitly state
  "range facts (req 2) use String-decimal representation (width-
  independent; covers u64::MAX which doesn't fit in i64)". Distinguished
  literal *payload* (stays i64) from range-bound *representation*
  (String) — both serve req 1's "no carrier widening" boundary.
- Line 44 (slice step 2): updated from "Range bounds use i64-
  representable magnitudes" to "Range bounds use String-decimal
  representation per req 2" with concrete example (u64 bounds).
- Acceptance bullet: updated from "Range facts on integer algebras
  (substrate-declared, not Rust-mirrored)" to add "using String-decimal
  representation ... width-independent; u64 bounds expressible without
  truncation."

The brief now consistently treats range bounds as String-decimal
across req 2, req 3, slice, acceptance, and the req 1 clarification —
no remaining authorities saying i64-typed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing

User + PM exchange 2026-04-25 surfaced that the in-flight effects
chain was importing wrong assumptions from external languages
(declared-effects-as-annotation + lens-vs-declaration check). Right
framing under gunbc's closed-system discipline is parallel to
complexity: every effect derives structurally from the composition
of typed primitive operations; nothing can hide because there's no
escape hatch; nothing needs annotation because the structure IS the
registry.

Four doc-only actions:

1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md.
   Frames the closed-system answer with PM's 5-behavior synergy
   table (Value/Transform/Branch/Loop/Bind as universal
   compositional-fold pattern). Four worked examples; aggressive
   reading on redundancy (compile-error-by-construction via
   referential-transparency proof; reread() primitive for legitimate
   cases); implementation-brief shape in §Q6.

2. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md.

3. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md.
   Notes Fn→Arrow refactor brief stays dispatchable as independent
   value.

4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by-
   construction framing replaces lens-detection framing.

Memory file feedback_closed_system_effects.md saved separately;
cross-link added to feedback_construction_over_ratchets.md.

Net cost: doc-level cleanup. Zero substrate code rework. Foundation
(OperationEffect + service-call infrastructure + 5-behavior
substrate) already exists.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect

Per PM convergence review on #808 + user's deeper 2026-04-25 framing:
the closed-system framing landed in #808 retired the user-facing
annotation but kept OperationEffect taxonomy as substrate-level tagging.
User's deeper framing: the taxonomy ITSELF is parallel-representation —
operations are intrinsically read-shaped or write-shaped via their
TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns-
derived-value-only → read). Tagging operations with Read | Upsert |
Create | Append | Delete names what the structure already says.

Three changes:

1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as
   normalized view, or retire as parallel-representation?"
   - Two paths: (i) tags derived from signature shape (acceptable
     normalized view) vs (ii) tags declared per-primitive (parallel-
     representation; retire).
   - Audit-as-existence-check (Q4 req 2 reframed): all effectful
     primitives derive cleanly from signature shape → path (i); any
     primitive needs hand-declared tag → path (ii) by existence proof.
   - Director default: path (ii). Logging primitives that return Unit
     are likely the audit's existence-proof.
   - Two design-question resolutions: (a) external effects not in
     return type → resource-threading discipline (typed param returned
     modified, IO-monad-without-the-monad pattern); (b) transactional
     grouping → derived structural fact from Bind composition + typed
     transaction primitives.

2. Q4 reqs revised: req 2 from "tag every primitive with explicit
   OperationEffect signature" to "audit-as-existence-check that every
   primitive's type signature derives the right effect classification";
   req 3 added (resource-threading discipline); req 6 added
   (transactional-pattern lens). Req 1 (effects lens) anchors on
   operation type-signature shape, not on hand-declared tags.

3. THESIS:345-347 amendment strengthened — "operations are
   intrinsically read-shaped or write-shaped via their type-signature
   shape; consumers walk the signatures directly; there is no parallel
   taxonomy or annotation layer to declare or maintain. Tracking
   effects as a separate enumerated concept IS the bug pattern,
   dissolved by construction." Plus references to resource-threading
   discipline + transactional grouping as derived structural fact.

Memory file feedback_closed_system_effects.md updated to reflect the
deeper framing (type-signature-shape, not taxonomy-tagging) +
resource-threading discipline section + transactional-patterns
section.

Net cost: doc-only delta on top of #808. Substrate retirement
(OperationEffect enum + derive_op_effect + idempotency.dag re-anchor)
deferred to the audit-as-existence-check phase of the implementation
brief; surfaced as Q5.5 OPEN CALL.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage

Resolves codex BLOCKING at sha d49ce79a on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real:
the prior text claimed service primitives "already carry typed effect
signatures" presenting future audit-state as current substrate fact
(P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the
OperationEffect line but left a parallel over-claim on the new
"signature-shape coverage" framing.

Fix: Q4 substrate-state listing rewritten to honestly distinguish:

- Live: Behavior enum + substrate foundation (the principle that
  operations should carry signature shape).
- Incomplete: signature-shape coverage across actual primitives.
  HTTP-derived primitives carry implicit shape via derive_op_effect's
  method-table; logging/mutation primitives that return Unit or don't
  thread their target resource do NOT carry the structural shape that
  would express read-vs-write. Achieving full coverage is required
  work under reqs 2 + 3, not a current fact.
- Pending audit-as-existence-check: OperationEffect + derive_op_effect
  (path (i) vs (ii) per Q5.5).

Honest live-state callout added explicitly: "the closed-system
FOUNDATION (5 behaviors + DAG substrate + the principle that
operations should carry signature-shape) is live. The IMPLEMENTATION
COVERAGE across all effectful primitives is partial. Req 2 + req 3
are the work that closes the gap."

Brief now distinguishes principle-is-live (foundation) from
coverage-is-partial (audit work) without conflating them.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim

Per PM follow-up review on #808 + user's stronger discipline framing
("substrate must make bypass structurally impossible at every layer
of the transport stack"): the closed-system claim is honest only when
typed primitives ARE the path. Today two structural holes exist where
bypasses sidestep the typed-primitive substrate. Both surfaced
explicitly as Q4.5 pre-conditions — load-bearing for the lens's
coverage claim.

Three changes:

1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed-
   system claim)" inserted between Q4 and Q5:

   P1 — Extdeps typed-primitive consumption structurally enforced.
   Substrate must make `messages: Json` impossible to declare in
   service definitions; typed `LlmMessage` / `ContentBlock` /
   `GitHubAuthToken`-with-full-scopes are the only path. Tracked
   debt at ROADMAP.md:153-154 (LLM provider flattening) +
   `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded).
   Required prereq for full lens coverage; lens can land first +
   surface structural-coverage-gap diagnostics on bypass surfaces
   so the gap becomes visible rather than silent.

   P2 — `ExecuteCommand` fully materialized as typed runner
   primitive. TESTING.md (post-#782) committed to 0-residual but
   ExecuteCommand isn't fully materialized; deleting Rust boundary
   tests creates verification gap. Already named under PB-Runtime
   in Zero-Floor; signal pending. Pre-requisite for ANY Rust
   boundary-test deletion.

2. Old leftover duplicate Q5 section deleted (artifact from prior
   Q5/Q5.5 reshape; second copy of asymmetric-tightening text was
   in the file alongside the earlier Q5 instance).

3. Worker-discretion-vs-Director-call section in Q4.5: lens
   implementation worker dispatchable now (reports gaps as
   findings); P1 closure is substantive substrate work touching
   extdeps (dedicated lane); P2 closure is PB-Runtime (signal
   pending).

Net: design doc now honestly distinguishes principle-is-live
(Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs
named explicitly). The closed-system claim has explicit pre-
conditions documented; implementation brief discovers them as
known dependencies, not as STOP-AND-ESCALATEs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default

Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two
real residuals after the Q5.5 reframe:

1. Q6's reqs/STOPs/acceptance still framed under path (i) — said
   "audit + tag std/ primitives — every effectful primitive carries
   an explicit OperationEffect signature." Directly contradicted Q4
   (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment
   ("there is no parallel taxonomy to declare or maintain"). Worker
   reading Q6 in isolation would author the retracted shape.

2. Capacity / sequencing table line about "audit lane (tag std/
   primitives with effect signatures)" carried the same stale
   framing.

3. Q6 STOP "primitive performing side effects without an
   OperationEffect tag" assumed tag-as-authority; under path (ii)
   the STOP shape is "primitive whose signature doesn't structurally
   reveal its effect."

Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale
(already fixed at f073aa95e Q4.5 commit).

## Q6 fixes

- Reqs renumbered + reframed:
  - Req 1 anchors on operation type-signature shape (not hand-declared
    OperationEffect tags); composition reads from signature shape per
    Q2 table.
  - Req 2 changed from "audit + tag every primitive" to
    "audit-as-existence-check" — verify signature-shape coverage; ANY
    primitive needing a hand-declared tag IS the existence-proof for
    path (ii) retirement.
  - Req 3 added: resource-threading discipline applied to existing
    primitives (logging that returns Unit gets reshaped per audit).
  - Req 6 added: transactional-pattern lens (Bind composition +
    Transaction → Transaction').
  - Req 7 added: asymmetric-tightening worked example in PR body
    (per claude review observation; the one place declaration-shaped
    surface re-enters).
  - Req 8 (was 5): tests now reference signature-shape derivation
    explicitly, not tag lookup.
- STOPs reframed:
  - "OperationEffect retirement decision" — audit produces path (i)
    vs (ii) verdict; substrate retirement is its own dedicated
    sub-lane; this lane does NOT absorb it.
  - Pure/impure carrier STOP notes that "pure" should also derive
    from signature shape (pure functions don't return modified
    resources) — so the STOP itself may dissolve under further design.
  - Q4.5 P1 explicitly NOT a STOP — lens reporting structural-
    coverage-gap on extdeps bypass surfaces is the lens delivering
    its foundation-gap-visibility value.
  - Q4.5 P2 explicitly independent — lens doesn't depend on
    ExecuteCommand materialization.
- Acceptance extended: lens reports gap diagnostics on P1 bypass
  surfaces; audit produces existence-proof verdict for Director
  re-decision; asymmetric-tightening worked example in PR body.

## Capacity / sequencing table

Replaced "1 audit lane (tag std/ primitives with effect signatures)"
with "1 audit-as-existence-check lane (verify primitives' signature-
shape coverage; NOT 'tag every primitive') — produces the path (i)
vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2
prereq lanes to the net summary. Closing line: "The taxonomy-
retirement scope (substrate-side) is not in this lane — it's
surfaced by audit and routed to dedicated retirement lane if path
(ii) wins."

Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity
table. Worker reading Q6 in isolation now sees path-(ii)-default
framing matching Q4 + Q5.5 + THESIS amendment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792

Resolves codex inline BLOCKING at sha 191be310 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150.
Real: my Q4.5 P2 framing described ExecuteCommand as still
NotYetImplemented (M1.5 allowlist + Rust TestRunner returning
NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand
extension before this PR's authoring. TESTING.md:195 capability-state
callout confirms:
- Rust TestRunner + M1.5 testgen harness share one std::process path
  for arbitrary command + args + expect_exit_code.
- M1.5 allowlist + fail-closed panic retired.
- Distinguishable ClaimResult::Fail messages for spawn / timeout /
  policy / exit-mismatch.
- Linux unshare(1) namespace isolation on host-allowing systems.
- T-PB-B-1 boundary migration example landed.

Fix:

P2 section rewritten:
- Header retitled "ExecuteCommand runner primitive: LANDED (PR #792);
  residual is bulk-migration."
- Status update naming PR #792 + the post-#792 capability state
  (allowlist retired, etc.).
- Honest acknowledgement: "My earlier P2 framing was stale."
- Residual narrowed to bulk-migration of existing Rust Command::new
  boundary tests (tracked as ROADMAP residual, not lens prereq).
- Sequencing reframed: P2 was always orthogonal to the effects lens
  itself; bulk migration proceeds at its own pace; lens not blocked.

Q4.5 footer updated:
- "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via
  #792; only consumer-side bulk migration remains)"
- Worker-discretion-vs-Director-call P2 line updated: "runner
  primitive landed; only consumer-side bulk migration remains;
  tracked as ROADMAP residual, independent of the lens."

Q6 STOP for P2 updated:
- "the lens itself doesn't depend on P2; only TESTING.md's 0-residual
  claim does" → "runner primitive landed via PR #792 (post-Q4.5-
  authoring update). The lens itself never depended on P2; bulk
  consumer migration is residual ROADMAP work and remains independent
  of this lane."

Brief now reflects live state. The closed-system claim's prereq
landscape is honest:
- P1 (extdeps typed-primitive consumption): real prereq, tracked
  debt at ROADMAP:153-154.
- P2 (ExecuteCommand runner): satisfied via #792; bulk migration is
  consumer-side residual, not foundation work.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale

Resolves codex non-blocking finding at sha bcac41bb on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real
residual: capacity-table line still listed P2 as "`ExecuteCommand`
materialization" prereq + framed both P1 and P2 as "pre-existing
tracked-debt" — but my prior 57a9b1318 fix established that PR #792
already landed the runner primitive, so P2 is no longer a
materialization prereq.

Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq)
from P2 (residual, not prereq):

  - P1: extdeps typed-primitive consumption — pre-existing tracked
    debt at ROADMAP:153-154; load-bearing for the lens's full-coverage
    claim.
  - P2: ExecuteCommand runner primitive landed via PR #792; only
    consumer-side bulk migration of existing Rust Command::new
    boundary tests remains (tracked as ROADMAP residual, independent
    of the lens; not a materialization prereq).

Brief now consistently treats P2 as bulk-migration-residual across:
- §Q4.5 P2 section header (LANDED via PR #792; residual is
  bulk-migration).
- §Q4.5 footer (P2: runner primitive landed; only consumer-side
  bulk migration remains).
- Q6 STOP for P2 (runner primitive landed; bulk migration is
  residual ROADMAP work).
- §Capacity / sequencing impact (P2 as residual, not prereq).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349

Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated
target-grounding prose; the matching extdeps typed-primitive bypass
entries (LLM service flattening, GitHub auth model bypass) live at
ROADMAP.md:348-349.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix third stale ROADMAP citation at line 271

Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence
at line 271 in the §Q4.5 capacity table. Now consistent with lines
139 and 173 (ROADMAP.md:348-349).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity

Codex flagged 'Effect-signature tagging on std/ primitives' as potentially
contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240)
already explicitly say 'NOT tag every primitive' — but the cross-manager
line used sloppy wording. Reworded to make explicit that the audit walks
signature shape; no parallel tag added.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5

- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)

B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).

B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — drop incoherent inner-fallback non-goal

Codex P2: the non-goal line excluding the inner declaration().name
unwrap_or_else fallback contradicted Slice step 2, which replaces the
whole chain with let-Some-else-return. Both fallbacks are in scope by
construction; remove the contradictory non-goal.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives

PM REQUEST_CHANGES: §Frame listed '4 type connectives
(Conjunction | Disjunction | Cardinality | Bit)' which contradicted
the canonical thesis source. Replaced with the canonical 6
(Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per
docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary
closes here'. Also removed 'typed substrate carriers' from the
vocabulary list — substrate carriers are defined using the vocabulary,
not part of it. Added a clarifying note that B4's carriers
(DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are
typed declarations composed from the vocabulary, not vocabulary
extensions.

Per feedback_verify_thesis_claims: brief framings citing thesis
structure must ground in the canonical source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority

Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of
naming the live substrate authority. Two coordinated fixes:

1. §Read first cites src/v3/std/substrate.dag (live .dag substrate
authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel
meta-type — already exists with consumers in verification.dag,
emit_model.dag, python.dag).

2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing
DeclarationRef'. The work is consumer migration + any role-extension
layer the audit reveals, NOT designing or landing the carrier.

Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers)
keep their 'new' framing but explicitly require sub-briefs to grep
src/v3/std/ + src/v3/spec/ for existing authority before authoring
'design and land' framing — per feedback_verify_thesis_claims +
feedback_emitter_workaround_is_gap_symptom.

Acceptance + sub-brief dispatch order updated to reflect B4.1's
consumer-migration shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — tighten Phase 1 umbrella sentence

The umbrella 'Land the typed carriers into src/v3/std/' framing was
stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced
with audit-first wording that covers both the consume-existing case (#1)
and the design-and-land case (#2-#4 if their audits show real gaps).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording

Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands'
which conflicted with the post-reframe reality that B4.1 consumes the
existing DeclarationRef. Updated to 'consumes or lands' with explicit
existing-authority citation and audit-pending caveat for B4.2-B4.4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — soften regression-test requirement (3 worker bounces)

Three consecutive B1 worker dispatches (zesty-crane-890 cursor →
valiant-boar-498 codex → cool-lynx-395 cursor) archived without
opening a PR. Likely friction point: brief Slice step 4 asks for a
unit test that constructs a Dag with an orphan variant declaration,
but emit.rs has zero existing #[test] precedent — emit testing
happens via integration fixtures. Workers see 'build novel test
harness' inside what's billed as an S-scope fix and bounce.

Per feedback_construction_over_ratchets: when a brief has friction,
fix the brief, don't ratchet the worker.

Softened step 4 + acceptance: regression test stays optional. If
test setup requires novel scaffolding, route the gap to follow-up.
The structural fail-closed at step 2 is the load-bearing change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt

PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description'
is too weak; PR descriptions don't survive squash-merge cleanly.

Two coordinated edits:
1. Slice step 4 — explicit substrate-signal framing: skipped test
   means emit-side hermetic-unit-test infrastructure is the missing
   substrate (feedback_emitter_workaround_is_gap_symptom).
2. Acceptance — require ROADMAP debt row (new or existing) with
   named dissolution trigger, referenced in PR body. Converts the
   skip from PR-local note (transient) into tracked debt (durable,
   dispatchable).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124

Codex BLOCKING: my earlier softening claimed emit.rs had no #[test]
precedent — wrong. The module has #[cfg(test)] mod tests at line 3124
with 12+ tests using compile_to_dag(source, filename) as harness
(e.g., go_struct_fields_render_with_separators :3143,
shared_walk_to_disj_finds_match_scrutinee_sum_type :3195).

This is a feedback_verify_thesis_claims violation on Director-side
brief authoring — claim made without grep verification.

Fix: restore step 4 as required, with explicit precedent citation.
Worker constructs the failure case via the existing harness
(direct Dag, fixture string, or BranchPattern exercise; worker's
call on cleanest path). STOP-AND-ESCALATE only if construction
proves materially harder than precedent suggests, in which case
that escalation surfaces a real substrate gap and warrants ROADMAP
debt — but the default is 'add the test.'

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites)

Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but
emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded
to 'several using compile_to_dag'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue

Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this
is Wave 1 of Director's 14-brief authoring queue, covering B4 program
internals.

Authored:
- b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) —
  replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag")
  fold-skip with structural template-formal carrier; mandatory
  authority audit per feedback_audit_adjacent_authority_first.
- b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) —
  replaces §0.6 emit.rs bind/branch.span.file equality with typed
  BindEmitParticipation/BranchEmitParticipation roles populated at
  lowering; aligned with #824 worker's in-flight implementation shape.
- b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4
  of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with
  typed substrate authority; explicit pre-promotion-constraint
  disposition (single-authority vs authority+tracked-debt) addresses
  parallel-representation risk surfaced on #825.
- b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) —
  names B4.5-B4.12 Phase 2 sites with carrier dependencies,
  cross-program coordination notes, and skeleton-brief template;
  full per-site briefs author at dispatch time per #827's
  Substrate Manager ownership.

Cross-cutting discipline applied per inbox #828 reply:
- feedback_audit_adjacent_authority_first (mandatory grep before design)
- feedback_no_textual_enforcement_bridges (no replacement sentinels)
- feedback_parallel_representation_debt (explicit if shape (b))
- feedback_construction_over_ratchets (no parity-by-runtime as primary)
- feedback_coproduct_dissolution (receipts for new variants)

Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling
worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3)

Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue.
Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by
Modeling Manager's Wave 3 worker briefs (gated on these landing).

Authored:
- r2-substrate-cardinality-for-int-lit-subset.md (M) — produces
  magnitude carrier consumed by T-Modeling int-lit. Coordinates with
  PR #806's prior cardinality work; mandatory authority audit guards
  against #796's rejected IntLiteralMagnitude shape resurfacing.
  Open design questions: magnitude representation, reconciliation
  narrowing point, i64::MIN representability.
- r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces
  nominal-opacity carrier consumed by T-Modeling Secret<T>. Open
  design questions: carrier shape (flag/connective/sealed-accessor),
  generic-walk discipline, accessor gating.
- r2-substrate-parametric-algebra-for-dimensions-subset.md (M) —
  produces phantom-parameter carrier consumed by T-Modeling
  Dimension<Carrier>. Open design questions: carrier shape,
  type-equivalence rule, algebra-method dispatch, lifting/coercion.

All three:
- Scoped narrowly to their paired R2 consumer; not full
  substrate-capability lanes.
- Mandatory pre-author authority audit per
  feedback_audit_adjacent_authority_first.
- Cross-program readiness signal pattern from #827's manager rework.
- Coproduct dissolution receipts required for any new variants.
- Open design questions surfaced explicitly so Substrate Manager
  (or Director pre-spin-up) can resolve at dispatch time.

Wave 3 (T-Modeling worker briefs × 4) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4)

Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue.
Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each
gated on a Substrate Manager readiness signal (Wave 2 producers).

