Skip to content

docs(briefs): debt-paydown + scaffolding-audit synthesis (2026-04-25 analyses → course of action) - #810

Merged
briansrls merged 9 commits into
mainfrom
session/keen-wren-319
Apr 25, 2026
Merged

briansrls merged 9 commits into
mainfrom
session/keen-wren-319

Conversation

@briansrls

@briansrls briansrls commented Apr 25, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Synthesis doc authored per Director ad-hoc dispatch (session keen-wren-319). Digests three 2026-04-25 analyses (Reflective gpt-5-5-pro@7f74f09, Exploratory gpt-5-4-pro@a8f0825, Exploratory gpt-5-5-pro@7f74f09) + PR #809 (debt rows from those analyses) + live ROADMAP.md §"Tracked debts" + live cited scaffold files, into a Director-actionable course of action.

Doc-only diff. No code change. No new debt entries (PR #809 already lands those).

Headline finding

Dominant scaffold pattern in the analyses is a single class of debt: string/path/name identity bridges. Eight surface instances (PROGRAM_INPUT_SENTINEL, fixture-filename routing, span.file == checks, include_str! side-channels, file-preference rank, etc.) all share one upstream missing-substrate-fact: lowering does not yet carry structural identity references end-to-end.

Surfaced explicitly per brief §STOP-AND-ESCALATE bullet 4 — Director should treat this as one M-scope substrate program (Tier 1, item #4 in the priority ordering), not as eight item-by-item paydowns distributed across PB-* lanes.

Acceptance — each requirement addressed

  • §1 Scaffolding inventory — every recent-window scaffold cited with file:line + named dissolution trigger + tracking pointer (test_runner.rs · lens_apply.rs · grounding_pilot/engine · patch_lower_helpers_* · host-Rust mirrors of std termination/computation/induction · effect-carrier Rust mirror). STOP bullet 2 does not fire: every inventoried scaffold has a named dissolution trigger.
  • §2 Velocity audit — 7-day window (2026-04-18 → 2026-04-25): 54 PRs merged, 8 dissolution-shaped, ~13 substantial introductions = 1.6:1 ratio. Below the 10:1 STOP threshold but imbalanced for the dissolution-first posture user concern flagged.
  • §3 Priority ordering — 12 items across 4 tiers. Tier 0: three P3 fail-closed leaks (Go UnknownVariant, lower.rs Arrow re-derive, lens fold ambiguous fallback) for parallel S-scope dispatch. Tier 1: identity-carrier substrate pass (the §0 class). Tier 2: R2-coupled risk-shaped items. Tier 3: substrate-deep, defer behind Tier 1.
  • §4 Framework recommendation — hybrid (b)+(c)-lite: paired-dispatch discipline at brief authoring time (every scaffold-introducing brief names adjacent debt + identity-bridge program) + velocity tripwire (≥3:1 ratio in any 7-day window triggers Director program review). No structural change to R2 or PB-* programs.
  • §5 Course-of-action recommendation — single-page Director-actionable summary with 7 follow-up briefs recommended (B1-B7).

STOP-AND-ESCALATE outcomes

  • Bullet 1 (10:1 velocity disaster): does not fire (1.6:1).
  • Bullet 2 (scaffold without trigger): does not fire (all triggered).
  • Bullet 3 (impossible trigger): borderline — surfaced as ⚠️ POTENTIALLY FUNDAMENTAL note in §1.8 (§0 class triggers point at substrate work that isn't yet a single named program; recommendation §3 Tier 1 item Consolidate binaries into gunbc-dag package #4 makes it one).
  • Bullet 4 (class-of-debt): fires — §0 surfaces this as the central recommendation (one program, not eight paydowns) rather than halting the synthesis.
  • Bullet 5 (scope balloon): does not fire (doc-only).

Brief drift surfaced (non-blocking)

Dispatching brief states "PR #809 ... just landed on `main`" but at synthesis time PR #809 is `OPEN` (`pm/roadmap-debt-from-2026-04-25-analyses`). Synthesis cites #809 diff content; line citations become authoritative once #809 merges. Synthesis recommendation §5.1 includes "land PR #809" as the prerequisite for follow-up briefs.

Cross-manager coordination

  • Grounding Manager (crisp-seal-366): §1.3 grounding scaffolds dissolve through Engine Phase 1+ work, gated on top-level ValueBody extension. No change requested.
  • Zero-Floor Manager (stern-swift-335): §1.4-1.6 scaffolds dissolve through PB-* lanes. One priority hint requested: lift patch_lower_helpers_generated_type_alias_refinement retirement to PB-Tier1-Sweep priority since it is explicitly named "first PB cleanup target."

Reporting on merge

Director (zesty-bear-812) reviews framework choice; if approved, dispatches per §3 priority ordering using §5's B1-B7 brief recommendations.

Test plan

  • Doc-only diff; no code touched.
  • cargo fmt --all --check clean.
  • Markdown renders.
  • All file:line citations verified against current main during synthesis.

🤖 Generated with Claude Code

…analyses → course of action)

Synthesis doc per Director ad-hoc dispatch (session keen-wren-319):
digests three 2026-04-25 analyses + PR #809 (open) + live ROADMAP debt
section + cited scaffold files into a Director-actionable course of
action.

Headline finding: dominant pattern in the analyses is a SINGLE class of
debt (string/path/name identity bridges across test_runner.rs,
lens_apply.rs, lower.rs, emit.rs, dag.rs file-preference rank). Eight
surface instances; one upstream missing-substrate-fact. Surfaced as the
class-of-pattern STOP-AND-ESCALATE finding (brief §STOP bullet 4):
treat as one M-scope substrate program, not eight item-by-item
paydowns.

Velocity audit: 1.6:1 introduction:dissolution ratio over the 7-day
window (54 PRs, 8 dissolution-shaped, ~13 substantial introductions).
Below the 10:1 STOP threshold; above the desired dissolution-first
posture for R2 close. Recommendation includes a 3:1 velocity tripwire.

Framework recommendation: hybrid (b)+(c)-lite — paired-dispatch at
brief authoring time + velocity tripwire reporting on integration-
reflection cadence. No structural change to R2 or PB-* programs.

Acceptance addressed:
- §1 scaffolding inventory (test_runner / lens_apply / grounding /
  patch_lower_helpers / host-Rust mirrors / effect mirror) — every
  scaffold has a named dissolution trigger; STOP bullet 2 does not fire
- §2 honest 1.6:1 velocity ratio
- §3 12-item priority ordering across 4 tiers
- §4 framework picked + justified
- §5 Director-actionable summary + 7 follow-up briefs recommended

PR #809 brief-drift surfaced (claimed "landed" but state=OPEN at
synthesis time); non-blocking.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls
briansrls force-pushed the session/keen-wren-319 branch from 1c609b9 to 21dec96 Compare April 25, 2026 18:18
@briansrls

Copy link
Copy Markdown
Contributor Author

PM review — synthesis is high-quality and the §0 class-of-pattern surfacing is exactly right. Three substantive pushes plus one frame addition before marking ready-for-review.

1. Add the groundedness frame to Tier 1 (item #4)

The Identity-Carrier Substrate Pass is currently framed as "lowering carries structural identity references end-to-end" — implicitly "force structural carriers everywhere." The user articulated a sharper frame on 2026-04-25 that should propagate here (saved as feedback_groundedness_gates_lenses.md):

Open surface, closed kernel. The compiler tracks whether each construct grounds in the kernel. Grounded → all lenses apply for free via compositional opacity. Ungrounded → the user opted out on that subtree; the lens reports "ungrounded, no claim" rather than failing or fabricating. Compositional opacity propagates the label.

Reframed Tier 1 brief: DeclarationRef / structural fold-step edge / explicit input carriers ARE the grounded identity carriers; span.file / sentinel-string fallbacks become the ungrounded fallback that lenses label and propagate, not silent failure. Same dissolution sites, sharper structural mechanism — the lens contract becomes "report ungrounded for ungrounded inputs," which is what makes the open surface safe.

This isn't a redesign — it just means the brief should specify the ungrounded-label propagation as part of the deliverable, not just the grounded carrier.

2. Strengthen §4 with a per-PR gate (not just paired dispatch + tripwire)

Paired-dispatch is good but lives at brief-authoring time and depends on author discipline. The cleaner mechanism is a per-PR gate: no new hand-Rust file in v3/ lands without naming the file/scaffold it deletes. This converts P5 (Progress Is Dissolution) from invariant-text into a reviewable line-item on every PR description.

Add as a third mechanism alongside paired-dispatch + velocity tripwire. Cheap to enforce (PR template line + reviewer check), no capacity tradeoff, catches drift even when ad-hoc dispatch skips paired discipline. The 3:1 tripwire stays as the late-warning; per-PR gate is the early-warning.

3. Loop-emission marker (Tier 2 #5) — verify construction-closure before authoring the brief

Currently Tier 2 #5 offers LoopKind discriminator OR integration test as the two paths. Both are bridges. The structural answer is likely "Loop is only reachable through the recursive-function lowering path because nothing else can construct one," enforced by construction — in which case both proposed paths are unnecessary and the ROADMAP entry reframes to "verify construction-closure + retire the speculative marker idea."

Add a prereq audit step to the Tier 2 #5 brief: enumerate every Loop construction site in lower.rs (and anywhere else); confirm/refute that all paths route through recursive-function lowering. If confirmed, the brief becomes "document the construction-closure invariant as a structural test"; if refuted, then the marker/test framing applies. Don't author the marker brief blind.

4. Frame note on velocity audit (§2)

The 1.6:1 ratio honestly read is good. One nuance worth adding: the dissolution-shaped PR count undercounts dissolution work that ships inside feature PRs (e.g., a T-LensAPI PR that adds the lens and retires three legacy paths in the same diff). If the velocity tripwire fires in a future window, before triggering review, do a manual sweep for dissolution-bearing feature PRs to avoid false positives. Not a blocker — just a calibration note for the §4 mechanism.


Disposition: address (1)-(3), keep (4) as a footnote in §2 or §4. Then mark ready-for-review and I'll PR-approve.

The §0 headline finding + Tier 1 program framing is the load-bearing recommendation and it's solid. The framework in §4 is sound; the per-PR gate makes it reviewable. Course-of-action ordering in §5 is the right shape.

@briansrls briansrls changed the title digest analyses docs(briefs): debt-paydown + scaffolding-audit synthesis (2026-04-25 analyses → course of action) Apr 25, 2026
@briansrls
briansrls marked this pull request as ready for review April 25, 2026 18:20
@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: 21dec967 · Trigger: schedule
  • Thinking: 12s wall

Doc-only diff. No code, no substrate change. Nothing in this diff touches INVARIANTS, modeling discipline, CODING, or TESTING in code form. The doc cites file:line locations as references; spot-checking isn't required for review since the doc is itself a synthesis.

Verdict: APPROVE — pure docs addition under docs/briefs/, no code or substrate change. Diff is internally consistent, scopes itself as synthesis-not-implementation, and acknowledges its own brief-drift caveat (PR #809 not yet merged) up front.

…e, Loop construction-closure audit, velocity calibration footnote

Address PM review on PR #810:

1. Tier 1 #4 (Identity-Carrier Substrate Pass) — reframed in the
   groundedness frame per feedback_groundedness_gates_lenses.md:
   grounded carriers + ungrounded-label propagation (lenses report
   "ungrounded, no claim" on remaining fallbacks rather than failing
   or fabricating). Brief deliverable now specifies label propagation,
   not just grounded carrier.

2. §4 framework — added per-PR gate as the Secondary mechanism (the
   early warning): no v3/ hand-Rust PR lands without naming what it
   deletes or defers. Lives at PR-review layer, complements
   paired-dispatch (dispatch layer) and velocity tripwire (cadence
   layer). Renamed velocity tripwire to Tertiary.

3. Tier 2 #5 (Loop emission marker) — reframed: brief MUST start with
   a construction-closure audit (enumerate every Behavior::Loop
   construction site; confirm/refute all paths route through
   recursive-function lowering). If closure holds, brief becomes
   "document closure as structural test" — no marker. Don't author
   marker brief blind. Per feedback_construction_over_ratchets.

4. §2 calibration footnote — PR-title heuristic undercounts
   dissolution that ships inside feature PRs; tripwire mechanism
   reflects this (manual sweep before Director review).

§5 follow-up brief recommendations updated correspondingly (B4 frame,
B5 audit-first, checklist + PR-template edit). No structural
re-recommendation; the §0 class-of-pattern finding + framework shape
unchanged.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

PM review addressed in 84982c4:

1. Tier 1 #4 — groundedness frame added. Now frames the program per feedback_groundedness_gates_lenses.md: grounded carriers (DeclarationRef / structural fold-step edge / explicit LensOutputEquals input carrier / structural emit-helper carriers) PLUS ungrounded-label propagation — lenses report "ungrounded, no claim" on remaining span.file/sentinel fallbacks rather than silent failure or fabrication. Brief deliverable explicitly specifies label propagation as part of the contract. §5 #3 + B4 updated to match.

2. §4 framework — per-PR gate added as Secondary mechanism. Three layers, finest to coarsest:

  • Primary (dispatch layer): paired-dispatch discipline at brief authoring time
  • Secondary (PR-review layer, NEW): no v3/ hand-Rust PR lands without naming what it deletes/shrinks/explicitly defers. Cheap reviewer line-item; converts P5 from invariant-text to per-PR review-gate.
  • Tertiary (cadence layer): velocity tripwire (≥3:1 with manual sweep)

§5 #4 + the "what changes if introduction outpaces dissolution" paragraph rewritten to reflect all three layers.

3. Tier 2 #5 — construction-closure audit added as prereq. Brief MUST start by enumerating every Behavior::Loop construction site in lower.rs and confirming/refuting that all paths route through recursive-function lowering. If closure holds → brief becomes "document closure as structural integration test, retire the marker idea" (no new substrate). If refuted → marker brief applies. Per feedback_construction_over_ratchets, prefer structural-closure outcome. B5 reframed to "audit-first, marker-conditional."

4. §2 calibration footnote added. Notes PR-title heuristic undercounts dissolution work shipping inside feature PRs (lower-bound on velocity); tripwire requires manual sweep for dissolution-bearing feature PRs before Director review fires, to avoid false positives. §4 tertiary mechanism cross-references this footnote.

The §0 class-of-pattern finding + Tier 1 program-shape recommendation are unchanged — load-bearing. Course-of-action ordering in §5 unchanged. PR is now ready-for-review.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 21dec967 · Trigger: schedule
  • Thinking: 210s wall

✅ Docs-only synthesis is scoped as a dated brief, acknowledges the #809 timing caveat, and I found no additional blocking concerns.

@briansrls

Copy link
Copy Markdown
Contributor Author

Correction to push (1) above — user sharpened the frame in chat after I posted; my "ungrounded label propagation" framing was wrong, please ignore that part.

Corrected frame for Tier 1 (item #4):

The language vocabulary is primitives + namespacing/composition only. There is no user-defined-primitive feature, no escape syntax, no annotation the compiler can't see through. Consequence: there is no "ungrounded user program" category — the lens contract is "applies to every program by construction," not "applies to grounded programs and labels ungrounded ones." If a lens needs an ungrounded-output path for user programs, the design has a leak.

What this means for the §0 identity-carrier sentinels (PROGRAM_INPUT_SENTINEL, span.file == checks, fixture-name routing, etc.): these aren't "ungrounded fallbacks the compiler labels." They are the compiler itself failing to use primitives + namespacing internally — the compiler reaching for sentinel strings instead of structural carriers (DeclarationRef, structural fold-step edges, explicit input carriers). The dissolution sites and the structural fix are unchanged from what you wrote; the diagnosis is sharper. The Tier 1 brief should frame it as "the compiler holds itself to the language's own vocabulary" rather than "carriers + ungrounded label propagation."

Pushes (2) per-PR gate, (3) Loop construction-closure audit, and the (4) velocity calibration footnote stand as written.

Saved as feedback_groundedness_gates_lenses.md (revised) for future reference: language has no escape syntax → lenses apply by construction → adoption is gated by economics (low entry cost × high free value), not enforcement.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: codex / codex-default
  • Commit: 84982c41 · Trigger: schedule
  • Thinking: 53s wall

Verdict: APPROVE

Doc-only synthesis, clearly marked as non-implementation, with scaffolds framed as tracked debt and dissolution triggers/program ownership called out. I don’t see a concrete violation of the pinned invariants, coding discipline, or testing discipline in this diff.

…tion; reframe as compiler-internal vocabulary leak

Per user correction on PR #810: previous "ungrounded label propagation"
framing was wrong. Language vocabulary is primitives + namespacing /
composition only — no escape syntax, no ungrounded user-program
category. Lenses apply by construction.

The §0 sentinels (PROGRAM_INPUT_SENTINEL, span.file == checks,
fixture-name routing, include_str! lens side-channels, file-preference
rank, etc.) are NOT ungrounded fallbacks the compiler labels. They
are the compiler itself failing to use the language's primitives +
namespacing internally — reaching for sentinel strings instead of
structural carriers (DeclarationRef, structural template-formal edges,
explicit input-value carriers, structural emit-helper carriers).

Tier 1 brief framing: "the compiler holds itself to the language's own
vocabulary."

Same 8 dissolution sites, same structural fix; sharper diagnosis.
Tier 1 #4, §5 #3, B4 updated. Pushes (2) per-PR gate, (3) Loop
construction-closure audit, (4) velocity calibration footnote stand
unchanged.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Frame correction landed in f329763. Tier 1 #4, §5 #3, B4 reframed:

  • Diagnosis sharpened. The §0 sentinels are NOT "ungrounded fallbacks the compiler labels" (the framing I posted earlier — wrong, retracted). They are the compiler itself failing to use the language's primitives + namespacing internally — reaching for sentinel strings instead of structural carriers. Language has no escape syntax → no ungrounded-user-program category → lenses apply by construction; if a lens needs an ungrounded output path for user programs, the design has a leak.
  • Tier 1 brief framing is now "the compiler holds itself to the language's own vocabulary." Same 8 dissolution sites, same structural fix (DeclarationRef, structural template-formal edges for fold-step identity, explicit LensOutputEquals input-value carriers, structural emit-helper carriers); the diagnosis no longer claims an ungrounded-label-propagation deliverable.

Pushes (2) per-PR gate, (3) Loop construction-closure audit, and (4) velocity calibration footnote stand as written from 84982c415. Class-of-pattern §0 finding + Tier 1 program-shape recommendation unchanged.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: openai-pro / gpt-5-5-pro
  • Commit: f3297636 · Trigger: manual
  • Conversation: View conversation

1. Story of the diff

This PR adds a single new synthesis brief, docs/briefs/debt-paydown-synthesis-2026-04-25.md, and does not change compiler code. The brief turns several 2026-04-25 analyses into a Director-facing course of action: it identifies string/path/name identity bridges as one underlying debt class rather than eight one-off cleanups, inventories recent scaffolds and their dissolution triggers, audits scaffold-introduction versus dissolution velocity, then recommends a paired-dispatch/per-PR-gate/velocity-tripwire framework. The load-bearing move is the reframing at docs/briefs/debt-paydown-synthesis-2026-04-25.md:23-61: identity carriers become the substrate-level program to dissolve multiple sentinel/file-name bridges, while genuinely independent fail-closed leaks are kept separate at docs/briefs/debt-paydown-synthesis-2026-04-25.md:63-66 and prioritized later in Tier 0.

2. Invariant categories

  1. LAYER MODEL (substrate vs implementation).

Compliant — this is a doc-only synthesis and does not add Dag fields, substrate variants, lowering behavior, or cross-pass Rust state; the proposed substrate work is explicitly framed as future Director action, e.g. “treat #4 … as one M-scope program” at docs/briefs/debt-paydown-synthesis-2026-04-25.md:59-61, not as a landed substrate change.

  1. INVARIANTS.md + modeling-discipline.md.

Finding — P5 / Progress Is Dissolution, no blind bridges. The brief correctly says the Loop-emission work “MUST start with a construction-closure audit, NOT with a marker design” at docs/briefs/debt-paydown-synthesis-2026-04-25.md:296-297, and further says the marker only applies if the audit refutes closure at docs/briefs/debt-paydown-synthesis-2026-04-25.md:300-306. But the final Director action list regresses to docs/briefs/debt-paydown-synthesis-2026-04-25.md:487: Loop-emission marker (S, R2-coupled), checklist undercount fix (S,. That line creates a second, higher-salience dispatch instruction that can send someone straight into the speculative marker path the brief just ruled out. Change the action-list wording to “Loop-emission construction-closure audit” or equivalent, preserving the marker as conditional only.

  1. CODING.md.

N/A — no Rust code, helpers, function shapes, methods, error carriers, or module organization are changed in this diff.

  1. TESTING.md.

N/A — no executable behavior changes. The brief’s own testing-relevant recommendation is appropriately scoped as future work: if Loop construction closure holds, document it with a structural integration test at docs/briefs/debt-paydown-synthesis-2026-04-25.md:300-302.

  1. LOCKED DESIGN DECISIONS.

Compliant — the brief references R2 and Pure Bootstrap/Zero-Floor plans but explicitly says those structures do not change: docs/briefs/debt-paydown-synthesis-2026-04-25.md:433-441.

  1. TRACKED vs UNTRACKED DEBT.

Compliant with the same correction above — the scaffold inventory is explicitly organized around trigger/tracking status, and the synthesis states that recent-window scaffolds have named dissolution triggers at docs/briefs/debt-paydown-synthesis-2026-04-25.md:152-157. The only debt-tracking concern I found is the Loop marker wording in the final action list: as written, docs/briefs/debt-paydown-synthesis-2026-04-25.md:487 drops the audit/bounds/conditional trigger that the earlier section requires.

3. Verdict

REQUEST_CHANGES. The document is otherwise coherent and well-grounded for a doc-only synthesis, but the final action list currently contradicts the brief’s own “audit first, marker only if needed” rule. That is small to fix, but important because this brief is meant to drive Director dispatch.

…810 review fix)

openai-pro REQUEST_CHANGES on f329763: §5 step 5 said "Loop-emission
marker (S, R2-coupled)" which contradicts Tier 2 #5's "MUST start with
construction-closure audit, NOT with a marker design." A reader hitting
the action list could go straight to the speculative marker path the
brief explicitly ruled out.

Fixed: §5 step 5 now reads "Loop-emission construction-closure audit
first (S, R2-coupled — marker brief is conditional on audit refuting
closure; if closure holds, deliverable is a structural integration
test, not a marker)." Action list now matches Tier 2 #5 + B5 framing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

openai-pro REQUEST_CHANGES addressed in 56d3a03.

Valid finding: §5 step 5 read "Loop-emission marker (S, R2-coupled)" which contradicts Tier 2 #5's "MUST start with a construction-closure audit, NOT with a marker design." A Director reading the action list could have gone straight to the speculative marker path the brief explicitly ruled out.

§5 step 5 now reads "Loop-emission construction-closure audit first (S, R2-coupled — the marker brief is conditional on the audit refuting closure per Tier 2 #5; if closure holds, deliverable is a structural integration test, not a marker)." Action list now matches Tier 2 #5 + B5 framing; the marker is preserved as conditional only.

No other findings raised. Awaiting re-review.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: 56d3a033 · Trigger: schedule
  • Thinking: 13s wall

APPROVE — Docs-only addition (single new file under docs/briefs/, 532 lines). No code, substrate, or test changes; nothing in this diff touches INVARIANTS, modeling discipline, CODING, or TESTING. The brief is well-cited (file:line references throughout, explicit dispatch tiers, named dissolution triggers) and self-flags its own drift caveat (PR #809 status, §2 PR-title heuristic undercount). No findings.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: codex / codex-default
  • Commit: 56d3a033 · Trigger: schedule
  • Thinking: 60s wall

Verdict: APPROVE — docs-only synthesis is clearly labeled as recommendation/planning, and the scaffolds it inventories are tied to named dissolution triggers or existing ROADMAP/PR #809 tracking. No concrete invariant, coding, or testing violations observed in this diff.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: 5a8f5562 · Trigger: schedule
  • Thinking: 21s wall

Docs-only diff: a single new synthesis brief under docs/briefs/. No code, no substrate, no invariants touched. Citations are file:line into existing files; framing is consistent with INVARIANTS.md (P3, P5) and the cited memory feedbacks.

Verdict: APPROVE — docs-only synthesis brief, well-grounded with file:line citations, internally consistent (e.g., §2 calibration footnote correctly informs the §4 tripwire and §5 step 5), and explicitly self-marked "no code change." Nothing in this diff to violate INVARIANTS / modeling-discipline / CODING / TESTING.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: codex / codex-default
  • Commit: 5a8f5562 · Trigger: schedule
  • Thinking: 244s wall

Findings

  • NON-BLOCKING: docs/briefs/debt-paydown-synthesis-2026-04-25.md:83 cites test_runner.rs:264, 1438 for a LensOutputEquals fixture-name special-case, but those live lines point to unrelated AlgebraicLaw / MockBackedInvariant code. That weakens the doc’s grounded inventory claim under P1 / “Documentation Describes Live State.” Replace with the actual cite for the special-case or drop the row.

Verdict: APPROVE_WITH_COMMENTS

The synthesis is docs-only, tracks scaffolds as recommendations rather than new implementation authority, and the main P5 framing looks consistent. I ran git diff --check; no whitespace issues.

…cial-case (PR #810 codex review)

codex APPROVE_WITH_COMMENTS on 5a8f556: §1.1 row 4 cited
test_runner.rs:264, 1438 for a "LensOutputEquals fixture-name
special-case" but those lines are AlgebraicLaw / MockBackedInvariant
code, not the special-case.

The actual parallel-authority arm is the
`lens_decl.name.as_deref() == Some("named_function_count")` branch at
:1683-1716 + :1763-1766 (canonical_named_function_count_dag driven by
lens name). Row updated to cite those lines and the upstream-fix
comment at :1611-1618. Reframed from "fixture-name special-case" to
"lens-name parallel-authority arm" to match what is actually there.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

codex APPROVE_WITH_COMMENTS finding addressed in 81fed33.

Valid: §1.1 row 4 cited test_runner.rs:264, 1438 for a "LensOutputEquals fixture-name special-case" but :264 is AlgebraicLaw code (int_associativity_holds_all_triples call) and :1438 is MockBackedInvariant requires.is_empty() handling — neither is a fixture-name special-case.

The actual parallel-authority arm is lens_decl.name.as_deref() == Some("named_function_count") at :1683-1716 and :1763-1766 (the canonical_named_function_count_dag branch driven by lens name). Row updated:

  • Cite: :1683-1716, :1763-1766 (and the upstream-fix comment at :1611-1618).
  • Reframed: "lens-name Some("named_function_count") parallel-authority arm" — matches what is actually there. Still in the §0 identity-carrier class (lens identity should be a DeclarationRef, not a string-keyed branch).

Inventory now grounded against current code.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: 81fed33d · Trigger: schedule
  • Thinking: 6.9s wall

Docs-only PR. APPROVE — pure docs addition, no code/invariant surface touched.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: codex / codex-default
  • Commit: d87719d6 · Trigger: schedule
  • Thinking: 44s wall

Verdict: APPROVE — doc-only synthesis, no compiler/test surface changes, and the new debt/scaffold guidance is explicitly framed as planning material with named dissolution paths. I don’t see a concrete violation of the pinned invariants, coding discipline, or testing discipline in this diff.

@briansrls

Copy link
Copy Markdown
Contributor Author

PM re-review — APPROVE with one housekeeping ask

All four pushes from the prior review are integrated cleanly:

(1) Groundedness reframe → "compiler holds itself to its own vocabulary" ✅
Tier 1 §3 (:264-289) and §5 step 3 (:467-481) both fully reframe per the revised feedback_groundedness_gates_lenses.md. The §0 sentinels are now diagnosed as "compiler-internal vocabulary leaks" (the compiler reaching for sentinels instead of structural carriers), not "ungrounded fallbacks the lens labels." The substrate carriers list is unchanged (DeclarationRef, structural template-formal edges, explicit input-value carriers, structural emit-helper carriers); the diagnosis is sharper. Brief framing locked.

(2) Per-PR gate added to §4 ✅
§4 now has three layered mechanisms: paired-dispatch (primary, brief-authoring time), per-PR gate (secondary, the early warning — "no new hand-Rust file in v3/ lands without naming the file or scaffold it deletes"), velocity tripwire (tertiary, the late warning). §5 step 4 + the bottom of §5 frame them as finest-grain → coarsest. P5 is now reviewable per-PR.

(3) Loop construction-closure audit prereq ✅
Tier 2 #5 (:293-307) explicitly: "Brief MUST start with a construction-closure audit, NOT with a marker design." Conditional Step 2 — if closure holds, deliverable is a structural integration test; if it doesn't, marker/test framing applies. Per feedback_construction_over_ratchets, the doc explicitly prefers the structural-closure outcome. §5 step 5 mirrors this. The marker brief is now genuinely conditional, not the default.

(4) Velocity calibration footnote ✅
§2 footnote (:190-197) explains the PR-title heuristic undercounts dissolution-bearing feature PRs; §4 references it (:423-431) requiring a manual sweep before the tripwire fires. Calibration encoded.

Housekeeping ask (non-blocking — can land in a follow-up)

The drift note at :12-17 says "PR #809 ... still OPEN at synthesis time." #809 merged earlier today (commit e78ed2d0b post-merge into amendment/grounding-completeness-program; landed on main per the cascade). The note is now obsolete — line citations to ROADMAP debt rows are authoritative. Either drop the drift note entirely or replace with "PR #809 landed 2026-04-25; line citations to ROADMAP debt rows are authoritative."

Not a merge blocker; can land as a follow-up touch or in the next synthesis revision.

Verdict

APPROVE for merge. This synthesis is the load-bearing input for Director's next dispatch wave (B1-B7 briefs in §5, plus the §4 discipline upgrades). Once it lands, Director has a clear authoring queue.

…housekeeping)

PM re-review on PR #810: brief-drift note + §5 step 1 + status block all
treated PR #809 as still OPEN, but #809 merged 2026-04-25T18:13:39Z
mid-synthesis-PR. Refreshed:

- Status block: "open at synthesis time" → "merged 2026-04-25 mid-PR"
- Brief-drift callout: rewritten as historical-traceability note pointing
  to authoritative ROADMAP debt-row line citations
- §5 step 1: "Land PR #809 (open at synthesis time)" → "PR #809
  prerequisite is satisfied; B1-B7 can be authored against current main"

§1.x inventory rows still reference "PR #809" as the tracking-row
pointer — those remain accurate (rows live in #809 / now on main).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

PM housekeeping ask addressed in 5b81b64.