Authored:
- r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2
  cardinality-for-int-lit; moves narrowing from tokenizer to
  reconciliation; MagnitudeOutOfRange diagnostic per C-8.
- r2-modeling-secret-graduation-worker.md — gated on Wave 2
  nominal-opaque-for-Secret; authors Secret<T> + gated accessors
  (redact, compare_in_constant_time); C-8 diagnostic on non-gated
  access; signals Impossible-Bugs Manager on close (thesis claim
  covered).
- r2-modeling-dimensions-phantom-worker.md — gated on Wave 2
  parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier>
  + core SI base units + algebra-method dispatch; cross-dimension
  arithmetic produces typed diagnostic; signals Impossible-Bugs
  Manager (thesis claim).
- r2-modeling-tokenizer-charclass-phase2-worker.md — gated on
  T-Substrate ValueBody-list/sum (#790); migrates tokenizer
  consumers to Char/List<Char>/CharClass canonical types; sibling
  consumer to Grounding Manager's Engine sharpened-(b).

All four:
- Explicit gating: 'do not dispatch until producer signal posts.'
- Producer/consumer signal pattern from #827.
- Cross-program signals to R2 Release Manager (Goal 2 closure)
  and Impossible-Bugs Manager (thesis-claim coverage).
- Spoofing regression tests: discipline anchor against
  feedback_no_textual_enforcement_bridges.

Wave 4 (T-ImpossibleBugs worker briefs × 3) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3)

Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue.
Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes,
consuming the existing design/scoping briefs as authority.

Authored:
- r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on
  cardinality refinement substrate (T-Substrate territory adjacent
  to int-lit / DB-11 alias-where). Implementation: structural normalize
  of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T??
  worker decision (reject vs normalize). Cites
  t-impossiblebugs-nested-optional-flatten-design.md as authority.
- r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated
  on Tier 2 substrate (predicate-entailment infrastructure; distinct
  from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes
  predicate entailment, (b) feedback_totality_by_omission dissolves
  partial primitives, (c) park. Worker decides at audit time. Cites
  t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority.
- r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate
  prerequisite per closed-system framing in design doc (#808). Audit-
  as-existence-check + lens implementation as compositional fold over
  5 behaviors; redundancy detection compile-error via referential
  transparency + reread() escape hatch; path (i/ii) decision on
  OperationEffect taxonomy retain-vs-retire (default retire). Cites
  design doc #808 as authority.

Cross-cutting:
- Each cites prior design/scoping brief as authority (the existing
  *-design.md / *-worker.md REFRAMED files).
- Explicit gating per #827 producer/consumer signal pattern; two
  briefs gated on substrate, one NOT gated (closed-system).
- STOP-AND-ESCALATE includes 'design brief assumptions don't hold'
  surfacing per feedback_thesis_gate_state_drift.

Wave 4 complete. Director's 14-brief queue done; awaiting PM portion
(6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4.4 — tighten Slice §3 per PM review on #836

PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b)
(authority + tracked debt parallel-rep) as autonomously acceptable
contradicts feedback_construction_over_ratchets +
feedback_parallel_representation_debt.

Tightened:
- Shape (a) is the only autonomous worker path.
- Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a
  regen-host-loader sub-lane decision; not authorable without explicit
  Substrate Manager approval citation in the PR body.
- Acceptance bullet requires the approval citation when shape (b)
  lands.
- STOP-AND-ESCALATE rephrased to make this explicit; permanent
  parallel-representation re-escalates even with manager approval.

This preserves shape (a) as autonomous; shape (b) becomes a
cross-manager design escalation, not a B4.4 implementation call.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief

Cursor review on #836 flagged the Read-first reference to
.claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md
as machine-specific (outside the repo, not resolvable from a normal
clone). Replaced with in-repo prose pointing at the design doc's
§Q1-Q3 as canonical authority — the discipline lives there in-repo.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs)

Codex flagged: src/v3/std/types.dag does not exist; the canonical
authority is at dsl/std/types.dag. Affected briefs (all from R2
spin-up Wave 2 + Wave 3):

- r2-substrate-cardinality-for-int-lit-subset.md
- r2-substrate-nominal-opaque-for-secret-subset.md
- r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs)
- r2-modeling-dimensions-phantom-worker.md
- r2-modeling-secret-graduation-worker.md

feedback_verify_thesis_claims violation on Director-side brief
authoring — assumed path without grep. Same family of error as
the earlier emit.rs precedent claim. Mass-replaced via perl;
verified no remaining stale refs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant

Codex BLOCKING on #836: my R2 worker brief gated nested-optional on
cardinality refinement substrate, but the design doc verifies v3 is
ALREADY past the cardinality bridge — TypeConnective::Cardinality
is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is
the carrier for Option. The dissolution is an UNGATED implementation
via substrate-constructor invariant.

feedback_verify_thesis_claims violation again — should have read the
design doc fully before assuming the substrate gate.

Rewrote brief to match design doc canonical sketch:
- Single predicate (cardinality_idempotent_target) owns the rule
- Single allocator (alloc_cardinality_decl) is THE substrate-constructor
- API closure on TypeConnective::Cardinality payload (modeling-discipline
  practice 6) — variant cannot be struct-init'd outside the allocator
- 3 hand-Rust + ~22 codegen call sites enumerated per design audit
- infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as
  the killer case for generic-instantiation paths
- Surface-syntax T?? decision left to worker (Director-lean: silent
  normalize)

Brief now dispatchable immediately, no producer signal needed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation

Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment
substrate path, but the design doc §4 explicitly recommends totality-by-
omission as the Director-actionable path. Predicate-entailment is M+ scope
that reopens DB-11's explicitly-closed asymmetric-strip design — design
doc explicitly discards it.

feedback_verify_thesis_claims violation again — same family as nested-
optional reframe. Should have read design doc §4 in full before assuming
the path ordering.

Rewrote brief to match design doc §4 follow-on shape:
- Primary path: per-class totality-by-omission (algebra retype + per-
  target realization migration). For Int/Int: OrderedRing.div retype
  at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 /
  python:486 + python_target.rs:680 helper).
- NOT predicate-entailment (out of scope; M+ + DB-11 reopen).
- NOT NonZero-typed-input (deferred to separate per-operand-variance
  substrate brief; STOP-AND-ESCALATE if chosen).
- Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i]
  indexing, quotient, remainder) queue separately per design doc audit.
- feedback_totality_by_omission discipline anchor explicit.

Brief now matches feedback_totality_by_omission discipline + design doc
recommendation. No substrate prerequisite; dispatchable immediately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure

Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a
pattern: I authored R2 worker briefs without fully reading each design
doc's Director-actionable recommendation. Pre-emptively re-verified
unenumerated-effects against design doc §Q6 to catch the same family
of error before reviewers do.

Findings: brief was substantively close but missing 3 of 8 design-doc
reqs:
- Req 3: Resource-threading discipline applied to existing primitives
- Req 5: reread(key) primitive in std/ as explicit Slice item (was
  only mentioned in tests)
- Req 7: Asymmetric-tightening worked example in PR body

Plus: Slice didn't cite the canonical lens path
src/v3/lenses/effect_enumeration.dag from design doc.

Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6
specifies 4 specific STOPs (path-decision-escalation, pure: Bool
carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP)
that I had elided.

Reframed Slice as 8 numbered reqs matching design doc verbatim;
STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs;
Acceptance enumerated per req.

This is the third reframe in the unhandled-bugs series — same
feedback_verify_thesis_claims violation each time. The pattern
suggests Director-side R2 brief authoring should ALWAYS read each
design doc's §Director-actionable / §Q-recommendation in full first,
not assume.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options

Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)"
listed as a worker-pick option violates THESIS.md substrate-shape
lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality |
Instantiation) are canonical (per #811 thesis additions and #827 PM
review); a 7th is a C1 stop signal requiring failed-dissolution
evidence + Director substrate-design call, not autonomous worker pick.

Removed the "new TypeConnective variant" option; replaced with
`inhabits`-edge-shape carrier as third option (audit-time check). The
explicit STOP-AND-ESCALATE clause now states: 7th connective is the
precondition for failed-dissolution-evidence + Director substrate-design
call, not a worker path.

feedback_verify_thesis_claims still in play — should have grounded
substrate-shape options against the THESIS lock before listing Opaque(T)
as worker-autonomous. Pattern continues; reading source-of-truth before
authoring options is the discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place)

Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter
already exist at dag.rs:186, :217 — explicitly authored for the
R2 Dimensions consumer per the doc comment at dag.rs:148-160.
phantom_unit_mismatch already wired at infer.rs:1057, :1132. The
substrate is fully landed; my brief framing it as 'producer sub-lane
to land carrier' is wrong on the same feedback_audit_adjacent_authority_first
violation that hit nested-optional / unhandled-diagnostic / unenumerated-
effects.

Reframed the substrate-side brief as no-op / closed-by-audit:
- Documents the audit receipt (5 sites confirming substrate exists)
- States the lane is closed
- Routes T-Modeling Dimensions consumer to dispatch immediately
  against the existing carrier
- Records the lesson: 'always grep substrate before authoring
  producer briefs' — discipline doesn't end at brief boundaries.

Updated r2-modeling-dimensions-phantom-worker.md correspondingly:
- Changed gating from 'do not dispatch until producer signal' to
  'NOT GATED — dispatch immediately'
- Read-first updated with concrete dag.rs/infer.rs cites
- Slice §1 changed from 'confirm producer signal' to 'verify
  substrate at HEAD'
- STOP reframed: existing carrier extension would need Substrate
  Manager call, not autonomous worker pick

Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit
both verified — no existing substrate (no is_nominal_opaque /
MagnitudeBound patterns in dag.rs); both still legitimately
producer-side work.

Pattern is now four reframes deep on the R2 spin-up wave. The lesson
saved is structural: read source-of-truth before authoring options.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority

Codex BLOCKING on #836: my new R2 spin-up brief duplicates the
existing t-substrate-cardinality-int-lit-worker.md, which carries
the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64)
stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane).
Single-authority violation per INVARIANTS P2.

Same feedback_audit_adjacent_authority_first failure as parametric-
algebra-for-Dimensions reframe (4 hours ago): assumed substrate
authority didn't exist; should have grepped docs/briefs/ before
authoring. This is the SECOND R2 spin-up substrate brief closed
as redundant — the discipline lesson is structural.

Reframed brief as no-op routing doc (documents the audit receipt;
routes consumers to the existing authority); updated
r2-modeling-int-lit-magnitude-worker.md to cite
t-substrate-cardinality-int-lit-worker.md instead.

Pattern across the R2 spin-up wave reframes (5 now):
1. nested-optional gating-on-substrate (substrate already past
   cardinality bridge)
2. unhandled-diagnostic predicate-entailment default (design doc
   recommends totality-by-omission)
3. unenumerated-effects 8-req design-doc elision
4. parametric-algebra Producer (Declaration.phantom_params already
   authored explicitly for this consumer)
5. cardinality-for-int-lit Producer (existing brief is authority)

All five are 'assumed state without grep before authoring'. Future
R2 subs…
briansrls added a commit that referenced this pull request Apr 29, 2026
…+ reflection completeness + Q6.5 two-layer diagnostic-kind) (#1129)

* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation)

Director-authored amendment following the 2026-04-24 escalation from PR
#693 (sub-child sharp-bear-829 under Surface Manager).

Two edits:

1. New "Class 5 Gap 3 — port-carried field values in data bodies"
   row in the 2026-04-21 post-merge-debt section. The substrate gap was
   documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP
   ledger row for cross-lane visibility. PR #693's execution surfaced it
   as the blocker on sub_charclass_in_std_unicode phase-2.

2. Retract the "ready-to-dispatch (no substrate capability gap)" claim
   on the Character-level row, annotate phase-1 landed via PR #693
   (CharClass vocabulary + Rust-mirror structural scanner path), and
   point phase-2 at the new Class 5 Gap 3 row.

Codifies the audit pattern: "this consumption gap has no substrate
capability gap" claims must be verified by attempting the retype before
the claim lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main

* docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review)

* docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review)

Row title still said 'consumption gap, not substrate gap' while the
body block retracted that claim and cited Class 5 Gap 3 as a substrate
dependency for phase-2. Title now matches body: mixed classification,
consumption for steps 1+3, substrate for step 2.

* docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit)

gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining
gap" description was wrong: field-level shapes (nested records, list
literals, declaration refs, Var refs, sum-variant literals) are
supported today via FieldValue variants + lower_structural_field_value
(dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the
top-level ValueBody boundary (non-scalar, non-record top-level bodies).

The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself
stale: it describes the pre-PR-B-unwind shape where FieldValue was
LiteralBits-only. PR-B's unwind extended FieldValue to carry
Reference / Record / List / Variant, moving the gap to ValueBody.

Two fixes:

1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody
   boundary, point at code paths (dag.rs, lower.rs) as live authority,
   flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass
   blocker classification to "provisional pending reproduction."

2. Update the Character-level row's phase-2 block to name that the
   specific shape of the CharClass failure needs concrete reproduction
   from the escalating sub-child before the blocker is finalized.

Recursive audit-pattern instance: the row I wrote to codify "verify
live state before claiming substrate gap" itself failed to verify live
state. Both incidents (2026-04-23 original row + 2026-04-24 my
retraction row) are now cited in the audit-pattern sub-note as
examples of the same discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33

Three substantive fixes addressing internal-consistency gaps in the cascade
promotion PR caught by codex review at sha 0d6e7c33:

1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane
   acceptance bullets and Hand-Rust census paragraph in line with the
   updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero
   (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is
   retracted under 0-floor with explicit migration to ExecuteCommand-based
   .dag TestClaim declarations.

2. docs/design-pure-bootstrap-zero.md promotion section — converted from
   future-tense ("This doc is PROPOSAL until promoted… promotion is a
   single Director-authored cascade PR…") to historical past-tense
   promotion-receipt framing ("This doc was PROPOSAL until promoted;
   promotion was a single Director-authored cascade PR that did all of the
   following atomically…"); blocking-clause struck through and resolved
   inline. Banner cites PR #782 explicitly.

3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_
   profile excluded (Map<String, AlgebraProfile> body, not list-of-sum;
   needs distinct ValueBody::Map substrate work, tracked separately as a
   future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass
   phase-2 + Engine sharpened-(b) pilot enumeration), both sharing
   list-of-sum substrate work. Lane table, dependency DAG, and capacity
   summary updated for consistency (slot count 9-13, was 10-14).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities

Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade
self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22
explicitly names THESIS.md and "any other authority docs" as required
retraction targets; the prior diff updated ROADMAP + r2-structure + design
docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting-
manager.md pointing at the now-SUPERSEDED ≤5-floor framing.

Files:

- THESIS.md (5 prose blocks updated):
  - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests
    migrate to ExecuteCommand-based .dag TestClaim declarations.
  - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag.
  - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor
    target citing design-pure-bootstrap-zero.md as live authority;
    hand_maintained_src list shrinks to empty set.
  - :301-318 — Tests-are-structural-data block: residual carve-out retracted;
    predicate name pb_rust_tests_outside_residual_zero retained as
    housekeeping (semantically the residual is empty under cascade).

- docs/thesis/compiler-std-consolidation.md (5 references):
  - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes
    design-pure-bootstrap.md (SUPERSEDED).
  - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process
    lane named as the dissolution trigger for bootstrap.rs itself.
  - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md.
  - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority
    re-cited.
  - :185 Related docs link.

- docs/briefs/r1-selfhosting-manager.md (active dispatch brief):
  - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5);
    T-PB-B residual carve-out retracted; predicate names retained for
    housekeeping; cascade-promoted authorities are source of truth.
  - Slice descriptions for T-PB-A / T-PB-B updated inline.
  - Framing-question + ask updated to 0-floor / no-residual framing.
  - Day-1 + up-to-director hand-off bullets updated.
  - Working-state checklist :111 ≤5 → 0 with cite.
  - Decisions log :164 ≤5 → 0-floor target updated.

- docs/r2-structure.md §2 design call (RETRACTED block):
  - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through
    in entirety (both Option A sharpen-and-keep and Option B rename are
    moot under 0-floor). Section preserved as audit-trail historical
    context.
  - Background-doc index: self-hosting anchor updated to
    design-pure-bootstrap-zero.md as live authority.

- docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per
  non-blocking suggestion):
  - Banner cites cascade promotion PR #782 explicitly.
  - New paragraph: "Treat all numeric floors below as retracted" with
    explicit lines named that quote in isolation (table row, body prose
    references). Prevents re-quoting from this doc as live authority.

Cascade is now atomically consistent across:
  THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔
  docs/thesis/compiler-std-consolidation.md ↔
  docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔
  docs/design-pure-bootstrap-zero.md (LIVE) ↔
  docs/design-pure-bootstrap.md (SUPERSEDED).

The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds
genuinely.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): correct ExecuteCommand runner-capability claim

Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation):
TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138
overstated live runner capability — claimed runner support landed in
PR #688/#741 with "emit Rust, invoke rustc on output, check exit code"
as a structurally-equivalent migration path. Verified against live
sources:

- src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema
  exists (declared via PR #678).
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5
  testgen harness allowlists ONLY `command == "true" && args.is_empty()
  && expect_exit == 0`.
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 —
  panics fail-closed on any other shape with explicit "ExecuteCommand
  shell shape is not supported here (runner-owned — do not treat as
  ordinary false)".
- src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no
  match arm for ExecuteCommand; falls through to ClaimResult::
  NotYetImplemented.

Reality: a TestClaim declaring rustc/python/go invocation is
structurally expressible as data today, but executing it is blocked.
Full arbitrary-command runner support is the PB-Runtime lane's
deliverable.

Files updated:

- TESTING.md:195 — capability state callout with file:line citations;
  "Full runner support — arbitrary command + args (rustc/python/go) with
  exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor
  program)." Bullet about migration shape preserved as the cascade-named
  successor pattern, not as a live capability.
- TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane
  lands the ExecuteCommand runner extension" as an explicit precondition.
- docs/design-pure-bootstrap-zero.md:138 — same correction for the
  matching prose, with PB-Runtime named as the runner-extension
  dependency for boundary-test migration.
- ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner
  foundation in #688/#741 with `true`-no-args allowlist only — full
  arbitrary-command runner support deferred to PB-Runtime lane,
  blocking the actual boundary-test migration." Dependencies column
  extended to "DB-15 + T-TestGen + PB-Runtime".

The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still
holds for atomic-cascade-across-authority-docs; this commit closes the
remaining capability/claim mismatch flagged by codex.

(Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still
SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief

Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation).
The prior banner contained:

> "Operationally R1 closure may still ship before the 0-floor is reached
>  — the ratchet ensures the trajectory; the gate's acceptance number is
>  what shifts."

This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0.
Two competing gate semantics in the cascade is exactly what the
atomic-cascade clause forbids.

Replaced with single-authority-honest framing:

> "R1 closure now requires the 0-floor target by gate semantics: T-PB-A
>  and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade
>  promotion changed their acceptance numbers to 0; R1 cannot close
>  while the SG-0 census carries non-zero hand-Rust."

Plus minor sharpening:
- "T-PB-A's non-test target is 0" → "non-test acceptance target is 0
  per ROADMAP.md:67" (cite the authority).
- T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep
  the capability-state honesty consistent with the recent fix wave.
- Predicate-rename housekeeping line moved into banner ("post-cascade
  housekeeping, not a pre-promotion blocker") — was implicit before.

The brief now genuinely inherits the cascade-promoted gate; no
competing release authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 second-wave worker-escalation fixes

Four substantive worker STOP-AND-ESCALATEs from briefs landed in
PR #797. All four worker recommendations correct; each needs a
Director call + brief update.

## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate

Worker correctly identified that brief req 2 (declared-effect carrier
as part of fn type signature, per feedback_no_annotations) requires
net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at
src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots.
Without parser surface, every user function would have
declared_effects = [] while inference returns non-empty — lens fires
EffectLeakageError everywhere on enable. Worker rejected power-through
and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map
parser split).

Director picked split:
- NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md
  Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface
  syntax + lookahead + body parser + lowerer extension + exhaustive-match
  audit + coproduct dissolution receipt.
- MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to
  post-parser-extension scope. Pre-flight check NOT a parser-extension
  step; STOP if parser sub-lane PR not merged.

## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping

Worker found load-bearing evidence at infer.rs:3693-3703: DB-11
deliberately strips refinements at operator dispatch as a designed-in
fix for symmetric-operators failure mode. Brief's "attach where b != 0
as a proof for a / b" directly contradicts this design choice. STOP-3
(where-clause conflict with DB-11) is real; STOP-1 (substrate scope)
needs net-new substrate (per-operator partiality fact + predicate-
entailment check + asymmetric per-operand refinement-honoring) — M+
minimum. ownership_lens precedent in original brief is post-hoc
observability, not proof carrier.

Worker recommended redirect to design/scoping per nested-optional
precedent. Director picked redirect.

Brief fully rewritten as design/scoping with four-question structure:
(1) DB-11 interaction analysis; (2) substrate proposal for proof-or-
totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes
with acceptance-theatre risk on user-defined-total-wrapper-only);
(4) Director-actionable recommendation. Output is doc PR.

## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C)

Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int)
with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136
closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b)
i128 implementation requires either path 1 (hierarchy refactor —
contradicts non-goal) or path 2 (regen lie between substrate and
emit — violates discipline). Worker leaned option (C) re-scope:
land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke)
to a sibling sub-lane that does proper Int128/Word128 substrate work.

Director picked option (C). Brief req 1 re-scoped to drop canonical-
carrier-widening; lane value comes from range facts + reconciliation
narrowing + out-of-range diagnostic against existing i64. Req 4
explicitly deferred with sibling-sub-lane reference. Sibling sub-lane
NOT to be authored or implied in this PR; tracked separately.

## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change)

Worker correctly STOP'd per the brief's own pre-flight check: parser
sub-lane has not landed; SurfaceExpr::Map not on main. Director
authorized cross-lane reassignment: wise-boar-480 takes the parser
sub-lane (t-substrate-valuebody-map-parser-worker.md) since they
already have full investigation context. No brief changes needed; the
routing decision is in the dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope

Resolves codex P2 inline at sha e35103fad on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer
carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still
required widening LiteralBits::Int(i64) to an unbounded carrier and
passing the i64::MIN smoke. Internally unsatisfiable.

Fix:

- Slice section retitled "range facts + reconciliation narrowing
  (against existing i64 carrier)" with explicit note about the
  re-scope.
- Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly
  forbids touching LiteralBits::Int shape, dag_scalar_generated.rs
  regen for that variant, or tokenize i64 parse path.
- Slice steps 2-5 reframed: range facts use i64-representable
  magnitudes; reconciliation narrowing uses existing i64 carrier;
  diagnostic only for i64-representable out-of-range; smoke tests
  for req 5 only (req 4 i64::MIN deferred).
- Acceptance checklist updated:
  - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as
    re-scoped/deferred.
  - LiteralBits::Int(i64) carrier untouched (no widening; no
    parallel; no shape change).
  - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference.
- STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the
  carrier" — explicit STOP if execution surfaces range-fact narrowing
  requiring carrier-widening; that's the boundary the re-scope drew;
  belongs in sibling Int128/Word128 sub-lane.

Brief now consistently treats carrier-widening as out-of-scope across
all sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty

Resolves codex BLOCKING #1 at sha e35103fa on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier
but req 2 required range facts using "the SAME magnitude carrier
as req 1" — meaning i64-typed range bounds. u64's max (2^64-1)
doesn't fit in i64; range fact for u64 would have to truncate,
omit, or mirror in Rust (representation drift). All three options
violate fail-closed declared-facts discipline (P1 / P3).

Fix:

- Req 2 rewritten to specify String-decimal representation:
  range_min_inclusive: String + range_max_inclusive: String fields
  on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127"
  for i8; "0"/"18446744073709551615" for u64).
- Explicit reasoning why String-decimal: u64's max doesn't fit in
  i64; binding range bounds to literal carrier forces truncation/
  omission/mirror-drift; all violate fail-closed declared-facts
  discipline.
- Bridge framing: String-decimal is pending the sibling Int128/
  Word128 sub-lane; both range bounds and literal payload migrate
  to typed carrier when that lands.

- Req 3 updated for String-decimal comparison semantics:
  reconciliation parses both bounds and literal magnitude into a
  common comparison space (i128 host comparison primitive — host
  narrowing, NOT carrier widening). Bounded by what the i64-typed
  literal can express; any i64-representable literal compares
  against any width's String-decimal bound. Carrier discipline
  preserved.

Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral)
is sha-stale — already resolved at 3e142d169.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed

Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback).
Real residual: req 2 specifies String-decimal range bounds (to cover
u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance
bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" /
"i64-representable magnitudes" for the range facts. Two incompatible
authorities for the same range-fact shape — would let a worker satisfy
the slice while truncating/omitting u64 bounds (P3 fail-closed
violation).

Fix:

- Line 31 (req 1 re-scope clarification): updated to explicitly state
  "range facts (req 2) use String-decimal representation (width-
  independent; covers u64::MAX which doesn't fit in i64)". Distinguished
  literal *payload* (stays i64) from range-bound *representation*
  (String) — both serve req 1's "no carrier widening" boundary.
- Line 44 (slice step 2): updated from "Range bounds use i64-
  representable magnitudes" to "Range bounds use String-decimal
  representation per req 2" with concrete example (u64 bounds).
- Acceptance bullet: updated from "Range facts on integer algebras
  (substrate-declared, not Rust-mirrored)" to add "using String-decimal
  representation ... width-independent; u64 bounds expressible without
  truncation."

The brief now consistently treats range bounds as String-decimal
across req 2, req 3, slice, acceptance, and the req 1 clarification —
no remaining authorities saying i64-typed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing

User + PM exchange 2026-04-25 surfaced that the in-flight effects
chain was importing wrong assumptions from external languages
(declared-effects-as-annotation + lens-vs-declaration check). Right
framing under gunbc's closed-system discipline is parallel to
complexity: every effect derives structurally from the composition
of typed primitive operations; nothing can hide because there's no
escape hatch; nothing needs annotation because the structure IS the
registry.

Four doc-only actions:

1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md.
   Frames the closed-system answer with PM's 5-behavior synergy
   table (Value/Transform/Branch/Loop/Bind as universal
   compositional-fold pattern). Four worked examples; aggressive
   reading on redundancy (compile-error-by-construction via
   referential-transparency proof; reread() primitive for legitimate
   cases); implementation-brief shape in §Q6.

2. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md.

3. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md.
   Notes Fn→Arrow refactor brief stays dispatchable as independent
   value.

4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by-
   construction framing replaces lens-detection framing.

Memory file feedback_closed_system_effects.md saved separately;
cross-link added to feedback_construction_over_ratchets.md.

Net cost: doc-level cleanup. Zero substrate code rework. Foundation
(OperationEffect + service-call infrastructure + 5-behavior
substrate) already exists.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect

Per PM convergence review on #808 + user's deeper 2026-04-25 framing:
the closed-system framing landed in #808 retired the user-facing
annotation but kept OperationEffect taxonomy as substrate-level tagging.
User's deeper framing: the taxonomy ITSELF is parallel-representation —
operations are intrinsically read-shaped or write-shaped via their
TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns-
derived-value-only → read). Tagging operations with Read | Upsert |
Create | Append | Delete names what the structure already says.

Three changes:

1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as
   normalized view, or retire as parallel-representation?"
   - Two paths: (i) tags derived from signature shape (acceptable
     normalized view) vs (ii) tags declared per-primitive (parallel-
     representation; retire).
   - Audit-as-existence-check (Q4 req 2 reframed): all effectful
     primitives derive cleanly from signature shape → path (i); any
     primitive needs hand-declared tag → path (ii) by existence proof.
   - Director default: path (ii). Logging primitives that return Unit
     are likely the audit's existence-proof.
   - Two design-question resolutions: (a) external effects not in
     return type → resource-threading discipline (typed param returned
     modified, IO-monad-without-the-monad pattern); (b) transactional
     grouping → derived structural fact from Bind composition + typed
     transaction primitives.

2. Q4 reqs revised: req 2 from "tag every primitive with explicit
   OperationEffect signature" to "audit-as-existence-check that every
   primitive's type signature derives the right effect classification";
   req 3 added (resource-threading discipline); req 6 added
   (transactional-pattern lens). Req 1 (effects lens) anchors on
   operation type-signature shape, not on hand-declared tags.

3. THESIS:345-347 amendment strengthened — "operations are
   intrinsically read-shaped or write-shaped via their type-signature
   shape; consumers walk the signatures directly; there is no parallel
   taxonomy or annotation layer to declare or maintain. Tracking
   effects as a separate enumerated concept IS the bug pattern,
   dissolved by construction." Plus references to resource-threading
   discipline + transactional grouping as derived structural fact.

Memory file feedback_closed_system_effects.md updated to reflect the
deeper framing (type-signature-shape, not taxonomy-tagging) +
resource-threading discipline section + transactional-patterns
section.

Net cost: doc-only delta on top of #808. Substrate retirement
(OperationEffect enum + derive_op_effect + idempotency.dag re-anchor)
deferred to the audit-as-existence-check phase of the implementation
brief; surfaced as Q5.5 OPEN CALL.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage

Resolves codex BLOCKING at sha d49ce79a on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real:
the prior text claimed service primitives "already carry typed effect
signatures" presenting future audit-state as current substrate fact
(P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the
OperationEffect line but left a parallel over-claim on the new
"signature-shape coverage" framing.

Fix: Q4 substrate-state listing rewritten to honestly distinguish:

- Live: Behavior enum + substrate foundation (the principle that
  operations should carry signature shape).
- Incomplete: signature-shape coverage across actual primitives.
  HTTP-derived primitives carry implicit shape via derive_op_effect's
  method-table; logging/mutation primitives that return Unit or don't
  thread their target resource do NOT carry the structural shape that
  would express read-vs-write. Achieving full coverage is required
  work under reqs 2 + 3, not a current fact.
- Pending audit-as-existence-check: OperationEffect + derive_op_effect
  (path (i) vs (ii) per Q5.5).

Honest live-state callout added explicitly: "the closed-system
FOUNDATION (5 behaviors + DAG substrate + the principle that
operations should carry signature-shape) is live. The IMPLEMENTATION
COVERAGE across all effectful primitives is partial. Req 2 + req 3
are the work that closes the gap."

Brief now distinguishes principle-is-live (foundation) from
coverage-is-partial (audit work) without conflating them.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim

Per PM follow-up review on #808 + user's stronger discipline framing
("substrate must make bypass structurally impossible at every layer
of the transport stack"): the closed-system claim is honest only when
typed primitives ARE the path. Today two structural holes exist where
bypasses sidestep the typed-primitive substrate. Both surfaced
explicitly as Q4.5 pre-conditions — load-bearing for the lens's
coverage claim.

Three changes:

1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed-
   system claim)" inserted between Q4 and Q5:

   P1 — Extdeps typed-primitive consumption structurally enforced.
   Substrate must make `messages: Json` impossible to declare in
   service definitions; typed `LlmMessage` / `ContentBlock` /
   `GitHubAuthToken`-with-full-scopes are the only path. Tracked
   debt at ROADMAP.md:153-154 (LLM provider flattening) +
   `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded).
   Required prereq for full lens coverage; lens can land first +
   surface structural-coverage-gap diagnostics on bypass surfaces
   so the gap becomes visible rather than silent.

   P2 — `ExecuteCommand` fully materialized as typed runner
   primitive. TESTING.md (post-#782) committed to 0-residual but
   ExecuteCommand isn't fully materialized; deleting Rust boundary
   tests creates verification gap. Already named under PB-Runtime
   in Zero-Floor; signal pending. Pre-requisite for ANY Rust
   boundary-test deletion.

2. Old leftover duplicate Q5 section deleted (artifact from prior
   Q5/Q5.5 reshape; second copy of asymmetric-tightening text was
   in the file alongside the earlier Q5 instance).

3. Worker-discretion-vs-Director-call section in Q4.5: lens
   implementation worker dispatchable now (reports gaps as
   findings); P1 closure is substantive substrate work touching
   extdeps (dedicated lane); P2 closure is PB-Runtime (signal
   pending).

Net: design doc now honestly distinguishes principle-is-live
(Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs
named explicitly). The closed-system claim has explicit pre-
conditions documented; implementation brief discovers them as
known dependencies, not as STOP-AND-ESCALATEs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default

Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two
real residuals after the Q5.5 reframe:

1. Q6's reqs/STOPs/acceptance still framed under path (i) — said
   "audit + tag std/ primitives — every effectful primitive carries
   an explicit OperationEffect signature." Directly contradicted Q4
   (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment
   ("there is no parallel taxonomy to declare or maintain"). Worker
   reading Q6 in isolation would author the retracted shape.

2. Capacity / sequencing table line about "audit lane (tag std/
   primitives with effect signatures)" carried the same stale
   framing.

3. Q6 STOP "primitive performing side effects without an
   OperationEffect tag" assumed tag-as-authority; under path (ii)
   the STOP shape is "primitive whose signature doesn't structurally
   reveal its effect."

Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale
(already fixed at f073aa95e Q4.5 commit).

## Q6 fixes

- Reqs renumbered + reframed:
  - Req 1 anchors on operation type-signature shape (not hand-declared
    OperationEffect tags); composition reads from signature shape per
    Q2 table.
  - Req 2 changed from "audit + tag every primitive" to
    "audit-as-existence-check" — verify signature-shape coverage; ANY
    primitive needing a hand-declared tag IS the existence-proof for
    path (ii) retirement.
  - Req 3 added: resource-threading discipline applied to existing
    primitives (logging that returns Unit gets reshaped per audit).
  - Req 6 added: transactional-pattern lens (Bind composition +
    Transaction → Transaction').
  - Req 7 added: asymmetric-tightening worked example in PR body
    (per claude review observation; the one place declaration-shaped
    surface re-enters).
  - Req 8 (was 5): tests now reference signature-shape derivation
    explicitly, not tag lookup.
- STOPs reframed:
  - "OperationEffect retirement decision" — audit produces path (i)
    vs (ii) verdict; substrate retirement is its own dedicated
    sub-lane; this lane does NOT absorb it.
  - Pure/impure carrier STOP notes that "pure" should also derive
    from signature shape (pure functions don't return modified
    resources) — so the STOP itself may dissolve under further design.
  - Q4.5 P1 explicitly NOT a STOP — lens reporting structural-
    coverage-gap on extdeps bypass surfaces is the lens delivering
    its foundation-gap-visibility value.
  - Q4.5 P2 explicitly independent — lens doesn't depend on
    ExecuteCommand materialization.
- Acceptance extended: lens reports gap diagnostics on P1 bypass
  surfaces; audit produces existence-proof verdict for Director
  re-decision; asymmetric-tightening worked example in PR body.

## Capacity / sequencing table

Replaced "1 audit lane (tag std/ primitives with effect signatures)"
with "1 audit-as-existence-check lane (verify primitives' signature-
shape coverage; NOT 'tag every primitive') — produces the path (i)
vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2
prereq lanes to the net summary. Closing line: "The taxonomy-
retirement scope (substrate-side) is not in this lane — it's
surfaced by audit and routed to dedicated retirement lane if path
(ii) wins."

Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity
table. Worker reading Q6 in isolation now sees path-(ii)-default
framing matching Q4 + Q5.5 + THESIS amendment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792

Resolves codex inline BLOCKING at sha 191be310 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150.
Real: my Q4.5 P2 framing described ExecuteCommand as still
NotYetImplemented (M1.5 allowlist + Rust TestRunner returning
NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand
extension before this PR's authoring. TESTING.md:195 capability-state
callout confirms:
- Rust TestRunner + M1.5 testgen harness share one std::process path
  for arbitrary command + args + expect_exit_code.
- M1.5 allowlist + fail-closed panic retired.
- Distinguishable ClaimResult::Fail messages for spawn / timeout /
  policy / exit-mismatch.
- Linux unshare(1) namespace isolation on host-allowing systems.
- T-PB-B-1 boundary migration example landed.

Fix:

P2 section rewritten:
- Header retitled "ExecuteCommand runner primitive: LANDED (PR #792);
  residual is bulk-migration."
- Status update naming PR #792 + the post-#792 capability state
  (allowlist retired, etc.).
- Honest acknowledgement: "My earlier P2 framing was stale."
- Residual narrowed to bulk-migration of existing Rust Command::new
  boundary tests (tracked as ROADMAP residual, not lens prereq).
- Sequencing reframed: P2 was always orthogonal to the effects lens
  itself; bulk migration proceeds at its own pace; lens not blocked.

Q4.5 footer updated:
- "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via
  #792; only consumer-side bulk migration remains)"
- Worker-discretion-vs-Director-call P2 line updated: "runner
  primitive landed; only consumer-side bulk migration remains;
  tracked as ROADMAP residual, independent of the lens."

Q6 STOP for P2 updated:
- "the lens itself doesn't depend on P2; only TESTING.md's 0-residual
  claim does" → "runner primitive landed via PR #792 (post-Q4.5-
  authoring update). The lens itself never depended on P2; bulk
  consumer migration is residual ROADMAP work and remains independent
  of this lane."

Brief now reflects live state. The closed-system claim's prereq
landscape is honest:
- P1 (extdeps typed-primitive consumption): real prereq, tracked
  debt at ROADMAP:153-154.
- P2 (ExecuteCommand runner): satisfied via #792; bulk migration is
  consumer-side residual, not foundation work.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale

Resolves codex non-blocking finding at sha bcac41bb on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real
residual: capacity-table line still listed P2 as "`ExecuteCommand`
materialization" prereq + framed both P1 and P2 as "pre-existing
tracked-debt" — but my prior 57a9b1318 fix established that PR #792
already landed the runner primitive, so P2 is no longer a
materialization prereq.

Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq)
from P2 (residual, not prereq):

  - P1: extdeps typed-primitive consumption — pre-existing tracked
    debt at ROADMAP:153-154; load-bearing for the lens's full-coverage
    claim.
  - P2: ExecuteCommand runner primitive landed via PR #792; only
    consumer-side bulk migration of existing Rust Command::new
    boundary tests remains (tracked as ROADMAP residual, independent
    of the lens; not a materialization prereq).

Brief now consistently treats P2 as bulk-migration-residual across:
- §Q4.5 P2 section header (LANDED via PR #792; residual is
  bulk-migration).
- §Q4.5 footer (P2: runner primitive landed; only consumer-side
  bulk migration remains).
- Q6 STOP for P2 (runner primitive landed; bulk migration is
  residual ROADMAP work).
- §Capacity / sequencing impact (P2 as residual, not prereq).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349

Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated
target-grounding prose; the matching extdeps typed-primitive bypass
entries (LLM service flattening, GitHub auth model bypass) live at
ROADMAP.md:348-349.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix third stale ROADMAP citation at line 271

Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence
at line 271 in the §Q4.5 capacity table. Now consistent with lines
139 and 173 (ROADMAP.md:348-349).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity

Codex flagged 'Effect-signature tagging on std/ primitives' as potentially
contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240)
already explicitly say 'NOT tag every primitive' — but the cross-manager
line used sloppy wording. Reworded to make explicit that the audit walks
signature shape; no parallel tag added.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5

- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)

B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).

B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — drop incoherent inner-fallback non-goal

Codex P2: the non-goal line excluding the inner declaration().name
unwrap_or_else fallback contradicted Slice step 2, which replaces the
whole chain with let-Some-else-return. Both fallbacks are in scope by
construction; remove the contradictory non-goal.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives

PM REQUEST_CHANGES: §Frame listed '4 type connectives
(Conjunction | Disjunction | Cardinality | Bit)' which contradicted
the canonical thesis source. Replaced with the canonical 6
(Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per
docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary
closes here'. Also removed 'typed substrate carriers' from the
vocabulary list — substrate carriers are defined using the vocabulary,
not part of it. Added a clarifying note that B4's carriers
(DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are
typed declarations composed from the vocabulary, not vocabulary
extensions.

Per feedback_verify_thesis_claims: brief framings citing thesis
structure must ground in the canonical source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority

Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of
naming the live substrate authority. Two coordinated fixes:

1. §Read first cites src/v3/std/substrate.dag (live .dag substrate
authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel
meta-type — already exists with consumers in verification.dag,
emit_model.dag, python.dag).

2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing
DeclarationRef'. The work is consumer migration + any role-extension
layer the audit reveals, NOT designing or landing the carrier.

Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers)
keep their 'new' framing but explicitly require sub-briefs to grep
src/v3/std/ + src/v3/spec/ for existing authority before authoring
'design and land' framing — per feedback_verify_thesis_claims +
feedback_emitter_workaround_is_gap_symptom.

Acceptance + sub-brief dispatch order updated to reflect B4.1's
consumer-migration shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — tighten Phase 1 umbrella sentence

The umbrella 'Land the typed carriers into src/v3/std/' framing was
stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced
with audit-first wording that covers both the consume-existing case (#1)
and the design-and-land case (#2-#4 if their audits show real gaps).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording

Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands'
which conflicted with the post-reframe reality that B4.1 consumes the
existing DeclarationRef. Updated to 'consumes or lands' with explicit
existing-authority citation and audit-pending caveat for B4.2-B4.4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — soften regression-test requirement (3 worker bounces)

Three consecutive B1 worker dispatches (zesty-crane-890 cursor →
valiant-boar-498 codex → cool-lynx-395 cursor) archived without
opening a PR. Likely friction point: brief Slice step 4 asks for a
unit test that constructs a Dag with an orphan variant declaration,
but emit.rs has zero existing #[test] precedent — emit testing
happens via integration fixtures. Workers see 'build novel test
harness' inside what's billed as an S-scope fix and bounce.

Per feedback_construction_over_ratchets: when a brief has friction,
fix the brief, don't ratchet the worker.

Softened step 4 + acceptance: regression test stays optional. If
test setup requires novel scaffolding, route the gap to follow-up.
The structural fail-closed at step 2 is the load-bearing change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt

PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description'
is too weak; PR descriptions don't survive squash-merge cleanly.

Two coordinated edits:
1. Slice step 4 — explicit substrate-signal framing: skipped test
   means emit-side hermetic-unit-test infrastructure is the missing
   substrate (feedback_emitter_workaround_is_gap_symptom).
2. Acceptance — require ROADMAP debt row (new or existing) with
   named dissolution trigger, referenced in PR body. Converts the
   skip from PR-local note (transient) into tracked debt (durable,
   dispatchable).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124

Codex BLOCKING: my earlier softening claimed emit.rs had no #[test]
precedent — wrong. The module has #[cfg(test)] mod tests at line 3124
with 12+ tests using compile_to_dag(source, filename) as harness
(e.g., go_struct_fields_render_with_separators :3143,
shared_walk_to_disj_finds_match_scrutinee_sum_type :3195).