PR #809 merged 2026-04-25T18:13:39Z (verified via gh pr view 809). Three sites refreshed:

  1. Status block (:6-7): "OPEN at synthesis time" → "merged 2026-04-25 mid-PR"
  2. Brief-drift callout (:12-17): rewritten as a historical-traceability note pointing to authoritative ROADMAP debt-row line citations
  3. §5 step 1 (:461-464): "Land PR docs(ROADMAP): post-merge debt — 2026-04-25 reflective + exploratory analyses (9 entries) #809 (open at synthesis time). Unblocks ..." → "PR docs(ROADMAP): post-merge debt — 2026-04-25 reflective + exploratory analyses (9 entries) #809 prerequisite is satisfied — merged 2026-04-25; B1-B7 can be authored against current main"

§1.x inventory rows still reference "PR #809" as the tracking-row pointer — those remain accurate since the rows live in #809 / now on main, and dropping the pointer would lose traceability.

Synthesis is now consistent with current main. PR ready for merge.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 5b81b640 · Trigger: schedule
  • Thinking: 202s wall

BLOCKING (1)

Root Cause

  • docs/briefs/debt-paydown-synthesis-2026-04-25.md §1.2 groups the two lens-fold issues by shared source row instead of distinct root causes → split the summary so the file-suffix fold-skip belongs to §0 identity-carrier work and the ambiguous unique-candidate fallback stays Tier 0 fail-closed work.

⚠️ One dispatch-plan contradiction should be fixed before this synthesis guides follow-up briefs.

| `span.file ends_with "std/algebra.dag"` fold-skip | `:22-39, :372-383` | ✅ — comment names structural fold-shape carrier | PR #809 "Lens fold execution" |
| `find_fold_step_bind_via_instantiation` ambiguous unique-candidate fallback | `:105-148` | ✅ — same row, requires template-formal-edge structural identity | PR #809 (P1+P2) |
| Lossy `Behavior → FieldValue` reflection (Transform/Branch/Loop/Bind drop fields) | `:859-907` | ✅ — generate from `src/v3/std/substrate.dag` or consume canonical .dag values | PR #809 "Lossy user-lens reflection" |

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

BLOCKING: §1.2 puts the ambiguous fold fallback inside the §0 identity class, but §0 and Tier 0 classify the same item as an independent P3 fail-closed fix; this contradicts the Director action plan and P2 Boundary Discipline.

briansrls added a commit that referenced this pull request Apr 25, 2026
- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)

B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).

B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 25, 2026
…813)

* docs(discipline): land §4 dispatch-discipline mechanisms + closed-vocabulary debt row

Lands the three-mechanism dispatch discipline from PR #810 §4 as durable
artifacts so they take effect before the next ad-hoc dispatch wave (B1-B7
briefs queued post-#810). All three mechanisms compose: per-PR gate is
finest grain (every PR), paired-dispatch is brief-authoring grain,
velocity tripwire is window grain.

INVARIANTS.md §P5 "Dispatch-Discipline Mechanisms" (new bullet under
P5 related rules):

- (a) Paired-dispatch at brief-authoring time — every Director-dispatched
  ad-hoc worker brief that introduces a scaffold MUST name the
  dissolution trigger, the adjacent ROADMAP debt row, and whether the
  PR contributes to or defers from that row's dissolution. Identity-
  bridge briefs MUST be authored against the §0 identity-carrier pass
  program, not as one-offs.
- (b) Per-PR gate — no new hand-Rust file in v3/ lands without the PR
  description naming the file or scaffold it deletes (or explicit
  deferral with a named row). Lives in PULL_REQUEST_TEMPLATE.md.
- (c) Velocity tripwire — cadence pass reports introduction:dissolution
  ratio; ≥3:1 in a 7-day window puts ad-hoc lane dispatch under Director
  review until ratio recovers, after manual sweep for dissolution-
  bearing feature PRs.

ROADMAP.md §"Reviewer-noise class — a practice, not a debt": extends
the integration-reflection cadence row with velocity-tripwire reporting
+ calibration caveat (PR-title heuristic undercounts dissolution-
bearing feature PRs; manual sweep before tripwire fires) + current
2026-04-18→2026-04-25 baseline (~1.6:1, lower bound).

ROADMAP.md §"Post-merge debt (2026-04-25 reflective + exploratory
analyses)": adds NOVEL row for the closed-vocabulary consumer-proof
follow-up debt from PR #811's meta-review (gpt-5-5-pro@8cf2051f,
SHIP_WITH_DEBT verdict). Mechanical claim is enforced by-construction
(parser grammar + 5/6-variant Disj + clippy exhaustive matches + no
fallback in lower phase); the documenting test converts the implicit
proof into a self-witnessing C1-class stop ratchet against future
substrate-extension PRs. S scope, single test file.

.github/PULL_REQUEST_TEMPLATE.md (new file): the per-PR gate section
with form-acceptance instructions ("deletes X" / "shrinks census line
Y" / "explicit deferral to lane Z with named row") and identity-bridge
escalation pointer to PR #810 §0.

No semantic shifts to existing INVARIANTS or ROADMAP entries; all three
additions are coordinated extensions of P5 (Progress Is Dissolution).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(discipline): close hand-Rust test exemption hole in per-PR gate

Per codex review on PR #812: the original PR template exempted "tests"
from the per-PR dissolution gate, but Rust tests under
src/v3/compiler/tests/ ARE hand-Rust and ARE part of the SG-0 census
(T-PB-B test subset). The exemption let exactly the T-PB-B class
bypass the required delete/shrink/defer statement — weakening P5.

Two coordinated tightenings:

- .github/PULL_REQUEST_TEMPLATE.md: replace blanket "tests" exemption
  with explicit inclusion of Rust tests under src/v3/compiler/tests/
  in the gate. Exempt list narrows to ".dag source, generated Rust,
  docs, non-Rust test fixtures, or hand-Rust outside src/v3/."
- INVARIANTS.md §P5 Dispatch-Discipline Mechanisms (b): mirror the
  template by adding "Hand-Rust includes Rust tests
  (src/v3/compiler/tests/**) — these are the T-PB-B test subset of
  the SG-0 census; the gate applies the same way it applies to T-PB-A
  non-test files."

The rule and the template now state the same scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 25, 2026
…strate Pass program (#814)

* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation)

Director-authored amendment following the 2026-04-24 escalation from PR
#693 (sub-child sharp-bear-829 under Surface Manager).

Two edits:

1. New "Class 5 Gap 3 — port-carried field values in data bodies"
   row in the 2026-04-21 post-merge-debt section. The substrate gap was
   documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP
   ledger row for cross-lane visibility. PR #693's execution surfaced it
   as the blocker on sub_charclass_in_std_unicode phase-2.

2. Retract the "ready-to-dispatch (no substrate capability gap)" claim
   on the Character-level row, annotate phase-1 landed via PR #693
   (CharClass vocabulary + Rust-mirror structural scanner path), and
   point phase-2 at the new Class 5 Gap 3 row.

Codifies the audit pattern: "this consumption gap has no substrate
capability gap" claims must be verified by attempting the retype before
the claim lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main

* docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review)

* docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review)

Row title still said 'consumption gap, not substrate gap' while the
body block retracted that claim and cited Class 5 Gap 3 as a substrate
dependency for phase-2. Title now matches body: mixed classification,
consumption for steps 1+3, substrate for step 2.

* docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit)

gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining
gap" description was wrong: field-level shapes (nested records, list
literals, declaration refs, Var refs, sum-variant literals) are
supported today via FieldValue variants + lower_structural_field_value
(dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the
top-level ValueBody boundary (non-scalar, non-record top-level bodies).

The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself
stale: it describes the pre-PR-B-unwind shape where FieldValue was
LiteralBits-only. PR-B's unwind extended FieldValue to carry
Reference / Record / List / Variant, moving the gap to ValueBody.

Two fixes:

1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody
   boundary, point at code paths (dag.rs, lower.rs) as live authority,
   flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass
   blocker classification to "provisional pending reproduction."

2. Update the Character-level row's phase-2 block to name that the
   specific shape of the CharClass failure needs concrete reproduction
   from the escalating sub-child before the blocker is finalized.

Recursive audit-pattern instance: the row I wrote to codify "verify
live state before claiming substrate gap" itself failed to verify live
state. Both incidents (2026-04-23 original row + 2026-04-24 my
retraction row) are now cited in the audit-pattern sub-note as
examples of the same discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c3

Three substantive fixes addressing internal-consistency gaps in the cascade
promotion PR caught by codex review at sha 0d6e7c3:

1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane
   acceptance bullets and Hand-Rust census paragraph in line with the
   updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero
   (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is
   retracted under 0-floor with explicit migration to ExecuteCommand-based
   .dag TestClaim declarations.

2. docs/design-pure-bootstrap-zero.md promotion section — converted from
   future-tense ("This doc is PROPOSAL until promoted… promotion is a
   single Director-authored cascade PR…") to historical past-tense
   promotion-receipt framing ("This doc was PROPOSAL until promoted;
   promotion was a single Director-authored cascade PR that did all of the
   following atomically…"); blocking-clause struck through and resolved
   inline. Banner cites PR #782 explicitly.

3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_
   profile excluded (Map<String, AlgebraProfile> body, not list-of-sum;
   needs distinct ValueBody::Map substrate work, tracked separately as a
   future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass
   phase-2 + Engine sharpened-(b) pilot enumeration), both sharing
   list-of-sum substrate work. Lane table, dependency DAG, and capacity
   summary updated for consistency (slot count 9-13, was 10-14).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities

Resolves claude REQUEST_CHANGES at sha fed6b03 — atomic-cascade
self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22
explicitly names THESIS.md and "any other authority docs" as required
retraction targets; the prior diff updated ROADMAP + r2-structure + design
docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting-
manager.md pointing at the now-SUPERSEDED ≤5-floor framing.

Files:

- THESIS.md (5 prose blocks updated):
  - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests
    migrate to ExecuteCommand-based .dag TestClaim declarations.
  - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag.
  - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor
    target citing design-pure-bootstrap-zero.md as live authority;
    hand_maintained_src list shrinks to empty set.
  - :301-318 — Tests-are-structural-data block: residual carve-out retracted;
    predicate name pb_rust_tests_outside_residual_zero retained as
    housekeeping (semantically the residual is empty under cascade).

- docs/thesis/compiler-std-consolidation.md (5 references):
  - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes
    design-pure-bootstrap.md (SUPERSEDED).
  - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process
    lane named as the dissolution trigger for bootstrap.rs itself.
  - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md.
  - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority
    re-cited.
  - :185 Related docs link.

- docs/briefs/r1-selfhosting-manager.md (active dispatch brief):
  - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5);
    T-PB-B residual carve-out retracted; predicate names retained for
    housekeeping; cascade-promoted authorities are source of truth.
  - Slice descriptions for T-PB-A / T-PB-B updated inline.
  - Framing-question + ask updated to 0-floor / no-residual framing.
  - Day-1 + up-to-director hand-off bullets updated.
  - Working-state checklist :111 ≤5 → 0 with cite.
  - Decisions log :164 ≤5 → 0-floor target updated.

- docs/r2-structure.md §2 design call (RETRACTED block):
  - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through
    in entirety (both Option A sharpen-and-keep and Option B rename are
    moot under 0-floor). Section preserved as audit-trail historical
    context.
  - Background-doc index: self-hosting anchor updated to
    design-pure-bootstrap-zero.md as live authority.

- docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per
  non-blocking suggestion):
  - Banner cites cascade promotion PR #782 explicitly.
  - New paragraph: "Treat all numeric floors below as retracted" with
    explicit lines named that quote in isolation (table row, body prose
    references). Prevents re-quoting from this doc as live authority.

Cascade is now atomically consistent across:
  THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔
  docs/thesis/compiler-std-consolidation.md ↔
  docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔
  docs/design-pure-bootstrap-zero.md (LIVE) ↔
  docs/design-pure-bootstrap.md (SUPERSEDED).

The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds
genuinely.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): correct ExecuteCommand runner-capability claim

Resolves codex BLOCKING #1 at sha fed6b03 (P1 live-state violation):
TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138
overstated live runner capability — claimed runner support landed in
PR #688/#741 with "emit Rust, invoke rustc on output, check exit code"
as a structurally-equivalent migration path. Verified against live
sources:

- src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema
  exists (declared via PR #678).
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5
  testgen harness allowlists ONLY `command == "true" && args.is_empty()
  && expect_exit == 0`.
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 —
  panics fail-closed on any other shape with explicit "ExecuteCommand
  shell shape is not supported here (runner-owned — do not treat as
  ordinary false)".
- src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no
  match arm for ExecuteCommand; falls through to ClaimResult::
  NotYetImplemented.

Reality: a TestClaim declaring rustc/python/go invocation is
structurally expressible as data today, but executing it is blocked.
Full arbitrary-command runner support is the PB-Runtime lane's
deliverable.

Files updated:

- TESTING.md:195 — capability state callout with file:line citations;
  "Full runner support — arbitrary command + args (rustc/python/go) with
  exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor
  program)." Bullet about migration shape preserved as the cascade-named
  successor pattern, not as a live capability.
- TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane
  lands the ExecuteCommand runner extension" as an explicit precondition.
- docs/design-pure-bootstrap-zero.md:138 — same correction for the
  matching prose, with PB-Runtime named as the runner-extension
  dependency for boundary-test migration.
- ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner
  foundation in #688/#741 with `true`-no-args allowlist only — full
  arbitrary-command runner support deferred to PB-Runtime lane,
  blocking the actual boundary-test migration." Dependencies column
  extended to "DB-15 + T-TestGen + PB-Runtime".

The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still
holds for atomic-cascade-across-authority-docs; this commit closes the
remaining capability/claim mismatch flagged by codex.

(Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still
SUPERSEDED-pointing — was sha-stale; resolved in c85e691.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief

Resolves codex BLOCKING at sha 0fb223a (P2 single-authority violation).
The prior banner contained:

> "Operationally R1 closure may still ship before the 0-floor is reached
>  — the ratchet ensures the trajectory; the gate's acceptance number is
>  what shifts."

This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0.
Two competing gate semantics in the cascade is exactly what the
atomic-cascade clause forbids.

Replaced with single-authority-honest framing:

> "R1 closure now requires the 0-floor target by gate semantics: T-PB-A
>  and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade
>  promotion changed their acceptance numbers to 0; R1 cannot close
>  while the SG-0 census carries non-zero hand-Rust."

Plus minor sharpening:
- "T-PB-A's non-test target is 0" → "non-test acceptance target is 0
  per ROADMAP.md:67" (cite the authority).
- T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep
  the capability-state honesty consistent with the recent fix wave.
- Predicate-rename housekeeping line moved into banner ("post-cascade
  housekeeping, not a pre-promotion blocker") — was implicit before.

The brief now genuinely inherits the cascade-promoted gate; no
competing release authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 second-wave worker-escalation fixes

Four substantive worker STOP-AND-ESCALATEs from briefs landed in
PR #797. All four worker recommendations correct; each needs a
Director call + brief update.

## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate

Worker correctly identified that brief req 2 (declared-effect carrier
as part of fn type signature, per feedback_no_annotations) requires
net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at
src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots.
Without parser surface, every user function would have
declared_effects = [] while inference returns non-empty — lens fires
EffectLeakageError everywhere on enable. Worker rejected power-through
and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map
parser split).

Director picked split:
- NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md
  Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface
  syntax + lookahead + body parser + lowerer extension + exhaustive-match
  audit + coproduct dissolution receipt.
- MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to
  post-parser-extension scope. Pre-flight check NOT a parser-extension
  step; STOP if parser sub-lane PR not merged.

## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping

Worker found load-bearing evidence at infer.rs:3693-3703: DB-11
deliberately strips refinements at operator dispatch as a designed-in
fix for symmetric-operators failure mode. Brief's "attach where b != 0
as a proof for a / b" directly contradicts this design choice. STOP-3
(where-clause conflict with DB-11) is real; STOP-1 (substrate scope)
needs net-new substrate (per-operator partiality fact + predicate-
entailment check + asymmetric per-operand refinement-honoring) — M+
minimum. ownership_lens precedent in original brief is post-hoc
observability, not proof carrier.

Worker recommended redirect to design/scoping per nested-optional
precedent. Director picked redirect.

Brief fully rewritten as design/scoping with four-question structure:
(1) DB-11 interaction analysis; (2) substrate proposal for proof-or-
totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes
with acceptance-theatre risk on user-defined-total-wrapper-only);
(4) Director-actionable recommendation. Output is doc PR.

## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C)

Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int)
with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136
closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b)
i128 implementation requires either path 1 (hierarchy refactor —
contradicts non-goal) or path 2 (regen lie between substrate and
emit — violates discipline). Worker leaned option (C) re-scope:
land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke)
to a sibling sub-lane that does proper Int128/Word128 substrate work.

Director picked option (C). Brief req 1 re-scoped to drop canonical-
carrier-widening; lane value comes from range facts + reconciliation
narrowing + out-of-range diagnostic against existing i64. Req 4
explicitly deferred with sibling-sub-lane reference. Sibling sub-lane
NOT to be authored or implied in this PR; tracked separately.

## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change)

Worker correctly STOP'd per the brief's own pre-flight check: parser
sub-lane has not landed; SurfaceExpr::Map not on main. Director
authorized cross-lane reassignment: wise-boar-480 takes the parser
sub-lane (t-substrate-valuebody-map-parser-worker.md) since they
already have full investigation context. No brief changes needed; the
routing decision is in the dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope

Resolves codex P2 inline at sha e35103f on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer
carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still
required widening LiteralBits::Int(i64) to an unbounded carrier and
passing the i64::MIN smoke. Internally unsatisfiable.

Fix:

- Slice section retitled "range facts + reconciliation narrowing
  (against existing i64 carrier)" with explicit note about the
  re-scope.
- Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly
  forbids touching LiteralBits::Int shape, dag_scalar_generated.rs
  regen for that variant, or tokenize i64 parse path.
- Slice steps 2-5 reframed: range facts use i64-representable
  magnitudes; reconciliation narrowing uses existing i64 carrier;
  diagnostic only for i64-representable out-of-range; smoke tests
  for req 5 only (req 4 i64::MIN deferred).
- Acceptance checklist updated:
  - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as
    re-scoped/deferred.
  - LiteralBits::Int(i64) carrier untouched (no widening; no
    parallel; no shape change).
  - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference.
- STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the
  carrier" — explicit STOP if execution surfaces range-fact narrowing
  requiring carrier-widening; that's the boundary the re-scope drew;
  belongs in sibling Int128/Word128 sub-lane.

Brief now consistently treats carrier-widening as out-of-scope across
all sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty

Resolves codex BLOCKING #1 at sha e35103f on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier
but req 2 required range facts using "the SAME magnitude carrier
as req 1" — meaning i64-typed range bounds. u64's max (2^64-1)
doesn't fit in i64; range fact for u64 would have to truncate,
omit, or mirror in Rust (representation drift). All three options
violate fail-closed declared-facts discipline (P1 / P3).

Fix:

- Req 2 rewritten to specify String-decimal representation:
  range_min_inclusive: String + range_max_inclusive: String fields
  on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127"
  for i8; "0"/"18446744073709551615" for u64).
- Explicit reasoning why String-decimal: u64's max doesn't fit in
  i64; binding range bounds to literal carrier forces truncation/
  omission/mirror-drift; all violate fail-closed declared-facts
  discipline.
- Bridge framing: String-decimal is pending the sibling Int128/
  Word128 sub-lane; both range bounds and literal payload migrate
  to typed carrier when that lands.

- Req 3 updated for String-decimal comparison semantics:
  reconciliation parses both bounds and literal magnitude into a
  common comparison space (i128 host comparison primitive — host
  narrowing, NOT carrier widening). Bounded by what the i64-typed
  literal can express; any i64-representable literal compares
  against any width's String-decimal bound. Carrier discipline
  preserved.

Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral)
is sha-stale — already resolved at 3e142d1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed

Resolves codex BLOCKING at sha 0815189 (post-#799-merge feedback).
Real residual: req 2 specifies String-decimal range bounds (to cover
u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance
bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" /
"i64-representable magnitudes" for the range facts. Two incompatible
authorities for the same range-fact shape — would let a worker satisfy
the slice while truncating/omitting u64 bounds (P3 fail-closed
violation).

Fix:

- Line 31 (req 1 re-scope clarification): updated to explicitly state
  "range facts (req 2) use String-decimal representation (width-
  independent; covers u64::MAX which doesn't fit in i64)". Distinguished
  literal *payload* (stays i64) from range-bound *representation*
  (String) — both serve req 1's "no carrier widening" boundary.
- Line 44 (slice step 2): updated from "Range bounds use i64-
  representable magnitudes" to "Range bounds use String-decimal
  representation per req 2" with concrete example (u64 bounds).
- Acceptance bullet: updated from "Range facts on integer algebras
  (substrate-declared, not Rust-mirrored)" to add "using String-decimal
  representation ... width-independent; u64 bounds expressible without
  truncation."

The brief now consistently treats range bounds as String-decimal
across req 2, req 3, slice, acceptance, and the req 1 clarification —
no remaining authorities saying i64-typed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing

User + PM exchange 2026-04-25 surfaced that the in-flight effects
chain was importing wrong assumptions from external languages
(declared-effects-as-annotation + lens-vs-declaration check). Right
framing under gunbc's closed-system discipline is parallel to
complexity: every effect derives structurally from the composition
of typed primitive operations; nothing can hide because there's no
escape hatch; nothing needs annotation because the structure IS the
registry.

Four doc-only actions:

1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md.
   Frames the closed-system answer with PM's 5-behavior synergy
   table (Value/Transform/Branch/Loop/Bind as universal
   compositional-fold pattern). Four worked examples; aggressive
   reading on redundancy (compile-error-by-construction via
   referential-transparency proof; reread() primitive for legitimate
   cases); implementation-brief shape in §Q6.

2. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md.

3. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md.
   Notes Fn→Arrow refactor brief stays dispatchable as independent
   value.

4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by-
   construction framing replaces lens-detection framing.

Memory file feedback_closed_system_effects.md saved separately;
cross-link added to feedback_construction_over_ratchets.md.

Net cost: doc-level cleanup. Zero substrate code rework. Foundation
(OperationEffect + service-call infrastructure + 5-behavior
substrate) already exists.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect

Per PM convergence review on #808 + user's deeper 2026-04-25 framing:
the closed-system framing landed in #808 retired the user-facing
annotation but kept OperationEffect taxonomy as substrate-level tagging.
User's deeper framing: the taxonomy ITSELF is parallel-representation —
operations are intrinsically read-shaped or write-shaped via their
TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns-
derived-value-only → read). Tagging operations with Read | Upsert |
Create | Append | Delete names what the structure already says.

Three changes:

1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as
   normalized view, or retire as parallel-representation?"
   - Two paths: (i) tags derived from signature shape (acceptable
     normalized view) vs (ii) tags declared per-primitive (parallel-
     representation; retire).
   - Audit-as-existence-check (Q4 req 2 reframed): all effectful
     primitives derive cleanly from signature shape → path (i); any
     primitive needs hand-declared tag → path (ii) by existence proof.
   - Director default: path (ii). Logging primitives that return Unit
     are likely the audit's existence-proof.
   - Two design-question resolutions: (a) external effects not in
     return type → resource-threading discipline (typed param returned
     modified, IO-monad-without-the-monad pattern); (b) transactional
     grouping → derived structural fact from Bind composition + typed
     transaction primitives.

2. Q4 reqs revised: req 2 from "tag every primitive with explicit
   OperationEffect signature" to "audit-as-existence-check that every
   primitive's type signature derives the right effect classification";
   req 3 added (resource-threading discipline); req 6 added
   (transactional-pattern lens). Req 1 (effects lens) anchors on
   operation type-signature shape, not on hand-declared tags.

3. THESIS:345-347 amendment strengthened — "operations are
   intrinsically read-shaped or write-shaped via their type-signature
   shape; consumers walk the signatures directly; there is no parallel
   taxonomy or annotation layer to declare or maintain. Tracking
   effects as a separate enumerated concept IS the bug pattern,
   dissolved by construction." Plus references to resource-threading
   discipline + transactional grouping as derived structural fact.

Memory file feedback_closed_system_effects.md updated to reflect the
deeper framing (type-signature-shape, not taxonomy-tagging) +
resource-threading discipline section + transactional-patterns
section.

Net cost: doc-only delta on top of #808. Substrate retirement
(OperationEffect enum + derive_op_effect + idempotency.dag re-anchor)
deferred to the audit-as-existence-check phase of the implementation
brief; surfaced as Q5.5 OPEN CALL.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage

Resolves codex BLOCKING at sha d49ce79 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real:
the prior text claimed service primitives "already carry typed effect
signatures" presenting future audit-state as current substrate fact
(P1 violation). My Q5.5 amendment at 2dc656b partially fixed the
OperationEffect line but left a parallel over-claim on the new
"signature-shape coverage" framing.

Fix: Q4 substrate-state listing rewritten to honestly distinguish:

- Live: Behavior enum + substrate foundation (the principle that
  operations should carry signature shape).
- Incomplete: signature-shape coverage across actual primitives.
  HTTP-derived primitives carry implicit shape via derive_op_effect's
  method-table; logging/mutation primitives that return Unit or don't
  thread their target resource do NOT carry the structural shape that
  would express read-vs-write. Achieving full coverage is required
  work under reqs 2 + 3, not a current fact.
- Pending audit-as-existence-check: OperationEffect + derive_op_effect
  (path (i) vs (ii) per Q5.5).

Honest live-state callout added explicitly: "the closed-system
FOUNDATION (5 behaviors + DAG substrate + the principle that
operations should carry signature-shape) is live. The IMPLEMENTATION
COVERAGE across all effectful primitives is partial. Req 2 + req 3
are the work that closes the gap."

Brief now distinguishes principle-is-live (foundation) from
coverage-is-partial (audit work) without conflating them.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim

Per PM follow-up review on #808 + user's stronger discipline framing
("substrate must make bypass structurally impossible at every layer
of the transport stack"): the closed-system claim is honest only when
typed primitives ARE the path. Today two structural holes exist where
bypasses sidestep the typed-primitive substrate. Both surfaced
explicitly as Q4.5 pre-conditions — load-bearing for the lens's
coverage claim.

Three changes:

1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed-
   system claim)" inserted between Q4 and Q5:

   P1 — Extdeps typed-primitive consumption structurally enforced.
   Substrate must make `messages: Json` impossible to declare in
   service definitions; typed `LlmMessage` / `ContentBlock` /
   `GitHubAuthToken`-with-full-scopes are the only path. Tracked
   debt at ROADMAP.md:153-154 (LLM provider flattening) +
   `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded).
   Required prereq for full lens coverage; lens can land first +
   surface structural-coverage-gap diagnostics on bypass surfaces
   so the gap becomes visible rather than silent.

   P2 — `ExecuteCommand` fully materialized as typed runner
   primitive. TESTING.md (post-#782) committed to 0-residual but
   ExecuteCommand isn't fully materialized; deleting Rust boundary
   tests creates verification gap. Already named under PB-Runtime
   in Zero-Floor; signal pending. Pre-requisite for ANY Rust
   boundary-test deletion.

2. Old leftover duplicate Q5 section deleted (artifact from prior
   Q5/Q5.5 reshape; second copy of asymmetric-tightening text was
   in the file alongside the earlier Q5 instance).

3. Worker-discretion-vs-Director-call section in Q4.5: lens
   implementation worker dispatchable now (reports gaps as
   findings); P1 closure is substantive substrate work touching
   extdeps (dedicated lane); P2 closure is PB-Runtime (signal
   pending).

Net: design doc now honestly distinguishes principle-is-live
(Q4 rewrite at 191be31) from coverage-is-partial (Q4.5 prereqs
named explicitly). The closed-system claim has explicit pre-
conditions documented; implementation brief discovers them as
known dependencies, not as STOP-AND-ESCALATEs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default

Resolves claude APPROVE_WITH_COMMENTS at sha 191be31 on #808. Two
real residuals after the Q5.5 reframe:

1. Q6's reqs/STOPs/acceptance still framed under path (i) — said
   "audit + tag std/ primitives — every effectful primitive carries
   an explicit OperationEffect signature." Directly contradicted Q4
   (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment
   ("there is no parallel taxonomy to declare or maintain"). Worker
   reading Q6 in isolation would author the retracted shape.

2. Capacity / sequencing table line about "audit lane (tag std/
   primitives with effect signatures)" carried the same stale
   framing.

3. Q6 STOP "primitive performing side effects without an
   OperationEffect tag" assumed tag-as-authority; under path (ii)
   the STOP shape is "primitive whose signature doesn't structurally
   reveal its effect."

Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale
(already fixed at f073aa9 Q4.5 commit).

## Q6 fixes

- Reqs renumbered + reframed:
  - Req 1 anchors on operation type-signature shape (not hand-declared
    OperationEffect tags); composition reads from signature shape per
    Q2 table.
  - Req 2 changed from "audit + tag every primitive" to
    "audit-as-existence-check" — verify signature-shape coverage; ANY
    primitive needing a hand-declared tag IS the existence-proof for
    path (ii) retirement.
  - Req 3 added: resource-threading discipline applied to existing
    primitives (logging that returns Unit gets reshaped per audit).
  - Req 6 added: transactional-pattern lens (Bind composition +
    Transaction → Transaction').
  - Req 7 added: asymmetric-tightening worked example in PR body
    (per claude review observation; the one place declaration-shaped
    surface re-enters).
  - Req 8 (was 5): tests now reference signature-shape derivation
    explicitly, not tag lookup.
- STOPs reframed:
  - "OperationEffect retirement decision" — audit produces path (i)
    vs (ii) verdict; substrate retirement is its own dedicated
    sub-lane; this lane does NOT absorb it.
  - Pure/impure carrier STOP notes that "pure" should also derive
    from signature shape (pure functions don't return modified
    resources) — so the STOP itself may dissolve under further design.
  - Q4.5 P1 explicitly NOT a STOP — lens reporting structural-
    coverage-gap on extdeps bypass surfaces is the lens delivering
    its foundation-gap-visibility value.
  - Q4.5 P2 explicitly independent — lens doesn't depend on
    ExecuteCommand materialization.
- Acceptance extended: lens reports gap diagnostics on P1 bypass
  surfaces; audit produces existence-proof verdict for Director
  re-decision; asymmetric-tightening worked example in PR body.