This is a feedback_verify_thesis_claims violation on Director-side
brief authoring — claim made without grep verification.

Fix: restore step 4 as required, with explicit precedent citation.
Worker constructs the failure case via the existing harness
(direct Dag, fixture string, or BranchPattern exercise; worker's
call on cleanest path). STOP-AND-ESCALATE only if construction
proves materially harder than precedent suggests, in which case
that escalation surfaces a real substrate gap and warrants ROADMAP
debt — but the default is 'add the test.'

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites)

Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but
emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded
to 'several using compile_to_dag'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue

Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this
is Wave 1 of Director's 14-brief authoring queue, covering B4 program
internals.

Authored:
- b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) —
  replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag")
  fold-skip with structural template-formal carrier; mandatory
  authority audit per feedback_audit_adjacent_authority_first.
- b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) —
  replaces §0.6 emit.rs bind/branch.span.file equality with typed
  BindEmitParticipation/BranchEmitParticipation roles populated at
  lowering; aligned with #824 worker's in-flight implementation shape.
- b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4
  of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with
  typed substrate authority; explicit pre-promotion-constraint
  disposition (single-authority vs authority+tracked-debt) addresses
  parallel-representation risk surfaced on #825.
- b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) —
  names B4.5-B4.12 Phase 2 sites with carrier dependencies,
  cross-program coordination notes, and skeleton-brief template;
  full per-site briefs author at dispatch time per #827's
  Substrate Manager ownership.

Cross-cutting discipline applied per inbox #828 reply:
- feedback_audit_adjacent_authority_first (mandatory grep before design)
- feedback_no_textual_enforcement_bridges (no replacement sentinels)
- feedback_parallel_representation_debt (explicit if shape (b))
- feedback_construction_over_ratchets (no parity-by-runtime as primary)
- feedback_coproduct_dissolution (receipts for new variants)

Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling
worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3)

Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue.
Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by
Modeling Manager's Wave 3 worker briefs (gated on these landing).

Authored:
- r2-substrate-cardinality-for-int-lit-subset.md (M) — produces
  magnitude carrier consumed by T-Modeling int-lit. Coordinates with
  PR #806's prior cardinality work; mandatory authority audit guards
  against #796's rejected IntLiteralMagnitude shape resurfacing.
  Open design questions: magnitude representation, reconciliation
  narrowing point, i64::MIN representability.
- r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces
  nominal-opacity carrier consumed by T-Modeling Secret<T>. Open
  design questions: carrier shape (flag/connective/sealed-accessor),
  generic-walk discipline, accessor gating.
- r2-substrate-parametric-algebra-for-dimensions-subset.md (M) —
  produces phantom-parameter carrier consumed by T-Modeling
  Dimension<Carrier>. Open design questions: carrier shape,
  type-equivalence rule, algebra-method dispatch, lifting/coercion.

All three:
- Scoped narrowly to their paired R2 consumer; not full
  substrate-capability lanes.
- Mandatory pre-author authority audit per
  feedback_audit_adjacent_authority_first.
- Cross-program readiness signal pattern from #827's manager rework.
- Coproduct dissolution receipts required for any new variants.
- Open design questions surfaced explicitly so Substrate Manager
  (or Director pre-spin-up) can resolve at dispatch time.

Wave 3 (T-Modeling worker briefs × 4) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4)

Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue.
Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each
gated on a Substrate Manager readiness signal (Wave 2 producers).

Authored:
- r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2
  cardinality-for-int-lit; moves narrowing from tokenizer to
  reconciliation; MagnitudeOutOfRange diagnostic per C-8.
- r2-modeling-secret-graduation-worker.md — gated on Wave 2
  nominal-opaque-for-Secret; authors Secret<T> + gated accessors
  (redact, compare_in_constant_time); C-8 diagnostic on non-gated
  access; signals Impossible-Bugs Manager on close (thesis claim
  covered).
- r2-modeling-dimensions-phantom-worker.md — gated on Wave 2
  parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier>
  + core SI base units + algebra-method dispatch; cross-dimension
  arithmetic produces typed diagnostic; signals Impossible-Bugs
  Manager (thesis claim).
- r2-modeling-tokenizer-charclass-phase2-worker.md — gated on
  T-Substrate ValueBody-list/sum (#790); migrates tokenizer
  consumers to Char/List<Char>/CharClass canonical types; sibling
  consumer to Grounding Manager's Engine sharpened-(b).

All four:
- Explicit gating: 'do not dispatch until producer signal posts.'
- Producer/consumer signal pattern from #827.
- Cross-program signals to R2 Release Manager (Goal 2 closure)
  and Impossible-Bugs Manager (thesis-claim coverage).
- Spoofing regression tests: discipline anchor against
  feedback_no_textual_enforcement_bridges.

Wave 4 (T-ImpossibleBugs worker briefs × 3) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3)

Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue.
Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes,
consuming the existing design/scoping briefs as authority.

Authored:
- r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on
  cardinality refinement substrate (T-Substrate territory adjacent
  to int-lit / DB-11 alias-where). Implementation: structural normalize
  of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T??
  worker decision (reject vs normalize). Cites
  t-impossiblebugs-nested-optional-flatten-design.md as authority.
- r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated
  on Tier 2 substrate (predicate-entailment infrastructure; distinct
  from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes
  predicate entailment, (b) feedback_totality_by_omission dissolves
  partial primitives, (c) park. Worker decides at audit time. Cites
  t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority.
- r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate
  prerequisite per closed-system framing in design doc (#808). Audit-
  as-existence-check + lens implementation as compositional fold over
  5 behaviors; redundancy detection compile-error via referential
  transparency + reread() escape hatch; path (i/ii) decision on
  OperationEffect taxonomy retain-vs-retire (default retire). Cites
  design doc #808 as authority.

Cross-cutting:
- Each cites prior design/scoping brief as authority (the existing
  *-design.md / *-worker.md REFRAMED files).
- Explicit gating per #827 producer/consumer signal pattern; two
  briefs gated on substrate, one NOT gated (closed-system).
- STOP-AND-ESCALATE includes 'design brief assumptions don't hold'
  surfacing per feedback_thesis_gate_state_drift.

Wave 4 complete. Director's 14-brief queue done; awaiting PM portion
(6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4.4 — tighten Slice §3 per PM review on #836

PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b)
(authority + tracked debt parallel-rep) as autonomously acceptable
contradicts feedback_construction_over_ratchets +
feedback_parallel_representation_debt.

Tightened:
- Shape (a) is the only autonomous worker path.
- Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a
  regen-host-loader sub-lane decision; not authorable without explicit
  Substrate Manager approval citation in the PR body.
- Acceptance bullet requires the approval citation when shape (b)
  lands.
- STOP-AND-ESCALATE rephrased to make this explicit; permanent
  parallel-representation re-escalates even with manager approval.

This preserves shape (a) as autonomous; shape (b) becomes a
cross-manager design escalation, not a B4.4 implementation call.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief

Cursor review on #836 flagged the Read-first reference to
.claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md
as machine-specific (outside the repo, not resolvable from a normal
clone). Replaced with in-repo prose pointing at the design doc's
§Q1-Q3 as canonical authority — the discipline lives there in-repo.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs)

Codex flagged: src/v3/std/types.dag does not exist; the canonical
authority is at dsl/std/types.dag. Affected briefs (all from R2
spin-up Wave 2 + Wave 3):

- r2-substrate-cardinality-for-int-lit-subset.md
- r2-substrate-nominal-opaque-for-secret-subset.md
- r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs)
- r2-modeling-dimensions-phantom-worker.md
- r2-modeling-secret-graduation-worker.md

feedback_verify_thesis_claims violation on Director-side brief
authoring — assumed path without grep. Same family of error as
the earlier emit.rs precedent claim. Mass-replaced via perl;
verified no remaining stale refs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant

Codex BLOCKING on #836: my R2 worker brief gated nested-optional on
cardinality refinement substrate, but the design doc verifies v3 is
ALREADY past the cardinality bridge — TypeConnective::Cardinality
is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is
the carrier for Option. The dissolution is an UNGATED implementation
via substrate-constructor invariant.

feedback_verify_thesis_claims violation again — should have read the
design doc fully before assuming the substrate gate.

Rewrote brief to match design doc canonical sketch:
- Single predicate (cardinality_idempotent_target) owns the rule
- Single allocator (alloc_cardinality_decl) is THE substrate-constructor
- API closure on TypeConnective::Cardinality payload (modeling-discipline
  practice 6) — variant cannot be struct-init'd outside the allocator
- 3 hand-Rust + ~22 codegen call sites enumerated per design audit
- infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as
  the killer case for generic-instantiation paths
- Surface-syntax T?? decision left to worker (Director-lean: silent
  normalize)

Brief now dispatchable immediately, no producer signal needed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation

Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment
substrate path, but the design doc §4 explicitly recommends totality-by-
omission as the Director-actionable path. Predicate-entailment is M+ scope
that reopens DB-11's explicitly-closed asymmetric-strip design — design
doc explicitly discards it.

feedback_verify_thesis_claims violation again — same family as nested-
optional reframe. Should have read design doc §4 in full before assuming
the path ordering.

Rewrote brief to match design doc §4 follow-on shape:
- Primary path: per-class totality-by-omission (algebra retype + per-
  target realization migration). For Int/Int: OrderedRing.div retype
  at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 /
  python:486 + python_target.rs:680 helper).
- NOT predicate-entailment (out of scope; M+ + DB-11 reopen).
- NOT NonZero-typed-input (deferred to separate per-operand-variance
  substrate brief; STOP-AND-ESCALATE if chosen).
- Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i]
  indexing, quotient, remainder) queue separately per design doc audit.
- feedback_totality_by_omission discipline anchor explicit.

Brief now matches feedback_totality_by_omission discipline + design doc
recommendation. No substrate prerequisite; dispatchable immediately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure

Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a
pattern: I authored R2 worker briefs without fully reading each design
doc's Director-actionable recommendation. Pre-emptively re-verified
unenumerated-effects against design doc §Q6 to catch the same family
of error before reviewers do.

Findings: brief was substantively close but missing 3 of 8 design-doc
reqs:
- Req 3: Resource-threading discipline applied to existing primitives
- Req 5: reread(key) primitive in std/ as explicit Slice item (was
  only mentioned in tests)
- Req 7: Asymmetric-tightening worked example in PR body

Plus: Slice didn't cite the canonical lens path
src/v3/lenses/effect_enumeration.dag from design doc.

Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6
specifies 4 specific STOPs (path-decision-escalation, pure: Bool
carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP)
that I had elided.

Reframed Slice as 8 numbered reqs matching design doc verbatim;
STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs;
Acceptance enumerated per req.

This is the third reframe in the unhandled-bugs series — same
feedback_verify_thesis_claims violation each time. The pattern
suggests Director-side R2 brief authoring should ALWAYS read each
design doc's §Director-actionable / §Q-recommendation in full first,
not assume.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options

Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)"
listed as a worker-pick option violates THESIS.md substrate-shape
lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality |
Instantiation) are canonical (per #811 thesis additions and #827 PM
review); a 7th is a C1 stop signal requiring failed-dissolution
evidence + Director substrate-design call, not autonomous worker pick.

Removed the "new TypeConnective variant" option; replaced with
`inhabits`-edge-shape carrier as third option (audit-time check). The
explicit STOP-AND-ESCALATE clause now states: 7th connective is the
precondition for failed-dissolution-evidence + Director substrate-design
call, not a worker path.

feedback_verify_thesis_claims still in play — should have grounded
substrate-shape options against the THESIS lock before listing Opaque(T)
as worker-autonomous. Pattern continues; reading source-of-truth before
authoring options is the discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place)

Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter
already exist at dag.rs:186, :217 — explicitly authored for the
R2 Dimensions consumer per the doc comment at dag.rs:148-160.
phantom_unit_mismatch already wired at infer.rs:1057, :1132. The
substrate is fully landed; my brief framing it as 'producer sub-lane
to land carrier' is wrong on the same feedback_audit_adjacent_authority_first
violation that hit nested-optional / unhandled-diagnostic / unenumerated-
effects.

Reframed the substrate-side brief as no-op / closed-by-audit:
- Documents the audit receipt (5 sites confirming substrate exists)
- States the lane is closed
- Routes T-Modeling Dimensions consumer to dispatch immediately
  against the existing carrier
- Records the lesson: 'always grep substrate before authoring
  producer briefs' — discipline doesn't end at brief boundaries.

Updated r2-modeling-dimensions-phantom-worker.md correspondingly:
- Changed gating from 'do not dispatch until producer signal' to
  'NOT GATED — dispatch immediately'
- Read-first updated with concrete dag.rs/infer.rs cites
- Slice §1 changed from 'confirm producer signal' to 'verify
  substrate at HEAD'
- STOP reframed: existing carrier extension would need Substrate
  Manager call, not autonomous worker pick

Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit
both verified — no existing substrate (no is_nominal_opaque /
MagnitudeBound patterns in dag.rs); both still legitimately
producer-side work.

Pattern is now four reframes deep on the R2 spin-up wave. The lesson
saved is structural: read source-of-truth before authoring options.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority

Codex BLOCKING on #836: my new R2 spin-up brief duplicates the
existing t-substrate-cardinality-int-lit-worker.md, which carries
the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64)
stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane).
Single-authority violation per INVARIANTS P2.

Same feedback_audit_adjacent_authority_first failure as parametric-
algebra-for-Dimensions reframe (4 hours ago): assumed substrate
authority didn't exist; should have grepped docs/briefs/ before
authoring. This is the SECOND R2 spin-up substrate brief closed
as redundant — the discipline lesson is structural.

Reframed brief as no-op routing doc (documents the audit receipt;
routes consumers to the existing authority); updated
r2-modeling-int-lit-magnitude-worker.md to cite
t-substrate-cardinality-int-lit-worker.md instead.

Pattern across the R2 spin-up wave reframes (5 now):
1. nested-optional gating-on-substrate (substrate already past
   cardinality bridge)
2. unhandled-diagnostic predicate-entailment default (design doc
   recommends totality-by-omission)
3. unenumerated-effects 8-req design-doc elision
4. parametric-algebra Producer (Declaration.phantom_params already
   authored explicitly for this consumer)
5. cardinality-for-int-lit…
briansrls added a commit that referenced this pull request Apr 29, 2026
…gpt-5-5-pro post-merge follow-up) (#1162)

* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation)

Director-authored amendment following the 2026-04-24 escalation from PR
#693 (sub-child sharp-bear-829 under Surface Manager).

Two edits:

1. New "Class 5 Gap 3 — port-carried field values in data bodies"
   row in the 2026-04-21 post-merge-debt section. The substrate gap was
   documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP
   ledger row for cross-lane visibility. PR #693's execution surfaced it
   as the blocker on sub_charclass_in_std_unicode phase-2.

2. Retract the "ready-to-dispatch (no substrate capability gap)" claim
   on the Character-level row, annotate phase-1 landed via PR #693
   (CharClass vocabulary + Rust-mirror structural scanner path), and
   point phase-2 at the new Class 5 Gap 3 row.

Codifies the audit pattern: "this consumption gap has no substrate
capability gap" claims must be verified by attempting the retype before
the claim lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main

* docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review)

* docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review)

Row title still said 'consumption gap, not substrate gap' while the
body block retracted that claim and cited Class 5 Gap 3 as a substrate
dependency for phase-2. Title now matches body: mixed classification,
consumption for steps 1+3, substrate for step 2.

* docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit)

gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining
gap" description was wrong: field-level shapes (nested records, list
literals, declaration refs, Var refs, sum-variant literals) are
supported today via FieldValue variants + lower_structural_field_value
(dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the
top-level ValueBody boundary (non-scalar, non-record top-level bodies).

The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself
stale: it describes the pre-PR-B-unwind shape where FieldValue was
LiteralBits-only. PR-B's unwind extended FieldValue to carry
Reference / Record / List / Variant, moving the gap to ValueBody.

Two fixes:

1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody
   boundary, point at code paths (dag.rs, lower.rs) as live authority,
   flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass
   blocker classification to "provisional pending reproduction."

2. Update the Character-level row's phase-2 block to name that the
   specific shape of the CharClass failure needs concrete reproduction
   from the escalating sub-child before the blocker is finalized.

Recursive audit-pattern instance: the row I wrote to codify "verify
live state before claiming substrate gap" itself failed to verify live
state. Both incidents (2026-04-23 original row + 2026-04-24 my
retraction row) are now cited in the audit-pattern sub-note as
examples of the same discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33

Three substantive fixes addressing internal-consistency gaps in the cascade
promotion PR caught by codex review at sha 0d6e7c33:

1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane
   acceptance bullets and Hand-Rust census paragraph in line with the
   updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero
   (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is
   retracted under 0-floor with explicit migration to ExecuteCommand-based
   .dag TestClaim declarations.

2. docs/design-pure-bootstrap-zero.md promotion section — converted from
   future-tense ("This doc is PROPOSAL until promoted… promotion is a
   single Director-authored cascade PR…") to historical past-tense
   promotion-receipt framing ("This doc was PROPOSAL until promoted;
   promotion was a single Director-authored cascade PR that did all of the
   following atomically…"); blocking-clause struck through and resolved
   inline. Banner cites PR #782 explicitly.

3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_
   profile excluded (Map<String, AlgebraProfile> body, not list-of-sum;
   needs distinct ValueBody::Map substrate work, tracked separately as a
   future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass
   phase-2 + Engine sharpened-(b) pilot enumeration), both sharing
   list-of-sum substrate work. Lane table, dependency DAG, and capacity
   summary updated for consistency (slot count 9-13, was 10-14).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities

Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade
self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22
explicitly names THESIS.md and "any other authority docs" as required
retraction targets; the prior diff updated ROADMAP + r2-structure + design
docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting-
manager.md pointing at the now-SUPERSEDED ≤5-floor framing.

Files:

- THESIS.md (5 prose blocks updated):
  - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests
    migrate to ExecuteCommand-based .dag TestClaim declarations.
  - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag.
  - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor
    target citing design-pure-bootstrap-zero.md as live authority;
    hand_maintained_src list shrinks to empty set.
  - :301-318 — Tests-are-structural-data block: residual carve-out retracted;
    predicate name pb_rust_tests_outside_residual_zero retained as
    housekeeping (semantically the residual is empty under cascade).

- docs/thesis/compiler-std-consolidation.md (5 references):
  - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes
    design-pure-bootstrap.md (SUPERSEDED).
  - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process
    lane named as the dissolution trigger for bootstrap.rs itself.
  - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md.
  - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority
    re-cited.
  - :185 Related docs link.

- docs/briefs/r1-selfhosting-manager.md (active dispatch brief):
  - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5);
    T-PB-B residual carve-out retracted; predicate names retained for
    housekeeping; cascade-promoted authorities are source of truth.
  - Slice descriptions for T-PB-A / T-PB-B updated inline.
  - Framing-question + ask updated to 0-floor / no-residual framing.
  - Day-1 + up-to-director hand-off bullets updated.
  - Working-state checklist :111 ≤5 → 0 with cite.
  - Decisions log :164 ≤5 → 0-floor target updated.

- docs/r2-structure.md §2 design call (RETRACTED block):
  - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through
    in entirety (both Option A sharpen-and-keep and Option B rename are
    moot under 0-floor). Section preserved as audit-trail historical
    context.
  - Background-doc index: self-hosting anchor updated to
    design-pure-bootstrap-zero.md as live authority.

- docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per
  non-blocking suggestion):
  - Banner cites cascade promotion PR #782 explicitly.
  - New paragraph: "Treat all numeric floors below as retracted" with
    explicit lines named that quote in isolation (table row, body prose
    references). Prevents re-quoting from this doc as live authority.

Cascade is now atomically consistent across:
  THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔
  docs/thesis/compiler-std-consolidation.md ↔
  docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔
  docs/design-pure-bootstrap-zero.md (LIVE) ↔
  docs/design-pure-bootstrap.md (SUPERSEDED).

The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds
genuinely.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): correct ExecuteCommand runner-capability claim

Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation):
TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138
overstated live runner capability — claimed runner support landed in
PR #688/#741 with "emit Rust, invoke rustc on output, check exit code"
as a structurally-equivalent migration path. Verified against live
sources:

- src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema
  exists (declared via PR #678).
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5
  testgen harness allowlists ONLY `command == "true" && args.is_empty()
  && expect_exit == 0`.
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 —
  panics fail-closed on any other shape with explicit "ExecuteCommand
  shell shape is not supported here (runner-owned — do not treat as
  ordinary false)".
- src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no
  match arm for ExecuteCommand; falls through to ClaimResult::
  NotYetImplemented.

Reality: a TestClaim declaring rustc/python/go invocation is
structurally expressible as data today, but executing it is blocked.
Full arbitrary-command runner support is the PB-Runtime lane's
deliverable.

Files updated:

- TESTING.md:195 — capability state callout with file:line citations;
  "Full runner support — arbitrary command + args (rustc/python/go) with
  exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor
  program)." Bullet about migration shape preserved as the cascade-named
  successor pattern, not as a live capability.
- TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane
  lands the ExecuteCommand runner extension" as an explicit precondition.
- docs/design-pure-bootstrap-zero.md:138 — same correction for the
  matching prose, with PB-Runtime named as the runner-extension
  dependency for boundary-test migration.
- ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner
  foundation in #688/#741 with `true`-no-args allowlist only — full
  arbitrary-command runner support deferred to PB-Runtime lane,
  blocking the actual boundary-test migration." Dependencies column
  extended to "DB-15 + T-TestGen + PB-Runtime".

The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still
holds for atomic-cascade-across-authority-docs; this commit closes the
remaining capability/claim mismatch flagged by codex.

(Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still
SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief

Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation).
The prior banner contained:

> "Operationally R1 closure may still ship before the 0-floor is reached
>  — the ratchet ensures the trajectory; the gate's acceptance number is
>  what shifts."

This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0.
Two competing gate semantics in the cascade is exactly what the
atomic-cascade clause forbids.

Replaced with single-authority-honest framing:

> "R1 closure now requires the 0-floor target by gate semantics: T-PB-A
>  and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade
>  promotion changed their acceptance numbers to 0; R1 cannot close
>  while the SG-0 census carries non-zero hand-Rust."

Plus minor sharpening:
- "T-PB-A's non-test target is 0" → "non-test acceptance target is 0
  per ROADMAP.md:67" (cite the authority).
- T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep
  the capability-state honesty consistent with the recent fix wave.
- Predicate-rename housekeeping line moved into banner ("post-cascade
  housekeeping, not a pre-promotion blocker") — was implicit before.

The brief now genuinely inherits the cascade-promoted gate; no
competing release authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 second-wave worker-escalation fixes

Four substantive worker STOP-AND-ESCALATEs from briefs landed in
PR #797. All four worker recommendations correct; each needs a
Director call + brief update.

## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate

Worker correctly identified that brief req 2 (declared-effect carrier
as part of fn type signature, per feedback_no_annotations) requires
net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at
src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots.
Without parser surface, every user function would have
declared_effects = [] while inference returns non-empty — lens fires
EffectLeakageError everywhere on enable. Worker rejected power-through
and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map
parser split).

Director picked split:
- NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md
  Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface
  syntax + lookahead + body parser + lowerer extension + exhaustive-match
  audit + coproduct dissolution receipt.
- MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to
  post-parser-extension scope. Pre-flight check NOT a parser-extension
  step; STOP if parser sub-lane PR not merged.

## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping

Worker found load-bearing evidence at infer.rs:3693-3703: DB-11
deliberately strips refinements at operator dispatch as a designed-in
fix for symmetric-operators failure mode. Brief's "attach where b != 0
as a proof for a / b" directly contradicts this design choice. STOP-3
(where-clause conflict with DB-11) is real; STOP-1 (substrate scope)
needs net-new substrate (per-operator partiality fact + predicate-
entailment check + asymmetric per-operand refinement-honoring) — M+
minimum. ownership_lens precedent in original brief is post-hoc
observability, not proof carrier.

Worker recommended redirect to design/scoping per nested-optional
precedent. Director picked redirect.

Brief fully rewritten as design/scoping with four-question structure:
(1) DB-11 interaction analysis; (2) substrate proposal for proof-or-
totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes
with acceptance-theatre risk on user-defined-total-wrapper-only);
(4) Director-actionable recommendation. Output is doc PR.

## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C)

Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int)
with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136
closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b)
i128 implementation requires either path 1 (hierarchy refactor —
contradicts non-goal) or path 2 (regen lie between substrate and
emit — violates discipline). Worker leaned option (C) re-scope:
land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke)
to a sibling sub-lane that does proper Int128/Word128 substrate work.

Director picked option (C). Brief req 1 re-scoped to drop canonical-
carrier-widening; lane value comes from range facts + reconciliation
narrowing + out-of-range diagnostic against existing i64. Req 4
explicitly deferred with sibling-sub-lane reference. Sibling sub-lane
NOT to be authored or implied in this PR; tracked separately.

## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change)

Worker correctly STOP'd per the brief's own pre-flight check: parser
sub-lane has not landed; SurfaceExpr::Map not on main. Director
authorized cross-lane reassignment: wise-boar-480 takes the parser
sub-lane (t-substrate-valuebody-map-parser-worker.md) since they
already have full investigation context. No brief changes needed; the
routing decision is in the dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope

Resolves codex P2 inline at sha e35103fad on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer
carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still
required widening LiteralBits::Int(i64) to an unbounded carrier and
passing the i64::MIN smoke. Internally unsatisfiable.

Fix:

- Slice section retitled "range facts + reconciliation narrowing
  (against existing i64 carrier)" with explicit note about the
  re-scope.
- Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly
  forbids touching LiteralBits::Int shape, dag_scalar_generated.rs
  regen for that variant, or tokenize i64 parse path.
- Slice steps 2-5 reframed: range facts use i64-representable
  magnitudes; reconciliation narrowing uses existing i64 carrier;
  diagnostic only for i64-representable out-of-range; smoke tests
  for req 5 only (req 4 i64::MIN deferred).
- Acceptance checklist updated:
  - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as
    re-scoped/deferred.
  - LiteralBits::Int(i64) carrier untouched (no widening; no
    parallel; no shape change).
  - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference.
- STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the
  carrier" — explicit STOP if execution surfaces range-fact narrowing
  requiring carrier-widening; that's the boundary the re-scope drew;
  belongs in sibling Int128/Word128 sub-lane.

Brief now consistently treats carrier-widening as out-of-scope across
all sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty

Resolves codex BLOCKING #1 at sha e35103fa on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier
but req 2 required range facts using "the SAME magnitude carrier
as req 1" — meaning i64-typed range bounds. u64's max (2^64-1)
doesn't fit in i64; range fact for u64 would have to truncate,
omit, or mirror in Rust (representation drift). All three options
violate fail-closed declared-facts discipline (P1 / P3).

Fix:

- Req 2 rewritten to specify String-decimal representation:
  range_min_inclusive: String + range_max_inclusive: String fields
  on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127"
  for i8; "0"/"18446744073709551615" for u64).
- Explicit reasoning why String-decimal: u64's max doesn't fit in
  i64; binding range bounds to literal carrier forces truncation/
  omission/mirror-drift; all violate fail-closed declared-facts
  discipline.
- Bridge framing: String-decimal is pending the sibling Int128/
  Word128 sub-lane; both range bounds and literal payload migrate
  to typed carrier when that lands.

- Req 3 updated for String-decimal comparison semantics:
  reconciliation parses both bounds and literal magnitude into a
  common comparison space (i128 host comparison primitive — host
  narrowing, NOT carrier widening). Bounded by what the i64-typed
  literal can express; any i64-representable literal compares
  against any width's String-decimal bound. Carrier discipline
  preserved.

Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral)
is sha-stale — already resolved at 3e142d169.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed

Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback).
Real residual: req 2 specifies String-decimal range bounds (to cover
u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance
bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" /
"i64-representable magnitudes" for the range facts. Two incompatible
authorities for the same range-fact shape — would let a worker satisfy
the slice while truncating/omitting u64 bounds (P3 fail-closed
violation).

Fix:

- Line 31 (req 1 re-scope clarification): updated to explicitly state
  "range facts (req 2) use String-decimal representation (width-
  independent; covers u64::MAX which doesn't fit in i64)". Distinguished
  literal *payload* (stays i64) from range-bound *representation*
  (String) — both serve req 1's "no carrier widening" boundary.
- Line 44 (slice step 2): updated from "Range bounds use i64-
  representable magnitudes" to "Range bounds use String-decimal
  representation per req 2" with concrete example (u64 bounds).
- Acceptance bullet: updated from "Range facts on integer algebras
  (substrate-declared, not Rust-mirrored)" to add "using String-decimal
  representation ... width-independent; u64 bounds expressible without
  truncation."

The brief now consistently treats range bounds as String-decimal
across req 2, req 3, slice, acceptance, and the req 1 clarification —
no remaining authorities saying i64-typed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing

User + PM exchange 2026-04-25 surfaced that the in-flight effects
chain was importing wrong assumptions from external languages
(declared-effects-as-annotation + lens-vs-declaration check). Right
framing under gunbc's closed-system discipline is parallel to
complexity: every effect derives structurally from the composition
of typed primitive operations; nothing can hide because there's no
escape hatch; nothing needs annotation because the structure IS the
registry.

Four doc-only actions:

1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md.
   Frames the closed-system answer with PM's 5-behavior synergy
   table (Value/Transform/Branch/Loop/Bind as universal
   compositional-fold pattern). Four worked examples; aggressive
   reading on redundancy (compile-error-by-construction via
   referential-transparency proof; reread() primitive for legitimate
   cases); implementation-brief shape in §Q6.

2. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md.

3. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md.
   Notes Fn→Arrow refactor brief stays dispatchable as independent
   value.

4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by-
   construction framing replaces lens-detection framing.

Memory file feedback_closed_system_effects.md saved separately;
cross-link added to feedback_construction_over_ratchets.md.

Net cost: doc-level cleanup. Zero substrate code rework. Foundation
(OperationEffect + service-call infrastructure + 5-behavior
substrate) already exists.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect

Per PM convergence review on #808 + user's deeper 2026-04-25 framing:
the closed-system framing landed in #808 retired the user-facing
annotation but kept OperationEffect taxonomy as substrate-level tagging.
User's deeper framing: the taxonomy ITSELF is parallel-representation —
operations are intrinsically read-shaped or write-shaped via their
TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns-
derived-value-only → read). Tagging operations with Read | Upsert |
Create | Append | Delete names what the structure already says.

Three changes:

1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as
   normalized view, or retire as parallel-representation?"
   - Two paths: (i) tags derived from signature shape (acceptable
     normalized view) vs (ii) tags declared per-primitive (parallel-
     representation; retire).
   - Audit-as-existence-check (Q4 req 2 reframed): all effectful
     primitives derive cleanly from signature shape → path (i); any
     primitive needs hand-declared tag → path (ii) by existence proof.
   - Director default: path (ii). Logging primitives that return Unit
     are likely the audit's existence-proof.
   - Two design-question resolutions: (a) external effects not in
     return type → resource-threading discipline (typed param returned
     modified, IO-monad-without-the-monad pattern); (b) transactional
     grouping → derived structural fact from Bind composition + typed
     transaction primitives.

2. Q4 reqs revised: req 2 from "tag every primitive with explicit
   OperationEffect signature" to "audit-as-existence-check that every
   primitive's type signature derives the right effect classification";
   req 3 added (resource-threading discipline); req 6 added
   (transactional-pattern lens). Req 1 (effects lens) anchors on
   operation type-signature shape, not on hand-declared tags.

3. THESIS:345-347 amendment strengthened — "operations are
   intrinsically read-shaped or write-shaped via their type-signature
   shape; consumers walk the signatures directly; there is no parallel
   taxonomy or annotation layer to declare or maintain. Tracking
   effects as a separate enumerated concept IS the bug pattern,
   dissolved by construction." Plus references to resource-threading
   discipline + transactional grouping as derived structural fact.

Memory file feedback_closed_system_effects.md updated to reflect the
deeper framing (type-signature-shape, not taxonomy-tagging) +
resource-threading discipline section + transactional-patterns
section.

Net cost: doc-only delta on top of #808. Substrate retirement
(OperationEffect enum + derive_op_effect + idempotency.dag re-anchor)
deferred to the audit-as-existence-check phase of the implementation
brief; surfaced as Q5.5 OPEN CALL.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage

Resolves codex BLOCKING at sha d49ce79a on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real:
the prior text claimed service primitives "already carry typed effect
signatures" presenting future audit-state as current substrate fact
(P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the
OperationEffect line but left a parallel over-claim on the new
"signature-shape coverage" framing.

Fix: Q4 substrate-state listing rewritten to honestly distinguish:

- Live: Behavior enum + substrate foundation (the principle that
  operations should carry signature shape).
- Incomplete: signature-shape coverage across actual primitives.
  HTTP-derived primitives carry implicit shape via derive_op_effect's
  method-table; logging/mutation primitives that return Unit or don't
  thread their target resource do NOT carry the structural shape that
  would express read-vs-write. Achieving full coverage is required
  work under reqs 2 + 3, not a current fact.
- Pending audit-as-existence-check: OperationEffect + derive_op_effect
  (path (i) vs (ii) per Q5.5).

Honest live-state callout added explicitly: "the closed-system
FOUNDATION (5 behaviors + DAG substrate + the principle that
operations should carry signature-shape) is live. The IMPLEMENTATION
COVERAGE across all effectful primitives is partial. Req 2 + req 3
are the work that closes the gap."

Brief now distinguishes principle-is-live (foundation) from
coverage-is-partial (audit work) without conflating them.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim

Per PM follow-up review on #808 + user's stronger discipline framing
("substrate must make bypass structurally impossible at every layer
of the transport stack"): the closed-system claim is honest only when
typed primitives ARE the path. Today two structural holes exist where
bypasses sidestep the typed-primitive substrate. Both surfaced
explicitly as Q4.5 pre-conditions — load-bearing for the lens's
coverage claim.

Three changes:

1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed-
   system claim)" inserted between Q4 and Q5:

   P1 — Extdeps typed-primitive consumption structurally enforced.
   Substrate must make `messages: Json` impossible to declare in
   service definitions; typed `LlmMessage` / `ContentBlock` /
   `GitHubAuthToken`-with-full-scopes are the only path. Tracked
   debt at ROADMAP.md:153-154 (LLM provider flattening) +
   `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded).
   Required prereq for full lens coverage; lens can land first +
   surface structural-coverage-gap diagnostics on bypass surfaces
   so the gap becomes visible rather than silent.

   P2 — `ExecuteCommand` fully materialized as typed runner
   primitive. TESTING.md (post-#782) committed to 0-residual but
   ExecuteCommand isn't fully materialized; deleting Rust boundary
   tests creates verification gap. Already named under PB-Runtime
   in Zero-Floor; signal pending. Pre-requisite for ANY Rust
   boundary-test deletion.

2. Old leftover duplicate Q5 section deleted (artifact from prior
   Q5/Q5.5 reshape; second copy of asymmetric-tightening text was
   in the file alongside the earlier Q5 instance).

3. Worker-discretion-vs-Director-call section in Q4.5: lens
   implementation worker dispatchable now (reports gaps as
   findings); P1 closure is substantive substrate work touching
   extdeps (dedicated lane); P2 closure is PB-Runtime (signal
   pending).

Net: design doc now honestly distinguishes principle-is-live
(Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs
named explicitly). The closed-system claim has explicit pre-
conditions documented; implementation brief discovers them as
known dependencies, not as STOP-AND-ESCALATEs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default

Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two
real residuals after the Q5.5 reframe:

1. Q6's reqs/STOPs/acceptance still framed under path (i) — said
   "audit + tag std/ primitives — every effectful primitive carries
   an explicit OperationEffect signature." Directly contradicted Q4
   (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment
   ("there is no parallel taxonomy to declare or maintain"). Worker
   reading Q6 in isolation would author the retracted shape.

2. Capacity / sequencing table line about "audit lane (tag std/
   primitives with effect signatures)" carried the same stale
   framing.

3. Q6 STOP "primitive performing side effects without an
   OperationEffect tag" assumed tag-as-authority; under path (ii)
   the STOP shape is "primitive whose signature doesn't structurally
   reveal its effect."

Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale
(already fixed at f073aa95e Q4.5 commit).

## Q6 fixes

- Reqs renumbered + reframed:
  - Req 1 anchors on operation type-signature shape (not hand-declared
    OperationEffect tags); composition reads from signature shape per
    Q2 table.
  - Req 2 changed from "audit + tag every primitive" to
    "audit-as-existence-check" — verify signature-shape coverage; ANY
    primitive needing a hand-declared tag IS the existence-proof for
    path (ii) retirement.
  - Req 3 added: resource-threading discipline applied to existing
    primitives (logging that returns Unit gets reshaped per audit).
  - Req 6 added: transactional-pattern lens (Bind composition +
    Transaction → Transaction').
  - Req 7 added: asymmetric-tightening worked example in PR body
    (per claude review observation; the one place declaration-shaped
    surface re-enters).
  - Req 8 (was 5): tests now reference signature-shape derivation
    explicitly, not tag lookup.
- STOPs reframed:
  - "OperationEffect retirement decision" — audit produces path (i)
    vs (ii) verdict; substrate retirement is its own dedicated
    sub-lane; this lane does NOT absorb it.
  - Pure/impure carrier STOP notes that "pure" should also derive
    from signature shape (pure functions don't return modified
    resources) — so the STOP itself may dissolve under further design.
  - Q4.5 P1 explicitly NOT a STOP — lens reporting structural-
    coverage-gap on extdeps bypass surfaces is the lens delivering
    its foundation-gap-visibility value.
  - Q4.5 P2 explicitly independent — lens doesn't depend on
    ExecuteCommand materialization.
- Acceptance extended: lens reports gap diagnostics on P1 bypass
  surfaces; audit produces existence-proof verdict for Director
  re-decision; asymmetric-tightening worked example in PR body.

## Capacity / sequencing table

Replaced "1 audit lane (tag std/ primitives with effect signatures)"
with "1 audit-as-existence-check lane (verify primitives' signature-
shape coverage; NOT 'tag every primitive') — produces the path (i)
vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2
prereq lanes to the net summary. Closing line: "The taxonomy-
retirement scope (substrate-side) is not in this lane — it's
surfaced by audit and routed to dedicated retirement lane if path
(ii) wins."

Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity
table. Worker reading Q6 in isolation now sees path-(ii)-default
framing matching Q4 + Q5.5 + THESIS amendment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792

Resolves codex inline BLOCKING at sha 191be310 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150.
Real: my Q4.5 P2 framing described ExecuteCommand as still
NotYetImplemented (M1.5 allowlist + Rust TestRunner returning
NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand
extension before this PR's authoring. TESTING.md:195 capability-state
callout confirms:
- Rust TestRunner + M1.5 testgen harness share one std::process path
  for arbitrary command + args + expect_exit_code.
- M1.5 allowlist + fail-closed panic retired.
- Distinguishable ClaimResult::Fail messages for spawn / timeout /
  policy / exit-mismatch.
- Linux unshare(1) namespace isolation on host-allowing systems.
- T-PB-B-1 boundary migration example landed.

Fix:

P2 section rewritten:
- Header retitled "ExecuteCommand runner primitive: LANDED (PR #792);
  residual is bulk-migration."
- Status update naming PR #792 + the post-#792 capability state
  (allowlist retired, etc.).
- Honest acknowledgement: "My earlier P2 framing was stale."
- Residual narrowed to bulk-migration of existing Rust Command::new
  boundary tests (tracked as ROADMAP residual, not lens prereq).
- Sequencing reframed: P2 was always orthogonal to the effects lens
  itself; bulk migration proceeds at its own pace; lens not blocked.

Q4.5 footer updated:
- "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via
  #792; only consumer-side bulk migration remains)"
- Worker-discretion-vs-Director-call P2 line updated: "runner
  primitive landed; only consumer-side bulk migration remains;
  tracked as ROADMAP residual, independent of the lens."

Q6 STOP for P2 updated:
- "the lens itself doesn't depend on P2; only TESTING.md's 0-residual
  claim does" → "runner primitive landed via PR #792 (post-Q4.5-
  authoring update). The lens itself never depended on P2; bulk
  consumer migration is residual ROADMAP work and remains independent
  of this lane."

Brief now reflects live state. The closed-system claim's prereq
landscape is honest:
- P1 (extdeps typed-primitive consumption): real prereq, tracked
  debt at ROADMAP:153-154.
- P2 (ExecuteCommand runner): satisfied via #792; bulk migration is
  consumer-side residual, not foundation work.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale

Resolves codex non-blocking finding at sha bcac41bb on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real
residual: capacity-table line still listed P2 as "`ExecuteCommand`
materialization" prereq + framed both P1 and P2 as "pre-existing
tracked-debt" — but my prior 57a9b1318 fix established that PR #792
already landed the runner primitive, so P2 is no longer a
materialization prereq.

Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq)
from P2 (residual, not prereq):

  - P1: extdeps typed-primitive consumption — pre-existing tracked
    debt at ROADMAP:153-154; load-bearing for the lens's full-coverage
    claim.
  - P2: ExecuteCommand runner primitive landed via PR #792; only
    consumer-side bulk migration of existing Rust Command::new
    boundary tests remains (tracked as ROADMAP residual, independent
    of the lens; not a materialization prereq).

Brief now consistently treats P2 as bulk-migration-residual across:
- §Q4.5 P2 section header (LANDED via PR #792; residual is
  bulk-migration).
- §Q4.5 footer (P2: runner primitive landed; only consumer-side
  bulk migration remains).
- Q6 STOP for P2 (runner primitive landed; bulk migration is
  residual ROADMAP work).
- §Capacity / sequencing impact (P2 as residual, not prereq).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349

Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated
target-grounding prose; the matching extdeps typed-primitive bypass
entries (LLM service flattening, GitHub auth model bypass) live at
ROADMAP.md:348-349.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix third stale ROADMAP citation at line 271

Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence
at line 271 in the §Q4.5 capacity table. Now consistent with lines
139 and 173 (ROADMAP.md:348-349).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity

Codex flagged 'Effect-signature tagging on std/ primitives' as potentially
contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240)
already explicitly say 'NOT tag every primitive' — but the cross-manager
line used sloppy wording. Reworded to make explicit that the audit walks
signature shape; no parallel tag added.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5

- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)

B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).