## Capacity / sequencing table

Replaced "1 audit lane (tag std/ primitives with effect signatures)"
with "1 audit-as-existence-check lane (verify primitives' signature-
shape coverage; NOT 'tag every primitive') — produces the path (i)
vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2
prereq lanes to the net summary. Closing line: "The taxonomy-
retirement scope (substrate-side) is not in this lane — it's
surfaced by audit and routed to dedicated retirement lane if path
(ii) wins."

Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity
table. Worker reading Q6 in isolation now sees path-(ii)-default
framing matching Q4 + Q5.5 + THESIS amendment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792

Resolves codex inline BLOCKING at sha 191be31 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150.
Real: my Q4.5 P2 framing described ExecuteCommand as still
NotYetImplemented (M1.5 allowlist + Rust TestRunner returning
NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand
extension before this PR's authoring. TESTING.md:195 capability-state
callout confirms:
- Rust TestRunner + M1.5 testgen harness share one std::process path
  for arbitrary command + args + expect_exit_code.
- M1.5 allowlist + fail-closed panic retired.
- Distinguishable ClaimResult::Fail messages for spawn / timeout /
  policy / exit-mismatch.
- Linux unshare(1) namespace isolation on host-allowing systems.
- T-PB-B-1 boundary migration example landed.

Fix:

P2 section rewritten:
- Header retitled "ExecuteCommand runner primitive: LANDED (PR #792);
  residual is bulk-migration."
- Status update naming PR #792 + the post-#792 capability state
  (allowlist retired, etc.).
- Honest acknowledgement: "My earlier P2 framing was stale."
- Residual narrowed to bulk-migration of existing Rust Command::new
  boundary tests (tracked as ROADMAP residual, not lens prereq).
- Sequencing reframed: P2 was always orthogonal to the effects lens
  itself; bulk migration proceeds at its own pace; lens not blocked.

Q4.5 footer updated:
- "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via
  #792; only consumer-side bulk migration remains)"
- Worker-discretion-vs-Director-call P2 line updated: "runner
  primitive landed; only consumer-side bulk migration remains;
  tracked as ROADMAP residual, independent of the lens."

Q6 STOP for P2 updated:
- "the lens itself doesn't depend on P2; only TESTING.md's 0-residual
  claim does" → "runner primitive landed via PR #792 (post-Q4.5-
  authoring update). The lens itself never depended on P2; bulk
  consumer migration is residual ROADMAP work and remains independent
  of this lane."

Brief now reflects live state. The closed-system claim's prereq
landscape is honest:
- P1 (extdeps typed-primitive consumption): real prereq, tracked
  debt at ROADMAP:153-154.
- P2 (ExecuteCommand runner): satisfied via #792; bulk migration is
  consumer-side residual, not foundation work.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale

Resolves codex non-blocking finding at sha bcac41b on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real
residual: capacity-table line still listed P2 as "`ExecuteCommand`
materialization" prereq + framed both P1 and P2 as "pre-existing
tracked-debt" — but my prior 57a9b13 fix established that PR #792
already landed the runner primitive, so P2 is no longer a
materialization prereq.

Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq)
from P2 (residual, not prereq):

  - P1: extdeps typed-primitive consumption — pre-existing tracked
    debt at ROADMAP:153-154; load-bearing for the lens's full-coverage
    claim.
  - P2: ExecuteCommand runner primitive landed via PR #792; only
    consumer-side bulk migration of existing Rust Command::new
    boundary tests remains (tracked as ROADMAP residual, independent
    of the lens; not a materialization prereq).

Brief now consistently treats P2 as bulk-migration-residual across:
- §Q4.5 P2 section header (LANDED via PR #792; residual is
  bulk-migration).
- §Q4.5 footer (P2: runner primitive landed; only consumer-side
  bulk migration remains).
- Q6 STOP for P2 (runner primitive landed; bulk migration is
  residual ROADMAP work).
- §Capacity / sequencing impact (P2 as residual, not prereq).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349

Codex finding on PR #808 sha ece964e: lines 153-154 are unrelated
target-grounding prose; the matching extdeps typed-primitive bypass
entries (LLM service flattening, GitHub auth model bypass) live at
ROADMAP.md:348-349.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix third stale ROADMAP citation at line 271

Codex follow-up on sha 2552ca3: prior fix missed a third occurrence
at line 271 in the §Q4.5 capacity table. Now consistent with lines
139 and 173 (ROADMAP.md:348-349).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity

Codex flagged 'Effect-signature tagging on std/ primitives' as potentially
contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240)
already explicitly say 'NOT tag every primitive' — but the cross-manager
line used sloppy wording. Reworded to make explicit that the audit walks
signature shape; no parallel tag added.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5

- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)

B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).

B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — drop incoherent inner-fallback non-goal

Codex P2: the non-goal line excluding the inner declaration().name
unwrap_or_else fallback contradicted Slice step 2, which replaces the
whole chain with let-Some-else-return. Both fallbacks are in scope by
construction; remove the contradictory non-goal.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives

PM REQUEST_CHANGES: §Frame listed '4 type connectives
(Conjunction | Disjunction | Cardinality | Bit)' which contradicted
the canonical thesis source. Replaced with the canonical 6
(Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per
docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary
closes here'. Also removed 'typed substrate carriers' from the
vocabulary list — substrate carriers are defined using the vocabulary,
not part of it. Added a clarifying note that B4's carriers
(DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are
typed declarations composed from the vocabulary, not vocabulary
extensions.

Per feedback_verify_thesis_claims: brief framings citing thesis
structure must ground in the canonical source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 25, 2026
…la tighten (post-#814 carry-forward) (#815)

* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation)

Director-authored amendment following the 2026-04-24 escalation from PR
#693 (sub-child sharp-bear-829 under Surface Manager).

Two edits:

1. New "Class 5 Gap 3 — port-carried field values in data bodies"
   row in the 2026-04-21 post-merge-debt section. The substrate gap was
   documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP
   ledger row for cross-lane visibility. PR #693's execution surfaced it
   as the blocker on sub_charclass_in_std_unicode phase-2.

2. Retract the "ready-to-dispatch (no substrate capability gap)" claim
   on the Character-level row, annotate phase-1 landed via PR #693
   (CharClass vocabulary + Rust-mirror structural scanner path), and
   point phase-2 at the new Class 5 Gap 3 row.

Codifies the audit pattern: "this consumption gap has no substrate
capability gap" claims must be verified by attempting the retype before
the claim lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main

* docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review)

* docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review)

Row title still said 'consumption gap, not substrate gap' while the
body block retracted that claim and cited Class 5 Gap 3 as a substrate
dependency for phase-2. Title now matches body: mixed classification,
consumption for steps 1+3, substrate for step 2.

* docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit)

gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining
gap" description was wrong: field-level shapes (nested records, list
literals, declaration refs, Var refs, sum-variant literals) are
supported today via FieldValue variants + lower_structural_field_value
(dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the
top-level ValueBody boundary (non-scalar, non-record top-level bodies).

The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself
stale: it describes the pre-PR-B-unwind shape where FieldValue was
LiteralBits-only. PR-B's unwind extended FieldValue to carry
Reference / Record / List / Variant, moving the gap to ValueBody.

Two fixes:

1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody
   boundary, point at code paths (dag.rs, lower.rs) as live authority,
   flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass
   blocker classification to "provisional pending reproduction."

2. Update the Character-level row's phase-2 block to name that the
   specific shape of the CharClass failure needs concrete reproduction
   from the escalating sub-child before the blocker is finalized.

Recursive audit-pattern instance: the row I wrote to codify "verify
live state before claiming substrate gap" itself failed to verify live
state. Both incidents (2026-04-23 original row + 2026-04-24 my
retraction row) are now cited in the audit-pattern sub-note as
examples of the same discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c3

Three substantive fixes addressing internal-consistency gaps in the cascade
promotion PR caught by codex review at sha 0d6e7c3:

1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane
   acceptance bullets and Hand-Rust census paragraph in line with the
   updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero
   (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is
   retracted under 0-floor with explicit migration to ExecuteCommand-based
   .dag TestClaim declarations.

2. docs/design-pure-bootstrap-zero.md promotion section — converted from
   future-tense ("This doc is PROPOSAL until promoted… promotion is a
   single Director-authored cascade PR…") to historical past-tense
   promotion-receipt framing ("This doc was PROPOSAL until promoted;
   promotion was a single Director-authored cascade PR that did all of the
   following atomically…"); blocking-clause struck through and resolved
   inline. Banner cites PR #782 explicitly.

3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_
   profile excluded (Map<String, AlgebraProfile> body, not list-of-sum;
   needs distinct ValueBody::Map substrate work, tracked separately as a
   future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass
   phase-2 + Engine sharpened-(b) pilot enumeration), both sharing
   list-of-sum substrate work. Lane table, dependency DAG, and capacity
   summary updated for consistency (slot count 9-13, was 10-14).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities

Resolves claude REQUEST_CHANGES at sha fed6b03 — atomic-cascade
self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22
explicitly names THESIS.md and "any other authority docs" as required
retraction targets; the prior diff updated ROADMAP + r2-structure + design
docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting-
manager.md pointing at the now-SUPERSEDED ≤5-floor framing.

Files:

- THESIS.md (5 prose blocks updated):
  - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests
    migrate to ExecuteCommand-based .dag TestClaim declarations.
  - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag.
  - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor
    target citing design-pure-bootstrap-zero.md as live authority;
    hand_maintained_src list shrinks to empty set.
  - :301-318 — Tests-are-structural-data block: residual carve-out retracted;
    predicate name pb_rust_tests_outside_residual_zero retained as
    housekeeping (semantically the residual is empty under cascade).

- docs/thesis/compiler-std-consolidation.md (5 references):
  - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes
    design-pure-bootstrap.md (SUPERSEDED).
  - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process
    lane named as the dissolution trigger for bootstrap.rs itself.
  - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md.
  - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority
    re-cited.
  - :185 Related docs link.

- docs/briefs/r1-selfhosting-manager.md (active dispatch brief):
  - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5);
    T-PB-B residual carve-out retracted; predicate names retained for
    housekeeping; cascade-promoted authorities are source of truth.
  - Slice descriptions for T-PB-A / T-PB-B updated inline.
  - Framing-question + ask updated to 0-floor / no-residual framing.
  - Day-1 + up-to-director hand-off bullets updated.
  - Working-state checklist :111 ≤5 → 0 with cite.
  - Decisions log :164 ≤5 → 0-floor target updated.

- docs/r2-structure.md §2 design call (RETRACTED block):
  - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through
    in entirety (both Option A sharpen-and-keep and Option B rename are
    moot under 0-floor). Section preserved as audit-trail historical
    context.
  - Background-doc index: self-hosting anchor updated to
    design-pure-bootstrap-zero.md as live authority.

- docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per
  non-blocking suggestion):
  - Banner cites cascade promotion PR #782 explicitly.
  - New paragraph: "Treat all numeric floors below as retracted" with
    explicit lines named that quote in isolation (table row, body prose
    references). Prevents re-quoting from this doc as live authority.

Cascade is now atomically consistent across:
  THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔
  docs/thesis/compiler-std-consolidation.md ↔
  docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔
  docs/design-pure-bootstrap-zero.md (LIVE) ↔
  docs/design-pure-bootstrap.md (SUPERSEDED).

The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds
genuinely.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): correct ExecuteCommand runner-capability claim

Resolves codex BLOCKING #1 at sha fed6b03 (P1 live-state violation):
TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138
overstated live runner capability — claimed runner support landed in
PR #688/#741 with "emit Rust, invoke rustc on output, check exit code"
as a structurally-equivalent migration path. Verified against live
sources:

- src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema
  exists (declared via PR #678).
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5
  testgen harness allowlists ONLY `command == "true" && args.is_empty()
  && expect_exit == 0`.
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 —
  panics fail-closed on any other shape with explicit "ExecuteCommand
  shell shape is not supported here (runner-owned — do not treat as
  ordinary false)".
- src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no
  match arm for ExecuteCommand; falls through to ClaimResult::
  NotYetImplemented.

Reality: a TestClaim declaring rustc/python/go invocation is
structurally expressible as data today, but executing it is blocked.
Full arbitrary-command runner support is the PB-Runtime lane's
deliverable.

Files updated:

- TESTING.md:195 — capability state callout with file:line citations;
  "Full runner support — arbitrary command + args (rustc/python/go) with
  exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor
  program)." Bullet about migration shape preserved as the cascade-named
  successor pattern, not as a live capability.
- TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane
  lands the ExecuteCommand runner extension" as an explicit precondition.
- docs/design-pure-bootstrap-zero.md:138 — same correction for the
  matching prose, with PB-Runtime named as the runner-extension
  dependency for boundary-test migration.
- ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner
  foundation in #688/#741 with `true`-no-args allowlist only — full
  arbitrary-command runner support deferred to PB-Runtime lane,
  blocking the actual boundary-test migration." Dependencies column
  extended to "DB-15 + T-TestGen + PB-Runtime".

The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still
holds for atomic-cascade-across-authority-docs; this commit closes the
remaining capability/claim mismatch flagged by codex.

(Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still
SUPERSEDED-pointing — was sha-stale; resolved in c85e691.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief

Resolves codex BLOCKING at sha 0fb223a (P2 single-authority violation).
The prior banner contained:

> "Operationally R1 closure may still ship before the 0-floor is reached
>  — the ratchet ensures the trajectory; the gate's acceptance number is
>  what shifts."

This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0.
Two competing gate semantics in the cascade is exactly what the
atomic-cascade clause forbids.

Replaced with single-authority-honest framing:

> "R1 closure now requires the 0-floor target by gate semantics: T-PB-A
>  and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade
>  promotion changed their acceptance numbers to 0; R1 cannot close
>  while the SG-0 census carries non-zero hand-Rust."

Plus minor sharpening:
- "T-PB-A's non-test target is 0" → "non-test acceptance target is 0
  per ROADMAP.md:67" (cite the authority).
- T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep
  the capability-state honesty consistent with the recent fix wave.
- Predicate-rename housekeeping line moved into banner ("post-cascade
  housekeeping, not a pre-promotion blocker") — was implicit before.

The brief now genuinely inherits the cascade-promoted gate; no
competing release authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 second-wave worker-escalation fixes

Four substantive worker STOP-AND-ESCALATEs from briefs landed in
PR #797. All four worker recommendations correct; each needs a
Director call + brief update.

## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate

Worker correctly identified that brief req 2 (declared-effect carrier
as part of fn type signature, per feedback_no_annotations) requires
net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at
src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots.
Without parser surface, every user function would have
declared_effects = [] while inference returns non-empty — lens fires
EffectLeakageError everywhere on enable. Worker rejected power-through
and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map
parser split).

Director picked split:
- NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md
  Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface
  syntax + lookahead + body parser + lowerer extension + exhaustive-match
  audit + coproduct dissolution receipt.
- MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to
  post-parser-extension scope. Pre-flight check NOT a parser-extension
  step; STOP if parser sub-lane PR not merged.

## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping

Worker found load-bearing evidence at infer.rs:3693-3703: DB-11
deliberately strips refinements at operator dispatch as a designed-in
fix for symmetric-operators failure mode. Brief's "attach where b != 0
as a proof for a / b" directly contradicts this design choice. STOP-3
(where-clause conflict with DB-11) is real; STOP-1 (substrate scope)
needs net-new substrate (per-operator partiality fact + predicate-
entailment check + asymmetric per-operand refinement-honoring) — M+
minimum. ownership_lens precedent in original brief is post-hoc
observability, not proof carrier.

Worker recommended redirect to design/scoping per nested-optional
precedent. Director picked redirect.

Brief fully rewritten as design/scoping with four-question structure:
(1) DB-11 interaction analysis; (2) substrate proposal for proof-or-
totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes
with acceptance-theatre risk on user-defined-total-wrapper-only);
(4) Director-actionable recommendation. Output is doc PR.

## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C)

Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int)
with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136
closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b)
i128 implementation requires either path 1 (hierarchy refactor —
contradicts non-goal) or path 2 (regen lie between substrate and
emit — violates discipline). Worker leaned option (C) re-scope:
land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke)
to a sibling sub-lane that does proper Int128/Word128 substrate work.

Director picked option (C). Brief req 1 re-scoped to drop canonical-
carrier-widening; lane value comes from range facts + reconciliation
narrowing + out-of-range diagnostic against existing i64. Req 4
explicitly deferred with sibling-sub-lane reference. Sibling sub-lane
NOT to be authored or implied in this PR; tracked separately.

## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change)

Worker correctly STOP'd per the brief's own pre-flight check: parser
sub-lane has not landed; SurfaceExpr::Map not on main. Director
authorized cross-lane reassignment: wise-boar-480 takes the parser
sub-lane (t-substrate-valuebody-map-parser-worker.md) since they
already have full investigation context. No brief changes needed; the
routing decision is in the dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope

Resolves codex P2 inline at sha e35103f on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer
carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still
required widening LiteralBits::Int(i64) to an unbounded carrier and
passing the i64::MIN smoke. Internally unsatisfiable.

Fix:

- Slice section retitled "range facts + reconciliation narrowing
  (against existing i64 carrier)" with explicit note about the
  re-scope.
- Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly
  forbids touching LiteralBits::Int shape, dag_scalar_generated.rs
  regen for that variant, or tokenize i64 parse path.
- Slice steps 2-5 reframed: range facts use i64-representable
  magnitudes; reconciliation narrowing uses existing i64 carrier;
  diagnostic only for i64-representable out-of-range; smoke tests
  for req 5 only (req 4 i64::MIN deferred).
- Acceptance checklist updated:
  - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as
    re-scoped/deferred.
  - LiteralBits::Int(i64) carrier untouched (no widening; no
    parallel; no shape change).
  - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference.
- STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the
  carrier" — explicit STOP if execution surfaces range-fact narrowing
  requiring carrier-widening; that's the boundary the re-scope drew;
  belongs in sibling Int128/Word128 sub-lane.

Brief now consistently treats carrier-widening as out-of-scope across
all sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty

Resolves codex BLOCKING #1 at sha e35103f on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier
but req 2 required range facts using "the SAME magnitude carrier
as req 1" — meaning i64-typed range bounds. u64's max (2^64-1)
doesn't fit in i64; range fact for u64 would have to truncate,
omit, or mirror in Rust (representation drift). All three options
violate fail-closed declared-facts discipline (P1 / P3).

Fix:

- Req 2 rewritten to specify String-decimal representation:
  range_min_inclusive: String + range_max_inclusive: String fields
  on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127"
  for i8; "0"/"18446744073709551615" for u64).
- Explicit reasoning why String-decimal: u64's max doesn't fit in
  i64; binding range bounds to literal carrier forces truncation/
  omission/mirror-drift; all violate fail-closed declared-facts
  discipline.
- Bridge framing: String-decimal is pending the sibling Int128/
  Word128 sub-lane; both range bounds and literal payload migrate
  to typed carrier when that lands.

- Req 3 updated for String-decimal comparison semantics:
  reconciliation parses both bounds and literal magnitude into a
  common comparison space (i128 host comparison primitive — host
  narrowing, NOT carrier widening). Bounded by what the i64-typed
  literal can express; any i64-representable literal compares
  against any width's String-decimal bound. Carrier discipline
  preserved.

Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral)
is sha-stale — already resolved at 3e142d1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed

Resolves codex BLOCKING at sha 0815189 (post-#799-merge feedback).
Real residual: req 2 specifies String-decimal range bounds (to cover
u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance
bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" /
"i64-representable magnitudes" for the range facts. Two incompatible
authorities for the same range-fact shape — would let a worker satisfy
the slice while truncating/omitting u64 bounds (P3 fail-closed
violation).

Fix:

- Line 31 (req 1 re-scope clarification): updated to explicitly state
  "range facts (req 2) use String-decimal representation (width-
  independent; covers u64::MAX which doesn't fit in i64)". Distinguished
  literal *payload* (stays i64) from range-bound *representation*
  (String) — both serve req 1's "no carrier widening" boundary.
- Line 44 (slice step 2): updated from "Range bounds use i64-
  representable magnitudes" to "Range bounds use String-decimal
  representation per req 2" with concrete example (u64 bounds).
- Acceptance bullet: updated from "Range facts on integer algebras
  (substrate-declared, not Rust-mirrored)" to add "using String-decimal
  representation ... width-independent; u64 bounds expressible without
  truncation."

The brief now consistently treats range bounds as String-decimal
across req 2, req 3, slice, acceptance, and the req 1 clarification —
no remaining authorities saying i64-typed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing

User + PM exchange 2026-04-25 surfaced that the in-flight effects
chain was importing wrong assumptions from external languages
(declared-effects-as-annotation + lens-vs-declaration check). Right
framing under gunbc's closed-system discipline is parallel to
complexity: every effect derives structurally from the composition
of typed primitive operations; nothing can hide because there's no
escape hatch; nothing needs annotation because the structure IS the
registry.

Four doc-only actions:

1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md.
   Frames the closed-system answer with PM's 5-behavior synergy
   table (Value/Transform/Branch/Loop/Bind as universal
   compositional-fold pattern). Four worked examples; aggressive
   reading on redundancy (compile-error-by-construction via
   referential-transparency proof; reread() primitive for legitimate
   cases); implementation-brief shape in §Q6.

2. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md.

3. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md.
   Notes Fn→Arrow refactor brief stays dispatchable as independent
   value.

4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by-
   construction framing replaces lens-detection framing.

Memory file feedback_closed_system_effects.md saved separately;
cross-link added to feedback_construction_over_ratchets.md.

Net cost: doc-level cleanup. Zero substrate code rework. Foundation
(OperationEffect + service-call infrastructure + 5-behavior
substrate) already exists.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect

Per PM convergence review on #808 + user's deeper 2026-04-25 framing:
the closed-system framing landed in #808 retired the user-facing
annotation but kept OperationEffect taxonomy as substrate-level tagging.
User's deeper framing: the taxonomy ITSELF is parallel-representation —
operations are intrinsically read-shaped or write-shaped via their
TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns-
derived-value-only → read). Tagging operations with Read | Upsert |
Create | Append | Delete names what the structure already says.

Three changes:

1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as
   normalized view, or retire as parallel-representation?"
   - Two paths: (i) tags derived from signature shape (acceptable
     normalized view) vs (ii) tags declared per-primitive (parallel-
     representation; retire).
   - Audit-as-existence-check (Q4 req 2 reframed): all effectful
     primitives derive cleanly from signature shape → path (i); any
     primitive needs hand-declared tag → path (ii) by existence proof.
   - Director default: path (ii). Logging primitives that return Unit
     are likely the audit's existence-proof.
   - Two design-question resolutions: (a) external effects not in
     return type → resource-threading discipline (typed param returned
     modified, IO-monad-without-the-monad pattern); (b) transactional
     grouping → derived structural fact from Bind composition + typed
     transaction primitives.

2. Q4 reqs revised: req 2 from "tag every primitive with explicit
   OperationEffect signature" to "audit-as-existence-check that every
   primitive's type signature derives the right effect classification";
   req 3 added (resource-threading discipline); req 6 added
   (transactional-pattern lens). Req 1 (effects lens) anchors on
   operation type-signature shape, not on hand-declared tags.

3. THESIS:345-347 amendment strengthened — "operations are
   intrinsically read-shaped or write-shaped via their type-signature
   shape; consumers walk the signatures directly; there is no parallel
   taxonomy or annotation layer to declare or maintain. Tracking
   effects as a separate enumerated concept IS the bug pattern,
   dissolved by construction." Plus references to resource-threading
   discipline + transactional grouping as derived structural fact.

Memory file feedback_closed_system_effects.md updated to reflect the
deeper framing (type-signature-shape, not taxonomy-tagging) +
resource-threading discipline section + transactional-patterns
section.

Net cost: doc-only delta on top of #808. Substrate retirement
(OperationEffect enum + derive_op_effect + idempotency.dag re-anchor)
deferred to the audit-as-existence-check phase of the implementation
brief; surfaced as Q5.5 OPEN CALL.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage

Resolves codex BLOCKING at sha d49ce79 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real:
the prior text claimed service primitives "already carry typed effect
signatures" presenting future audit-state as current substrate fact
(P1 violation). My Q5.5 amendment at 2dc656b partially fixed the
OperationEffect line but left a parallel over-claim on the new
"signature-shape coverage" framing.

Fix: Q4 substrate-state listing rewritten to honestly distinguish:

- Live: Behavior enum + substrate foundation (the principle that
  operations should carry signature shape).
- Incomplete: signature-shape coverage across actual primitives.
  HTTP-derived primitives carry implicit shape via derive_op_effect's
  method-table; logging/mutation primitives that return Unit or don't
  thread their target resource do NOT carry the structural shape that
  would express read-vs-write. Achieving full coverage is required
  work under reqs 2 + 3, not a current fact.
- Pending audit-as-existence-check: OperationEffect + derive_op_effect
  (path (i) vs (ii) per Q5.5).

Honest live-state callout added explicitly: "the closed-system
FOUNDATION (5 behaviors + DAG substrate + the principle that
operations should carry signature-shape) is live. The IMPLEMENTATION
COVERAGE across all effectful primitives is partial. Req 2 + req 3
are the work that closes the gap."

Brief now distinguishes principle-is-live (foundation) from
coverage-is-partial (audit work) without conflating them.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim

Per PM follow-up review on #808 + user's stronger discipline framing
("substrate must make bypass structurally impossible at every layer
of the transport stack"): the closed-system claim is honest only when
typed primitives ARE the path. Today two structural holes exist where
bypasses sidestep the typed-primitive substrate. Both surfaced
explicitly as Q4.5 pre-conditions — load-bearing for the lens's
coverage claim.

Three changes:

1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed-
   system claim)" inserted between Q4 and Q5:

   P1 — Extdeps typed-primitive consumption structurally enforced.
   Substrate must make `messages: Json` impossible to declare in
   service definitions; typed `LlmMessage` / `ContentBlock` /
   `GitHubAuthToken`-with-full-scopes are the only path. Tracked
   debt at ROADMAP.md:153-154 (LLM provider flattening) +
   `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded).
   Required prereq for full lens coverage; lens can land first +
   surface structural-coverage-gap diagnostics on bypass surfaces
   so the gap becomes visible rather than silent.

   P2 — `ExecuteCommand` fully materialized as typed runner
   primitive. TESTING.md (post-#782) committed to 0-residual but
   ExecuteCommand isn't fully materialized; deleting Rust boundary
   tests creates verification gap. Already named under PB-Runtime
   in Zero-Floor; signal pending. Pre-requisite for ANY Rust
   boundary-test deletion.

2. Old leftover duplicate Q5 section deleted (artifact from prior
   Q5/Q5.5 reshape; second copy of asymmetric-tightening text was
   in the file alongside the earlier Q5 instance).

3. Worker-discretion-vs-Director-call section in Q4.5: lens
   implementation worker dispatchable now (reports gaps as
   findings); P1 closure is substantive substrate work touching
   extdeps (dedicated lane); P2 closure is PB-Runtime (signal
   pending).

Net: design doc now honestly distinguishes principle-is-live
(Q4 rewrite at 191be31) from coverage-is-partial (Q4.5 prereqs
named explicitly). The closed-system claim has explicit pre-
conditions documented; implementation brief discovers them as
known dependencies, not as STOP-AND-ESCALATEs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default

Resolves claude APPROVE_WITH_COMMENTS at sha 191be31 on #808. Two
real residuals after the Q5.5 reframe:

1. Q6's reqs/STOPs/acceptance still framed under path (i) — said
   "audit + tag std/ primitives — every effectful primitive carries
   an explicit OperationEffect signature." Directly contradicted Q4
   (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment
   ("there is no parallel taxonomy to declare or maintain"). Worker
   reading Q6 in isolation would author the retracted shape.

2. Capacity / sequencing table line about "audit lane (tag std/
   primitives with effect signatures)" carried the same stale
   framing.

3. Q6 STOP "primitive performing side effects without an
   OperationEffect tag" assumed tag-as-authority; under path (ii)
   the STOP shape is "primitive whose signature doesn't structurally
   reveal its effect."

Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale
(already fixed at f073aa9 Q4.5 commit).

## Q6 fixes

- Reqs renumbered + reframed:
  - Req 1 anchors on operation type-signature shape (not hand-declared
    OperationEffect tags); composition reads from signature shape per
    Q2 table.
  - Req 2 changed from "audit + tag every primitive" to
    "audit-as-existence-check" — verify signature-shape coverage; ANY
    primitive needing a hand-declared tag IS the existence-proof for
    path (ii) retirement.
  - Req 3 added: resource-threading discipline applied to existing
    primitives (logging that returns Unit gets reshaped per audit).
  - Req 6 added: transactional-pattern lens (Bind composition +
    Transaction → Transaction').
  - Req 7 added: asymmetric-tightening worked example in PR body
    (per claude review observation; the one place declaration-shaped
    surface re-enters).
  - Req 8 (was 5): tests now reference signature-shape derivation
    explicitly, not tag lookup.
- STOPs reframed:
  - "OperationEffect retirement decision" — audit produces path (i)
    vs (ii) verdict; substrate retirement is its own dedicated
    sub-lane; this lane does NOT absorb it.
  - Pure/impure carrier STOP notes that "pure" should also derive
    from signature shape (pure functions don't return modified
    resources) — so the STOP itself may dissolve under further design.
  - Q4.5 P1 explicitly NOT a STOP — lens reporting structural-
    coverage-gap on extdeps bypass surfaces is the lens delivering
    its foundation-gap-visibility value.
  - Q4.5 P2 explicitly independent — lens doesn't depend on
    ExecuteCommand materialization.
- Acceptance extended: lens reports gap diagnostics on P1 bypass
  surfaces; audit produces existence-proof verdict for Director
  re-decision; asymmetric-tightening worked example in PR body.

## Capacity / sequencing table

Replaced "1 audit lane (tag std/ primitives with effect signatures)"
with "1 audit-as-existence-check lane (verify primitives' signature-
shape coverage; NOT 'tag every primitive') — produces the path (i)
vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2
prereq lanes to the net summary. Closing line: "The taxonomy-
retirement scope (substrate-side) is not in this lane — it's
surfaced by audit and routed to dedicated retirement lane if path
(ii) wins."

Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity
table. Worker reading Q6 in isolation now sees path-(ii)-default
framing matching Q4 + Q5.5 + THESIS amendment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792

Resolves codex inline BLOCKING at sha 191be31 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150.
Real: my Q4.5 P2 framing described ExecuteCommand as still
NotYetImplemented (M1.5 allowlist + Rust TestRunner returning
NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand
extension before this PR's authoring. TESTING.md:195 capability-state
callout confirms:
- Rust TestRunner + M1.5 testgen harness share one std::process path
  for arbitrary command + args + expect_exit_code.
- M1.5 allowlist + fail-closed panic retired.
- Distinguishable ClaimResult::Fail messages for spawn / timeout /
  policy / exit-mismatch.
- Linux unshare(1) namespace isolation on host-allowing systems.
- T-PB-B-1 boundary migration example landed.