B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — drop incoherent inner-fallback non-goal

Codex P2: the non-goal line excluding the inner declaration().name
unwrap_or_else fallback contradicted Slice step 2, which replaces the
whole chain with let-Some-else-return. Both fallbacks are in scope by
construction; remove the contradictory non-goal.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives

PM REQUEST_CHANGES: §Frame listed '4 type connectives
(Conjunction | Disjunction | Cardinality | Bit)' which contradicted
the canonical thesis source. Replaced with the canonical 6
(Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per
docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary
closes here'. Also removed 'typed substrate carriers' from the
vocabulary list — substrate carriers are defined using the vocabulary,
not part of it. Added a clarifying note that B4's carriers
(DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are
typed declarations composed from the vocabulary, not vocabulary
extensions.

Per feedback_verify_thesis_claims: brief framings citing thesis
structure must ground in the canonical source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority

Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of
naming the live substrate authority. Two coordinated fixes:

1. §Read first cites src/v3/std/substrate.dag (live .dag substrate
authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel
meta-type — already exists with consumers in verification.dag,
emit_model.dag, python.dag).

2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing
DeclarationRef'. The work is consumer migration + any role-extension
layer the audit reveals, NOT designing or landing the carrier.

Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers)
keep their 'new' framing but explicitly require sub-briefs to grep
src/v3/std/ + src/v3/spec/ for existing authority before authoring
'design and land' framing — per feedback_verify_thesis_claims +
feedback_emitter_workaround_is_gap_symptom.

Acceptance + sub-brief dispatch order updated to reflect B4.1's
consumer-migration shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — tighten Phase 1 umbrella sentence

The umbrella 'Land the typed carriers into src/v3/std/' framing was
stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced
with audit-first wording that covers both the consume-existing case (#1)
and the design-and-land case (#2-#4 if their audits show real gaps).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording

Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands'
which conflicted with the post-reframe reality that B4.1 consumes the
existing DeclarationRef. Updated to 'consumes or lands' with explicit
existing-authority citation and audit-pending caveat for B4.2-B4.4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — soften regression-test requirement (3 worker bounces)

Three consecutive B1 worker dispatches (zesty-crane-890 cursor →
valiant-boar-498 codex → cool-lynx-395 cursor) archived without
opening a PR. Likely friction point: brief Slice step 4 asks for a
unit test that constructs a Dag with an orphan variant declaration,
but emit.rs has zero existing #[test] precedent — emit testing
happens via integration fixtures. Workers see 'build novel test
harness' inside what's billed as an S-scope fix and bounce.

Per feedback_construction_over_ratchets: when a brief has friction,
fix the brief, don't ratchet the worker.

Softened step 4 + acceptance: regression test stays optional. If
test setup requires novel scaffolding, route the gap to follow-up.
The structural fail-closed at step 2 is the load-bearing change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt

PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description'
is too weak; PR descriptions don't survive squash-merge cleanly.

Two coordinated edits:
1. Slice step 4 — explicit substrate-signal framing: skipped test
   means emit-side hermetic-unit-test infrastructure is the missing
   substrate (feedback_emitter_workaround_is_gap_symptom).
2. Acceptance — require ROADMAP debt row (new or existing) with
   named dissolution trigger, referenced in PR body. Converts the
   skip from PR-local note (transient) into tracked debt (durable,
   dispatchable).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124

Codex BLOCKING: my earlier softening claimed emit.rs had no #[test]
precedent — wrong. The module has #[cfg(test)] mod tests at line 3124
with 12+ tests using compile_to_dag(source, filename) as harness
(e.g., go_struct_fields_render_with_separators :3143,
shared_walk_to_disj_finds_match_scrutinee_sum_type :3195).

This is a feedback_verify_thesis_claims violation on Director-side
brief authoring — claim made without grep verification.

Fix: restore step 4 as required, with explicit precedent citation.
Worker constructs the failure case via the existing harness
(direct Dag, fixture string, or BranchPattern exercise; worker's
call on cleanest path). STOP-AND-ESCALATE only if construction
proves materially harder than precedent suggests, in which case
that escalation surfaces a real substrate gap and warrants ROADMAP
debt — but the default is 'add the test.'

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites)

Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but
emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded
to 'several using compile_to_dag'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue

Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this
is Wave 1 of Director's 14-brief authoring queue, covering B4 program
internals.

Authored:
- b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) —
  replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag")
  fold-skip with structural template-formal carrier; mandatory
  authority audit per feedback_audit_adjacent_authority_first.
- b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) —
  replaces §0.6 emit.rs bind/branch.span.file equality with typed
  BindEmitParticipation/BranchEmitParticipation roles populated at
  lowering; aligned with #824 worker's in-flight implementation shape.
- b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4
  of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with
  typed substrate authority; explicit pre-promotion-constraint
  disposition (single-authority vs authority+tracked-debt) addresses
  parallel-representation risk surfaced on #825.
- b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) —
  names B4.5-B4.12 Phase 2 sites with carrier dependencies,
  cross-program coordination notes, and skeleton-brief template;
  full per-site briefs author at dispatch time per #827's
  Substrate Manager ownership.

Cross-cutting discipline applied per inbox #828 reply:
- feedback_audit_adjacent_authority_first (mandatory grep before design)
- feedback_no_textual_enforcement_bridges (no replacement sentinels)
- feedback_parallel_representation_debt (explicit if shape (b))
- feedback_construction_over_ratchets (no parity-by-runtime as primary)
- feedback_coproduct_dissolution (receipts for new variants)

Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling
worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3)

Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue.
Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by
Modeling Manager's Wave 3 worker briefs (gated on these landing).

Authored:
- r2-substrate-cardinality-for-int-lit-subset.md (M) — produces
  magnitude carrier consumed by T-Modeling int-lit. Coordinates with
  PR #806's prior cardinality work; mandatory authority audit guards
  against #796's rejected IntLiteralMagnitude shape resurfacing.
  Open design questions: magnitude representation, reconciliation
  narrowing point, i64::MIN representability.
- r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces
  nominal-opacity carrier consumed by T-Modeling Secret<T>. Open
  design questions: carrier shape (flag/connective/sealed-accessor),
  generic-walk discipline, accessor gating.
- r2-substrate-parametric-algebra-for-dimensions-subset.md (M) —
  produces phantom-parameter carrier consumed by T-Modeling
  Dimension<Carrier>. Open design questions: carrier shape,
  type-equivalence rule, algebra-method dispatch, lifting/coercion.

All three:
- Scoped narrowly to their paired R2 consumer; not full
  substrate-capability lanes.
- Mandatory pre-author authority audit per
  feedback_audit_adjacent_authority_first.
- Cross-program readiness signal pattern from #827's manager rework.
- Coproduct dissolution receipts required for any new variants.
- Open design questions surfaced explicitly so Substrate Manager
  (or Director pre-spin-up) can resolve at dispatch time.

Wave 3 (T-Modeling worker briefs × 4) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4)

Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue.
Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each
gated on a Substrate Manager readiness signal (Wave 2 producers).

Authored:
- r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2
  cardinality-for-int-lit; moves narrowing from tokenizer to
  reconciliation; MagnitudeOutOfRange diagnostic per C-8.
- r2-modeling-secret-graduation-worker.md — gated on Wave 2
  nominal-opaque-for-Secret; authors Secret<T> + gated accessors
  (redact, compare_in_constant_time); C-8 diagnostic on non-gated
  access; signals Impossible-Bugs Manager on close (thesis claim
  covered).
- r2-modeling-dimensions-phantom-worker.md — gated on Wave 2
  parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier>
  + core SI base units + algebra-method dispatch; cross-dimension
  arithmetic produces typed diagnostic; signals Impossible-Bugs
  Manager (thesis claim).
- r2-modeling-tokenizer-charclass-phase2-worker.md — gated on
  T-Substrate ValueBody-list/sum (#790); migrates tokenizer
  consumers to Char/List<Char>/CharClass canonical types; sibling
  consumer to Grounding Manager's Engine sharpened-(b).

All four:
- Explicit gating: 'do not dispatch until producer signal posts.'
- Producer/consumer signal pattern from #827.
- Cross-program signals to R2 Release Manager (Goal 2 closure)
  and Impossible-Bugs Manager (thesis-claim coverage).
- Spoofing regression tests: discipline anchor against
  feedback_no_textual_enforcement_bridges.

Wave 4 (T-ImpossibleBugs worker briefs × 3) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3)

Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue.
Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes,
consuming the existing design/scoping briefs as authority.

Authored:
- r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on
  cardinality refinement substrate (T-Substrate territory adjacent
  to int-lit / DB-11 alias-where). Implementation: structural normalize
  of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T??
  worker decision (reject vs normalize). Cites
  t-impossiblebugs-nested-optional-flatten-design.md as authority.
- r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated
  on Tier 2 substrate (predicate-entailment infrastructure; distinct
  from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes
  predicate entailment, (b) feedback_totality_by_omission dissolves
  partial primitives, (c) park. Worker decides at audit time. Cites
  t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority.
- r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate
  prerequisite per closed-system framing in design doc (#808). Audit-
  as-existence-check + lens implementation as compositional fold over
  5 behaviors; redundancy detection compile-error via referential
  transparency + reread() escape hatch; path (i/ii) decision on
  OperationEffect taxonomy retain-vs-retire (default retire). Cites
  design doc #808 as authority.

Cross-cutting:
- Each cites prior design/scoping brief as authority (the existing
  *-design.md / *-worker.md REFRAMED files).
- Explicit gating per #827 producer/consumer signal pattern; two
  briefs gated on substrate, one NOT gated (closed-system).
- STOP-AND-ESCALATE includes 'design brief assumptions don't hold'
  surfacing per feedback_thesis_gate_state_drift.

Wave 4 complete. Director's 14-brief queue done; awaiting PM portion
(6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4.4 — tighten Slice §3 per PM review on #836

PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b)
(authority + tracked debt parallel-rep) as autonomously acceptable
contradicts feedback_construction_over_ratchets +
feedback_parallel_representation_debt.

Tightened:
- Shape (a) is the only autonomous worker path.
- Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a
  regen-host-loader sub-lane decision; not authorable without explicit
  Substrate Manager approval citation in the PR body.
- Acceptance bullet requires the approval citation when shape (b)
  lands.
- STOP-AND-ESCALATE rephrased to make this explicit; permanent
  parallel-representation re-escalates even with manager approval.

This preserves shape (a) as autonomous; shape (b) becomes a
cross-manager design escalation, not a B4.4 implementation call.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief

Cursor review on #836 flagged the Read-first reference to
.claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md
as machine-specific (outside the repo, not resolvable from a normal
clone). Replaced with in-repo prose pointing at the design doc's
§Q1-Q3 as canonical authority — the discipline lives there in-repo.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs)

Codex flagged: src/v3/std/types.dag does not exist; the canonical
authority is at dsl/std/types.dag. Affected briefs (all from R2
spin-up Wave 2 + Wave 3):

- r2-substrate-cardinality-for-int-lit-subset.md
- r2-substrate-nominal-opaque-for-secret-subset.md
- r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs)
- r2-modeling-dimensions-phantom-worker.md
- r2-modeling-secret-graduation-worker.md

feedback_verify_thesis_claims violation on Director-side brief
authoring — assumed path without grep. Same family of error as
the earlier emit.rs precedent claim. Mass-replaced via perl;
verified no remaining stale refs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant

Codex BLOCKING on #836: my R2 worker brief gated nested-optional on
cardinality refinement substrate, but the design doc verifies v3 is
ALREADY past the cardinality bridge — TypeConnective::Cardinality
is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is
the carrier for Option. The dissolution is an UNGATED implementation
via substrate-constructor invariant.

feedback_verify_thesis_claims violation again — should have read the
design doc fully before assuming the substrate gate.

Rewrote brief to match design doc canonical sketch:
- Single predicate (cardinality_idempotent_target) owns the rule
- Single allocator (alloc_cardinality_decl) is THE substrate-constructor
- API closure on TypeConnective::Cardinality payload (modeling-discipline
  practice 6) — variant cannot be struct-init'd outside the allocator
- 3 hand-Rust + ~22 codegen call sites enumerated per design audit
- infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as
  the killer case for generic-instantiation paths
- Surface-syntax T?? decision left to worker (Director-lean: silent
  normalize)

Brief now dispatchable immediately, no producer signal needed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation

Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment
substrate path, but the design doc §4 explicitly recommends totality-by-
omission as the Director-actionable path. Predicate-entailment is M+ scope
that reopens DB-11's explicitly-closed asymmetric-strip design — design
doc explicitly discards it.

feedback_verify_thesis_claims violation again — same family as nested-
optional reframe. Should have read design doc §4 in full before assuming
the path ordering.

Rewrote brief to match design doc §4 follow-on shape:
- Primary path: per-class totality-by-omission (algebra retype + per-
  target realization migration). For Int/Int: OrderedRing.div retype
  at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 /
  python:486 + python_target.rs:680 helper).
- NOT predicate-entailment (out of scope; M+ + DB-11 reopen).
- NOT NonZero-typed-input (deferred to separate per-operand-variance
  substrate brief; STOP-AND-ESCALATE if chosen).
- Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i]
  indexing, quotient, remainder) queue separately per design doc audit.
- feedback_totality_by_omission discipline anchor explicit.

Brief now matches feedback_totality_by_omission discipline + design doc
recommendation. No substrate prerequisite; dispatchable immediately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure

Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a
pattern: I authored R2 worker briefs without fully reading each design
doc's Director-actionable recommendation. Pre-emptively re-verified
unenumerated-effects against design doc §Q6 to catch the same family
of error before reviewers do.

Findings: brief was substantively close but missing 3 of 8 design-doc
reqs:
- Req 3: Resource-threading discipline applied to existing primitives
- Req 5: reread(key) primitive in std/ as explicit Slice item (was
  only mentioned in tests)
- Req 7: Asymmetric-tightening worked example in PR body

Plus: Slice didn't cite the canonical lens path
src/v3/lenses/effect_enumeration.dag from design doc.

Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6
specifies 4 specific STOPs (path-decision-escalation, pure: Bool
carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP)
that I had elided.

Reframed Slice as 8 numbered reqs matching design doc verbatim;
STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs;
Acceptance enumerated per req.

This is the third reframe in the unhandled-bugs series — same
feedback_verify_thesis_claims violation each time. The pattern
suggests Director-side R2 brief authoring should ALWAYS read each
design doc's §Director-actionable / §Q-recommendation in full first,
not assume.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options

Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)"
listed as a worker-pick option violates THESIS.md substrate-shape
lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality |
Instantiation) are canonical (per #811 thesis additions and #827 PM
review); a 7th is a C1 stop signal requiring failed-dissolution
evidence + Director substrate-design call, not autonomous worker pick.

Removed the "new TypeConnective variant" option; replaced with
`inhabits`-edge-shape carrier as third option (audit-time check). The
explicit STOP-AND-ESCALATE clause now states: 7th connective is the
precondition for failed-dissolution-evidence + Director substrate-design
call, not a worker path.

feedback_verify_thesis_claims still in play — should have grounded
substrate-shape options against the THESIS lock before listing Opaque(T)
as worker-autonomous. Pattern continues; reading source-of-truth before
authoring options is the discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place)

Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter
already exist at dag.rs:186, :217 — explicitly authored for the
R2 Dimensions consumer per the doc comment at dag.rs:148-160.
phantom_unit_mismatch already wired at infer.rs:1057, :1132. The
substrate is fully landed; my brief framing it as 'producer sub-lane
to land carrier' is wrong on the same feedback_audit_adjacent_authority_first
violation that hit nested-optional / unhandled-diagnostic / unenumerated-
effects.

Reframed the substrate-side brief as no-op / closed-by-audit:
- Documents the audit receipt (5 sites confirming substrate exists)
- States the lane is closed
- Routes T-Modeling Dimensions consumer to dispatch immediately
  against the existing carrier
- Records the lesson: 'always grep substrate before authoring
  producer briefs' — discipline doesn't end at brief boundaries.

Updated r2-modeling-dimensions-phantom-worker.md correspondingly:
- Changed gating from 'do not dispatch until producer signal' to
  'NOT GATED — dispatch immediately'
- Read-first updated with concrete dag.rs/infer.rs cites
- Slice §1 changed from 'confirm producer signal' to 'verify
  substrate at HEAD'
- STOP reframed: existing carrier extension would need Substrate
  Manager call, not autonomous worker pick

Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit
both verified — no existing substrate (no is_nominal_opaque /
MagnitudeBound patterns in dag.rs); both still legitimately
producer-side work.

Pattern is now four reframes deep on the R2 spin-up wave. The lesson
saved is structural: read source-of-truth before authoring options.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority

Codex BLOCKING on #836: my new R2 spin-up brief duplicates the
existing t-substrate-cardinality-int-lit-worker.md, which carries
the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64)
stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane).
Single-authority violation per INVARIANTS P2.

Same feedback_audit_adjacent_authority_first failure as parametric-
algebra-for-Dimensions reframe (4 hours ago): assumed substrate
authority didn't exist; should have grepped docs/briefs/ before
authoring. This is the SECOND R2 spin-up substrate brief closed
as redundant — the discipline lesson is structural.

Reframed brief as no-op routing doc (documents the audit receipt;
routes consumers to the existing authority); updated
r2-modeling-int-lit-magnitude-worker.md to cite
t-substrate-cardinality-int-lit-worker.md instead.

Pattern across the R2 spin-up wave reframes (5 now):
1. nested-optional gating-on-substrate (substrate already past
   cardinality bridge)
2. unhandled-diagnostic predicate-entailment default (design doc
   recommends totality-by-omission)
3. unenumerated-effects 8-req design-doc elision
4. parametric-algebra Producer (Declaration.phantom_params already
   authored explicitly for this consumer)
5. cardinality-for-int-lit Producer (existing brief …
briansrls added a commit that referenced this pull request Apr 29, 2026
… + bin-shim emit pattern) (#1176)

* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation)

Director-authored amendment following the 2026-04-24 escalation from PR
#693 (sub-child sharp-bear-829 under Surface Manager).

Two edits:

1. New "Class 5 Gap 3 — port-carried field values in data bodies"
   row in the 2026-04-21 post-merge-debt section. The substrate gap was
   documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP
   ledger row for cross-lane visibility. PR #693's execution surfaced it
   as the blocker on sub_charclass_in_std_unicode phase-2.

2. Retract the "ready-to-dispatch (no substrate capability gap)" claim
   on the Character-level row, annotate phase-1 landed via PR #693
   (CharClass vocabulary + Rust-mirror structural scanner path), and
   point phase-2 at the new Class 5 Gap 3 row.

Codifies the audit pattern: "this consumption gap has no substrate
capability gap" claims must be verified by attempting the retype before
the claim lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main

* docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review)

* docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review)

Row title still said 'consumption gap, not substrate gap' while the
body block retracted that claim and cited Class 5 Gap 3 as a substrate
dependency for phase-2. Title now matches body: mixed classification,
consumption for steps 1+3, substrate for step 2.

* docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit)

gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining
gap" description was wrong: field-level shapes (nested records, list
literals, declaration refs, Var refs, sum-variant literals) are
supported today via FieldValue variants + lower_structural_field_value
(dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the
top-level ValueBody boundary (non-scalar, non-record top-level bodies).

The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself
stale: it describes the pre-PR-B-unwind shape where FieldValue was
LiteralBits-only. PR-B's unwind extended FieldValue to carry
Reference / Record / List / Variant, moving the gap to ValueBody.

Two fixes:

1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody
   boundary, point at code paths (dag.rs, lower.rs) as live authority,
   flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass
   blocker classification to "provisional pending reproduction."

2. Update the Character-level row's phase-2 block to name that the
   specific shape of the CharClass failure needs concrete reproduction
   from the escalating sub-child before the blocker is finalized.

Recursive audit-pattern instance: the row I wrote to codify "verify
live state before claiming substrate gap" itself failed to verify live
state. Both incidents (2026-04-23 original row + 2026-04-24 my
retraction row) are now cited in the audit-pattern sub-note as
examples of the same discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33

Three substantive fixes addressing internal-consistency gaps in the cascade
promotion PR caught by codex review at sha 0d6e7c33:

1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane
   acceptance bullets and Hand-Rust census paragraph in line with the
   updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero
   (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is
   retracted under 0-floor with explicit migration to ExecuteCommand-based
   .dag TestClaim declarations.

2. docs/design-pure-bootstrap-zero.md promotion section — converted from
   future-tense ("This doc is PROPOSAL until promoted… promotion is a
   single Director-authored cascade PR…") to historical past-tense
   promotion-receipt framing ("This doc was PROPOSAL until promoted;
   promotion was a single Director-authored cascade PR that did all of the
   following atomically…"); blocking-clause struck through and resolved
   inline. Banner cites PR #782 explicitly.

3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_
   profile excluded (Map<String, AlgebraProfile> body, not list-of-sum;
   needs distinct ValueBody::Map substrate work, tracked separately as a
   future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass
   phase-2 + Engine sharpened-(b) pilot enumeration), both sharing
   list-of-sum substrate work. Lane table, dependency DAG, and capacity
   summary updated for consistency (slot count 9-13, was 10-14).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities

Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade
self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22
explicitly names THESIS.md and "any other authority docs" as required
retraction targets; the prior diff updated ROADMAP + r2-structure + design
docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting-
manager.md pointing at the now-SUPERSEDED ≤5-floor framing.

Files:

- THESIS.md (5 prose blocks updated):
  - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests
    migrate to ExecuteCommand-based .dag TestClaim declarations.
  - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag.
  - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor
    target citing design-pure-bootstrap-zero.md as live authority;
    hand_maintained_src list shrinks to empty set.
  - :301-318 — Tests-are-structural-data block: residual carve-out retracted;
    predicate name pb_rust_tests_outside_residual_zero retained as
    housekeeping (semantically the residual is empty under cascade).

- docs/thesis/compiler-std-consolidation.md (5 references):
  - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes
    design-pure-bootstrap.md (SUPERSEDED).
  - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process
    lane named as the dissolution trigger for bootstrap.rs itself.
  - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md.
  - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority
    re-cited.
  - :185 Related docs link.

- docs/briefs/r1-selfhosting-manager.md (active dispatch brief):
  - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5);
    T-PB-B residual carve-out retracted; predicate names retained for
    housekeeping; cascade-promoted authorities are source of truth.
  - Slice descriptions for T-PB-A / T-PB-B updated inline.
  - Framing-question + ask updated to 0-floor / no-residual framing.
  - Day-1 + up-to-director hand-off bullets updated.
  - Working-state checklist :111 ≤5 → 0 with cite.
  - Decisions log :164 ≤5 → 0-floor target updated.

- docs/r2-structure.md §2 design call (RETRACTED block):
  - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through
    in entirety (both Option A sharpen-and-keep and Option B rename are
    moot under 0-floor). Section preserved as audit-trail historical
    context.
  - Background-doc index: self-hosting anchor updated to
    design-pure-bootstrap-zero.md as live authority.

- docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per
  non-blocking suggestion):
  - Banner cites cascade promotion PR #782 explicitly.
  - New paragraph: "Treat all numeric floors below as retracted" with
    explicit lines named that quote in isolation (table row, body prose
    references). Prevents re-quoting from this doc as live authority.

Cascade is now atomically consistent across:
  THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔
  docs/thesis/compiler-std-consolidation.md ↔
  docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔
  docs/design-pure-bootstrap-zero.md (LIVE) ↔
  docs/design-pure-bootstrap.md (SUPERSEDED).

The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds
genuinely.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): correct ExecuteCommand runner-capability claim

Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation):
TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138
overstated live runner capability — claimed runner support landed in
PR #688/#741 with "emit Rust, invoke rustc on output, check exit code"
as a structurally-equivalent migration path. Verified against live
sources:

- src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema
  exists (declared via PR #678).
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5
  testgen harness allowlists ONLY `command == "true" && args.is_empty()
  && expect_exit == 0`.
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 —
  panics fail-closed on any other shape with explicit "ExecuteCommand
  shell shape is not supported here (runner-owned — do not treat as
  ordinary false)".
- src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no
  match arm for ExecuteCommand; falls through to ClaimResult::
  NotYetImplemented.

Reality: a TestClaim declaring rustc/python/go invocation is
structurally expressible as data today, but executing it is blocked.
Full arbitrary-command runner support is the PB-Runtime lane's
deliverable.

Files updated:

- TESTING.md:195 — capability state callout with file:line citations;
  "Full runner support — arbitrary command + args (rustc/python/go) with
  exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor
  program)." Bullet about migration shape preserved as the cascade-named
  successor pattern, not as a live capability.
- TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane
  lands the ExecuteCommand runner extension" as an explicit precondition.
- docs/design-pure-bootstrap-zero.md:138 — same correction for the
  matching prose, with PB-Runtime named as the runner-extension
  dependency for boundary-test migration.
- ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner
  foundation in #688/#741 with `true`-no-args allowlist only — full
  arbitrary-command runner support deferred to PB-Runtime lane,
  blocking the actual boundary-test migration." Dependencies column
  extended to "DB-15 + T-TestGen + PB-Runtime".

The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still
holds for atomic-cascade-across-authority-docs; this commit closes the
remaining capability/claim mismatch flagged by codex.

(Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still
SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief

Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation).
The prior banner contained:

> "Operationally R1 closure may still ship before the 0-floor is reached
>  — the ratchet ensures the trajectory; the gate's acceptance number is
>  what shifts."

This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0.
Two competing gate semantics in the cascade is exactly what the
atomic-cascade clause forbids.

Replaced with single-authority-honest framing:

> "R1 closure now requires the 0-floor target by gate semantics: T-PB-A
>  and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade
>  promotion changed their acceptance numbers to 0; R1 cannot close
>  while the SG-0 census carries non-zero hand-Rust."

Plus minor sharpening:
- "T-PB-A's non-test target is 0" → "non-test acceptance target is 0
  per ROADMAP.md:67" (cite the authority).
- T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep
  the capability-state honesty consistent with the recent fix wave.
- Predicate-rename housekeeping line moved into banner ("post-cascade
  housekeeping, not a pre-promotion blocker") — was implicit before.

The brief now genuinely inherits the cascade-promoted gate; no
competing release authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 second-wave worker-escalation fixes

Four substantive worker STOP-AND-ESCALATEs from briefs landed in
PR #797. All four worker recommendations correct; each needs a
Director call + brief update.

## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate

Worker correctly identified that brief req 2 (declared-effect carrier
as part of fn type signature, per feedback_no_annotations) requires
net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at
src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots.
Without parser surface, every user function would have
declared_effects = [] while inference returns non-empty — lens fires
EffectLeakageError everywhere on enable. Worker rejected power-through
and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map
parser split).

Director picked split:
- NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md
  Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface
  syntax + lookahead + body parser + lowerer extension + exhaustive-match
  audit + coproduct dissolution receipt.
- MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to
  post-parser-extension scope. Pre-flight check NOT a parser-extension
  step; STOP if parser sub-lane PR not merged.

## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping

Worker found load-bearing evidence at infer.rs:3693-3703: DB-11
deliberately strips refinements at operator dispatch as a designed-in
fix for symmetric-operators failure mode. Brief's "attach where b != 0
as a proof for a / b" directly contradicts this design choice. STOP-3
(where-clause conflict with DB-11) is real; STOP-1 (substrate scope)
needs net-new substrate (per-operator partiality fact + predicate-
entailment check + asymmetric per-operand refinement-honoring) — M+
minimum. ownership_lens precedent in original brief is post-hoc
observability, not proof carrier.

Worker recommended redirect to design/scoping per nested-optional
precedent. Director picked redirect.

Brief fully rewritten as design/scoping with four-question structure:
(1) DB-11 interaction analysis; (2) substrate proposal for proof-or-
totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes
with acceptance-theatre risk on user-defined-total-wrapper-only);
(4) Director-actionable recommendation. Output is doc PR.

## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C)

Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int)
with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136
closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b)
i128 implementation requires either path 1 (hierarchy refactor —
contradicts non-goal) or path 2 (regen lie between substrate and
emit — violates discipline). Worker leaned option (C) re-scope:
land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke)
to a sibling sub-lane that does proper Int128/Word128 substrate work.

Director picked option (C). Brief req 1 re-scoped to drop canonical-
carrier-widening; lane value comes from range facts + reconciliation
narrowing + out-of-range diagnostic against existing i64. Req 4
explicitly deferred with sibling-sub-lane reference. Sibling sub-lane
NOT to be authored or implied in this PR; tracked separately.

## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change)

Worker correctly STOP'd per the brief's own pre-flight check: parser
sub-lane has not landed; SurfaceExpr::Map not on main. Director
authorized cross-lane reassignment: wise-boar-480 takes the parser
sub-lane (t-substrate-valuebody-map-parser-worker.md) since they
already have full investigation context. No brief changes needed; the
routing decision is in the dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope

Resolves codex P2 inline at sha e35103fad on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer
carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still
required widening LiteralBits::Int(i64) to an unbounded carrier and
passing the i64::MIN smoke. Internally unsatisfiable.

Fix:

- Slice section retitled "range facts + reconciliation narrowing
  (against existing i64 carrier)" with explicit note about the
  re-scope.
- Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly
  forbids touching LiteralBits::Int shape, dag_scalar_generated.rs
  regen for that variant, or tokenize i64 parse path.
- Slice steps 2-5 reframed: range facts use i64-representable
  magnitudes; reconciliation narrowing uses existing i64 carrier;
  diagnostic only for i64-representable out-of-range; smoke tests
  for req 5 only (req 4 i64::MIN deferred).
- Acceptance checklist updated:
  - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as
    re-scoped/deferred.
  - LiteralBits::Int(i64) carrier untouched (no widening; no
    parallel; no shape change).
  - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference.
- STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the
  carrier" — explicit STOP if execution surfaces range-fact narrowing
  requiring carrier-widening; that's the boundary the re-scope drew;
  belongs in sibling Int128/Word128 sub-lane.

Brief now consistently treats carrier-widening as out-of-scope across
all sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty

Resolves codex BLOCKING #1 at sha e35103fa on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier
but req 2 required range facts using "the SAME magnitude carrier
as req 1" — meaning i64-typed range bounds. u64's max (2^64-1)
doesn't fit in i64; range fact for u64 would have to truncate,
omit, or mirror in Rust (representation drift). All three options
violate fail-closed declared-facts discipline (P1 / P3).

Fix:

- Req 2 rewritten to specify String-decimal representation:
  range_min_inclusive: String + range_max_inclusive: String fields
  on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127"
  for i8; "0"/"18446744073709551615" for u64).
- Explicit reasoning why String-decimal: u64's max doesn't fit in
  i64; binding range bounds to literal carrier forces truncation/
  omission/mirror-drift; all violate fail-closed declared-facts
  discipline.
- Bridge framing: String-decimal is pending the sibling Int128/
  Word128 sub-lane; both range bounds and literal payload migrate
  to typed carrier when that lands.

- Req 3 updated for String-decimal comparison semantics:
  reconciliation parses both bounds and literal magnitude into a
  common comparison space (i128 host comparison primitive — host
  narrowing, NOT carrier widening). Bounded by what the i64-typed
  literal can express; any i64-representable literal compares
  against any width's String-decimal bound. Carrier discipline
  preserved.

Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral)
is sha-stale — already resolved at 3e142d169.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed

Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback).
Real residual: req 2 specifies String-decimal range bounds (to cover
u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance
bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" /
"i64-representable magnitudes" for the range facts. Two incompatible
authorities for the same range-fact shape — would let a worker satisfy
the slice while truncating/omitting u64 bounds (P3 fail-closed
violation).

Fix:

- Line 31 (req 1 re-scope clarification): updated to explicitly state
  "range facts (req 2) use String-decimal representation (width-
  independent; covers u64::MAX which doesn't fit in i64)". Distinguished
  literal *payload* (stays i64) from range-bound *representation*
  (String) — both serve req 1's "no carrier widening" boundary.
- Line 44 (slice step 2): updated from "Range bounds use i64-
  representable magnitudes" to "Range bounds use String-decimal
  representation per req 2" with concrete example (u64 bounds).
- Acceptance bullet: updated from "Range facts on integer algebras
  (substrate-declared, not Rust-mirrored)" to add "using String-decimal
  representation ... width-independent; u64 bounds expressible without
  truncation."

The brief now consistently treats range bounds as String-decimal
across req 2, req 3, slice, acceptance, and the req 1 clarification —
no remaining authorities saying i64-typed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing

User + PM exchange 2026-04-25 surfaced that the in-flight effects
chain was importing wrong assumptions from external languages
(declared-effects-as-annotation + lens-vs-declaration check). Right
framing under gunbc's closed-system discipline is parallel to
complexity: every effect derives structurally from the composition
of typed primitive operations; nothing can hide because there's no
escape hatch; nothing needs annotation because the structure IS the
registry.

Four doc-only actions:

1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md.
   Frames the closed-system answer with PM's 5-behavior synergy
   table (Value/Transform/Branch/Loop/Bind as universal
   compositional-fold pattern). Four worked examples; aggressive
   reading on redundancy (compile-error-by-construction via
   referential-transparency proof; reread() primitive for legitimate
   cases); implementation-brief shape in §Q6.

2. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md.

3. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md.
   Notes Fn→Arrow refactor brief stays dispatchable as independent
   value.

4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by-
   construction framing replaces lens-detection framing.

Memory file feedback_closed_system_effects.md saved separately;
cross-link added to feedback_construction_over_ratchets.md.

Net cost: doc-level cleanup. Zero substrate code rework. Foundation
(OperationEffect + service-call infrastructure + 5-behavior
substrate) already exists.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect

Per PM convergence review on #808 + user's deeper 2026-04-25 framing:
the closed-system framing landed in #808 retired the user-facing
annotation but kept OperationEffect taxonomy as substrate-level tagging.
User's deeper framing: the taxonomy ITSELF is parallel-representation —
operations are intrinsically read-shaped or write-shaped via their
TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns-
derived-value-only → read). Tagging operations with Read | Upsert |
Create | Append | Delete names what the structure already says.

Three changes:

1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as
   normalized view, or retire as parallel-representation?"
   - Two paths: (i) tags derived from signature shape (acceptable
     normalized view) vs (ii) tags declared per-primitive (parallel-
     representation; retire).
   - Audit-as-existence-check (Q4 req 2 reframed): all effectful
     primitives derive cleanly from signature shape → path (i); any
     primitive needs hand-declared tag → path (ii) by existence proof.
   - Director default: path (ii). Logging primitives that return Unit
     are likely the audit's existence-proof.
   - Two design-question resolutions: (a) external effects not in
     return type → resource-threading discipline (typed param returned
     modified, IO-monad-without-the-monad pattern); (b) transactional
     grouping → derived structural fact from Bind composition + typed
     transaction primitives.

2. Q4 reqs revised: req 2 from "tag every primitive with explicit
   OperationEffect signature" to "audit-as-existence-check that every
   primitive's type signature derives the right effect classification";
   req 3 added (resource-threading discipline); req 6 added
   (transactional-pattern lens). Req 1 (effects lens) anchors on
   operation type-signature shape, not on hand-declared tags.

3. THESIS:345-347 amendment strengthened — "operations are
   intrinsically read-shaped or write-shaped via their type-signature
   shape; consumers walk the signatures directly; there is no parallel
   taxonomy or annotation layer to declare or maintain. Tracking
   effects as a separate enumerated concept IS the bug pattern,
   dissolved by construction." Plus references to resource-threading
   discipline + transactional grouping as derived structural fact.

Memory file feedback_closed_system_effects.md updated to reflect the
deeper framing (type-signature-shape, not taxonomy-tagging) +
resource-threading discipline section + transactional-patterns
section.

Net cost: doc-only delta on top of #808. Substrate retirement
(OperationEffect enum + derive_op_effect + idempotency.dag re-anchor)
deferred to the audit-as-existence-check phase of the implementation
brief; surfaced as Q5.5 OPEN CALL.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage

Resolves codex BLOCKING at sha d49ce79a on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real:
the prior text claimed service primitives "already carry typed effect
signatures" presenting future audit-state as current substrate fact
(P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the
OperationEffect line but left a parallel over-claim on the new
"signature-shape coverage" framing.

Fix: Q4 substrate-state listing rewritten to honestly distinguish:

- Live: Behavior enum + substrate foundation (the principle that
  operations should carry signature shape).
- Incomplete: signature-shape coverage across actual primitives.
  HTTP-derived primitives carry implicit shape via derive_op_effect's
  method-table; logging/mutation primitives that return Unit or don't
  thread their target resource do NOT carry the structural shape that
  would express read-vs-write. Achieving full coverage is required
  work under reqs 2 + 3, not a current fact.
- Pending audit-as-existence-check: OperationEffect + derive_op_effect
  (path (i) vs (ii) per Q5.5).

Honest live-state callout added explicitly: "the closed-system
FOUNDATION (5 behaviors + DAG substrate + the principle that
operations should carry signature-shape) is live. The IMPLEMENTATION
COVERAGE across all effectful primitives is partial. Req 2 + req 3
are the work that closes the gap."

Brief now distinguishes principle-is-live (foundation) from
coverage-is-partial (audit work) without conflating them.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim

Per PM follow-up review on #808 + user's stronger discipline framing
("substrate must make bypass structurally impossible at every layer
of the transport stack"): the closed-system claim is honest only when
typed primitives ARE the path. Today two structural holes exist where
bypasses sidestep the typed-primitive substrate. Both surfaced
explicitly as Q4.5 pre-conditions — load-bearing for the lens's
coverage claim.

Three changes:

1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed-
   system claim)" inserted between Q4 and Q5:

   P1 — Extdeps typed-primitive consumption structurally enforced.
   Substrate must make `messages: Json` impossible to declare in
   service definitions; typed `LlmMessage` / `ContentBlock` /
   `GitHubAuthToken`-with-full-scopes are the only path. Tracked
   debt at ROADMAP.md:153-154 (LLM provider flattening) +
   `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded).
   Required prereq for full lens coverage; lens can land first +
   surface structural-coverage-gap diagnostics on bypass surfaces
   so the gap becomes visible rather than silent.

   P2 — `ExecuteCommand` fully materialized as typed runner
   primitive. TESTING.md (post-#782) committed to 0-residual but
   ExecuteCommand isn't fully materialized; deleting Rust boundary
   tests creates verification gap. Already named under PB-Runtime
   in Zero-Floor; signal pending. Pre-requisite for ANY Rust
   boundary-test deletion.

2. Old leftover duplicate Q5 section deleted (artifact from prior
   Q5/Q5.5 reshape; second copy of asymmetric-tightening text was
   in the file alongside the earlier Q5 instance).

3. Worker-discretion-vs-Director-call section in Q4.5: lens
   implementation worker dispatchable now (reports gaps as
   findings); P1 closure is substantive substrate work touching
   extdeps (dedicated lane); P2 closure is PB-Runtime (signal
   pending).

Net: design doc now honestly distinguishes principle-is-live
(Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs
named explicitly). The closed-system claim has explicit pre-
conditions documented; implementation brief discovers them as
known dependencies, not as STOP-AND-ESCALATEs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default

Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two
real residuals after the Q5.5 reframe:

1. Q6's reqs/STOPs/acceptance still framed under path (i) — said
   "audit + tag std/ primitives — every effectful primitive carries
   an explicit OperationEffect signature." Directly contradicted Q4
   (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment
   ("there is no parallel taxonomy to declare or maintain"). Worker
   reading Q6 in isolation would author the retracted shape.

2. Capacity / sequencing table line about "audit lane (tag std/
   primitives with effect signatures)" carried the same stale
   framing.

3. Q6 STOP "primitive performing side effects without an
   OperationEffect tag" assumed tag-as-authority; under path (ii)
   the STOP shape is "primitive whose signature doesn't structurally
   reveal its effect."

Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale
(already fixed at f073aa95e Q4.5 commit).

## Q6 fixes

- Reqs renumbered + reframed:
  - Req 1 anchors on operation type-signature shape (not hand-declared
    OperationEffect tags); composition reads from signature shape per
    Q2 table.
  - Req 2 changed from "audit + tag every primitive" to
    "audit-as-existence-check" — verify signature-shape coverage; ANY
    primitive needing a hand-declared tag IS the existence-proof for
    path (ii) retirement.
  - Req 3 added: resource-threading discipline applied to existing
    primitives (logging that returns Unit gets reshaped per audit).
  - Req 6 added: transactional-pattern lens (Bind composition +
    Transaction → Transaction').
  - Req 7 added: asymmetric-tightening worked example in PR body
    (per claude review observation; the one place declaration-shaped
    surface re-enters).
  - Req 8 (was 5): tests now reference signature-shape derivation
    explicitly, not tag lookup.
- STOPs reframed:
  - "OperationEffect retirement decision" — audit produces path (i)
    vs (ii) verdict; substrate retirement is its own dedicated
    sub-lane; this lane does NOT absorb it.
  - Pure/impure carrier STOP notes that "pure" should also derive
    from signature shape (pure functions don't return modified
    resources) — so the STOP itself may dissolve under further design.
  - Q4.5 P1 explicitly NOT a STOP — lens reporting structural-
    coverage-gap on extdeps bypass surfaces is the lens delivering
    its foundation-gap-visibility value.
  - Q4.5 P2 explicitly independent — lens doesn't depend on
    ExecuteCommand materialization.
- Acceptance extended: lens reports gap diagnostics on P1 bypass
  surfaces; audit produces existence-proof verdict for Director
  re-decision; asymmetric-tightening worked example in PR body.

## Capacity / sequencing table

Replaced "1 audit lane (tag std/ primitives with effect signatures)"
with "1 audit-as-existence-check lane (verify primitives' signature-
shape coverage; NOT 'tag every primitive') — produces the path (i)
vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2
prereq lanes to the net summary. Closing line: "The taxonomy-
retirement scope (substrate-side) is not in this lane — it's
surfaced by audit and routed to dedicated retirement lane if path
(ii) wins."

Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity
table. Worker reading Q6 in isolation now sees path-(ii)-default
framing matching Q4 + Q5.5 + THESIS amendment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792

Resolves codex inline BLOCKING at sha 191be310 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150.
Real: my Q4.5 P2 framing described ExecuteCommand as still
NotYetImplemented (M1.5 allowlist + Rust TestRunner returning
NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand
extension before this PR's authoring. TESTING.md:195 capability-state
callout confirms:
- Rust TestRunner + M1.5 testgen harness share one std::process path
  for arbitrary command + args + expect_exit_code.
- M1.5 allowlist + fail-closed panic retired.
- Distinguishable ClaimResult::Fail messages for spawn / timeout /
  policy / exit-mismatch.
- Linux unshare(1) namespace isolation on host-allowing systems.
- T-PB-B-1 boundary migration example landed.