Fix:

P2 section rewritten:
- Header retitled "ExecuteCommand runner primitive: LANDED (PR #792);
  residual is bulk-migration."
- Status update naming PR #792 + the post-#792 capability state
  (allowlist retired, etc.).
- Honest acknowledgement: "My earlier P2 framing was stale."
- Residual narrowed to bulk-migration of existing Rust Command::new
  boundary tests (tracked as ROADMAP residual, not lens prereq).
- Sequencing reframed: P2 was always orthogonal to the effects lens
  itself; bulk migration proceeds at its own pace; lens not blocked.

Q4.5 footer updated:
- "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via
  #792; only consumer-side bulk migration remains)"
- Worker-discretion-vs-Director-call P2 line updated: "runner
  primitive landed; only consumer-side bulk migration remains;
  tracked as ROADMAP residual, independent of the lens."

Q6 STOP for P2 updated:
- "the lens itself doesn't depend on P2; only TESTING.md's 0-residual
  claim does" → "runner primitive landed via PR #792 (post-Q4.5-
  authoring update). The lens itself never depended on P2; bulk
  consumer migration is residual ROADMAP work and remains independent
  of this lane."

Brief now reflects live state. The closed-system claim's prereq
landscape is honest:
- P1 (extdeps typed-primitive consumption): real prereq, tracked
  debt at ROADMAP:153-154.
- P2 (ExecuteCommand runner): satisfied via #792; bulk migration is
  consumer-side residual, not foundation work.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale

Resolves codex non-blocking finding at sha bcac41b on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real
residual: capacity-table line still listed P2 as "`ExecuteCommand`
materialization" prereq + framed both P1 and P2 as "pre-existing
tracked-debt" — but my prior 57a9b13 fix established that PR #792
already landed the runner primitive, so P2 is no longer a
materialization prereq.

Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq)
from P2 (residual, not prereq):

  - P1: extdeps typed-primitive consumption — pre-existing tracked
    debt at ROADMAP:153-154; load-bearing for the lens's full-coverage
    claim.
  - P2: ExecuteCommand runner primitive landed via PR #792; only
    consumer-side bulk migration of existing Rust Command::new
    boundary tests remains (tracked as ROADMAP residual, independent
    of the lens; not a materialization prereq).

Brief now consistently treats P2 as bulk-migration-residual across:
- §Q4.5 P2 section header (LANDED via PR #792; residual is
  bulk-migration).
- §Q4.5 footer (P2: runner primitive landed; only consumer-side
  bulk migration remains).
- Q6 STOP for P2 (runner primitive landed; bulk migration is
  residual ROADMAP work).
- §Capacity / sequencing impact (P2 as residual, not prereq).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349

Codex finding on PR #808 sha ece964e: lines 153-154 are unrelated
target-grounding prose; the matching extdeps typed-primitive bypass
entries (LLM service flattening, GitHub auth model bypass) live at
ROADMAP.md:348-349.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix third stale ROADMAP citation at line 271

Codex follow-up on sha 2552ca3: prior fix missed a third occurrence
at line 271 in the §Q4.5 capacity table. Now consistent with lines
139 and 173 (ROADMAP.md:348-349).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity

Codex flagged 'Effect-signature tagging on std/ primitives' as potentially
contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240)
already explicitly say 'NOT tag every primitive' — but the cross-manager
line used sloppy wording. Reworded to make explicit that the audit walks
signature shape; no parallel tag added.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5

- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)

B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).

B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — drop incoherent inner-fallback non-goal

Codex P2: the non-goal line excluding the inner declaration().name
unwrap_or_else fallback contradicted Slice step 2, which replaces the
whole chain with let-Some-else-return. Both fallbacks are in scope by
construction; remove the contradictory non-goal.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives

PM REQUEST_CHANGES: §Frame listed '4 type connectives
(Conjunction | Disjunction | Cardinality | Bit)' which contradicted
the canonical thesis source. Replaced with the canonical 6
(Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per
docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary
closes here'. Also removed 'typed substrate carriers' from the
vocabulary list — substrate carriers are defined using the vocabulary,
not part of it. Added a clarifying note that B4's carriers
(DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are
typed declarations composed from the vocabulary, not vocabulary
extensions.

Per feedback_verify_thesis_claims: brief framings citing thesis
structure must ground in the canonical source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority

Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of
naming the live substrate authority. Two coordinated fixes:

1. §Read first cites src/v3/std/substrate.dag (live .dag substrate
authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel
meta-type — already exists with consumers in verification.dag,
emit_model.dag, python.dag).

2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing
DeclarationRef'. The work is consumer migration + any role-extension
layer the audit reveals, NOT designing or landing the carrier.

Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers)
keep their 'new' framing but explicitly require sub-briefs to grep
src/v3/std/ + src/v3/spec/ for existing authority before authoring
'design and land' framing — per feedback_verify_thesis_claims +
feedback_emitter_workaround_is_gap_symptom.

Acceptance + sub-brief dispatch order updated to reflect B4.1's
consumer-migration shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — tighten Phase 1 umbrella sentence

The umbrella 'Land the typed carriers into src/v3/std/' framing was
stale after f52e2ce's reframe of #1 to consumer-migration. Replaced
with audit-first wording that covers both the consume-existing case (#1)
and the design-and-land case (#2-#4 if their audits show real gaps).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 25, 2026
…ost-#815 follow-up) (#816)

* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation)

Director-authored amendment following the 2026-04-24 escalation from PR
#693 (sub-child sharp-bear-829 under Surface Manager).

Two edits:

1. New "Class 5 Gap 3 — port-carried field values in data bodies"
   row in the 2026-04-21 post-merge-debt section. The substrate gap was
   documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP
   ledger row for cross-lane visibility. PR #693's execution surfaced it
   as the blocker on sub_charclass_in_std_unicode phase-2.

2. Retract the "ready-to-dispatch (no substrate capability gap)" claim
   on the Character-level row, annotate phase-1 landed via PR #693
   (CharClass vocabulary + Rust-mirror structural scanner path), and
   point phase-2 at the new Class 5 Gap 3 row.

Codifies the audit pattern: "this consumption gap has no substrate
capability gap" claims must be verified by attempting the retype before
the claim lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main

* docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review)

* docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review)

Row title still said 'consumption gap, not substrate gap' while the
body block retracted that claim and cited Class 5 Gap 3 as a substrate
dependency for phase-2. Title now matches body: mixed classification,
consumption for steps 1+3, substrate for step 2.

* docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit)

gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining
gap" description was wrong: field-level shapes (nested records, list
literals, declaration refs, Var refs, sum-variant literals) are
supported today via FieldValue variants + lower_structural_field_value
(dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the
top-level ValueBody boundary (non-scalar, non-record top-level bodies).

The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself
stale: it describes the pre-PR-B-unwind shape where FieldValue was
LiteralBits-only. PR-B's unwind extended FieldValue to carry
Reference / Record / List / Variant, moving the gap to ValueBody.

Two fixes:

1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody
   boundary, point at code paths (dag.rs, lower.rs) as live authority,
   flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass
   blocker classification to "provisional pending reproduction."

2. Update the Character-level row's phase-2 block to name that the
   specific shape of the CharClass failure needs concrete reproduction
   from the escalating sub-child before the blocker is finalized.

Recursive audit-pattern instance: the row I wrote to codify "verify
live state before claiming substrate gap" itself failed to verify live
state. Both incidents (2026-04-23 original row + 2026-04-24 my
retraction row) are now cited in the audit-pattern sub-note as
examples of the same discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c3

Three substantive fixes addressing internal-consistency gaps in the cascade
promotion PR caught by codex review at sha 0d6e7c3:

1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane
   acceptance bullets and Hand-Rust census paragraph in line with the
   updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero
   (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is
   retracted under 0-floor with explicit migration to ExecuteCommand-based
   .dag TestClaim declarations.

2. docs/design-pure-bootstrap-zero.md promotion section — converted from
   future-tense ("This doc is PROPOSAL until promoted… promotion is a
   single Director-authored cascade PR…") to historical past-tense
   promotion-receipt framing ("This doc was PROPOSAL until promoted;
   promotion was a single Director-authored cascade PR that did all of the
   following atomically…"); blocking-clause struck through and resolved
   inline. Banner cites PR #782 explicitly.

3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_
   profile excluded (Map<String, AlgebraProfile> body, not list-of-sum;
   needs distinct ValueBody::Map substrate work, tracked separately as a
   future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass
   phase-2 + Engine sharpened-(b) pilot enumeration), both sharing
   list-of-sum substrate work. Lane table, dependency DAG, and capacity
   summary updated for consistency (slot count 9-13, was 10-14).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities

Resolves claude REQUEST_CHANGES at sha fed6b03 — atomic-cascade
self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22
explicitly names THESIS.md and "any other authority docs" as required
retraction targets; the prior diff updated ROADMAP + r2-structure + design
docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting-
manager.md pointing at the now-SUPERSEDED ≤5-floor framing.

Files:

- THESIS.md (5 prose blocks updated):
  - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests
    migrate to ExecuteCommand-based .dag TestClaim declarations.
  - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag.
  - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor
    target citing design-pure-bootstrap-zero.md as live authority;
    hand_maintained_src list shrinks to empty set.
  - :301-318 — Tests-are-structural-data block: residual carve-out retracted;
    predicate name pb_rust_tests_outside_residual_zero retained as
    housekeeping (semantically the residual is empty under cascade).

- docs/thesis/compiler-std-consolidation.md (5 references):
  - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes
    design-pure-bootstrap.md (SUPERSEDED).
  - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process
    lane named as the dissolution trigger for bootstrap.rs itself.
  - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md.
  - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority
    re-cited.
  - :185 Related docs link.

- docs/briefs/r1-selfhosting-manager.md (active dispatch brief):
  - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5);
    T-PB-B residual carve-out retracted; predicate names retained for
    housekeeping; cascade-promoted authorities are source of truth.
  - Slice descriptions for T-PB-A / T-PB-B updated inline.
  - Framing-question + ask updated to 0-floor / no-residual framing.
  - Day-1 + up-to-director hand-off bullets updated.
  - Working-state checklist :111 ≤5 → 0 with cite.
  - Decisions log :164 ≤5 → 0-floor target updated.

- docs/r2-structure.md §2 design call (RETRACTED block):
  - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through
    in entirety (both Option A sharpen-and-keep and Option B rename are
    moot under 0-floor). Section preserved as audit-trail historical
    context.
  - Background-doc index: self-hosting anchor updated to
    design-pure-bootstrap-zero.md as live authority.

- docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per
  non-blocking suggestion):
  - Banner cites cascade promotion PR #782 explicitly.
  - New paragraph: "Treat all numeric floors below as retracted" with
    explicit lines named that quote in isolation (table row, body prose
    references). Prevents re-quoting from this doc as live authority.

Cascade is now atomically consistent across:
  THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔
  docs/thesis/compiler-std-consolidation.md ↔
  docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔
  docs/design-pure-bootstrap-zero.md (LIVE) ↔
  docs/design-pure-bootstrap.md (SUPERSEDED).

The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds
genuinely.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): correct ExecuteCommand runner-capability claim

Resolves codex BLOCKING #1 at sha fed6b03 (P1 live-state violation):
TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138
overstated live runner capability — claimed runner support landed in
PR #688/#741 with "emit Rust, invoke rustc on output, check exit code"
as a structurally-equivalent migration path. Verified against live
sources:

- src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema
  exists (declared via PR #678).
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5
  testgen harness allowlists ONLY `command == "true" && args.is_empty()
  && expect_exit == 0`.
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 —
  panics fail-closed on any other shape with explicit "ExecuteCommand
  shell shape is not supported here (runner-owned — do not treat as
  ordinary false)".
- src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no
  match arm for ExecuteCommand; falls through to ClaimResult::
  NotYetImplemented.

Reality: a TestClaim declaring rustc/python/go invocation is
structurally expressible as data today, but executing it is blocked.
Full arbitrary-command runner support is the PB-Runtime lane's
deliverable.

Files updated:

- TESTING.md:195 — capability state callout with file:line citations;
  "Full runner support — arbitrary command + args (rustc/python/go) with
  exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor
  program)." Bullet about migration shape preserved as the cascade-named
  successor pattern, not as a live capability.
- TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane
  lands the ExecuteCommand runner extension" as an explicit precondition.
- docs/design-pure-bootstrap-zero.md:138 — same correction for the
  matching prose, with PB-Runtime named as the runner-extension
  dependency for boundary-test migration.
- ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner
  foundation in #688/#741 with `true`-no-args allowlist only — full
  arbitrary-command runner support deferred to PB-Runtime lane,
  blocking the actual boundary-test migration." Dependencies column
  extended to "DB-15 + T-TestGen + PB-Runtime".

The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still
holds for atomic-cascade-across-authority-docs; this commit closes the
remaining capability/claim mismatch flagged by codex.

(Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still
SUPERSEDED-pointing — was sha-stale; resolved in c85e691.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief

Resolves codex BLOCKING at sha 0fb223a (P2 single-authority violation).
The prior banner contained:

> "Operationally R1 closure may still ship before the 0-floor is reached
>  — the ratchet ensures the trajectory; the gate's acceptance number is
>  what shifts."

This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0.
Two competing gate semantics in the cascade is exactly what the
atomic-cascade clause forbids.

Replaced with single-authority-honest framing:

> "R1 closure now requires the 0-floor target by gate semantics: T-PB-A
>  and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade
>  promotion changed their acceptance numbers to 0; R1 cannot close
>  while the SG-0 census carries non-zero hand-Rust."

Plus minor sharpening:
- "T-PB-A's non-test target is 0" → "non-test acceptance target is 0
  per ROADMAP.md:67" (cite the authority).
- T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep
  the capability-state honesty consistent with the recent fix wave.
- Predicate-rename housekeeping line moved into banner ("post-cascade
  housekeeping, not a pre-promotion blocker") — was implicit before.

The brief now genuinely inherits the cascade-promoted gate; no
competing release authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 second-wave worker-escalation fixes

Four substantive worker STOP-AND-ESCALATEs from briefs landed in
PR #797. All four worker recommendations correct; each needs a
Director call + brief update.

## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate

Worker correctly identified that brief req 2 (declared-effect carrier
as part of fn type signature, per feedback_no_annotations) requires
net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at
src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots.
Without parser surface, every user function would have
declared_effects = [] while inference returns non-empty — lens fires
EffectLeakageError everywhere on enable. Worker rejected power-through
and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map
parser split).

Director picked split:
- NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md
  Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface
  syntax + lookahead + body parser + lowerer extension + exhaustive-match
  audit + coproduct dissolution receipt.
- MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to
  post-parser-extension scope. Pre-flight check NOT a parser-extension
  step; STOP if parser sub-lane PR not merged.

## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping

Worker found load-bearing evidence at infer.rs:3693-3703: DB-11
deliberately strips refinements at operator dispatch as a designed-in
fix for symmetric-operators failure mode. Brief's "attach where b != 0
as a proof for a / b" directly contradicts this design choice. STOP-3
(where-clause conflict with DB-11) is real; STOP-1 (substrate scope)
needs net-new substrate (per-operator partiality fact + predicate-
entailment check + asymmetric per-operand refinement-honoring) — M+
minimum. ownership_lens precedent in original brief is post-hoc
observability, not proof carrier.

Worker recommended redirect to design/scoping per nested-optional
precedent. Director picked redirect.

Brief fully rewritten as design/scoping with four-question structure:
(1) DB-11 interaction analysis; (2) substrate proposal for proof-or-
totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes
with acceptance-theatre risk on user-defined-total-wrapper-only);
(4) Director-actionable recommendation. Output is doc PR.

## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C)

Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int)
with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136
closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b)
i128 implementation requires either path 1 (hierarchy refactor —
contradicts non-goal) or path 2 (regen lie between substrate and
emit — violates discipline). Worker leaned option (C) re-scope:
land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke)
to a sibling sub-lane that does proper Int128/Word128 substrate work.

Director picked option (C). Brief req 1 re-scoped to drop canonical-
carrier-widening; lane value comes from range facts + reconciliation
narrowing + out-of-range diagnostic against existing i64. Req 4
explicitly deferred with sibling-sub-lane reference. Sibling sub-lane
NOT to be authored or implied in this PR; tracked separately.

## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change)

Worker correctly STOP'd per the brief's own pre-flight check: parser
sub-lane has not landed; SurfaceExpr::Map not on main. Director
authorized cross-lane reassignment: wise-boar-480 takes the parser
sub-lane (t-substrate-valuebody-map-parser-worker.md) since they
already have full investigation context. No brief changes needed; the
routing decision is in the dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope

Resolves codex P2 inline at sha e35103f on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer
carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still
required widening LiteralBits::Int(i64) to an unbounded carrier and
passing the i64::MIN smoke. Internally unsatisfiable.

Fix:

- Slice section retitled "range facts + reconciliation narrowing
  (against existing i64 carrier)" with explicit note about the
  re-scope.
- Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly
  forbids touching LiteralBits::Int shape, dag_scalar_generated.rs
  regen for that variant, or tokenize i64 parse path.
- Slice steps 2-5 reframed: range facts use i64-representable
  magnitudes; reconciliation narrowing uses existing i64 carrier;
  diagnostic only for i64-representable out-of-range; smoke tests
  for req 5 only (req 4 i64::MIN deferred).
- Acceptance checklist updated:
  - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as
    re-scoped/deferred.
  - LiteralBits::Int(i64) carrier untouched (no widening; no
    parallel; no shape change).
  - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference.
- STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the
  carrier" — explicit STOP if execution surfaces range-fact narrowing
  requiring carrier-widening; that's the boundary the re-scope drew;
  belongs in sibling Int128/Word128 sub-lane.

Brief now consistently treats carrier-widening as out-of-scope across
all sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty

Resolves codex BLOCKING #1 at sha e35103f on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier
but req 2 required range facts using "the SAME magnitude carrier
as req 1" — meaning i64-typed range bounds. u64's max (2^64-1)
doesn't fit in i64; range fact for u64 would have to truncate,
omit, or mirror in Rust (representation drift). All three options
violate fail-closed declared-facts discipline (P1 / P3).

Fix:

- Req 2 rewritten to specify String-decimal representation:
  range_min_inclusive: String + range_max_inclusive: String fields
  on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127"
  for i8; "0"/"18446744073709551615" for u64).
- Explicit reasoning why String-decimal: u64's max doesn't fit in
  i64; binding range bounds to literal carrier forces truncation/
  omission/mirror-drift; all violate fail-closed declared-facts
  discipline.
- Bridge framing: String-decimal is pending the sibling Int128/
  Word128 sub-lane; both range bounds and literal payload migrate
  to typed carrier when that lands.

- Req 3 updated for String-decimal comparison semantics:
  reconciliation parses both bounds and literal magnitude into a
  common comparison space (i128 host comparison primitive — host
  narrowing, NOT carrier widening). Bounded by what the i64-typed
  literal can express; any i64-representable literal compares
  against any width's String-decimal bound. Carrier discipline
  preserved.

Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral)
is sha-stale — already resolved at 3e142d1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed

Resolves codex BLOCKING at sha 0815189 (post-#799-merge feedback).
Real residual: req 2 specifies String-decimal range bounds (to cover
u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance
bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" /
"i64-representable magnitudes" for the range facts. Two incompatible
authorities for the same range-fact shape — would let a worker satisfy
the slice while truncating/omitting u64 bounds (P3 fail-closed
violation).

Fix:

- Line 31 (req 1 re-scope clarification): updated to explicitly state
  "range facts (req 2) use String-decimal representation (width-
  independent; covers u64::MAX which doesn't fit in i64)". Distinguished
  literal *payload* (stays i64) from range-bound *representation*
  (String) — both serve req 1's "no carrier widening" boundary.
- Line 44 (slice step 2): updated from "Range bounds use i64-
  representable magnitudes" to "Range bounds use String-decimal
  representation per req 2" with concrete example (u64 bounds).
- Acceptance bullet: updated from "Range facts on integer algebras
  (substrate-declared, not Rust-mirrored)" to add "using String-decimal
  representation ... width-independent; u64 bounds expressible without
  truncation."

The brief now consistently treats range bounds as String-decimal
across req 2, req 3, slice, acceptance, and the req 1 clarification —
no remaining authorities saying i64-typed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing

User + PM exchange 2026-04-25 surfaced that the in-flight effects
chain was importing wrong assumptions from external languages
(declared-effects-as-annotation + lens-vs-declaration check). Right
framing under gunbc's closed-system discipline is parallel to
complexity: every effect derives structurally from the composition
of typed primitive operations; nothing can hide because there's no
escape hatch; nothing needs annotation because the structure IS the
registry.

Four doc-only actions:

1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md.
   Frames the closed-system answer with PM's 5-behavior synergy
   table (Value/Transform/Branch/Loop/Bind as universal
   compositional-fold pattern). Four worked examples; aggressive
   reading on redundancy (compile-error-by-construction via
   referential-transparency proof; reread() primitive for legitimate
   cases); implementation-brief shape in §Q6.

2. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md.

3. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md.
   Notes Fn→Arrow refactor brief stays dispatchable as independent
   value.

4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by-
   construction framing replaces lens-detection framing.

Memory file feedback_closed_system_effects.md saved separately;
cross-link added to feedback_construction_over_ratchets.md.

Net cost: doc-level cleanup. Zero substrate code rework. Foundation
(OperationEffect + service-call infrastructure + 5-behavior
substrate) already exists.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect

Per PM convergence review on #808 + user's deeper 2026-04-25 framing:
the closed-system framing landed in #808 retired the user-facing
annotation but kept OperationEffect taxonomy as substrate-level tagging.
User's deeper framing: the taxonomy ITSELF is parallel-representation —
operations are intrinsically read-shaped or write-shaped via their
TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns-
derived-value-only → read). Tagging operations with Read | Upsert |
Create | Append | Delete names what the structure already says.

Three changes:

1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as
   normalized view, or retire as parallel-representation?"
   - Two paths: (i) tags derived from signature shape (acceptable
     normalized view) vs (ii) tags declared per-primitive (parallel-
     representation; retire).
   - Audit-as-existence-check (Q4 req 2 reframed): all effectful
     primitives derive cleanly from signature shape → path (i); any
     primitive needs hand-declared tag → path (ii) by existence proof.
   - Director default: path (ii). Logging primitives that return Unit
     are likely the audit's existence-proof.
   - Two design-question resolutions: (a) external effects not in
     return type → resource-threading discipline (typed param returned
     modified, IO-monad-without-the-monad pattern); (b) transactional
     grouping → derived structural fact from Bind composition + typed
     transaction primitives.

2. Q4 reqs revised: req 2 from "tag every primitive with explicit
   OperationEffect signature" to "audit-as-existence-check that every
   primitive's type signature derives the right effect classification";
   req 3 added (resource-threading discipline); req 6 added
   (transactional-pattern lens). Req 1 (effects lens) anchors on
   operation type-signature shape, not on hand-declared tags.

3. THESIS:345-347 amendment strengthened — "operations are
   intrinsically read-shaped or write-shaped via their type-signature
   shape; consumers walk the signatures directly; there is no parallel
   taxonomy or annotation layer to declare or maintain. Tracking
   effects as a separate enumerated concept IS the bug pattern,
   dissolved by construction." Plus references to resource-threading
   discipline + transactional grouping as derived structural fact.

Memory file feedback_closed_system_effects.md updated to reflect the
deeper framing (type-signature-shape, not taxonomy-tagging) +
resource-threading discipline section + transactional-patterns
section.

Net cost: doc-only delta on top of #808. Substrate retirement
(OperationEffect enum + derive_op_effect + idempotency.dag re-anchor)
deferred to the audit-as-existence-check phase of the implementation
brief; surfaced as Q5.5 OPEN CALL.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage

Resolves codex BLOCKING at sha d49ce79 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real:
the prior text claimed service primitives "already carry typed effect
signatures" presenting future audit-state as current substrate fact
(P1 violation). My Q5.5 amendment at 2dc656b partially fixed the
OperationEffect line but left a parallel over-claim on the new
"signature-shape coverage" framing.

Fix: Q4 substrate-state listing rewritten to honestly distinguish:

- Live: Behavior enum + substrate foundation (the principle that
  operations should carry signature shape).
- Incomplete: signature-shape coverage across actual primitives.
  HTTP-derived primitives carry implicit shape via derive_op_effect's
  method-table; logging/mutation primitives that return Unit or don't
  thread their target resource do NOT carry the structural shape that
  would express read-vs-write. Achieving full coverage is required
  work under reqs 2 + 3, not a current fact.
- Pending audit-as-existence-check: OperationEffect + derive_op_effect
  (path (i) vs (ii) per Q5.5).

Honest live-state callout added explicitly: "the closed-system
FOUNDATION (5 behaviors + DAG substrate + the principle that
operations should carry signature-shape) is live. The IMPLEMENTATION
COVERAGE across all effectful primitives is partial. Req 2 + req 3
are the work that closes the gap."

Brief now distinguishes principle-is-live (foundation) from
coverage-is-partial (audit work) without conflating them.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim

Per PM follow-up review on #808 + user's stronger discipline framing
("substrate must make bypass structurally impossible at every layer
of the transport stack"): the closed-system claim is honest only when
typed primitives ARE the path. Today two structural holes exist where
bypasses sidestep the typed-primitive substrate. Both surfaced
explicitly as Q4.5 pre-conditions — load-bearing for the lens's
coverage claim.

Three changes:

1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed-
   system claim)" inserted between Q4 and Q5:

   P1 — Extdeps typed-primitive consumption structurally enforced.
   Substrate must make `messages: Json` impossible to declare in
   service definitions; typed `LlmMessage` / `ContentBlock` /
   `GitHubAuthToken`-with-full-scopes are the only path. Tracked
   debt at ROADMAP.md:153-154 (LLM provider flattening) +
   `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded).
   Required prereq for full lens coverage; lens can land first +
   surface structural-coverage-gap diagnostics on bypass surfaces
   so the gap becomes visible rather than silent.

   P2 — `ExecuteCommand` fully materialized as typed runner
   primitive. TESTING.md (post-#782) committed to 0-residual but
   ExecuteCommand isn't fully materialized; deleting Rust boundary
   tests creates verification gap. Already named under PB-Runtime
   in Zero-Floor; signal pending. Pre-requisite for ANY Rust
   boundary-test deletion.

2. Old leftover duplicate Q5 section deleted (artifact from prior
   Q5/Q5.5 reshape; second copy of asymmetric-tightening text was
   in the file alongside the earlier Q5 instance).

3. Worker-discretion-vs-Director-call section in Q4.5: lens
   implementation worker dispatchable now (reports gaps as
   findings); P1 closure is substantive substrate work touching
   extdeps (dedicated lane); P2 closure is PB-Runtime (signal
   pending).

Net: design doc now honestly distinguishes principle-is-live
(Q4 rewrite at 191be31) from coverage-is-partial (Q4.5 prereqs
named explicitly). The closed-system claim has explicit pre-
conditions documented; implementation brief discovers them as
known dependencies, not as STOP-AND-ESCALATEs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default

Resolves claude APPROVE_WITH_COMMENTS at sha 191be31 on #808. Two
real residuals after the Q5.5 reframe:

1. Q6's reqs/STOPs/acceptance still framed under path (i) — said
   "audit + tag std/ primitives — every effectful primitive carries
   an explicit OperationEffect signature." Directly contradicted Q4
   (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment
   ("there is no parallel taxonomy to declare or maintain"). Worker
   reading Q6 in isolation would author the retracted shape.

2. Capacity / sequencing table line about "audit lane (tag std/
   primitives with effect signatures)" carried the same stale
   framing.

3. Q6 STOP "primitive performing side effects without an
   OperationEffect tag" assumed tag-as-authority; under path (ii)
   the STOP shape is "primitive whose signature doesn't structurally
   reveal its effect."

Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale
(already fixed at f073aa9 Q4.5 commit).

## Q6 fixes

- Reqs renumbered + reframed:
  - Req 1 anchors on operation type-signature shape (not hand-declared
    OperationEffect tags); composition reads from signature shape per
    Q2 table.
  - Req 2 changed from "audit + tag every primitive" to
    "audit-as-existence-check" — verify signature-shape coverage; ANY
    primitive needing a hand-declared tag IS the existence-proof for
    path (ii) retirement.
  - Req 3 added: resource-threading discipline applied to existing
    primitives (logging that returns Unit gets reshaped per audit).
  - Req 6 added: transactional-pattern lens (Bind composition +
    Transaction → Transaction').
  - Req 7 added: asymmetric-tightening worked example in PR body
    (per claude review observation; the one place declaration-shaped
    surface re-enters).
  - Req 8 (was 5): tests now reference signature-shape derivation
    explicitly, not tag lookup.
- STOPs reframed:
  - "OperationEffect retirement decision" — audit produces path (i)
    vs (ii) verdict; substrate retirement is its own dedicated
    sub-lane; this lane does NOT absorb it.
  - Pure/impure carrier STOP notes that "pure" should also derive
    from signature shape (pure functions don't return modified
    resources) — so the STOP itself may dissolve under further design.
  - Q4.5 P1 explicitly NOT a STOP — lens reporting structural-
    coverage-gap on extdeps bypass surfaces is the lens delivering
    its foundation-gap-visibility value.
  - Q4.5 P2 explicitly independent — lens doesn't depend on
    ExecuteCommand materialization.
- Acceptance extended: lens reports gap diagnostics on P1 bypass
  surfaces; audit produces existence-proof verdict for Director
  re-decision; asymmetric-tightening worked example in PR body.

## Capacity / sequencing table

Replaced "1 audit lane (tag std/ primitives with effect signatures)"
with "1 audit-as-existence-check lane (verify primitives' signature-
shape coverage; NOT 'tag every primitive') — produces the path (i)
vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2
prereq lanes to the net summary. Closing line: "The taxonomy-
retirement scope (substrate-side) is not in this lane — it's
surfaced by audit and routed to dedicated retirement lane if path
(ii) wins."

Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity
table. Worker reading Q6 in isolation now sees path-(ii)-default
framing matching Q4 + Q5.5 + THESIS amendment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792

Resolves codex inline BLOCKING at sha 191be31 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150.
Real: my Q4.5 P2 framing described ExecuteCommand as still
NotYetImplemented (M1.5 allowlist + Rust TestRunner returning
NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand
extension before this PR's authoring. TESTING.md:195 capability-state
callout confirms:
- Rust TestRunner + M1.5 testgen harness share one std::process path
  for arbitrary command + args + expect_exit_code.
- M1.5 allowlist + fail-closed panic retired.
- Distinguishable ClaimResult::Fail messages for spawn / timeout /
  policy / exit-mismatch.
- Linux unshare(1) namespace isolation on host-allowing systems.
- T-PB-B-1 boundary migration example landed.

Fix:

P2 section rewritten:
- Header retitled "ExecuteCommand runner primitive: LANDED (PR #792);
  residual is bulk-migration."
- Status update naming PR #792 + the post-#792 capability state
  (allowlist retired, etc.).
- Honest acknowledgement: "My earlier P2 framing was stale."
- Residual narrowed to bulk-migration of existing Rust Command::new
  boundary tests (tracked as ROADMAP residual, not lens prereq).
- Sequencing reframed: P2 was always orthogonal to the effects lens
  itself; bulk migration proceeds at its own pace; lens not blocked.

Q4.5 footer updated:
- "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via
  #792; only consumer-side bulk migration remains)"
- Worker-discretion-vs-Director-call P2 line updated: "runner
  primitive landed; only consumer-side bulk migration remains;
  tracked as ROADMAP residual, independent of the lens."

Q6 STOP for P2 updated:
- "the lens itself doesn't depend on P2; only TESTING.md's 0-residual
  claim does" → "runner primitive landed via PR #792 (post-Q4.5-
  authoring update). The lens itself never depended on P2; bulk
  consumer migration is residual ROADMAP work and remains independent
  of this lane."

Brief now reflects live state. The closed-system claim's prereq
landscape is honest:
- P1 (extdeps typed-primitive consumption): real prereq, tracked
  debt at ROADMAP:153-154.
- P2 (ExecuteCommand runner): satisfied via #792; bulk migration is
  consumer-side residual, not foundation work.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale

Resolves codex non-blocking finding at sha bcac41b on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real
residual: capacity-table line still listed P2 as "`ExecuteCommand`
materialization" prereq + framed both P1 and P2 as "pre-existing
tracked-debt" — but my prior 57a9b13 fix established that PR #792
already landed the runner primitive, so P2 is no longer a
materialization prereq.

Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq)
from P2 (residual, not prereq):

  - P1: extdeps typed-primitive consumption — pre-existing tracked
    debt at ROADMAP:153-154; load-bearing for the lens's full-coverage
    claim.
  - P2: ExecuteCommand runner primitive landed via PR #792; only
    consumer-side bulk migration of existing Rust Command::new
    boundary tests remains (tracked as ROADMAP residual, independent
    of the lens; not a materialization prereq).

Brief now consistently treats P2 as bulk-migration-residual across:
- §Q4.5 P2 section header (LANDED via PR #792; residual is
  bulk-migration).
- §Q4.5 footer (P2: runner primitive landed; only consumer-side
  bulk migration remains).
- Q6 STOP for P2 (runner primitive landed; bulk migration is
  residual ROADMAP work).
- §Capacity / sequencing impact (P2 as residual, not prereq).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349

Codex finding on PR #808 sha ece964e: lines 153-154 are unrelated
target-grounding prose; the matching extdeps typed-primitive bypass
entries (LLM service flattening, GitHub auth model bypass) live at
ROADMAP.md:348-349.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix third stale ROADMAP citation at line 271

Codex follow-up on sha 2552ca3: prior fix missed a third occurrence
at line 271 in the §Q4.5 capacity table. Now consistent with lines
139 and 173 (ROADMAP.md:348-349).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity

Codex flagged 'Effect-signature tagging on std/ primitives' as potentially
contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240)
already explicitly say 'NOT tag every primitive' — but the cross-manager
line used sloppy wording. Reworded to make explicit that the audit walks
signature shape; no parallel tag added.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5

- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)

B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).

B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — drop incoherent inner-fallback non-goal

Codex P2: the non-goal line excluding the inner declaration().name
unwrap_or_else fallback contradicted Slice step 2, which replaces the
whole chain with let-Some-else-return. Both fallbacks are in scope by
construction; remove the contradictory non-goal.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives

PM REQUEST_CHANGES: §Frame listed '4 type connectives
(Conjunction | Disjunction | Cardinality | Bit)' which contradicted
the canonical thesis source. Replaced with the canonical 6
(Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per
docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary
closes here'. Also removed 'typed substrate carriers' from the
vocabulary list — substrate carriers are defined using the vocabulary,
not part of it. Added a clarifying note that B4's carriers
(DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are
typed declarations composed from the vocabulary, not vocabulary
extensions.

Per feedback_verify_thesis_claims: brief framings citing thesis
structure must ground in the canonical source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority

Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of
naming the live substrate authority. Two coordinated fixes:

1. §Read first cites src/v3/std/substrate.dag (live .dag substrate
authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel
meta-type — already exists with consumers in verification.dag,
emit_model.dag, python.dag).

2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing
DeclarationRef'. The work is consumer migration + any role-extension
layer the audit reveals, NOT designing or landing the carrier.

Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers)
keep their 'new' framing but explicitly require sub-briefs to grep
src/v3/std/ + src/v3/spec/ for existing authority before authoring
'design and land' framing — per feedback_verify_thesis_claims +
feedback_emitter_workaround_is_gap_symptom.

Acceptance + sub-brief dispatch order updated to reflect B4.1's
consumer-migration shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — tighten Phase 1 umbrella sentence

The umbrella 'Land the typed carriers into src/v3/std/' framing was
stale after f52e2ce's reframe of #1 to consumer-migration. Replaced
with audit-first wording that covers both the consume-existing case (#1)
and the design-and-land case (#2-#4 if their audits show real gaps).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording

Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands'
which conflicted with the post-reframe reality that B4.1 consumes the
existing DeclarationRef. Updated to 'consumes or lands' with explicit
existing-authority citation and audit-pending caveat for B4.2-B4.4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 26, 2026
…4 precedent (rev. softening) (#818)

* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation)

Director-authored amendment following the 2026-04-24 escalation from PR
#693 (sub-child sharp-bear-829 under Surface Manager).

Two edits:

1. New "Class 5 Gap 3 — port-carried field values in data bodies"
   row in the 2026-04-21 post-merge-debt section. The substrate gap was
   documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP
   ledger row for cross-lane visibility. PR #693's execution surfaced it
   as the blocker on sub_charclass_in_std_unicode phase-2.

2. Retract the "ready-to-dispatch (no substrate capability gap)" claim
   on the Character-level row, annotate phase-1 landed via PR #693
   (CharClass vocabulary + Rust-mirror structural scanner path), and
   point phase-2 at the new Class 5 Gap 3 row.

Codifies the audit pattern: "this consumption gap has no substrate
capability gap" claims must be verified by attempting the retype before
the claim lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main

* docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review)

* docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review)

Row title still said 'consumption gap, not substrate gap' while the
body block retracted that claim and cited Class 5 Gap 3 as a substrate
dependency for phase-2. Title now matches body: mixed classification,
consumption for steps 1+3, substrate for step 2.

* docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit)

gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining
gap" description was wrong: field-level shapes (nested records, list
literals, declaration refs, Var refs, sum-variant literals) are
supported today via FieldValue variants + lower_structural_field_value
(dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the
top-level ValueBody boundary (non-scalar, non-record top-level bodies).

The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself
stale: it describes the pre-PR-B-unwind shape where FieldValue was
LiteralBits-only. PR-B's unwind extended FieldValue to carry
Reference / Record / List / Variant, moving the gap to ValueBody.

Two fixes:

1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody
   boundary, point at code paths (dag.rs, lower.rs) as live authority,
   flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass
   blocker classification to "provisional pending reproduction."

2. Update the Character-level row's phase-2 block to name that the
   specific shape of the CharClass failure needs concrete reproduction
   from the escalating sub-child before the blocker is finalized.

Recursive audit-pattern instance: the row I wrote to codify "verify
live state before claiming substrate gap" itself failed to verify live
state. Both incidents (2026-04-23 original row + 2026-04-24 my
retraction row) are now cited in the audit-pattern sub-note as
examples of the same discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c3

Three substantive fixes addressing internal-consistency gaps in the cascade
promotion PR caught by codex review at sha 0d6e7c3:

1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane
   acceptance bullets and Hand-Rust census paragraph in line with the
   updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero
   (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is
   retracted under 0-floor with explicit migration to ExecuteCommand-based
   .dag TestClaim declarations.

2. docs/design-pure-bootstrap-zero.md promotion section — converted from
   future-tense ("This doc is PROPOSAL until promoted… promotion is a
   single Director-authored cascade PR…") to historical past-tense
   promotion-receipt framing ("This doc was PROPOSAL until promoted;
   promotion was a single Director-authored cascade PR that did all of the
   following atomically…"); blocking-clause struck through and resolved
   inline. Banner cites PR #782 explicitly.

3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_
   profile excluded (Map<String, AlgebraProfile> body, not list-of-sum;
   needs distinct ValueBody::Map substrate work, tracked separately as a
   future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass
   phase-2 + Engine sharpened-(b) pilot enumeration), both sharing
   list-of-sum substrate work. Lane table, dependency DAG, and capacity
   summary updated for consistency (slot count 9-13, was 10-14).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities

Resolves claude REQUEST_CHANGES at sha fed6b03 — atomic-cascade
self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22
explicitly names THESIS.md and "any other authority docs" as required
retraction targets; the prior diff updated ROADMAP + r2-structure + design
docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting-
manager.md pointing at the now-SUPERSEDED ≤5-floor framing.

Files:

- THESIS.md (5 prose blocks updated):
  - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests
    migrate to ExecuteCommand-based .dag TestClaim declarations.
  - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag.
  - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor
    target citing design-pure-bootstrap-zero.md as live authority;
    hand_maintained_src list shrinks to empty set.
  - :301-318 — Tests-are-structural-data block: residual carve-out retracted;
    predicate name pb_rust_tests_outside_residual_zero retained as
    housekeeping (semantically the residual is empty under cascade).

- docs/thesis/compiler-std-consolidation.md (5 references):
  - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes
    design-pure-bootstrap.md (SUPERSEDED).
  - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process
    lane named as the dissolution trigger for bootstrap.rs itself.
  - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md.
  - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority
    re-cited.
  - :185 Related docs link.

- docs/briefs/r1-selfhosting-manager.md (active dispatch brief):
  - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5);
    T-PB-B residual carve-out retracted; predicate names retained for
    housekeeping; cascade-promoted authorities are source of truth.
  - Slice descriptions for T-PB-A / T-PB-B updated inline.
  - Framing-question + ask updated to 0-floor / no-residual framing.
  - Day-1 + up-to-director hand-off bullets updated.
  - Working-state checklist :111 ≤5 → 0 with cite.
  - Decisions log :164 ≤5 → 0-floor target updated.

- docs/r2-structure.md §2 design call (RETRACTED block):
  - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through
    in entirety (both Option A sharpen-and-keep and Option B rename are
    moot under 0-floor). Section preserved as audit-trail historical
    context.
  - Background-doc index: self-hosting anchor updated to
    design-pure-bootstrap-zero.md as live authority.

- docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per
  non-blocking suggestion):
  - Banner cites cascade promotion PR #782 explicitly.
  - New paragraph: "Treat all numeric floors below as retracted" with
    explicit lines named that quote in isolation (table row, body prose
    references). Prevents re-quoting from this doc as live authority.

Cascade is now atomically consistent across:
  THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔
  docs/thesis/compiler-std-consolidation.md ↔
  docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔
  docs/design-pure-bootstrap-zero.md (LIVE) ↔
  docs/design-pure-bootstrap.md (SUPERSEDED).

The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds
genuinely.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): correct ExecuteCommand runner-capability claim

Resolves codex BLOCKING #1 at sha fed6b03 (P1 live-state violation):
TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138
overstated live runner capability — claimed runner support landed in
PR #688/#741 with "emit Rust, invoke rustc on output, check exit code"
as a structurally-equivalent migration path. Verified against live
sources:

- src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema
  exists (declared via PR #678).
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5
  testgen harness allowlists ONLY `command == "true" && args.is_empty()
  && expect_exit == 0`.
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 —
  panics fail-closed on any other shape with explicit "ExecuteCommand
  shell shape is not supported here (runner-owned — do not treat as
  ordinary false)".
- src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no
  match arm for ExecuteCommand; falls through to ClaimResult::
  NotYetImplemented.

Reality: a TestClaim declaring rustc/python/go invocation is
structurally expressible as data today, but executing it is blocked.
Full arbitrary-command runner support is the PB-Runtime lane's
deliverable.

Files updated:

- TESTING.md:195 — capability state callout with file:line citations;
  "Full runner support — arbitrary command + args (rustc/python/go) with
  exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor
  program)." Bullet about migration shape preserved as the cascade-named
  successor pattern, not as a live capability.
- TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane
  lands the ExecuteCommand runner extension" as an explicit precondition.
- docs/design-pure-bootstrap-zero.md:138 — same correction for the
  matching prose, with PB-Runtime named as the runner-extension
  dependency for boundary-test migration.
- ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner
  foundation in #688/#741 with `true`-no-args allowlist only — full
  arbitrary-command runner support deferred to PB-Runtime lane,
  blocking the actual boundary-test migration." Dependencies column
  extended to "DB-15 + T-TestGen + PB-Runtime".

The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still
holds for atomic-cascade-across-authority-docs; this commit closes the
remaining capability/claim mismatch flagged by codex.

(Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still
SUPERSEDED-pointing — was sha-stale; resolved in c85e691.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief

Resolves codex BLOCKING at sha 0fb223a (P2 single-authority violation).
The prior banner contained:

> "Operationally R1 closure may still ship before the 0-floor is reached
>  — the ratchet ensures the trajectory; the gate's acceptance number is
>  what shifts."

This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0.
Two competing gate semantics in the cascade is exactly what the
atomic-cascade clause forbids.

Replaced with single-authority-honest framing:

> "R1 closure now requires the 0-floor target by gate semantics: T-PB-A
>  and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade
>  promotion changed their acceptance numbers to 0; R1 cannot close
>  while the SG-0 census carries non-zero hand-Rust."

Plus minor sharpening:
- "T-PB-A's non-test target is 0" → "non-test acceptance target is 0
  per ROADMAP.md:67" (cite the authority).
- T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep
  the capability-state honesty consistent with the recent fix wave.
- Predicate-rename housekeeping line moved into banner ("post-cascade
  housekeeping, not a pre-promotion blocker") — was implicit before.

The brief now genuinely inherits the cascade-promoted gate; no
competing release authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 second-wave worker-escalation fixes

Four substantive worker STOP-AND-ESCALATEs from briefs landed in
PR #797. All four worker recommendations correct; each needs a
Director call + brief update.

## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate

Worker correctly identified that brief req 2 (declared-effect carrier
as part of fn type signature, per feedback_no_annotations) requires
net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at
src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots.
Without parser surface, every user function would have
declared_effects = [] while inference returns non-empty — lens fires
EffectLeakageError everywhere on enable. Worker rejected power-through
and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map
parser split).

Director picked split:
- NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md
  Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface
  syntax + lookahead + body parser + lowerer extension + exhaustive-match
  audit + coproduct dissolution receipt.
- MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to
  post-parser-extension scope. Pre-flight check NOT a parser-extension
  step; STOP if parser sub-lane PR not merged.

## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping

Worker found load-bearing evidence at infer.rs:3693-3703: DB-11
deliberately strips refinements at operator dispatch as a designed-in
fix for symmetric-operators failure mode. Brief's "attach where b != 0
as a proof for a / b" directly contradicts this design choice. STOP-3
(where-clause conflict with DB-11) is real; STOP-1 (substrate scope)
needs net-new substrate (per-operator partiality fact + predicate-
entailment check + asymmetric per-operand refinement-honoring) — M+
minimum. ownership_lens precedent in original brief is post-hoc
observability, not proof carrier.

Worker recommended redirect to design/scoping per nested-optional
precedent. Director picked redirect.

Brief fully rewritten as design/scoping with four-question structure:
(1) DB-11 interaction analysis; (2) substrate proposal for proof-or-
totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes
with acceptance-theatre risk on user-defined-total-wrapper-only);
(4) Director-actionable recommendation. Output is doc PR.

## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C)

Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int)
with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136
closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b)
i128 implementation requires either path 1 (hierarchy refactor —
contradicts non-goal) or path 2 (regen lie between substrate and
emit — violates discipline). Worker leaned option (C) re-scope:
land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke)
to a sibling sub-lane that does proper Int128/Word128 substrate work.

Director picked option (C). Brief req 1 re-scoped to drop canonical-
carrier-widening; lane value comes from range facts + reconciliation
narrowing + out-of-range diagnostic against existing i64. Req 4
explicitly deferred with sibling-sub-lane reference. Sibling sub-lane
NOT to be authored or implied in this PR; tracked separately.

## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change)

Worker correctly STOP'd per the brief's own pre-flight check: parser
sub-lane has not landed; SurfaceExpr::Map not on main. Director
authorized cross-lane reassignment: wise-boar-480 takes the parser
sub-lane (t-substrate-valuebody-map-parser-worker.md) since they
already have full investigation context. No brief changes needed; the
routing decision is in the dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope

Resolves codex P2 inline at sha e35103f on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer
carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still
required widening LiteralBits::Int(i64) to an unbounded carrier and
passing the i64::MIN smoke. Internally unsatisfiable.

Fix:

- Slice section retitled "range facts + reconciliation narrowing
  (against existing i64 carrier)" with explicit note about the
  re-scope.
- Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly
  forbids touching LiteralBits::Int shape, dag_scalar_generated.rs
  regen for that variant, or tokenize i64 parse path.
- Slice steps 2-5 reframed: range facts use i64-representable
  magnitudes; reconciliation narrowing uses existing i64 carrier;
  diagnostic only for i64-representable out-of-range; smoke tests
  for req 5 only (req 4 i64::MIN deferred).
- Acceptance checklist updated:
  - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as
    re-scoped/deferred.
  - LiteralBits::Int(i64) carrier untouched (no widening; no
    parallel; no shape change).
  - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference.
- STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the
  carrier" — explicit STOP if execution surfaces range-fact narrowing
  requiring carrier-widening; that's the boundary the re-scope drew;
  belongs in sibling Int128/Word128 sub-lane.

Brief now consistently treats carrier-widening as out-of-scope across
all sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty

Resolves codex BLOCKING #1 at sha e35103f on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier
but req 2 required range facts using "the SAME magnitude carrier
as req 1" — meaning i64-typed range bounds. u64's max (2^64-1)
doesn't fit in i64; range fact for u64 would have to truncate,
omit, or mirror in Rust (representation drift). All three options
violate fail-closed declared-facts discipline (P1 / P3).

Fix:

- Req 2 rewritten to specify String-decimal representation:
  range_min_inclusive: String + range_max_inclusive: String fields
  on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127"
  for i8; "0"/"18446744073709551615" for u64).
- Explicit reasoning why String-decimal: u64's max doesn't fit in
  i64; binding range bounds to literal carrier forces truncation/
  omission/mirror-drift; all violate fail-closed declared-facts
  discipline.
- Bridge framing: String-decimal is pending the sibling Int128/
  Word128 sub-lane; both range bounds and literal payload migrate
  to typed carrier when that lands.

- Req 3 updated for String-decimal comparison semantics:
  reconciliation parses both bounds and literal magnitude into a
  common comparison space (i128 host comparison primitive — host
  narrowing, NOT carrier widening). Bounded by what the i64-typed
  literal can express; any i64-representable literal compares
  against any width's String-decimal bound. Carrier discipline
  preserved.

Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral)
is sha-stale — already resolved at 3e142d1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed

Resolves codex BLOCKING at sha 0815189 (post-#799-merge feedback).
Real residual: req 2 specifies String-decimal range bounds (to cover
u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance
bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" /
"i64-representable magnitudes" for the range facts. Two incompatible
authorities for the same range-fact shape — would let a worker satisfy
the slice while truncating/omitting u64 bounds (P3 fail-closed
violation).

Fix:

- Line 31 (req 1 re-scope clarification): updated to explicitly state
  "range facts (req 2) use String-decimal representation (width-
  independent; covers u64::MAX which doesn't fit in i64)". Distinguished
  literal *payload* (stays i64) from range-bound *representation*
  (String) — both serve req 1's "no carrier widening" boundary.
- Line 44 (slice step 2): updated from "Range bounds use i64-
  representable magnitudes" to "Range bounds use String-decimal
  representation per req 2" with concrete example (u64 bounds).
- Acceptance bullet: updated from "Range facts on integer algebras
  (substrate-declared, not Rust-mirrored)" to add "using String-decimal
  representation ... width-independent; u64 bounds expressible without
  truncation."

The brief now consistently treats range bounds as String-decimal
across req 2, req 3, slice, acceptance, and the req 1 clarification —
no remaining authorities saying i64-typed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing

User + PM exchange 2026-04-25 surfaced that the in-flight effects
chain was importing wrong assumptions from external languages
(declared-effects-as-annotation + lens-vs-declaration check). Right
framing under gunbc's closed-system discipline is parallel to
complexity: every effect derives structurally from the composition
of typed primitive operations; nothing can hide because there's no
escape hatch; nothing needs annotation because the structure IS the
registry.

Four doc-only actions:

1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md.
   Frames the closed-system answer with PM's 5-behavior synergy
   table (Value/Transform/Branch/Loop/Bind as universal
   compositional-fold pattern). Four worked examples; aggressive
   reading on redundancy (compile-error-by-construction via
   referential-transparency proof; reread() primitive for legitimate
   cases); implementation-brief shape in §Q6.

2. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md.

3. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md.
   Notes Fn→Arrow refactor brief stays dispatchable as independent
   value.

4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by-
   construction framing replaces lens-detection framing.

Memory file feedback_closed_system_effects.md saved separately;
cross-link added to feedback_construction_over_ratchets.md.

Net cost: doc-level cleanup. Zero substrate code rework. Foundation
(OperationEffect + service-call infrastructure + 5-behavior
substrate) already exists.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect

Per PM convergence review on #808 + user's deeper 2026-04-25 framing:
the closed-system framing landed in #808 retired the user-facing
annotation but kept OperationEffect taxonomy as substrate-level tagging.
User's deeper framing: the taxonomy ITSELF is parallel-representation —
operations are intrinsically read-shaped or write-shaped via their
TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns-
derived-value-only → read). Tagging operations with Read | Upsert |
Create | Append | Delete names what the structure already says.

Three changes:

1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as
   normalized view, or retire as parallel-representation?"
   - Two paths: (i) tags derived from signature shape (acceptable
     normalized view) vs (ii) tags declared per-primitive (parallel-
     representation; retire).
   - Audit-as-existence-check (Q4 req 2 reframed): all effectful
     primitives derive cleanly from signature shape → path (i); any
     primitive needs hand-declared tag → path (ii) by existence proof.
   - Director default: path (ii). Logging primitives that return Unit
     are likely the audit's existence-proof.
   - Two design-question resolutions: (a) external effects not in
     return type → resource-threading discipline (typed param returned
     modified, IO-monad-without-the-monad pattern); (b) transactional
     grouping → derived structural fact from Bind composition + typed
     transaction primitives.

2. Q4 reqs revised: req 2 from "tag every primitive with explicit
   OperationEffect signature" to "audit-as-existence-check that every
   primitive's type signature derives the right effect classification";
   req 3 added (resource-threading discipline); req 6 added
   (transactional-pattern lens). Req 1 (effects lens) anchors on
   operation type-signature shape, not on hand-declared tags.

3. THESIS:345-347 amendment strengthened — "operations are
   intrinsically read-shaped or write-shaped via their type-signature
   shape; consumers walk the signatures directly; there is no parallel
   taxonomy or annotation layer to declare or maintain. Tracking
   effects as a separate enumerated concept IS the bug pattern,
   dissolved by construction." Plus references to resource-threading
   discipline + transactional grouping as derived structural fact.

Memory file feedback_closed_system_effects.md updated to reflect the
deeper framing (type-signature-shape, not taxonomy-tagging) +
resource-threading discipline section + transactional-patterns
section.

Net cost: doc-only delta on top of #808. Substrate retirement
(OperationEffect enum + derive_op_effect + idempotency.dag re-anchor)
deferred to the audit-as-existence-check phase of the implementation
brief; surfaced as Q5.5 OPEN CALL.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage

Resolves codex BLOCKING at sha d49ce79 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real:
the prior text claimed service primitives "already carry typed effect
signatures" presenting future audit-state as current substrate fact
(P1 violation). My Q5.5 amendment at 2dc656b partially fixed the
OperationEffect line but left a parallel over-claim on the new
"signature-shape coverage" framing.

Fix: Q4 substrate-state listing rewritten to honestly distinguish:

- Live: Behavior enum + substrate foundation (the principle that
  operations should carry signature shape).
- Incomplete: signature-shape coverage across actual primitives.
  HTTP-derived primitives carry implicit shape via derive_op_effect's
  method-table; logging/mutation primitives that return Unit or don't
  thread their target resource do NOT carry the structural shape that
  would express read-vs-write. Achieving full coverage is required
  work under reqs 2 + 3, not a current fact.
- Pending audit-as-existence-check: OperationEffect + derive_op_effect
  (path (i) vs (ii) per Q5.5).

Honest live-state callout added explicitly: "the closed-system
FOUNDATION (5 behaviors + DAG substrate + the principle that
operations should carry signature-shape) is live. The IMPLEMENTATION
COVERAGE across all effectful primitives is partial. Req 2 + req 3
are the work that closes the gap."

Brief now distinguishes principle-is-live (foundation) from
coverage-is-partial (audit work) without conflating them.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim

Per PM follow-up review on #808 + user's stronger discipline framing
("substrate must make bypass structurally impossible at every layer
of the transport stack"): the closed-system claim is honest only when
typed primitives ARE the path. Today two structural holes exist where
bypasses sidestep the typed-primitive substrate. Both surfaced
explicitly as Q4.5 pre-conditions — load-bearing for the lens's
coverage claim.

Three changes:

1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed-
   system claim)" inserted between Q4 and Q5:

   P1 — Extdeps typed-primitive consumption structurally enforced.
   Substrate must make `messages: Json` impossible to declare in
   service definitions; typed `LlmMessage` / `ContentBlock` /
   `GitHubAuthToken`-with-full-scopes are the only path. Tracked
   debt at ROADMAP.md:153-154 (LLM provider flattening) +
   `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded).
   Required prereq for full lens coverage; lens can land first +
   surface structural-coverage-gap diagnostics on bypass surfaces
   so the gap becomes visible rather than silent.

   P2 — `ExecuteCommand` fully materialized as typed runner
   primitive. TESTING.md (post-#782) committed to 0-residual but
   ExecuteCommand isn't fully materialized; deleting Rust boundary
   tests creates verification gap. Already named under PB-Runtime
   in Zero-Floor; signal pending. Pre-requisite for ANY Rust
   boundary-test deletion.

2. Old leftover duplicate Q5 section deleted (artifact from prior
   Q5/Q5.5 reshape; second copy of asymmetric-tightening text was
   in the file alongside the earlier Q5 instance).

3. Worker-discretion-vs-Director-call section in Q4.5: lens
   implementation worker dispatchable now (reports gaps as
   findings); P1 closure is substantive substrate work touching
   extdeps (dedicated lane); P2 closure is PB-Runtime (signal
   pending).

Net: design doc now honestly distinguishes principle-is-live
(Q4 rewrite at 191be31) from coverage-is-partial (Q4.5 prereqs
named explicitly). The closed-system claim has explicit pre-
conditions documented; implementation brief discovers them as
known dependencies, not as STOP-AND-ESCALATEs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default

Resolves claude APPROVE_WITH_COMMENTS at sha 191be31 on #808. Two
real residuals after the Q5.5 reframe:

1. Q6's reqs/STOPs/acceptance still framed under path (i) — said
   "audit + tag std/ primitives — every effectful primitive carries
   an explicit OperationEffect signature." Directly contradicted Q4
   (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment
   ("there is no parallel taxonomy to declare or maintain"). Worker
   reading Q6 in isolation would author the retracted shape.

2. Capacity / sequencing table line about "audit lane (tag std/
   primitives with effect signatures)" carried the same stale
   framing.

3. Q6 STOP "primitive performing side effects without an
   OperationEffect tag" assumed tag-as-authority; under path (ii)
   the STOP shape is "primitive whose signature doesn't structurally
   reveal its effect."

Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale
(already fixed at f073aa9 Q4.5 commit).

## Q6 fixes

- Reqs renumbered + reframed:
  - Req 1 anchors on operation type-signature shape (not hand-declared
    OperationEffect tags); composition reads from signature shape per
    Q2 table.
  - Req 2 changed from "audit + tag every primitive" to
    "audit-as-existence-check" — verify signature-shape coverage; ANY
    primitive needing a hand-declared tag IS the existence-proof for
    path (ii) retirement.
  - Req 3 added: resource-threading discipline applied to existing
    primitives (logging that returns Unit gets reshaped per audit).
  - Req 6 added: transactional-pattern lens (Bind composition +
    Transaction → Transaction').
  - Req 7 added: asymmetric-tightening worked example in PR body
    (per claude review observation; the one place declaration-shaped
    surface re-enters).
  - Req 8 (was 5): tests now reference signature-shape derivation
    explicitly, not tag lookup.
- STOPs reframed:
  - "OperationEffect retirement decision" — audit produces path (i)
    vs (ii) verdict; substrate retirement is its own dedicated
    sub-lane; this lane does NOT absorb it.
  - Pure/impure carrier STOP notes that "pure" should also derive
    from signature shape (pure functions don't return modified
    resources) — so the STOP itself may dissolve under further design.
  - Q4.5 P1 explicitly NOT a STOP — lens reporting structural-
    coverage-gap on extdeps bypass surfaces is the lens delivering
    its foundation-gap-visibility value.
  - Q4.5 P2 explicitly independent — lens doesn't depend on
    ExecuteCommand materialization.
- Acceptance extended: lens reports gap diagnostics on P1 bypass
  surfaces; audit produces existence-proof verdict for Director
  re-decision; asymmetric-tightening worked example in PR body.

## Capacity / sequencing table

Replaced "1 audit lane (tag std/ primitives with effect signatures)"
with "1 audit-as-existence-check lane (verify primitives' signature-
shape coverage; NOT 'tag every primitive') — produces the path (i)
vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2
prereq lanes to the net summary. Closing line: "The taxonomy-
retirement scope (substrate-side) is not in this lane — it's
surfaced by audit and routed to dedicated retirement lane if path
(ii) wins."

Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity
table. Worker reading Q6 in isolation now sees path-(ii)-default
framing matching Q4 + Q5.5 + THESIS amendment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792

Resolves codex inline BLOCKING at sha 191be31 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150.
Real: my Q4.5 P2 framing described ExecuteCommand as still
NotYetImplemented (M1.5 allowlist + Rust TestRunner returning
NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand
extension before this PR's authoring. TESTING.md:195 capability-state
callout confirms:
- Rust TestRunner + M1.5 testgen harness share one std::process path
  for arbitrary command + args + expect_exit_code.
- M1.5 allowlist + fail-closed panic retired.
- Distinguishable ClaimResult::Fail messages for spawn / timeout /
  policy / exit-mismatch.
- Linux unshare(1) namespace isolation on host-allowing systems.
- T-PB-B-1 boundary migration example landed.

Fix:

P2 section rewritten:
- Header retitled "ExecuteCommand runner primitive: LANDED (PR #792);
  residual is bulk-migration."
- Status update naming PR #792 + the post-#792 capability state
  (allowlist retired, etc.).
- Honest acknowledgement: "My earlier P2 framing was stale."
- Residual narrowed to bulk-migration of existing Rust Command::new
  boundary tests (tracked as ROADMAP residual, not lens prereq).
- Sequencing reframed: P2 was always orthogonal to the effects lens
  itself; bulk migration proceeds at its own pace; lens not blocked.

Q4.5 footer updated:
- "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via
  #792; only consumer-side bulk migration remains)"
- Worker-discretion-vs-Director-call P2 line updated: "runner
  primitive landed; only consumer-side bulk migration remains;
  tracked as ROADMAP residual, independent of the lens."

Q6 STOP for P2 updated:
- "the lens itself doesn't depend on P2; only TESTING.md's 0-residual
  claim does" → "runner primitive landed via PR #792 (post-Q4.5-
  authoring update). The lens itself never depended on P2; bulk
  consumer migration is residual ROADMAP work and remains independent
  of this lane."

Brief now reflects live state. The closed-system claim's prereq
landscape is honest:
- P1 (extdeps typed-primitive consumption): real prereq, tracked
  debt at ROADMAP:153-154.
- P2 (ExecuteCommand runner): satisfied via #792; bulk migration is
  consumer-side residual, not foundation work.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale

Resolves codex non-blocking finding at sha bcac41b on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real
residual: capacity-table line still listed P2 as "`ExecuteCommand`
materialization" prereq + framed both P1 and P2 as "pre-existing
tracked-debt" — but my prior 57a9b13 fix established that PR #792
already landed the runner primitive, so P2 is no longer a
materialization prereq.

Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq)
from P2 (residual, not prereq):

  - P1: extdeps typed-primitive consumption — pre-existing tracked
    debt at ROADMAP:153-154; load-bearing for the lens's full-coverage
    claim.
  - P2: ExecuteCommand runner primitive landed via PR #792; only
    consumer-side bulk migration of existing Rust Command::new
    boundary tests remains (tracked as ROADMAP residual, independent
    of the lens; not a materialization prereq).

Brief now consistently treats P2 as bulk-migration-residual across:
- §Q4.5 P2 section header (LANDED via PR #792; residual is
  bulk-migration).
- §Q4.5 footer (P2: runner primitive landed; only consumer-side
  bulk migration remains).
- Q6 STOP for P2 (runner primitive landed; bulk migration is
  residual ROADMAP work).
- §Capacity / sequencing impact (P2 as residual, not prereq).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349

Codex finding on PR #808 sha ece964e: lines 153-154 are unrelated
target-grounding prose; the matching extdeps typed-primitive bypass
entries (LLM service flattening, GitHub auth model bypass) live at
ROADMAP.md:348-349.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix third stale ROADMAP citation at line 271

Codex follow-up on sha 2552ca3: prior fix missed a third occurrence
at line 271 in the §Q4.5 capacity table. Now consistent with lines
139 and 173 (ROADMAP.md:348-349).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity

Codex flagged 'Effect-signature tagging on std/ primitives' as potentially
contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240)
already explicitly say 'NOT tag every primitive' — but the cross-manager
line used sloppy wording. Reworded to make explicit that the audit walks
signature shape; no parallel tag added.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5

- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)

B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).

B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — drop incoherent inner-fallback non-goal

Codex P2: the non-goal line excluding the inner declaration().name
unwrap_or_else fallback contradicted Slice step 2, which replaces the
whole chain with let-Some-else-return. Both fallbacks are in scope by
construction; remove the contradictory non-goal.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives

PM REQUEST_CHANGES: §Frame listed '4 type connectives
(Conjunction | Disjunction | Cardinality | Bit)' which contradicted
the canonical thesis source. Replaced with the canonical 6
(Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per
docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary
closes here'. Also removed 'typed substrate carriers' from the
vocabulary list — substrate carriers are defined using the vocabulary,
not part of it. Added a clarifying note that B4's carriers
(DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are
typed declarations composed from the vocabulary, not vocabulary
extensions.

Per feedback_verify_thesis_claims: brief framings citing thesis
structure must ground in the canonical source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority

Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of
naming the live substrate authority. Two coordinated fixes:

1. §Read first cites src/v3/std/substrate.dag (live .dag substrate
authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel
meta-type — already exists with consumers in verification.dag,
emit_model.dag, python.dag).

2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing
DeclarationRef'. The work is consumer migration + any role-extension
layer the audit reveals, NOT designing or landing the carrier.

Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers)
keep their 'new' framing but explicitly require sub-briefs to grep
src/v3/std/ + src/v3/spec/ for existing authority before authoring
'design and land' framing — per feedback_verify_thesis_claims +
feedback_emitter_workaround_is_gap_symptom.

Acceptance + sub-brief dispatch order updated to reflect B4.1's
consumer-migration shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — tighten Phase 1 umbrella sentence

The umbrella 'Land the typed carriers into src/v3/std/' framing was
stale after f52e2ce's reframe of #1 to consumer-migration. Replaced
with audit-first wording that covers both the consume-existing case (#1)
and the design-and-land case (#2-#4 if their audits show real gaps).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording

Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands'
which conflicted with the post-reframe reality that B4.1 consumes the
existing DeclarationRef. Updated to 'consumes or lands' with explicit
existing-authority citation and audit-pending caveat for B4.2-B4.4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — soften regression-test requirement (3 worker bounces)

Three consecutive B1 worker dispatches (zesty-crane-890 cursor →
valiant-boar-498 codex → cool-lynx-395 cursor) archived without
opening a PR. Likely friction point: brief Slice step 4 asks for a
unit test that constructs a Dag with an orphan variant declaration,
but emit.rs has zero existing #[test] precedent — emit testing
happens via integration fixtures. Workers see 'build novel test
harness' inside what's billed as an S-scope fix and bounce.

Per feedback_construction_over_ratchets: when a brief has friction,
fix the brief, don't ratchet the worker.

Softened step 4 + acceptance: regression test stays optional. If
test setup requires novel scaffolding, route the gap to follow-up.
The structural fail-closed at step 2 is the load-bearing change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt

PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description'
is too weak; PR descriptions don't survive squash-merge cleanly.

Two coordinated edits:
1. Slice step 4 — explicit substrate-signal framing: skipped test
   means emit-side hermetic-unit-test infrastructure is the missing
   substrate (feedback_emitter_workaround_is_gap_symptom).
2. Acceptance — require ROADMAP debt row (new or existing) with
   named dissolution trigger, referenced in PR body. Converts the
   skip from PR-local note (transient) into tracked debt (durable,
   dispatchable).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124

Codex BLOCKING: my earlier softening claimed emit.rs had no #[test]
precedent — wrong. The module has #[cfg(test)] mod tests at line 3124
with 12+ tests using compile_to_dag(source, filename) as harness
(e.g., go_struct_fields_render_with_separators :3143,
shared_walk_to_disj_finds_match_scrutinee_sum_type :3195).

This is a feedback_verify_thesis_claims violation on Director-side
brief authoring — claim made without grep verification.

Fix: restore step 4 as required, with explicit precedent citation.
Worker constructs the failure case via the existing harness
(direct Dag, fixture string, or BranchPattern exercise; worker's
call on cleanest path). STOP-AND-ESCALATE only if construction
proves materially harder than precedent suggests, in which case
that escalation surfaces a real substrate gap and warrants ROADMAP
debt — but the default is 'add the test.'

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites)

Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but
emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded
to 'several using compile_to_dag'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 26, 2026
…(retracts 1-manager decision)

The prior "1 standing manager (Grounding) + Director ad-hoc" decision
locked in r2-structure.md was empirically wrong: under that structure,
named standing managers (Grounding, Zero-Floor) sat idle while Director
became the dispatch bottleneck for every other lane, starving 3 of 4
non-Grounding lanes. User direction 2026-04-26: kill the idle managers
and rework R2 to mirror R1's program-manager pattern.

Restores R1's success pattern: N managers, each owning a complete
program with autonomous brief-authoring + worker-dispatch authority
through R2 close. Director's role narrows to cross-program conflict
resolution + scope-change escalation.

Six R2 standing managers, mutually-exclusive program ownership:

1. Grounding Manager — T-Ground sub-program (Goal 1; the one true
   critical path: Pilot → Rust → Engine → Tests → Dissolve, with
   Python/Go fill).

2. Substrate Manager — T-Substrate (4 sub-lanes: cardinality /
   nominal-opaque / parametric-algebra / ValueBody-list/sum) PLUS the
   B4 Identity-Carrier Substrate Pass program from #810 synthesis (4
   Phase 1 carriers + 8 Phase 2 site dissolutions). The largest single
   concentration of R2 work; produces carriers consumed by Modeling
   Manager (3 sub-lanes) + Grounding Manager (Engine sharpened-(b)).

3. Modeling Manager — T-Modeling (Goal 2: int-lit, Secret<T>,
   Dimensions) plus tokenizer charclass phase-2. Each item dispatches
   as its T-Substrate dependency lands.

4. Impossible-Bugs Manager — T-ImpossibleBugs (Goal 4: nested-optional
   flatten, unhandled diagnostic paths, unenumerated effects).
   Substrate-gap discoveries escalate to Substrate Manager.

5. Pure Bootstrap Manager — T-PB program (PB-A non-test → 0; PB-B
   tests → 0 via ExecuteCommand .dag TestClaim migration; Tier 2
   patch_lower_helpers retirement; mirror dissolutions from
   #810 Tier 3). Replaces the prior Zero-Floor Manager standing role
   with active deliverable ownership.

6. R2 Release Manager — Goal 5 (§6a metadata-pick), Goal 6 (R2 demo
   coordination), B-wave Tier 0/2 dispatch (#810), discipline-framework
   enforcement (velocity-tripwire reporting), thesis-claim coverage
   mapping (Open call 1), R2 closure ledger, v2 retirement coordination.

Cross-program dependencies handled via R1's `Cross-manager
notifications queued` brief pattern (producer signals readiness;
consumer acks and dispatches).

Steady-state parallel capacity: ~20+ concurrent worker slots across 6
programs, vs. ~9-13 under the prior 1-manager structure where Director
was the brief-authoring bottleneck.

Locked decisions block:
- Prior "Manager count = 1 + Director" decision retracted with
  empirical reasoning + lesson saved as feedback memory
  (feedback_standing_managers_need_owned_deliverables).
- New decision: "Manager count = 6 standing managers + Director
  coordinator" locked 2026-04-26.

Transition mechanics block:
- Step 4 expanded: spin-up of six manager briefs by Director on R2
  promotion; existing grounding-manager.md + pure-bootstrap-zero-manager.md
  migrate content into the new r2-*-manager.md briefs and archive.

No semantic shifts to R2 goals (1-6), demo discipline, R1 closure
criteria, or v2 retirement framing — those remain as-locked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 26, 2026
…et (codex on #827)

Codex noted at line 325: stray fragment 'bra prereq.' (artifact from
some prior edit/WIP commit) plus duplicated 'Related PRs' bullet.
Cleaned both; consolidated Related PRs to a single bullet that also
adds #810 (synthesis B-wave + dispatch discipline) and #812 (P5
mechanisms wiring) as new related PRs landed since the original list.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 26, 2026
…827)

* WIP: gunbc PM

* docs(r2-structure): rework — 6 program managers, autonomous dispatch (retracts 1-manager decision)

The prior "1 standing manager (Grounding) + Director ad-hoc" decision
locked in r2-structure.md was empirically wrong: under that structure,
named standing managers (Grounding, Zero-Floor) sat idle while Director
became the dispatch bottleneck for every other lane, starving 3 of 4
non-Grounding lanes. User direction 2026-04-26: kill the idle managers
and rework R2 to mirror R1's program-manager pattern.

Restores R1's success pattern: N managers, each owning a complete
program with autonomous brief-authoring + worker-dispatch authority
through R2 close. Director's role narrows to cross-program conflict
resolution + scope-change escalation.

Six R2 standing managers, mutually-exclusive program ownership:

1. Grounding Manager — T-Ground sub-program (Goal 1; the one true
   critical path: Pilot → Rust → Engine → Tests → Dissolve, with
   Python/Go fill).

2. Substrate Manager — T-Substrate (4 sub-lanes: cardinality /
   nominal-opaque / parametric-algebra / ValueBody-list/sum) PLUS the
   B4 Identity-Carrier Substrate Pass program from #810 synthesis (4
   Phase 1 carriers + 8 Phase 2 site dissolutions). The largest single
   concentration of R2 work; produces carriers consumed by Modeling
   Manager (3 sub-lanes) + Grounding Manager (Engine sharpened-(b)).

3. Modeling Manager — T-Modeling (Goal 2: int-lit, Secret<T>,
   Dimensions) plus tokenizer charclass phase-2. Each item dispatches
   as its T-Substrate dependency lands.

4. Impossible-Bugs Manager — T-ImpossibleBugs (Goal 4: nested-optional
   flatten, unhandled diagnostic paths, unenumerated effects).
   Substrate-gap discoveries escalate to Substrate Manager.

5. Pure Bootstrap Manager — T-PB program (PB-A non-test → 0; PB-B
   tests → 0 via ExecuteCommand .dag TestClaim migration; Tier 2
   patch_lower_helpers retirement; mirror dissolutions from
   #810 Tier 3). Replaces the prior Zero-Floor Manager standing role
   with active deliverable ownership.

6. R2 Release Manager — Goal 5 (§6a metadata-pick), Goal 6 (R2 demo
   coordination), B-wave Tier 0/2 dispatch (#810), discipline-framework
   enforcement (velocity-tripwire reporting), thesis-claim coverage
   mapping (Open call 1), R2 closure ledger, v2 retirement coordination.

Cross-program dependencies handled via R1's `Cross-manager
notifications queued` brief pattern (producer signals readiness;
consumer acks and dispatches).

Steady-state parallel capacity: ~20+ concurrent worker slots across 6
programs, vs. ~9-13 under the prior 1-manager structure where Director
was the brief-authoring bottleneck.

Locked decisions block:
- Prior "Manager count = 1 + Director" decision retracted with
  empirical reasoning + lesson saved as feedback memory
  (feedback_standing_managers_need_owned_deliverables).
- New decision: "Manager count = 6 standing managers + Director
  coordinator" locked 2026-04-26.

Transition mechanics block:
- Step 4 expanded: spin-up of six manager briefs by Director on R2
  promotion; existing grounding-manager.md + pure-bootstrap-zero-manager.md
  migrate content into the new r2-*-manager.md briefs and archive.

No semantic shifts to R2 goals (1-6), demo discipline, R1 closure
criteria, or v2 retirement framing — those remain as-locked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r2-structure): apply codex exploratory observations on #827

Three non-blocking codex observations addressed:

(1) Substrate Manager bottleneck risk (T-Substrate + B4 = 8+ slots is
    intentionally heavy). Added explicit watch-condition + named split
    trigger: if Substrate becomes the new bottleneck (workers idle
    waiting >7 days for Substrate-authored briefs), split B4 out as a
    dedicated standing B4 Identity-Carrier Manager. R2 Release Manager
    surfaces this signal via velocity-tripwire reporting.

(2) Six manager briefs at R2 promotion = authoring burden on Director
    at the exact transition point. Added pre-staging discipline to
    Transition mechanics step 4: Director authors brief skeletons during
    R1 final week; promotion PR fills in scope-final details. Decouples
    R1→R2 transition from six fresh authoring cycles.

(3) "20+ concurrent worker slots" wording risk (reads as committed
    target). Softened to "Aspirational dispatch ceiling: ~20+
    concurrent worker slots ... (capacity, not committed throughput —
    actual concurrency depends on idle-worker availability and
    cross-program unblock timing)."

No structural changes to manager assignments, lane breakdown, or
dependency DAG. Three small wording tightenings.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r2-structure): resolve PB gate-vs-program ambiguity (codex P2 inline on #827)

Codex caught a real contradiction: my new T-PB lane row in R2 included
T-PB-A and T-PB-B work, but the doc's R1 closure criteria + Lanes-
deliberately-absent block said those gates are R1-owned. Same
deliverables looked like both R1 close criteria and R2 program scope —
ambiguous release ownership.

Real resolution: R1's PB gate predicates are `[ext]` (threshold reads
from sg0_census_test.rs at evaluation time, not frozen at 0). R1 closes
at the then-current census-baked threshold; full 0-floor is the multi-
release dissolution scope owned by Pure Bootstrap Manager in R2 and
beyond. This matches the cascade promotion's de facto move (PB
promoted to LIVE as a standing program, not a one-time R1 gate).

Four coordinated edits make this explicit:

1. Pure Bootstrap Manager section now opens with "Post-R1 work of
   Pure Bootstrap to Zero program" framing + dedicated R1-vs-R2 split
   block stating: R1 owns gate close at `[ext]` threshold; R2 owns
   continued census reduction toward 0.

2. R1 closure criteria block adds new paragraph: "PB gates are `[ext]`
   — threshold reads from authority, not frozen at 0 in this doc."
   Cites the codex P2 finding for audit trail.

3. Lanes-deliberately-absent block updated for both PB rows: "Not
   absent from R2 — gate closes in R1, program work continues in R2."

4. Lane structure T-PB row reworded to "Post-R1 continuation" with
   explicit gate-vs-program split reference.

Plus the "R2 inherits nothing" sentence is corrected to acknowledge
post-R1 PB program continuation as legitimate R2 inheritance.

No structural changes to the 6-manager assignments, dependency DAG,
or other lanes. Resolution is purely the gate-vs-program semantic
distinction.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r2-structure): consolidate demo coordination authority on R2 Release Manager

Codex finding 2 on PR #827 (sha bf9a05c): demo coordination authority
was split between R2 Release Manager (new section, line 134) and
Director (Goals row line 59 + Modeling Manager auth line 102 + lane-
table footer line 160 + Demo discipline section line 256). P2 single-
authority violation — readers had two release owners for Goal 6.

Resolution: consolidate all four sites onto R2 Release Manager.

- Goals row (line 59): "Director-coordinated" → "R2 Release Manager-
  coordinated" with note explaining the rework reassignment.
- Modeling Manager authority (line 102): "signals item-close to
  Director" → "signals item-close to R2 Release Manager."
- Lane-table footer (line 160): "Director coordinates surfacing" →
  "R2 Release Manager coordinates surfacing."
- Demo discipline section (line 256): same fix.

Codex finding 1 (PB gate-vs-program ambiguity at line 116) was already
addressed in 90eb86f — codex was running against the older sha
bf9a05c so didn't see the fix. No additional action on finding 1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc PM

* docs(r2-structure): apply P5 dispatch-discipline to all manager-authored briefs (codex APPROVE_WITH_COMMENTS on #827)

Codex P2 finding on PR #827 sha d2bc1ec: with 6 autonomous dispatch
paths from the rework, the P5 paired-dispatch + per-PR gate discipline
must apply to all manager-authored briefs uniformly, not just
Director's. R2 Release Manager's prior "Discipline framework
enforcement" line was scoped only to velocity-tripwire reporting —
left the per-brief and per-PR mechanisms under-specified.

Two coordinated edits:

1. New paragraph in Manager structure ("Cross-manager dependency
   discipline" block): "P5 dispatch-discipline applies to all manager-
   authored briefs." Each standing manager responsible for paired-
   dispatch (brief-authoring time) + per-PR gate (PR-review time) on
   their own briefs/PRs. Per-brief and per-PR enforcement at each
   manager's authoring point, not a central choke.

2. R2 Release Manager's "Discipline framework enforcement" line
   updated to clarify role: owns the **central reporting** layer of
   P5 (velocity-tripwire ratio + systemic-violation surfacing through
   closure ledger). NOT the choke point for per-brief and per-PR
   enforcement — those happen at each manager's authoring point.

Resolves the gap the codex P2 finding identified: P5 was previously
de facto only enforced at Director, leaving manager-authored work
outside the gate. Now uniform across all 6 managers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r2-structure): consolidate all manager lane-close signals on R2 Release Manager (gpt-5-5-pro APPROVE_WITH_COMMENTS on #827)

gpt-5-5-pro flagged Impossible-Bugs Manager's "signals class-close to
Director" as a P2 single-authority violation: R2 Release Manager owns
the closure ledger (line 140), so routing class-close to Director
created two close-status authorities and risked the Release Manager's
ledger being bypassed.

Audit revealed the same ambiguity in Grounding Manager's "reports
cross-program signals to Director." Resolution applied uniformly
across all five non-Release managers:

- Grounding (line 78): "reports cross-program signals to Director"
  → "signals lane-close to R2 Release Manager (for closure ledger);
  escalates blockers and scope changes to Director."

- Substrate (line 92): added "signals sub-lane / Phase close to R2
  Release Manager (for closure ledger); escalates blockers and scope
  changes to Director."

- Modeling (line 104): "signals item-close to R2 Release Manager for
  R2 demo coordination" → "signals item-close to R2 Release Manager
  (for closure ledger + demo coordination); escalates blockers and
  scope changes to Director."

- Impossible-Bugs (line 115): "signals class-close to Director"
  → "signals class-close to R2 Release Manager (for closure ledger);
  escalates blockers and scope changes to Director."

- Pure Bootstrap (line 128): already correctly dual-routed ("reports
  SG-0 census deltas to Director and to R2 Release Manager"); kept
  as-is.

Pattern is now uniform across all 5 non-Release managers:
- lane/sub-lane/item/class close → R2 Release Manager (closure ledger)
- blockers + scope changes → Director (cross-program coordination)

Single authority per concern: closure-ledger reporting concentrated on
R2 Release Manager; Director's role narrows to conflict resolution +
scope escalation as the rework intended.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r2-structure): drop dangling feedback memory citation (claude observation 3 on #827)

Claude noted that the doc cited `feedback_standing_managers_need_owned_deliverables`
as if it were a repo artifact (backticked file reference), but that
file is PM-private session memory living in
`~/.claude/projects/-Users-briansrls-gunbc/memory/`, not a public
repo file. Future readers (Director, codex, contributors) would look
for it in the repo and not find it.

Two sites cleaned (Manager structure REVISED banner + Decisions-locked
RETRACTED block): drop the parenthetical citation. The empirical
signal explanation is preserved verbatim in both places — the citation
was redundant scaffolding around content that already explains itself.

Claude's other two observations confirmed already in place:
(1) velocity-tripwire reporting wired in INVARIANTS.md:265 §P5
mechanism (c) + ROADMAP.md:442 cadence row (landed via PR #812);
(2) six forward-referenced manager briefs deliberately deferred to
R1→R2 transition window per Transition mechanics step 4 pre-stage.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r2-structure): defer PB gate semantics to ROADMAP authority (codex BLOCKING on #827 sha a6e26c0)

Codex BLOCKING — my prior "R1 closes at then-current sg0_census_test.rs
baseline; R2 owns continued census reduction" framing introduced a
second authority for PB gate thresholds. ROADMAP.md is the named gate
authority and its T-PB-A / T-PB-B lane rows target 0 per
docs/design-pure-bootstrap-zero.md LIVE. r2-structure.md was
reinterpreting that — P2 single-authority violation; R1 closure
semantics depended on which doc a reader followed.

Real fix: defer to ROADMAP. Drop the gate-vs-program "split" framing
entirely. Narrow R2 Pure Bootstrap Manager scope to post-R1 program
work that survives R1 close, not a duplicate of R1's census-reduction
lanes.

Five coordinated edits:

1. Pure Bootstrap Manager section rewritten:
   - "R1 vs R2 split" subsection → "R1 vs R2 boundary — defers to
     ROADMAP gate authority" stating r2-structure does NOT reinterpret
     gate semantics; ROADMAP single-authority on gate close.
   - "R2 lanes" subsection → "R2 PB Manager scope = work that survives
     R1 close" — concretely: mirror dissolutions (Tier 3), Tier 2
     patch_lower_helpers retirement (if survives R1), post-R1
     emergent dissolutions, kernel_algebra_profile Map-shaped work
     gated on Substrate Manager.
   - Explicit "Does NOT own R1 census-reduction work" callout.

2. R1 closure criteria block: prior "PB gates are [ext] — threshold
   reads from authority" paragraph rewritten to "ROADMAP is single
   authority on PB gate semantics" — defers to ROADMAP T-PB-A / T-PB-B
   target=0, doesn't reinterpret.

3. Lanes-deliberately-absent block (both PB rows): removed prior
   "Not absent from R2 — gate closes in R1, work continues in R2"
   wording (which was the offending dual-authority claim). Replaced
   with "Not in R2 — R1 owns census-reduction per ROADMAP single
   authority on gate semantics. R2 Pure Bootstrap Manager exists for
   post-R1 PB program work that survives R1 close."

4. Lane structure T-PB row: size XL → M (narrowed scope). Description
   rewritten to post-R1-only with explicit "Does NOT duplicate R1
   T-PB-A / T-PB-B census-reduction work."

5. R2-inherits sentence: corrected to acknowledge post-R1 PB program
   work as legitimate inheritance (not the census-reduction work itself).

6. Dependency DAG Pure Bootstrap Manager block: stripped the T-PB-A /
   T-PB-B census-reduction lines; replaced with Tier 3 mirror
   dissolutions + Tier 2 patch retirement + post-R1 emergent. Header
   now reads "POST-R1 only (R1 owns census-reduction lanes per ROADMAP)."

ROADMAP.md is unchanged — r2-structure.md correctly defers to its
existing PB gate authority. No reinterpretation, no second authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r2-structure): clean stray fragment + duplicate Related PRs bullet (codex on #827)

Codex noted at line 325: stray fragment 'bra prereq.' (artifact from
some prior edit/WIP commit) plus duplicated 'Related PRs' bullet.
Cleaned both; consolidated Related PRs to a single bullet that also
adds #810 (synthesis B-wave + dispatch discipline) and #812 (P5
mechanisms wiring) as new related PRs landed since the original list.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 26, 2026
#836)

* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation)

Director-authored amendment following the 2026-04-24 escalation from PR
#693 (sub-child sharp-bear-829 under Surface Manager).

Two edits:

1. New "Class 5 Gap 3 — port-carried field values in data bodies"
   row in the 2026-04-21 post-merge-debt section. The substrate gap was
   documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP
   ledger row for cross-lane visibility. PR #693's execution surfaced it
   as the blocker on sub_charclass_in_std_unicode phase-2.

2. Retract the "ready-to-dispatch (no substrate capability gap)" claim
   on the Character-level row, annotate phase-1 landed via PR #693
   (CharClass vocabulary + Rust-mirror structural scanner path), and
   point phase-2 at the new Class 5 Gap 3 row.

Codifies the audit pattern: "this consumption gap has no substrate
capability gap" claims must be verified by attempting the retype before
the claim lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main

* docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review)

* docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review)

Row title still said 'consumption gap, not substrate gap' while the
body block retracted that claim and cited Class 5 Gap 3 as a substrate
dependency for phase-2. Title now matches body: mixed classification,
consumption for steps 1+3, substrate for step 2.

* docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit)

gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining
gap" description was wrong: field-level shapes (nested records, list
literals, declaration refs, Var refs, sum-variant literals) are
supported today via FieldValue variants + lower_structural_field_value
(dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the
top-level ValueBody boundary (non-scalar, non-record top-level bodies).

The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself
stale: it describes the pre-PR-B-unwind shape where FieldValue was
LiteralBits-only. PR-B's unwind extended FieldValue to carry
Reference / Record / List / Variant, moving the gap to ValueBody.

Two fixes:

1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody
   boundary, point at code paths (dag.rs, lower.rs) as live authority,
   flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass
   blocker classification to "provisional pending reproduction."

2. Update the Character-level row's phase-2 block to name that the
   specific shape of the CharClass failure needs concrete reproduction
   from the escalating sub-child before the blocker is finalized.

Recursive audit-pattern instance: the row I wrote to codify "verify
live state before claiming substrate gap" itself failed to verify live
state. Both incidents (2026-04-23 original row + 2026-04-24 my
retraction row) are now cited in the audit-pattern sub-note as
examples of the same discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33

Three substantive fixes addressing internal-consistency gaps in the cascade
promotion PR caught by codex review at sha 0d6e7c33:

1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane
   acceptance bullets and Hand-Rust census paragraph in line with the
   updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero
   (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is
   retracted under 0-floor with explicit migration to ExecuteCommand-based
   .dag TestClaim declarations.

2. docs/design-pure-bootstrap-zero.md promotion section — converted from
   future-tense ("This doc is PROPOSAL until promoted… promotion is a
   single Director-authored cascade PR…") to historical past-tense
   promotion-receipt framing ("This doc was PROPOSAL until promoted;
   promotion was a single Director-authored cascade PR that did all of the
   following atomically…"); blocking-clause struck through and resolved
   inline. Banner cites PR #782 explicitly.

3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_
   profile excluded (Map<String, AlgebraProfile> body, not list-of-sum;
   needs distinct ValueBody::Map substrate work, tracked separately as a
   future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass
   phase-2 + Engine sharpened-(b) pilot enumeration), both sharing
   list-of-sum substrate work. Lane table, dependency DAG, and capacity
   summary updated for consistency (slot count 9-13, was 10-14).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities

Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade
self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22
explicitly names THESIS.md and "any other authority docs" as required
retraction targets; the prior diff updated ROADMAP + r2-structure + design
docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting-
manager.md pointing at the now-SUPERSEDED ≤5-floor framing.

Files:

- THESIS.md (5 prose blocks updated):
  - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests
    migrate to ExecuteCommand-based .dag TestClaim declarations.
  - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag.
  - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor
    target citing design-pure-bootstrap-zero.md as live authority;
    hand_maintained_src list shrinks to empty set.
  - :301-318 — Tests-are-structural-data block: residual carve-out retracted;
    predicate name pb_rust_tests_outside_residual_zero retained as
    housekeeping (semantically the residual is empty under cascade).

- docs/thesis/compiler-std-consolidation.md (5 references):
  - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes
    design-pure-bootstrap.md (SUPERSEDED).
  - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process
    lane named as the dissolution trigger for bootstrap.rs itself.
  - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md.
  - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority
    re-cited.
  - :185 Related docs link.

- docs/briefs/r1-selfhosting-manager.md (active dispatch brief):
  - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5);
    T-PB-B residual carve-out retracted; predicate names retained for
    housekeeping; cascade-promoted authorities are source of truth.
  - Slice descriptions for T-PB-A / T-PB-B updated inline.
  - Framing-question + ask updated to 0-floor / no-residual framing.
  - Day-1 + up-to-director hand-off bullets updated.
  - Working-state checklist :111 ≤5 → 0 with cite.
  - Decisions log :164 ≤5 → 0-floor target updated.

- docs/r2-structure.md §2 design call (RETRACTED block):
  - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through
    in entirety (both Option A sharpen-and-keep and Option B rename are
    moot under 0-floor). Section preserved as audit-trail historical
    context.
  - Background-doc index: self-hosting anchor updated to
    design-pure-bootstrap-zero.md as live authority.

- docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per
  non-blocking suggestion):
  - Banner cites cascade promotion PR #782 explicitly.
  - New paragraph: "Treat all numeric floors below as retracted" with
    explicit lines named that quote in isolation (table row, body prose
    references). Prevents re-quoting from this doc as live authority.

Cascade is now atomically consistent across:
  THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔
  docs/thesis/compiler-std-consolidation.md ↔
  docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔
  docs/design-pure-bootstrap-zero.md (LIVE) ↔
  docs/design-pure-bootstrap.md (SUPERSEDED).

The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds
genuinely.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): correct ExecuteCommand runner-capability claim

Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation):
TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138
overstated live runner capability — claimed runner support landed in
PR #688/#741 with "emit Rust, invoke rustc on output, check exit code"
as a structurally-equivalent migration path. Verified against live
sources:

- src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema
  exists (declared via PR #678).
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5
  testgen harness allowlists ONLY `command == "true" && args.is_empty()
  && expect_exit == 0`.
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 —
  panics fail-closed on any other shape with explicit "ExecuteCommand
  shell shape is not supported here (runner-owned — do not treat as
  ordinary false)".
- src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no
  match arm for ExecuteCommand; falls through to ClaimResult::
  NotYetImplemented.

Reality: a TestClaim declaring rustc/python/go invocation is
structurally expressible as data today, but executing it is blocked.
Full arbitrary-command runner support is the PB-Runtime lane's
deliverable.

Files updated:

- TESTING.md:195 — capability state callout with file:line citations;
  "Full runner support — arbitrary command + args (rustc/python/go) with
  exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor
  program)." Bullet about migration shape preserved as the cascade-named
  successor pattern, not as a live capability.
- TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane
  lands the ExecuteCommand runner extension" as an explicit precondition.
- docs/design-pure-bootstrap-zero.md:138 — same correction for the
  matching prose, with PB-Runtime named as the runner-extension
  dependency for boundary-test migration.
- ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner
  foundation in #688/#741 with `true`-no-args allowlist only — full
  arbitrary-command runner support deferred to PB-Runtime lane,
  blocking the actual boundary-test migration." Dependencies column
  extended to "DB-15 + T-TestGen + PB-Runtime".

The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still
holds for atomic-cascade-across-authority-docs; this commit closes the
remaining capability/claim mismatch flagged by codex.

(Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still
SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief

Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation).
The prior banner contained:

> "Operationally R1 closure may still ship before the 0-floor is reached
>  — the ratchet ensures the trajectory; the gate's acceptance number is
>  what shifts."

This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0.
Two competing gate semantics in the cascade is exactly what the
atomic-cascade clause forbids.

Replaced with single-authority-honest framing:

> "R1 closure now requires the 0-floor target by gate semantics: T-PB-A
>  and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade
>  promotion changed their acceptance numbers to 0; R1 cannot close
>  while the SG-0 census carries non-zero hand-Rust."

Plus minor sharpening:
- "T-PB-A's non-test target is 0" → "non-test acceptance target is 0
  per ROADMAP.md:67" (cite the authority).
- T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep
  the capability-state honesty consistent with the recent fix wave.
- Predicate-rename housekeeping line moved into banner ("post-cascade
  housekeeping, not a pre-promotion blocker") — was implicit before.

The brief now genuinely inherits the cascade-promoted gate; no
competing release authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 second-wave worker-escalation fixes

Four substantive worker STOP-AND-ESCALATEs from briefs landed in
PR #797. All four worker recommendations correct; each needs a
Director call + brief update.

## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate

Worker correctly identified that brief req 2 (declared-effect carrier
as part of fn type signature, per feedback_no_annotations) requires
net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at
src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots.
Without parser surface, every user function would have
declared_effects = [] while inference returns non-empty — lens fires
EffectLeakageError everywhere on enable. Worker rejected power-through
and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map
parser split).

Director picked split:
- NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md
  Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface
  syntax + lookahead + body parser + lowerer extension + exhaustive-match
  audit + coproduct dissolution receipt.
- MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to
  post-parser-extension scope. Pre-flight check NOT a parser-extension
  step; STOP if parser sub-lane PR not merged.

## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping

Worker found load-bearing evidence at infer.rs:3693-3703: DB-11
deliberately strips refinements at operator dispatch as a designed-in
fix for symmetric-operators failure mode. Brief's "attach where b != 0
as a proof for a / b" directly contradicts this design choice. STOP-3
(where-clause conflict with DB-11) is real; STOP-1 (substrate scope)
needs net-new substrate (per-operator partiality fact + predicate-
entailment check + asymmetric per-operand refinement-honoring) — M+
minimum. ownership_lens precedent in original brief is post-hoc
observability, not proof carrier.

Worker recommended redirect to design/scoping per nested-optional
precedent. Director picked redirect.

Brief fully rewritten as design/scoping with four-question structure:
(1) DB-11 interaction analysis; (2) substrate proposal for proof-or-
totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes
with acceptance-theatre risk on user-defined-total-wrapper-only);
(4) Director-actionable recommendation. Output is doc PR.

## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C)

Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int)
with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136
closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b)
i128 implementation requires either path 1 (hierarchy refactor —
contradicts non-goal) or path 2 (regen lie between substrate and
emit — violates discipline). Worker leaned option (C) re-scope:
land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke)
to a sibling sub-lane that does proper Int128/Word128 substrate work.

Director picked option (C). Brief req 1 re-scoped to drop canonical-
carrier-widening; lane value comes from range facts + reconciliation
narrowing + out-of-range diagnostic against existing i64. Req 4
explicitly deferred with sibling-sub-lane reference. Sibling sub-lane
NOT to be authored or implied in this PR; tracked separately.

## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change)

Worker correctly STOP'd per the brief's own pre-flight check: parser
sub-lane has not landed; SurfaceExpr::Map not on main. Director
authorized cross-lane reassignment: wise-boar-480 takes the parser
sub-lane (t-substrate-valuebody-map-parser-worker.md) since they
already have full investigation context. No brief changes needed; the
routing decision is in the dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope

Resolves codex P2 inline at sha e35103fad on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer
carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still
required widening LiteralBits::Int(i64) to an unbounded carrier and
passing the i64::MIN smoke. Internally unsatisfiable.

Fix:

- Slice section retitled "range facts + reconciliation narrowing
  (against existing i64 carrier)" with explicit note about the
  re-scope.
- Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly
  forbids touching LiteralBits::Int shape, dag_scalar_generated.rs
  regen for that variant, or tokenize i64 parse path.
- Slice steps 2-5 reframed: range facts use i64-representable
  magnitudes; reconciliation narrowing uses existing i64 carrier;
  diagnostic only for i64-representable out-of-range; smoke tests
  for req 5 only (req 4 i64::MIN deferred).
- Acceptance checklist updated:
  - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as
    re-scoped/deferred.
  - LiteralBits::Int(i64) carrier untouched (no widening; no
    parallel; no shape change).
  - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference.
- STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the
  carrier" — explicit STOP if execution surfaces range-fact narrowing
  requiring carrier-widening; that's the boundary the re-scope drew;
  belongs in sibling Int128/Word128 sub-lane.

Brief now consistently treats carrier-widening as out-of-scope across
all sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty

Resolves codex BLOCKING #1 at sha e35103fa on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier
but req 2 required range facts using "the SAME magnitude carrier
as req 1" — meaning i64-typed range bounds. u64's max (2^64-1)
doesn't fit in i64; range fact for u64 would have to truncate,
omit, or mirror in Rust (representation drift). All three options
violate fail-closed declared-facts discipline (P1 / P3).

Fix:

- Req 2 rewritten to specify String-decimal representation:
  range_min_inclusive: String + range_max_inclusive: String fields
  on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127"
  for i8; "0"/"18446744073709551615" for u64).
- Explicit reasoning why String-decimal: u64's max doesn't fit in
  i64; binding range bounds to literal carrier forces truncation/
  omission/mirror-drift; all violate fail-closed declared-facts
  discipline.
- Bridge framing: String-decimal is pending the sibling Int128/
  Word128 sub-lane; both range bounds and literal payload migrate
  to typed carrier when that lands.

- Req 3 updated for String-decimal comparison semantics:
  reconciliation parses both bounds and literal magnitude into a
  common comparison space (i128 host comparison primitive — host
  narrowing, NOT carrier widening). Bounded by what the i64-typed
  literal can express; any i64-representable literal compares
  against any width's String-decimal bound. Carrier discipline
  preserved.

Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral)
is sha-stale — already resolved at 3e142d169.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed

Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback).
Real residual: req 2 specifies String-decimal range bounds (to cover
u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance
bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" /
"i64-representable magnitudes" for the range facts. Two incompatible
authorities for the same range-fact shape — would let a worker satisfy
the slice while truncating/omitting u64 bounds (P3 fail-closed
violation).

Fix:

- Line 31 (req 1 re-scope clarification): updated to explicitly state
  "range facts (req 2) use String-decimal representation (width-
  independent; covers u64::MAX which doesn't fit in i64)". Distinguished
  literal *payload* (stays i64) from range-bound *representation*
  (String) — both serve req 1's "no carrier widening" boundary.
- Line 44 (slice step 2): updated from "Range bounds use i64-
  representable magnitudes" to "Range bounds use String-decimal
  representation per req 2" with concrete example (u64 bounds).
- Acceptance bullet: updated from "Range facts on integer algebras
  (substrate-declared, not Rust-mirrored)" to add "using String-decimal
  representation ... width-independent; u64 bounds expressible without
  truncation."

The brief now consistently treats range bounds as String-decimal
across req 2, req 3, slice, acceptance, and the req 1 clarification —
no remaining authorities saying i64-typed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing

User + PM exchange 2026-04-25 surfaced that the in-flight effects
chain was importing wrong assumptions from external languages
(declared-effects-as-annotation + lens-vs-declaration check). Right
framing under gunbc's closed-system discipline is parallel to
complexity: every effect derives structurally from the composition
of typed primitive operations; nothing can hide because there's no
escape hatch; nothing needs annotation because the structure IS the
registry.

Four doc-only actions:

1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md.
   Frames the closed-system answer with PM's 5-behavior synergy
   table (Value/Transform/Branch/Loop/Bind as universal
   compositional-fold pattern). Four worked examples; aggressive
   reading on redundancy (compile-error-by-construction via
   referential-transparency proof; reread() primitive for legitimate
   cases); implementation-brief shape in §Q6.

2. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md.

3. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md.
   Notes Fn→Arrow refactor brief stays dispatchable as independent
   value.

4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by-
   construction framing replaces lens-detection framing.

Memory file feedback_closed_system_effects.md saved separately;
cross-link added to feedback_construction_over_ratchets.md.

Net cost: doc-level cleanup. Zero substrate code rework. Foundation
(OperationEffect + service-call infrastructure + 5-behavior
substrate) already exists.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect

Per PM convergence review on #808 + user's deeper 2026-04-25 framing:
the closed-system framing landed in #808 retired the user-facing
annotation but kept OperationEffect taxonomy as substrate-level tagging.
User's deeper framing: the taxonomy ITSELF is parallel-representation —
operations are intrinsically read-shaped or write-shaped via their
TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns-
derived-value-only → read). Tagging operations with Read | Upsert |
Create | Append | Delete names what the structure already says.

Three changes:

1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as
   normalized view, or retire as parallel-representation?"
   - Two paths: (i) tags derived from signature shape (acceptable
     normalized view) vs (ii) tags declared per-primitive (parallel-
     representation; retire).
   - Audit-as-existence-check (Q4 req 2 reframed): all effectful
     primitives derive cleanly from signature shape → path (i); any
     primitive needs hand-declared tag → path (ii) by existence proof.
   - Director default: path (ii). Logging primitives that return Unit
     are likely the audit's existence-proof.
   - Two design-question resolutions: (a) external effects not in
     return type → resource-threading discipline (typed param returned
     modified, IO-monad-without-the-monad pattern); (b) transactional
     grouping → derived structural fact from Bind composition + typed
     transaction primitives.

2. Q4 reqs revised: req 2 from "tag every primitive with explicit
   OperationEffect signature" to "audit-as-existence-check that every
   primitive's type signature derives the right effect classification";
   req 3 added (resource-threading discipline); req 6 added
   (transactional-pattern lens). Req 1 (effects lens) anchors on
   operation type-signature shape, not on hand-declared tags.

3. THESIS:345-347 amendment strengthened — "operations are
   intrinsically read-shaped or write-shaped via their type-signature
   shape; consumers walk the signatures directly; there is no parallel
   taxonomy or annotation layer to declare or maintain. Tracking
   effects as a separate enumerated concept IS the bug pattern,
   dissolved by construction." Plus references to resource-threading
   discipline + transactional grouping as derived structural fact.

Memory file feedback_closed_system_effects.md updated to reflect the
deeper framing (type-signature-shape, not taxonomy-tagging) +
resource-threading discipline section + transactional-patterns
section.

Net cost: doc-only delta on top of #808. Substrate retirement
(OperationEffect enum + derive_op_effect + idempotency.dag re-anchor)
deferred to the audit-as-existence-check phase of the implementation
brief; surfaced as Q5.5 OPEN CALL.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage

Resolves codex BLOCKING at sha d49ce79a on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real:
the prior text claimed service primitives "already carry typed effect
signatures" presenting future audit-state as current substrate fact
(P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the
OperationEffect line but left a parallel over-claim on the new
"signature-shape coverage" framing.

Fix: Q4 substrate-state listing rewritten to honestly distinguish:

- Live: Behavior enum + substrate foundation (the principle that
  operations should carry signature shape).
- Incomplete: signature-shape coverage across actual primitives.
  HTTP-derived primitives carry implicit shape via derive_op_effect's
  method-table; logging/mutation primitives that return Unit or don't
  thread their target resource do NOT carry the structural shape that
  would express read-vs-write. Achieving full coverage is required
  work under reqs 2 + 3, not a current fact.
- Pending audit-as-existence-check: OperationEffect + derive_op_effect
  (path (i) vs (ii) per Q5.5).

Honest live-state callout added explicitly: "the closed-system
FOUNDATION (5 behaviors + DAG substrate + the principle that
operations should carry signature-shape) is live. The IMPLEMENTATION
COVERAGE across all effectful primitives is partial. Req 2 + req 3
are the work that closes the gap."

Brief now distinguishes principle-is-live (foundation) from
coverage-is-partial (audit work) without conflating them.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim

Per PM follow-up review on #808 + user's stronger discipline framing
("substrate must make bypass structurally impossible at every layer
of the transport stack"): the closed-system claim is honest only when
typed primitives ARE the path. Today two structural holes exist where
bypasses sidestep the typed-primitive substrate. Both surfaced
explicitly as Q4.5 pre-conditions — load-bearing for the lens's
coverage claim.

Three changes:

1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed-
   system claim)" inserted between Q4 and Q5:

   P1 — Extdeps typed-primitive consumption structurally enforced.
   Substrate must make `messages: Json` impossible to declare in
   service definitions; typed `LlmMessage` / `ContentBlock` /
   `GitHubAuthToken`-with-full-scopes are the only path. Tracked
   debt at ROADMAP.md:153-154 (LLM provider flattening) +
   `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded).
   Required prereq for full lens coverage; lens can land first +
   surface structural-coverage-gap diagnostics on bypass surfaces
   so the gap becomes visible rather than silent.

   P2 — `ExecuteCommand` fully materialized as typed runner
   primitive. TESTING.md (post-#782) committed to 0-residual but
   ExecuteCommand isn't fully materialized; deleting Rust boundary
   tests creates verification gap. Already named under PB-Runtime
   in Zero-Floor; signal pending. Pre-requisite for ANY Rust
   boundary-test deletion.

2. Old leftover duplicate Q5 section deleted (artifact from prior
   Q5/Q5.5 reshape; second copy of asymmetric-tightening text was
   in the file alongside the earlier Q5 instance).

3. Worker-discretion-vs-Director-call section in Q4.5: lens
   implementation worker dispatchable now (reports gaps as
   findings); P1 closure is substantive substrate work touching
   extdeps (dedicated lane); P2 closure is PB-Runtime (signal
   pending).

Net: design doc now honestly distinguishes principle-is-live
(Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs
named explicitly). The closed-system claim has explicit pre-
conditions documented; implementation brief discovers them as
known dependencies, not as STOP-AND-ESCALATEs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default

Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two
real residuals after the Q5.5 reframe:

1. Q6's reqs/STOPs/acceptance still framed under path (i) — said
   "audit + tag std/ primitives — every effectful primitive carries
   an explicit OperationEffect signature." Directly contradicted Q4
   (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment
   ("there is no parallel taxonomy to declare or maintain"). Worker
   reading Q6 in isolation would author the retracted shape.

2. Capacity / sequencing table line about "audit lane (tag std/
   primitives with effect signatures)" carried the same stale
   framing.

3. Q6 STOP "primitive performing side effects without an
   OperationEffect tag" assumed tag-as-authority; under path (ii)
   the STOP shape is "primitive whose signature doesn't structurally
   reveal its effect."

Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale
(already fixed at f073aa95e Q4.5 commit).

## Q6 fixes

- Reqs renumbered + reframed:
  - Req 1 anchors on operation type-signature shape (not hand-declared
    OperationEffect tags); composition reads from signature shape per
    Q2 table.
  - Req 2 changed from "audit + tag every primitive" to
    "audit-as-existence-check" — verify signature-shape coverage; ANY
    primitive needing a hand-declared tag IS the existence-proof for
    path (ii) retirement.
  - Req 3 added: resource-threading discipline applied to existing
    primitives (logging that returns Unit gets reshaped per audit).
  - Req 6 added: transactional-pattern lens (Bind composition +
    Transaction → Transaction').
  - Req 7 added: asymmetric-tightening worked example in PR body
    (per claude review observation; the one place declaration-shaped
    surface re-enters).
  - Req 8 (was 5): tests now reference signature-shape derivation
    explicitly, not tag lookup.
- STOPs reframed:
  - "OperationEffect retirement decision" — audit produces path (i)
    vs (ii) verdict; substrate retirement is its own dedicated
    sub-lane; this lane does NOT absorb it.
  - Pure/impure carrier STOP notes that "pure" should also derive
    from signature shape (pure functions don't return modified
    resources) — so the STOP itself may dissolve under further design.
  - Q4.5 P1 explicitly NOT a STOP — lens reporting structural-
    coverage-gap on extdeps bypass surfaces is the lens delivering
    its foundation-gap-visibility value.
  - Q4.5 P2 explicitly independent — lens doesn't depend on
    ExecuteCommand materialization.
- Acceptance extended: lens reports gap diagnostics on P1 bypass
  surfaces; audit produces existence-proof verdict for Director
  re-decision; asymmetric-tightening worked example in PR body.

## Capacity / sequencing table

Replaced "1 audit lane (tag std/ primitives with effect signatures)"
with "1 audit-as-existence-check lane (verify primitives' signature-
shape coverage; NOT 'tag every primitive') — produces the path (i)
vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2
prereq lanes to the net summary. Closing line: "The taxonomy-
retirement scope (substrate-side) is not in this lane — it's
surfaced by audit and routed to dedicated retirement lane if path
(ii) wins."

Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity
table. Worker reading Q6 in isolation now sees path-(ii)-default
framing matching Q4 + Q5.5 + THESIS amendment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792

Resolves codex inline BLOCKING at sha 191be310 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150.
Real: my Q4.5 P2 framing described ExecuteCommand as still
NotYetImplemented (M1.5 allowlist + Rust TestRunner returning
NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand
extension before this PR's authoring. TESTING.md:195 capability-state
callout confirms:
- Rust TestRunner + M1.5 testgen harness share one std::process path
  for arbitrary command + args + expect_exit_code.
- M1.5 allowlist + fail-closed panic retired.
- Distinguishable ClaimResult::Fail messages for spawn / timeout /
  policy / exit-mismatch.
- Linux unshare(1) namespace isolation on host-allowing systems.
- T-PB-B-1 boundary migration example landed.

Fix:

P2 section rewritten:
- Header retitled "ExecuteCommand runner primitive: LANDED (PR #792);
  residual is bulk-migration."
- Status update naming PR #792 + the post-#792 capability state
  (allowlist retired, etc.).
- Honest acknowledgement: "My earlier P2 framing was stale."
- Residual narrowed to bulk-migration of existing Rust Command::new
  boundary tests (tracked as ROADMAP residual, not lens prereq).
- Sequencing reframed: P2 was always orthogonal to the effects lens
  itself; bulk migration proceeds at its own pace; lens not blocked.

Q4.5 footer updated:
- "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via
  #792; only consumer-side bulk migration remains)"
- Worker-discretion-vs-Director-call P2 line updated: "runner
  primitive landed; only consumer-side bulk migration remains;
  tracked as ROADMAP residual, independent of the lens."

Q6 STOP for P2 updated:
- "the lens itself doesn't depend on P2; only TESTING.md's 0-residual
  claim does" → "runner primitive landed via PR #792 (post-Q4.5-
  authoring update). The lens itself never depended on P2; bulk
  consumer migration is residual ROADMAP work and remains independent
  of this lane."

Brief now reflects live state. The closed-system claim's prereq
landscape is honest:
- P1 (extdeps typed-primitive consumption): real prereq, tracked
  debt at ROADMAP:153-154.
- P2 (ExecuteCommand runner): satisfied via #792; bulk migration is
  consumer-side residual, not foundation work.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale

Resolves codex non-blocking finding at sha bcac41bb on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real
residual: capacity-table line still listed P2 as "`ExecuteCommand`
materialization" prereq + framed both P1 and P2 as "pre-existing
tracked-debt" — but my prior 57a9b1318 fix established that PR #792
already landed the runner primitive, so P2 is no longer a
materialization prereq.

Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq)
from P2 (residual, not prereq):

  - P1: extdeps typed-primitive consumption — pre-existing tracked
    debt at ROADMAP:153-154; load-bearing for the lens's full-coverage
    claim.
  - P2: ExecuteCommand runner primitive landed via PR #792; only
    consumer-side bulk migration of existing Rust Command::new
    boundary tests remains (tracked as ROADMAP residual, independent
    of the lens; not a materialization prereq).

Brief now consistently treats P2 as bulk-migration-residual across:
- §Q4.5 P2 section header (LANDED via PR #792; residual is
  bulk-migration).
- §Q4.5 footer (P2: runner primitive landed; only consumer-side
  bulk migration remains).
- Q6 STOP for P2 (runner primitive landed; bulk migration is
  residual ROADMAP work).
- §Capacity / sequencing impact (P2 as residual, not prereq).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349

Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated
target-grounding prose; the matching extdeps typed-primitive bypass
entries (LLM service flattening, GitHub auth model bypass) live at
ROADMAP.md:348-349.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix third stale ROADMAP citation at line 271

Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence
at line 271 in the §Q4.5 capacity table. Now consistent with lines
139 and 173 (ROADMAP.md:348-349).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity

Codex flagged 'Effect-signature tagging on std/ primitives' as potentially
contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240)
already explicitly say 'NOT tag every primitive' — but the cross-manager
line used sloppy wording. Reworded to make explicit that the audit walks
signature shape; no parallel tag added.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5

- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)

B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).

B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — drop incoherent inner-fallback non-goal

Codex P2: the non-goal line excluding the inner declaration().name
unwrap_or_else fallback contradicted Slice step 2, which replaces the
whole chain with let-Some-else-return. Both fallbacks are in scope by
construction; remove the contradictory non-goal.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives

PM REQUEST_CHANGES: §Frame listed '4 type connectives
(Conjunction | Disjunction | Cardinality | Bit)' which contradicted
the canonical thesis source. Replaced with the canonical 6
(Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per
docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary
closes here'. Also removed 'typed substrate carriers' from the
vocabulary list — substrate carriers are defined using the vocabulary,
not part of it. Added a clarifying note that B4's carriers
(DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are
typed declarations composed from the vocabulary, not vocabulary
extensions.

Per feedback_verify_thesis_claims: brief framings citing thesis
structure must ground in the canonical source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority

Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of
naming the live substrate authority. Two coordinated fixes:

1. §Read first cites src/v3/std/substrate.dag (live .dag substrate
authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel
meta-type — already exists with consumers in verification.dag,
emit_model.dag, python.dag).

2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing
DeclarationRef'. The work is consumer migration + any role-extension
layer the audit reveals, NOT designing or landing the carrier.

Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers)
keep their 'new' framing but explicitly require sub-briefs to grep
src/v3/std/ + src/v3/spec/ for existing authority before authoring
'design and land' framing — per feedback_verify_thesis_claims +
feedback_emitter_workaround_is_gap_symptom.

Acceptance + sub-brief dispatch order updated to reflect B4.1's
consumer-migration shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — tighten Phase 1 umbrella sentence

The umbrella 'Land the typed carriers into src/v3/std/' framing was
stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced
with audit-first wording that covers both the consume-existing case (#1)
and the design-and-land case (#2-#4 if their audits show real gaps).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording

Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands'
which conflicted with the post-reframe reality that B4.1 consumes the
existing DeclarationRef. Updated to 'consumes or lands' with explicit
existing-authority citation and audit-pending caveat for B4.2-B4.4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — soften regression-test requirement (3 worker bounces)

Three consecutive B1 worker dispatches (zesty-crane-890 cursor →
valiant-boar-498 codex → cool-lynx-395 cursor) archived without
opening a PR. Likely friction point: brief Slice step 4 asks for a
unit test that constructs a Dag with an orphan variant declaration,
but emit.rs has zero existing #[test] precedent — emit testing
happens via integration fixtures. Workers see 'build novel test
harness' inside what's billed as an S-scope fix and bounce.

Per feedback_construction_over_ratchets: when a brief has friction,
fix the brief, don't ratchet the worker.

Softened step 4 + acceptance: regression test stays optional. If
test setup requires novel scaffolding, route the gap to follow-up.
The structural fail-closed at step 2 is the load-bearing change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt

PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description'
is too weak; PR descriptions don't survive squash-merge cleanly.

Two coordinated edits:
1. Slice step 4 — explicit substrate-signal framing: skipped test
   means emit-side hermetic-unit-test infrastructure is the missing
   substrate (feedback_emitter_workaround_is_gap_symptom).
2. Acceptance — require ROADMAP debt row (new or existing) with
   named dissolution trigger, referenced in PR body. Converts the
   skip from PR-local note (transient) into tracked debt (durable,
   dispatchable).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124

Codex BLOCKING: my earlier softening claimed emit.rs had no #[test]
precedent — wrong. The module has #[cfg(test)] mod tests at line 3124
with 12+ tests using compile_to_dag(source, filename) as harness
(e.g., go_struct_fields_render_with_separators :3143,
shared_walk_to_disj_finds_match_scrutinee_sum_type :3195).

This is a feedback_verify_thesis_claims violation on Director-side
brief authoring — claim made without grep verification.

Fix: restore step 4 as required, with explicit precedent citation.
Worker constructs the failure case via the existing harness
(direct Dag, fixture string, or BranchPattern exercise; worker's
call on cleanest path). STOP-AND-ESCALATE only if construction
proves materially harder than precedent suggests, in which case
that escalation surfaces a real substrate gap and warrants ROADMAP
debt — but the default is 'add the test.'

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites)

Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but
emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded
to 'several using compile_to_dag'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue

Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this
is Wave 1 of Director's 14-brief authoring queue, covering B4 program
internals.

Authored:
- b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) —
  replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag")
  fold-skip with structural template-formal carrier; mandatory
  authority audit per feedback_audit_adjacent_authority_first.
- b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) —
  replaces §0.6 emit.rs bind/branch.span.file equality with typed
  BindEmitParticipation/BranchEmitParticipation roles populated at
  lowering; aligned with #824 worker's in-flight implementation shape.
- b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4
  of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with
  typed substrate authority; explicit pre-promotion-constraint
  disposition (single-authority vs authority+tracked-debt) addresses
  parallel-representation risk surfaced on #825.
- b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) —
  names B4.5-B4.12 Phase 2 sites with carrier dependencies,
  cross-program coordination notes, and skeleton-brief template;
  full per-site briefs author at dispatch time per #827's
  Substrate Manager ownership.

Cross-cutting discipline applied per inbox #828 reply:
- feedback_audit_adjacent_authority_first (mandatory grep before design)
- feedback_no_textual_enforcement_bridges (no replacement sentinels)
- feedback_parallel_representation_debt (explicit if shape (b))
- feedback_construction_over_ratchets (no parity-by-runtime as primary)
- feedback_coproduct_dissolution (receipts for new variants)

Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling
worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3)

Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue.
Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by
Modeling Manager's Wave 3 worker briefs (gated on these landing).

Authored:
- r2-substrate-cardinality-for-int-lit-subset.md (M) — produces
  magnitude carrier consumed by T-Modeling int-lit. Coordinates with
  PR #806's prior cardinality work; mandatory authority audit guards
  against #796's rejected IntLiteralMagnitude shape resurfacing.
  Open design questions: magnitude representation, reconciliation
  narrowing point, i64::MIN representability.
- r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces
  nominal-opacity carrier consumed by T-Modeling Secret<T>. Open
  design questions: carrier shape (flag/connective/sealed-accessor),
  generic-walk discipline, accessor gating.
- r2-substrate-parametric-algebra-for-dimensions-subset.md (M) —
  produces phantom-parameter carrier consumed by T-Modeling
  Dimension<Carrier>. Open design questions: carrier shape,
  type-equivalence rule, algebra-method dispatch, lifting/coercion.

All three:
- Scoped narrowly to their paired R2 consumer; not full
  substrate-capability lanes.
- Mandatory pre-author authority audit per
  feedback_audit_adjacent_authority_first.
- Cross-program readiness signal pattern from #827's manager rework.
- Coproduct dissolution receipts required for any new variants.
- Open design questions surfaced explicitly so Substrate Manager
  (or Director pre-spin-up) can resolve at dispatch time.

Wave 3 (T-Modeling worker briefs × 4) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4)

Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue.
Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each
gated on a Substrate Manager readiness signal (Wave 2 producers).

Authored:
- r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2
  cardinality-for-int-lit; moves narrowing from tokenizer to
  reconciliation; MagnitudeOutOfRange diagnostic per C-8.
- r2-modeling-secret-graduation-worker.md — gated on Wave 2
  nominal-opaque-for-Secret; authors Secret<T> + gated accessors
  (redact, compare_in_constant_time); C-8 diagnostic on non-gated
  access; signals Impossible-Bugs Manager on close (thesis claim
  covered).
- r2-modeling-dimensions-phantom-worker.md — gated on Wave 2
  parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier>
  + core SI base units + algebra-method dispatch; cross-dimension
  arithmetic produces typed diagnostic; signals Impossible-Bugs
  Manager (thesis claim).
- r2-modeling-tokenizer-charclass-phase2-worker.md — gated on
  T-Substrate ValueBody-list/sum (#790); migrates tokenizer
  consumers to Char/List<Char>/CharClass canonical types; sibling
  consumer to Grounding Manager's Engine sharpened-(b).

All four:
- Explicit gating: 'do not dispatch until producer signal posts.'
- Producer/consumer signal pattern from #827.
- Cross-program signals to R2 Release Manager (Goal 2 closure)
  and Impossible-Bugs Manager (thesis-claim coverage).
- Spoofing regression tests: discipline anchor against
  feedback_no_textual_enforcement_bridges.

Wave 4 (T-ImpossibleBugs worker briefs × 3) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3)

Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue.
Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes,
consuming the existing design/scoping briefs as authority.

Authored:
- r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on
  cardinality refinement substrate (T-Substrate territory adjacent
  to int-lit / DB-11 alias-where). Implementation: structural normalize
  of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T??
  worker decision (reject vs normalize). Cites
  t-impossiblebugs-nested-optional-flatten-design.md as authority.
- r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated
  on Tier 2 substrate (predicate-entailment infrastructure; distinct
  from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes
  predicate entailment, (b) feedback_totality_by_omission dissolves
  partial primitives, (c) park. Worker decides at audit time. Cites
  t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority.
- r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate
  prerequisite per closed-system framing in design doc (#808). Audit-
  as-existence-check + lens implementation as compositional fold over
  5 behaviors; redundancy detection compile-error via referential
  transparency + reread() escape hatch; path (i/ii) decision on
  OperationEffect taxonomy retain-vs-retire (default retire). Cites
  design doc #808 as authority.

Cross-cutting:
- Each cites prior design/scoping brief as authority (the existing
  *-design.md / *-worker.md REFRAMED files).
- Explicit gating per #827 producer/consumer signal pattern; two
  briefs gated on substrate, one NOT gated (closed-system).
- STOP-AND-ESCALATE includes 'design brief assumptions don't hold'
  surfacing per feedback_thesis_gate_state_drift.

Wave 4 complete. Director's 14-brief queue done; awaiting PM portion
(6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4.4 — tighten Slice §3 per PM review on #836

PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b)
(authority + tracked debt parallel-rep) as autonomously acceptable
contradicts feedback_construction_over_ratchets +
feedback_parallel_representation_debt.

Tightened:
- Shape (a) is the only autonomous worker path.
- Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a
  regen-host-loader sub-lane decision; not authorable without explicit
  Substrate Manager approval citation in the PR body.
- Acceptance bullet requires the approval citation when shape (b)
  lands.
- STOP-AND-ESCALATE rephrased to make this explicit; permanent
  parallel-representation re-escalates even with manager approval.

This preserves shape (a) as autonomous; shape (b) becomes a
cross-manager design escalation, not a B4.4 implementation call.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief

Cursor review on #836 flagged the Read-first reference to
.claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md
as machine-specific (outside the repo, not resolvable from a normal
clone). Replaced with in-repo prose pointing at the design doc's
§Q1-Q3 as canonical authority — the discipline lives there in-repo.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs)

Codex flagged: src/v3/std/types.dag does not exist; the canonical
authority is at dsl/std/types.dag. Affected briefs (all from R2
spin-up Wave 2 + Wave 3):

- r2-substrate-cardinality-for-int-lit-subset.md
- r2-substrate-nominal-opaque-for-secret-subset.md
- r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs)
- r2-modeling-dimensions-phantom-worker.md
- r2-modeling-secret-graduation-worker.md

feedback_verify_thesis_claims violation on Director-side brief
authoring — assumed path without grep. Same family of error as
the earlier emit.rs precedent claim. Mass-replaced via perl;
verified no remaining stale refs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant

Codex BLOCKING on #836: my R2 worker brief gated nested-optional on
cardinality refinement substrate, but the design doc verifies v3 is
ALREADY past the cardinality bridge — TypeConnective::Cardinality
is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is
the carrier for Option. The dissolution is an UNGATED implementation
via substrate-constructor invariant.

feedback_verify_thesis_claims violation again — should have read the
design doc fully before assuming the substrate gate.

Rewrote brief to match design doc canonical sketch:
- Single predicate (cardinality_idempotent_target) owns the rule
- Single allocator (alloc_cardinality_decl) is THE substrate-constructor
- API closure on TypeConnective::Cardinality payload (modeling-discipline
  practice 6) — variant cannot be struct-init'd outside the allocator
- 3 hand-Rust + ~22 codegen call sites enumerated per design audit
- infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as
  the killer case for generic-instantiation paths
- Surface-syntax T?? decision left to worker (Director-lean: silent
  normalize)

Brief now dispatchable immediately, no producer signal needed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation

Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment
substrate path, but the design doc §4 explicitly recommends totality-by-
omission as the Director-actionable path. Predicate-entailment is M+ scope
that reopens DB-11's explicitly-closed asymmetric-strip design — design
doc explicitly discards it.

feedback_verify_thesis_claims violation again — same family as nested-
optional reframe. Should have read design doc §4 in full before assuming
the path ordering.

Rewrote brief to match design doc §4 follow-on shape:
- Primary path: per-class totality-by-omission (algebra retype + per-
  target realization migration). For Int/Int: OrderedRing.div retype
  at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 /
  python:486 + python_target.rs:680 helper).
- NOT predicate-entailment (out of scope; M+ + DB-11 reopen).
- NOT NonZero-typed-input (deferred to separate per-operand-variance
  substrate brief; STOP-AND-ESCALATE if chosen).
- Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i]
  indexing, quotient, remainder) queue separately per design doc audit.
- feedback_totality_by_omission discipline anchor explicit.

Brief now matches feedback_totality_by_omission discipline + design doc
recommendation. No substrate prerequisite; dispatchable immediately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure

Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a
pattern: I authored R2 worker briefs without fully reading each design
doc's Director-actionable recommendation. Pre-emptively re-verified
unenumerated-effects against design doc §Q6 to catch the same family
of error before reviewers do.

Findings: brief was substantively close but missing 3 of 8 design-doc
reqs:
- Req 3: Resource-threading discipline applied to existing primitives
- Req 5: reread(key) primitive in std/ as explicit Slice item (was
  only mentioned in tests)
- Req 7: Asymmetric-tightening worked example in PR body

Plus: Slice didn't cite the canonical lens path
src/v3/lenses/effect_enumeration.dag from design doc.

Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6
specifies 4 specific STOPs (path-decision-escalation, pure: Bool
carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP)
that I had elided.

Reframed Slice as 8 numbered reqs matching design doc verbatim;
STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs;
Acceptance enumerated per req.

This is the third reframe in the unhandled-bugs series — same
feedback_verify_thesis_claims violation each time. The pattern
suggests Director-side R2 brief authoring should ALWAYS read each
design doc's §Director-actionable / §Q-recommendation in full first,
not assume.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options

Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)"
listed as a worker-pick option violates THESIS.md substrate-shape
lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality |
Instantiation) are canonical (per #811 thesis additions and #827 PM
review); a 7th is a C1 stop signal requiring failed-dissolution
evidence + Director substrate-design call, not autonomous worker pick.

Removed the "new TypeConnective variant" option; replaced with
`inhabits`-edge-shape carrier as third option (audit-time check). The
explicit STOP-AND-ESCALATE clause now states: 7th connective is the
precondition for failed-dissolution-evidence + Director substrate-design
call, not a worker path.

feedback_verify_thesis_claims still in play — should have grounded
substrate-shape options against the THESIS lock before listing Opaque(T)
as worker-autonomous. Pattern continues; reading source-of-truth before
authoring options is the discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place)

Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter
already exist at dag.rs:186, :217 — explicitly authored for the
R2 Dimensions consumer per the doc comment at dag.rs:148-160.
phantom_unit_mismatch already wired at infer.rs:1057, :1132. The
substrate is fully landed; my brief framing it as 'producer sub-lane
to land carrier' is wrong on the same feedback_audit_adjacent_authority_first
violation that hit nested-optional / unhandled-diagnostic / unenumerated-
effects.

Reframed the substrate-side brief as no-op / closed-by-audit:
- Documents the audit receipt (5 sites confirming substrate exists)
- States the lane is closed
- Routes T-Modeling Dimensions consumer to dispatch immediately
  against the existing carrier
- Records the lesson: 'always grep substrate before authoring
  producer briefs' — discipline doesn't end at brief boundaries.

Updated r2-modeling-dimensions-phantom-worker.md correspondingly:
- Changed gating from 'do not dispatch until producer signal' to
  'NOT GATED — dispatch immediately'
- Read-first updated with concrete dag.rs/infer.rs cites
- Slice §1 changed from 'confirm producer signal' to 'verify
  substrate at HEAD'
- STOP reframed: existing carrier extension would need Substrate
  Manager call, not autonomous worker pick

Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit
both verified — no existing substrate (no is_nominal_opaque /
MagnitudeBound patterns in dag.rs); both still legitimately
producer-side work.

Pattern is now four reframes deep on the R2 spin-up wave. The lesson
saved is structural: read source-of-truth before authoring options.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority

Codex BLOCKING on #836: my new R2 spin-up brief duplicates the
existing t-substrate-cardinality-int-lit-worker.md, which carries
the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64)
stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane).
Single-authority violation per INVARIANTS P2.

Same feedback_audit_adjacent_authority_first failure as parametric-
algebra-for-Dimensions reframe (4 hours ago): assumed substrate
authority didn't exist; should have grepped docs/briefs/ before
authoring. This is the SECOND R2 spin-up substrate brief closed
as redundant — the discipline lesson is structural.

Reframed brief as no-op routing doc (documents the audit receipt;
routes consumers to the existing authority); updated
r2-modeling-int-lit-magnitude-worker.md to cite
t-substrate-cardinality-int-lit-worker.md instead.

Pattern across the R2 spin-up wave reframes (5 now):
1. nested-optional gating-on-substrate (substrate already past
   cardinality bridge)
2. unhandled-diagnostic predicate-entailment default (design doc
   recommends totality-by-omission)
3. unenumerated-effects 8-req design-doc elision
4. parametric-algebra Producer (Declaration.phantom_params already
   authored explicitly for this consumer)
5. cardinality-for-int-lit Producer (existing brief is authority)

All five are 'as…
briansrls added a commit that referenced this pull request Apr 26, 2026
… readiness) (#835)

* docs(briefs): pre-stage 6 R2 manager briefs (PM portion of R2 spin-up readiness)

Per user direction: every lane/brief/design must be authored before
R2 managers spawn. PR #827 (merged) named the 6-manager structure;
Transition mechanics step 4 said "pre-stage skeletons during R1 final
week" — accelerated to "pre-stage now."

This PR lands all 6 R2 manager briefs as one bundle, structured
consistently:
- Status (PROPOSAL pre-spawn, spawns on R1 close)
- Orient before reading (R2 structure authority, scope source,
  cross-program coordination, demo coordination)
- Program scope (the lane/sub-program scope this manager owns)
- Owned deliverables (table of lanes/sub-lanes with status)
- Cross-program dependencies (produces/consumes signals)
- Autonomous dispatch authority (what manager does without Director)
- Reporting cadence (where signals flow)
- Sub-briefs (authored / pending)
- Working state (placeholder for fill on spawn)
- Cross-refs

Six briefs:

1. r2-grounding-manager.md — T-Ground sub-program (the one true R2
   critical path: Pilot → Rust → Engine → Tests → Dissolve, with
   Python/Go fill). Migrates from grounding-manager.md (which archives
   on R2 promotion). Names Engine sharpened-(b) consumer dependency
   on Substrate Manager's ValueBody-list/sum carrier.

2. r2-substrate-manager.md — T-Substrate (4 sub-lanes) + B4
   Identity-Carrier Substrate Pass program (12 sub-briefs). Largest
   single program in R2; produces 4 carriers consumed by Modeling
   (3 sub-lanes) + Grounding (Engine sharpened-(b)). Names watch
   condition for B4 split if Substrate becomes the new bottleneck.

3. r2-modeling-manager.md — T-Modeling (3 Goal 2 items + tokenizer
   charclass phase-2 added per shared T-Substrate dependency). All
   gated on Substrate Manager carrier readiness.

4. r2-impossible-bugs-manager.md — T-ImpossibleBugs (3 R2+ classes:
   nested-optional flatten, unhandled diagnostic paths, unenumerated
   effects). Design docs already authored (#798, #801, #808+#805
   prereq); needs Director conversion to worker briefs.

5. r2-pure-bootstrap-manager.md — POST-R1 only per gate-vs-program
   resolution in PR #827. Migrates from pure-bootstrap-zero-manager.md
   with scope narrowed (does NOT duplicate R1 T-PB-A/T-PB-B census-
   reduction work). Owns Tier 3 mirror dissolutions + Tier 2
   patch_lower_helpers retirement + post-R1 emergent dissolutions.

6. r2-release-manager.md — Goal 5 (§6a metadata-pick) + Goal 6 (R2
   demo coordination) + B-wave Tier 0/2 dispatch (#810) + discipline
   framework central reporting + thesis-claim coverage mapping
   (Open call 1) + R2 closure ledger + v2 retirement. Single authority
   for closure ledger and demo coordination.

Each brief explicitly defers to ROADMAP/THESIS/r2-structure.md for
upstream authority; does not duplicate gate semantics or scope
decisions. Cross-program coordination via R1 `Cross-manager
notifications queued` brief pattern.

Coordination split with Director on inbox #828: Director takes the
worker-level briefs (B4.2/B4.3/B4.4 + T-Substrate sub-lane scoping +
T-Modeling worker briefs + T-ImpossibleBugs design→worker conversion);
PM takes §6a + B5/B6/B7 + thesis-claim mapping in follow-up PRs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(briefs): r2-impossible-bugs-manager — canonical filenames + corrected scope (codex P2 on #835)

Codex P2 inline at r2-impossible-bugs-manager.md:63: design-brief
filenames were missing the canonical -design suffix; the actual
files are t-impossiblebugs-*-design.md.

Audit revealed a bigger correction needed than just filename suffix:

1. Worker briefs ALREADY EXIST for all three classes (I had said
   'needs Director conversion to worker briefs' — wrong). Correct
   state:
   - Nested-optional flatten: design + worker (DESIGN/SCOPING shape) authored
   - Unhandled diagnostic paths: design + worker (DESIGN/SCOPING shape) authored
   - Unenumerated effects: design authored, prior worker briefs SUPERSEDED 2026-04-25 by design doc

2. The two non-effects workers are DESIGN/SCOPING shape — they
   produce substrate proposals, not direct implementation. Manager
   role is dispatch + Substrate-Manager-handoff coordination, not
   convert-design-to-worker.

3. Effects has SUPERSEDED workers (closed-system framing dissolved
   the prior lens-vs-declaration framing). Manager owns design-doc
   routing + post-supersede implementation worker authoring against
   the canonical design.

4. Fn→Arrow refactor (PR #805) reframed as independent vestigial-
   syntax cleanup, not direct effects-framing prereq.

Three coordinated fixes in r2-impossible-bugs-manager.md:
- Program scope table: canonical filenames + per-class authored-status
  + SUPERSEDED notes
- Owned deliverables: 'Manager dispatches existing worker' (not
  'convert design to worker')
- Sub-briefs section: explicit Authored/SUPERSEDED/Pending tri-state
  with full canonical paths

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc PM

* fix(briefs): add pre-spawn vs post-spawn authority subsection to all 6 R2 manager briefs (codex P2 on #835)

Codex flagged ownership ambiguity in r2-impossible-bugs-manager.md:
the brief said design/scoping docs would be 'converted to worker
briefs by Director' but elsewhere said the manager authors all worker
briefs autonomously. Without an explicit phase boundary (pre-spawn
vs post-spawn), ownership is ambiguous and dispatch can stall.

Resolution applied uniformly to all 6 briefs: new 'Pre-spawn vs
post-spawn authority' subsection inserted before 'Autonomous dispatch
authority':

- Pre-spawn (now, before R1 close): Director + PM coordinate on brief
  authoring per inbox #828 split. PM authors the manager skeleton;
  Director authors worker-level briefs not yet existing. Both stop
  authoring once R2 spawns.

- Post-spawn (R2 promotion onward): Manager owns all worker-brief
  authoring autonomously per Autonomous dispatch authority. Director
  narrows to cross-program conflict resolution + scope-change
  escalation.

Release Manager variant has the same boundary plus an explicit note
that PM also authors the §6a / B5 / B6 / B7 / thesis-claim-mapping
briefs as Release-Manager-portion PM deliverables (per inbox #828).

The phase boundary is now structurally explicit: no dispatch stall
from both Director and Manager assuming the other owns authoring.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(briefs): tighten Pending-line authority qualifier (codex BLOCKING on #835 sha 3803266 :90)

Codex flagged the 'Pending — Director-authored per coordination on
inbox #828:' lines as creating dual authority — the line read in
isolation contradicted the 'Manager authors autonomously' framing
elsewhere. The d42f17e phase-boundary subsection resolved this
contextually, but a reader scanning just the Pending line could still
read it as a permanent assignment.

Surgical tightening: add explicit pre-spawn qualifier inline so the
Pending line is self-resolving without requiring the reader to
cross-reference the phase-boundary subsection.

Old: 'Pending — Director-authored per coordination on inbox #828:'
New: 'Pending — pre-spawn Director-authored per inbox #828
      coordination split; post-spawn manager-authored autonomously
      per "Pre-spawn vs post-spawn authority" subsection above:'

Applied to 4 briefs (Modeling, Substrate, Pure Bootstrap, Release).
Release variant uses 'PM-authored' instead of 'Director-authored'
since R2 Release Manager's pre-spawn portion is PM-owned per inbox
#828 split (the §6a / B5 / B6 / B7 / thesis-claim-mapping briefs).

The Pending line now reads cleanly in isolation: pre-spawn / post-
spawn boundary is explicit at the line itself, not deferred to a
cross-reference.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(briefs): resolve openai-pro REQUEST_CHANGES on #835 sha bfaab66

Two surgical fixes for the two BLOCKING findings (P2 + P5):

1. r2-release-manager.md:67 — B7 dual-authority contradiction.
   Was: "Authors all T-Release worker briefs without Director (§6a pick, B5/B6/B7, ...)"
   But B7 is "Cross-manager signal, not a worker brief" per :33 + :86.
   Now: "Authors all T-Release owned deliverables ...: worker briefs
   (§6a pick, B5, B6, thesis-claim coverage mapping) and cross-manager
   signals (B7 priority-hint relay)." — distinguishes briefs from signals,
   no item carries two contracts.

2. r2-grounding-manager.md:62 — Pending line unbounded across pre/post
   spawn. The other 4 briefs got the "pre-spawn Director-authored;
   post-spawn manager-authored" temporal qualifier in bfaab66;
   Grounding was missed. Same pattern applied here.

Both fixes mechanical; no scope or authority change beyond removing
the ambiguity openai-pro flagged.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(briefs): resolve codex BLOCKING on #835 sha bfaab66 — stale §6a + B4.1 status

Two codex BLOCKING findings, both about briefs copying status from earlier
state without verifying against live receipts:

1. r2-release-manager.md §6a — DECISION already locked.
   docs/design-substrate-carrier-port-program.md §6a:171 says
   "pick **Option 3, unified MethodContract carrier**." :173 names the
   live receipt (src/v3/std/algebra.dag declares MethodContract;
   src/v3/lenses/cost.dag imports it via method_contract_cost_shape).
   :175 names the dissolution trigger (size_effect / cost_shape /
   callback_element_position field-by-field retirement).

   Brief was framing this as "DECISION BRIEF NOT YET AUTHORED — write
   up the 4 options ... recommend one based on E-I evidence." Stale.

   Fix: rename "pick decision brief" → "follow-through brief"; status
   from "NOT YET AUTHORED" to "DECISION LOCKED — Option 3 ... live
   receipt landed"; describe remaining work as bulk migration +
   dissolution-trigger tracking. Updated the deliverable table row,
   the Core deliverables list, the Autonomous dispatch authority line,
   the Sub-briefs Pending list, and the Cross-refs §6a source.

2. r2-substrate-manager.md B4.1 — BLOCKING already resolved.
   PR #819 ("docs(briefs): add B4.1a DeclarationRef runner migration
   brief") merged 2026-04-26 01:13:32. The §0.2 scope gap was resolved
   in 6f564f5 BEFORE merge per Director receipt on inbox #828. B4.1a
   follow-on brief landed in the same PR. Real open residual is the
   first-consumer migration at PR #826 (regen drift on r1_gates.dag —
   worker CI-fix, not brief authoring).

   Brief was still saying "DRAFTED (with §0.2 BLOCKING outstanding —
   codex finding on PR #819)" and "with outstanding BLOCKING ...
   resolution pending." Stale on both the BLOCKING and the residual
   shape.

   Fix: status to "BRIEF LANDED (PR #819, merged 2026-04-26 — §0.2
   scope gap resolved in 6f564f5 before merge); B4.1a runner-migration
   follow-on brief landed same PR. Real residual: first-consumer
   migration #826 OPEN with regen drift (worker CI-fix)." Updated the
   deliverable table row, the Sub-briefs Authored list, and the
   Cross-refs adjacent line.

Both findings: feedback_verify_thesis_claims violation on the PM
authoring side. Two surgical text updates per finding; no scope or
authority change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(briefs): anchor §6a follow-through against existing pick worker brief

Codex inline BLOCKING on r2-release-manager.md:30 surfaced that
docs/briefs/t-permethodmetadata-pick-worker.md (landed PR #794) already
exists as the pick-worker brief. My prior fix (74b679b) reframed
"pick decision brief" → "follow-through brief" but didn't reference the
existing worker, leaving readers to wonder if the follow-through was
re-picking.

Two precision tightenings:

- "Pick is closed." Names the worker brief explicitly + cites its
  scope-closure clause ("Do not migrate all consumer lenses ... bulk
  migration is post-pick work").
- "No duplicate decision authority — pick is closed; follow-through is
  post-pick scope." Closes the P2 single-authority concern codex named.

Surface change only; no scope expansion. The follow-through scope
(bulk migration + dissolution-trigger tracking) is unchanged from the
74b679b state — what's added is the explicit worker-brief anchor.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(briefs): resolve openai-pro APPROVE_WITH_COMMENTS on #835 sha 3260d71

Finding (P2 single-authority): T-Ground-Rust had two contradictory states —
deliverables table at :23 said DISPATCHED, but Sub-briefs Pending list at
:62-63 listed "T-Ground-Rust full implementation" as pending pre-spawn work.
Same lane, two authoritative states.

Audit: T-Ground-Rust full lane (Rust target-spec primitive declarations
end-to-end) has not been authored. Pilot (PR #765) and Engine Phase 1
typestructure (PR #788) are separate dispatched lanes (their own rows in the
table); the "DISPATCHED (Engine implementation parked pending loader-close)"
parenthetical was a status leak from the Engine row's parking note.

Fix: row status now reads "NOT YET AUTHORED — listed under Sub-briefs
Pending below; gated on pre-spawn Director scope refinement per inbox #828.
(Pilot PR #765 + Engine Phase 1 typestructure PR #788 are separate dispatched
lanes — see those rows; the prior 'DISPATCHED' status here was a parenthetical
leak from the Engine row's loader-close parking note.)"

Now table status matches Sub-briefs Pending list. Single authority restored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(briefs): refresh impossible-bugs manager against PR #836 merge

Codex BLOCKING on r2-impossible-bugs-manager.md:78 (sha bfaab66) was
correct in spirit and now newly actionable: the brief's Pending section
re-dispatched the older DESIGN/SCOPING workers
(t-impossiblebugs-nested-optional-flatten-worker.md +
t-impossiblebugs-unhandled-diagnostic-paths-worker.md) even though
their design docs (PR #798 + PR #801) had landed with next-step
recommendations + PR #836 just authored the IMPLEMENTATION workers
(r2-impossible-bugs-{nested-optional-flatten,unhandled-diagnostic-paths,
unenumerated-effects}-worker.md).

Re-dispatching DESIGN/SCOPING workers when implementation workers are
authored = duplicate decision authority under P2 + accumulating ad-hoc
state under P5. Codex was right.

Three sections updated to reflect PR #836-merged state:

## Program scope table (lines 17-19)

Reframed columns: "Design authority + implementation worker (post PR #836
merge)" / "Implementation status" / "Substrate gating". Each class row
now names:
- Design doc PR + closed-in-scope status
- Implementation worker filename (PR #836) + IMPLEMENTATION WORKER LANDED
- UNGATED status per design-doc audit (Director's reframes #1, #2 confirmed
  no substrate gates — substrate-constructor invariant for nested-optional;
  totality-by-omission for unhandled-diagnostic; closed-system for effects)

The OLD DESIGN/SCOPING workers are explicitly named SUPERSEDED for
unenumerated-effects already; nested-optional + unhandled-diagnostic
older workers are now also marked superseded by their PR #836
implementation counterparts.

## Owned deliverables (lines 25-31)

Reframed from "Worker brief is already authored ... DESIGN/SCOPING shape"
to "Implementation worker brief landed on main via PR #836 merge ... do
not re-dispatch the older workers." Substrate-gap escalation reframed as
the exception path (was the expected path under the older DESIGN/SCOPING
worker assumption); expected path is direct implementation per design-doc
Director-actionable recommendation.

## Sub-briefs Pending (lines 78-86)

Reframed from "Dispatch nested-optional-flatten worker (DESIGN/SCOPING
produces substrate proposal → escalate)" to "Dispatch nested-optional-flatten
implementation worker (ungated; dispatchable Day-1 post-spawn)" + same
pattern for the other two classes. PR #836's 3 implementation workers are
now the canonical dispatch targets.

Added explicit SUPERSEDED list for the older workers (4 entries: 2
DESIGN/SCOPING + 2 effects-worker variants) with their respective
implementation-worker successors named.

## Discipline note

This finding was real, not an echo. PR #836 merging changed the substrate
of facts the manager brief grounds against. Same class as the §6a stale
framing on Release Manager + the B4.1 stale BLOCKING on Substrate Manager:
brief authored against pre-merge state; merge surfaces the staleness.

The matrix's pre-author verification invariant catches state-drift at
authoring time; the matrix's status-consistency rule catches dual-state
within a single brief. This finding is a third class: cross-PR state drift
(brief A's Pending list cites brief B's content; brief B merges and
brief A's content goes stale). Worth noting as a refresh-discipline
trigger separately from authoring discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 26, 2026
* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation)

Director-authored amendment following the 2026-04-24 escalation from PR
#693 (sub-child sharp-bear-829 under Surface Manager).

Two edits:

1. New "Class 5 Gap 3 — port-carried field values in data bodies"
   row in the 2026-04-21 post-merge-debt section. The substrate gap was
   documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP
   ledger row for cross-lane visibility. PR #693's execution surfaced it
   as the blocker on sub_charclass_in_std_unicode phase-2.

2. Retract the "ready-to-dispatch (no substrate capability gap)" claim
   on the Character-level row, annotate phase-1 landed via PR #693
   (CharClass vocabulary + Rust-mirror structural scanner path), and
   point phase-2 at the new Class 5 Gap 3 row.

Codifies the audit pattern: "this consumption gap has no substrate
capability gap" claims must be verified by attempting the retype before
the claim lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main

* docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review)

* docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review)

Row title still said 'consumption gap, not substrate gap' while the
body block retracted that claim and cited Class 5 Gap 3 as a substrate
dependency for phase-2. Title now matches body: mixed classification,
consumption for steps 1+3, substrate for step 2.

* docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit)

gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining
gap" description was wrong: field-level shapes (nested records, list
literals, declaration refs, Var refs, sum-variant literals) are
supported today via FieldValue variants + lower_structural_field_value
(dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the
top-level ValueBody boundary (non-scalar, non-record top-level bodies).

The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself
stale: it describes the pre-PR-B-unwind shape where FieldValue was
LiteralBits-only. PR-B's unwind extended FieldValue to carry
Reference / Record / List / Variant, moving the gap to ValueBody.

Two fixes:

1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody
   boundary, point at code paths (dag.rs, lower.rs) as live authority,
   flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass
   blocker classification to "provisional pending reproduction."

2. Update the Character-level row's phase-2 block to name that the
   specific shape of the CharClass failure needs concrete reproduction
   from the escalating sub-child before the blocker is finalized.

Recursive audit-pattern instance: the row I wrote to codify "verify
live state before claiming substrate gap" itself failed to verify live
state. Both incidents (2026-04-23 original row + 2026-04-24 my
retraction row) are now cited in the audit-pattern sub-note as
examples of the same discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33

Three substantive fixes addressing internal-consistency gaps in the cascade
promotion PR caught by codex review at sha 0d6e7c33:

1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane
   acceptance bullets and Hand-Rust census paragraph in line with the
   updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero
   (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is
   retracted under 0-floor with explicit migration to ExecuteCommand-based
   .dag TestClaim declarations.

2. docs/design-pure-bootstrap-zero.md promotion section — converted from
   future-tense ("This doc is PROPOSAL until promoted… promotion is a
   single Director-authored cascade PR…") to historical past-tense