Fix:

P2 section rewritten:
- Header retitled "ExecuteCommand runner primitive: LANDED (PR #792);
  residual is bulk-migration."
- Status update naming PR #792 + the post-#792 capability state
  (allowlist retired, etc.).
- Honest acknowledgement: "My earlier P2 framing was stale."
- Residual narrowed to bulk-migration of existing Rust Command::new
  boundary tests (tracked as ROADMAP residual, not lens prereq).
- Sequencing reframed: P2 was always orthogonal to the effects lens
  itself; bulk migration proceeds at its own pace; lens not blocked.

Q4.5 footer updated:
- "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via
  #792; only consumer-side bulk migration remains)"
- Worker-discretion-vs-Director-call P2 line updated: "runner
  primitive landed; only consumer-side bulk migration remains;
  tracked as ROADMAP residual, independent of the lens."

Q6 STOP for P2 updated:
- "the lens itself doesn't depend on P2; only TESTING.md's 0-residual
  claim does" → "runner primitive landed via PR #792 (post-Q4.5-
  authoring update). The lens itself never depended on P2; bulk
  consumer migration is residual ROADMAP work and remains independent
  of this lane."

Brief now reflects live state. The closed-system claim's prereq
landscape is honest:
- P1 (extdeps typed-primitive consumption): real prereq, tracked
  debt at ROADMAP:153-154.
- P2 (ExecuteCommand runner): satisfied via #792; bulk migration is
  consumer-side residual, not foundation work.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale

Resolves codex non-blocking finding at sha bcac41bb on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real
residual: capacity-table line still listed P2 as "`ExecuteCommand`
materialization" prereq + framed both P1 and P2 as "pre-existing
tracked-debt" — but my prior 57a9b1318 fix established that PR #792
already landed the runner primitive, so P2 is no longer a
materialization prereq.

Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq)
from P2 (residual, not prereq):

  - P1: extdeps typed-primitive consumption — pre-existing tracked
    debt at ROADMAP:153-154; load-bearing for the lens's full-coverage
    claim.
  - P2: ExecuteCommand runner primitive landed via PR #792; only
    consumer-side bulk migration of existing Rust Command::new
    boundary tests remains (tracked as ROADMAP residual, independent
    of the lens; not a materialization prereq).

Brief now consistently treats P2 as bulk-migration-residual across:
- §Q4.5 P2 section header (LANDED via PR #792; residual is
  bulk-migration).
- §Q4.5 footer (P2: runner primitive landed; only consumer-side
  bulk migration remains).
- Q6 STOP for P2 (runner primitive landed; bulk migration is
  residual ROADMAP work).
- §Capacity / sequencing impact (P2 as residual, not prereq).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349

Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated
target-grounding prose; the matching extdeps typed-primitive bypass
entries (LLM service flattening, GitHub auth model bypass) live at
ROADMAP.md:348-349.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix third stale ROADMAP citation at line 271

Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence
at line 271 in the §Q4.5 capacity table. Now consistent with lines
139 and 173 (ROADMAP.md:348-349).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity

Codex flagged 'Effect-signature tagging on std/ primitives' as potentially
contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240)
already explicitly say 'NOT tag every primitive' — but the cross-manager
line used sloppy wording. Reworded to make explicit that the audit walks
signature shape; no parallel tag added.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5

- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)

B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).

B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — drop incoherent inner-fallback non-goal

Codex P2: the non-goal line excluding the inner declaration().name
unwrap_or_else fallback contradicted Slice step 2, which replaces the
whole chain with let-Some-else-return. Both fallbacks are in scope by
construction; remove the contradictory non-goal.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives

PM REQUEST_CHANGES: §Frame listed '4 type connectives
(Conjunction | Disjunction | Cardinality | Bit)' which contradicted
the canonical thesis source. Replaced with the canonical 6
(Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per
docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary
closes here'. Also removed 'typed substrate carriers' from the
vocabulary list — substrate carriers are defined using the vocabulary,
not part of it. Added a clarifying note that B4's carriers
(DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are
typed declarations composed from the vocabulary, not vocabulary
extensions.

Per feedback_verify_thesis_claims: brief framings citing thesis
structure must ground in the canonical source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority

Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of
naming the live substrate authority. Two coordinated fixes:

1. §Read first cites src/v3/std/substrate.dag (live .dag substrate
authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel
meta-type — already exists with consumers in verification.dag,
emit_model.dag, python.dag).

2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing
DeclarationRef'. The work is consumer migration + any role-extension
layer the audit reveals, NOT designing or landing the carrier.

Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers)
keep their 'new' framing but explicitly require sub-briefs to grep
src/v3/std/ + src/v3/spec/ for existing authority before authoring
'design and land' framing — per feedback_verify_thesis_claims +
feedback_emitter_workaround_is_gap_symptom.

Acceptance + sub-brief dispatch order updated to reflect B4.1's
consumer-migration shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — tighten Phase 1 umbrella sentence

The umbrella 'Land the typed carriers into src/v3/std/' framing was
stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced
with audit-first wording that covers both the consume-existing case (#1)
and the design-and-land case (#2-#4 if their audits show real gaps).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording

Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands'
which conflicted with the post-reframe reality that B4.1 consumes the
existing DeclarationRef. Updated to 'consumes or lands' with explicit
existing-authority citation and audit-pending caveat for B4.2-B4.4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — soften regression-test requirement (3 worker bounces)

Three consecutive B1 worker dispatches (zesty-crane-890 cursor →
valiant-boar-498 codex → cool-lynx-395 cursor) archived without
opening a PR. Likely friction point: brief Slice step 4 asks for a
unit test that constructs a Dag with an orphan variant declaration,
but emit.rs has zero existing #[test] precedent — emit testing
happens via integration fixtures. Workers see 'build novel test
harness' inside what's billed as an S-scope fix and bounce.

Per feedback_construction_over_ratchets: when a brief has friction,
fix the brief, don't ratchet the worker.

Softened step 4 + acceptance: regression test stays optional. If
test setup requires novel scaffolding, route the gap to follow-up.
The structural fail-closed at step 2 is the load-bearing change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt

PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description'
is too weak; PR descriptions don't survive squash-merge cleanly.

Two coordinated edits:
1. Slice step 4 — explicit substrate-signal framing: skipped test
   means emit-side hermetic-unit-test infrastructure is the missing
   substrate (feedback_emitter_workaround_is_gap_symptom).
2. Acceptance — require ROADMAP debt row (new or existing) with
   named dissolution trigger, referenced in PR body. Converts the
   skip from PR-local note (transient) into tracked debt (durable,
   dispatchable).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124

Codex BLOCKING: my earlier softening claimed emit.rs had no #[test]
precedent — wrong. The module has #[cfg(test)] mod tests at line 3124
with 12+ tests using compile_to_dag(source, filename) as harness
(e.g., go_struct_fields_render_with_separators :3143,
shared_walk_to_disj_finds_match_scrutinee_sum_type :3195).

This is a feedback_verify_thesis_claims violation on Director-side
brief authoring — claim made without grep verification.

Fix: restore step 4 as required, with explicit precedent citation.
Worker constructs the failure case via the existing harness
(direct Dag, fixture string, or BranchPattern exercise; worker's
call on cleanest path). STOP-AND-ESCALATE only if construction
proves materially harder than precedent suggests, in which case
that escalation surfaces a real substrate gap and warrants ROADMAP
debt — but the default is 'add the test.'

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites)

Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but
emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded
to 'several using compile_to_dag'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue

Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this
is Wave 1 of Director's 14-brief authoring queue, covering B4 program
internals.

Authored:
- b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) —
  replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag")
  fold-skip with structural template-formal carrier; mandatory
  authority audit per feedback_audit_adjacent_authority_first.
- b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) —
  replaces §0.6 emit.rs bind/branch.span.file equality with typed
  BindEmitParticipation/BranchEmitParticipation roles populated at
  lowering; aligned with #824 worker's in-flight implementation shape.
- b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4
  of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with
  typed substrate authority; explicit pre-promotion-constraint
  disposition (single-authority vs authority+tracked-debt) addresses
  parallel-representation risk surfaced on #825.
- b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) —
  names B4.5-B4.12 Phase 2 sites with carrier dependencies,
  cross-program coordination notes, and skeleton-brief template;
  full per-site briefs author at dispatch time per #827's
  Substrate Manager ownership.

Cross-cutting discipline applied per inbox #828 reply:
- feedback_audit_adjacent_authority_first (mandatory grep before design)
- feedback_no_textual_enforcement_bridges (no replacement sentinels)
- feedback_parallel_representation_debt (explicit if shape (b))
- feedback_construction_over_ratchets (no parity-by-runtime as primary)
- feedback_coproduct_dissolution (receipts for new variants)

Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling
worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3)

Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue.
Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by
Modeling Manager's Wave 3 worker briefs (gated on these landing).

Authored:
- r2-substrate-cardinality-for-int-lit-subset.md (M) — produces
  magnitude carrier consumed by T-Modeling int-lit. Coordinates with
  PR #806's prior cardinality work; mandatory authority audit guards
  against #796's rejected IntLiteralMagnitude shape resurfacing.
  Open design questions: magnitude representation, reconciliation
  narrowing point, i64::MIN representability.
- r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces
  nominal-opacity carrier consumed by T-Modeling Secret<T>. Open
  design questions: carrier shape (flag/connective/sealed-accessor),
  generic-walk discipline, accessor gating.
- r2-substrate-parametric-algebra-for-dimensions-subset.md (M) —
  produces phantom-parameter carrier consumed by T-Modeling
  Dimension<Carrier>. Open design questions: carrier shape,
  type-equivalence rule, algebra-method dispatch, lifting/coercion.

All three:
- Scoped narrowly to their paired R2 consumer; not full
  substrate-capability lanes.
- Mandatory pre-author authority audit per
  feedback_audit_adjacent_authority_first.
- Cross-program readiness signal pattern from #827's manager rework.
- Coproduct dissolution receipts required for any new variants.
- Open design questions surfaced explicitly so Substrate Manager
  (or Director pre-spin-up) can resolve at dispatch time.

Wave 3 (T-Modeling worker briefs × 4) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4)

Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue.
Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each
gated on a Substrate Manager readiness signal (Wave 2 producers).

Authored:
- r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2
  cardinality-for-int-lit; moves narrowing from tokenizer to
  reconciliation; MagnitudeOutOfRange diagnostic per C-8.
- r2-modeling-secret-graduation-worker.md — gated on Wave 2
  nominal-opaque-for-Secret; authors Secret<T> + gated accessors
  (redact, compare_in_constant_time); C-8 diagnostic on non-gated
  access; signals Impossible-Bugs Manager on close (thesis claim
  covered).
- r2-modeling-dimensions-phantom-worker.md — gated on Wave 2
  parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier>
  + core SI base units + algebra-method dispatch; cross-dimension
  arithmetic produces typed diagnostic; signals Impossible-Bugs
  Manager (thesis claim).
- r2-modeling-tokenizer-charclass-phase2-worker.md — gated on
  T-Substrate ValueBody-list/sum (#790); migrates tokenizer
  consumers to Char/List<Char>/CharClass canonical types; sibling
  consumer to Grounding Manager's Engine sharpened-(b).

All four:
- Explicit gating: 'do not dispatch until producer signal posts.'
- Producer/consumer signal pattern from #827.
- Cross-program signals to R2 Release Manager (Goal 2 closure)
  and Impossible-Bugs Manager (thesis-claim coverage).
- Spoofing regression tests: discipline anchor against
  feedback_no_textual_enforcement_bridges.

Wave 4 (T-ImpossibleBugs worker briefs × 3) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3)

Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue.
Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes,
consuming the existing design/scoping briefs as authority.

Authored:
- r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on
  cardinality refinement substrate (T-Substrate territory adjacent
  to int-lit / DB-11 alias-where). Implementation: structural normalize
  of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T??
  worker decision (reject vs normalize). Cites
  t-impossiblebugs-nested-optional-flatten-design.md as authority.
- r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated
  on Tier 2 substrate (predicate-entailment infrastructure; distinct
  from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes
  predicate entailment, (b) feedback_totality_by_omission dissolves
  partial primitives, (c) park. Worker decides at audit time. Cites
  t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority.
- r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate
  prerequisite per closed-system framing in design doc (#808). Audit-
  as-existence-check + lens implementation as compositional fold over
  5 behaviors; redundancy detection compile-error via referential
  transparency + reread() escape hatch; path (i/ii) decision on
  OperationEffect taxonomy retain-vs-retire (default retire). Cites
  design doc #808 as authority.

Cross-cutting:
- Each cites prior design/scoping brief as authority (the existing
  *-design.md / *-worker.md REFRAMED files).
- Explicit gating per #827 producer/consumer signal pattern; two
  briefs gated on substrate, one NOT gated (closed-system).
- STOP-AND-ESCALATE includes 'design brief assumptions don't hold'
  surfacing per feedback_thesis_gate_state_drift.

Wave 4 complete. Director's 14-brief queue done; awaiting PM portion
(6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4.4 — tighten Slice §3 per PM review on #836

PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b)
(authority + tracked debt parallel-rep) as autonomously acceptable
contradicts feedback_construction_over_ratchets +
feedback_parallel_representation_debt.

Tightened:
- Shape (a) is the only autonomous worker path.
- Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a
  regen-host-loader sub-lane decision; not authorable without explicit
  Substrate Manager approval citation in the PR body.
- Acceptance bullet requires the approval citation when shape (b)
  lands.
- STOP-AND-ESCALATE rephrased to make this explicit; permanent
  parallel-representation re-escalates even with manager approval.

This preserves shape (a) as autonomous; shape (b) becomes a
cross-manager design escalation, not a B4.4 implementation call.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief

Cursor review on #836 flagged the Read-first reference to
.claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md
as machine-specific (outside the repo, not resolvable from a normal
clone). Replaced with in-repo prose pointing at the design doc's
§Q1-Q3 as canonical authority — the discipline lives there in-repo.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs)

Codex flagged: src/v3/std/types.dag does not exist; the canonical
authority is at dsl/std/types.dag. Affected briefs (all from R2
spin-up Wave 2 + Wave 3):

- r2-substrate-cardinality-for-int-lit-subset.md
- r2-substrate-nominal-opaque-for-secret-subset.md
- r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs)
- r2-modeling-dimensions-phantom-worker.md
- r2-modeling-secret-graduation-worker.md

feedback_verify_thesis_claims violation on Director-side brief
authoring — assumed path without grep. Same family of error as
the earlier emit.rs precedent claim. Mass-replaced via perl;
verified no remaining stale refs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant

Codex BLOCKING on #836: my R2 worker brief gated nested-optional on
cardinality refinement substrate, but the design doc verifies v3 is
ALREADY past the cardinality bridge — TypeConnective::Cardinality
is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is
the carrier for Option. The dissolution is an UNGATED implementation
via substrate-constructor invariant.

feedback_verify_thesis_claims violation again — should have read the
design doc fully before assuming the substrate gate.

Rewrote brief to match design doc canonical sketch:
- Single predicate (cardinality_idempotent_target) owns the rule
- Single allocator (alloc_cardinality_decl) is THE substrate-constructor
- API closure on TypeConnective::Cardinality payload (modeling-discipline
  practice 6) — variant cannot be struct-init'd outside the allocator
- 3 hand-Rust + ~22 codegen call sites enumerated per design audit
- infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as
  the killer case for generic-instantiation paths
- Surface-syntax T?? decision left to worker (Director-lean: silent
  normalize)

Brief now dispatchable immediately, no producer signal needed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation

Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment
substrate path, but the design doc §4 explicitly recommends totality-by-
omission as the Director-actionable path. Predicate-entailment is M+ scope
that reopens DB-11's explicitly-closed asymmetric-strip design — design
doc explicitly discards it.

feedback_verify_thesis_claims violation again — same family as nested-
optional reframe. Should have read design doc §4 in full before assuming
the path ordering.

Rewrote brief to match design doc §4 follow-on shape:
- Primary path: per-class totality-by-omission (algebra retype + per-
  target realization migration). For Int/Int: OrderedRing.div retype
  at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 /
  python:486 + python_target.rs:680 helper).
- NOT predicate-entailment (out of scope; M+ + DB-11 reopen).
- NOT NonZero-typed-input (deferred to separate per-operand-variance
  substrate brief; STOP-AND-ESCALATE if chosen).
- Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i]
  indexing, quotient, remainder) queue separately per design doc audit.
- feedback_totality_by_omission discipline anchor explicit.

Brief now matches feedback_totality_by_omission discipline + design doc
recommendation. No substrate prerequisite; dispatchable immediately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure

Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a
pattern: I authored R2 worker briefs without fully reading each design
doc's Director-actionable recommendation. Pre-emptively re-verified
unenumerated-effects against design doc §Q6 to catch the same family
of error before reviewers do.

Findings: brief was substantively close but missing 3 of 8 design-doc
reqs:
- Req 3: Resource-threading discipline applied to existing primitives
- Req 5: reread(key) primitive in std/ as explicit Slice item (was
  only mentioned in tests)
- Req 7: Asymmetric-tightening worked example in PR body

Plus: Slice didn't cite the canonical lens path
src/v3/lenses/effect_enumeration.dag from design doc.

Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6
specifies 4 specific STOPs (path-decision-escalation, pure: Bool
carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP)
that I had elided.

Reframed Slice as 8 numbered reqs matching design doc verbatim;
STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs;
Acceptance enumerated per req.

This is the third reframe in the unhandled-bugs series — same
feedback_verify_thesis_claims violation each time. The pattern
suggests Director-side R2 brief authoring should ALWAYS read each
design doc's §Director-actionable / §Q-recommendation in full first,
not assume.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options

Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)"
listed as a worker-pick option violates THESIS.md substrate-shape
lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality |
Instantiation) are canonical (per #811 thesis additions and #827 PM
review); a 7th is a C1 stop signal requiring failed-dissolution
evidence + Director substrate-design call, not autonomous worker pick.

Removed the "new TypeConnective variant" option; replaced with
`inhabits`-edge-shape carrier as third option (audit-time check). The
explicit STOP-AND-ESCALATE clause now states: 7th connective is the
precondition for failed-dissolution-evidence + Director substrate-design
call, not a worker path.

feedback_verify_thesis_claims still in play — should have grounded
substrate-shape options against the THESIS lock before listing Opaque(T)
as worker-autonomous. Pattern continues; reading source-of-truth before
authoring options is the discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place)

Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter
already exist at dag.rs:186, :217 — explicitly authored for the
R2 Dimensions consumer per the doc comment at dag.rs:148-160.
phantom_unit_mismatch already wired at infer.rs:1057, :1132. The
substrate is fully landed; my brief framing it as 'producer sub-lane
to land carrier' is wrong on the same feedback_audit_adjacent_authority_first
violation that hit nested-optional / unhandled-diagnostic / unenumerated-
effects.

Reframed the substrate-side brief as no-op / closed-by-audit:
- Documents the audit receipt (5 sites confirming substrate exists)
- States the lane is closed
- Routes T-Modeling Dimensions consumer to dispatch immediately
  against the existing carrier
- Records the lesson: 'always grep substrate before authoring
  producer briefs' — discipline doesn't end at brief boundaries.

Updated r2-modeling-dimensions-phantom-worker.md correspondingly:
- Changed gating from 'do not dispatch until producer signal' to
  'NOT GATED — dispatch immediately'
- Read-first updated with concrete dag.rs/infer.rs cites
- Slice §1 changed from 'confirm producer signal' to 'verify
  substrate at HEAD'
- STOP reframed: existing carrier extension would need Substrate
  Manager call, not autonomous worker pick

Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit
both verified — no existing substrate (no is_nominal_opaque /
MagnitudeBound patterns in dag.rs); both still legitimately
producer-side work.

Pattern is now four reframes deep on the R2 spin-up wave. The lesson
saved is structural: read source-of-truth before authoring options.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority

Codex BLOCKING on #836: my new R2 spin-up brief duplicates the
existing t-substrate-cardinality-int-lit-worker.md, which carries
the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64)
stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane).
Single-authority violation per INVARIANTS P2.

Same feedback_audit_adjacent_authority_first failure as parametric-
algebra-for-Dimensions reframe (4 hours ago): assumed substrate
authority didn't exist; should have grepped docs/briefs/ before
authoring. This is the SECOND R2 spin-up substrate brief closed
as redundant — the discipline lesson is structural.

Reframed brief as no-op routing doc (documents the audit receipt;
routes consumers to the existing authority); updated
r2-modeling-int-lit-magnitude-worker.md to cite
t-substrate-cardinality-int-lit-worker.md instead.

Pattern across the R2 spin-up wave reframes (5 now):
1. nested-optional gating-on-substrate (substrate already past
   cardinality bridge)
2. unhandled-diagnostic predicate-entailment default (design doc
   recommends totality-by-omission)
3. unenumerated-effects 8-req design-doc elision
4. parametric-algebra Producer (Declaration.phantom_params already
   authored explicitly for this consumer)
5. cardinality-for-int-lit Producer (existing brief is autho…
@briansrls
briansrls deleted the session/royal-badger-316 branch June 1, 2026 18:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant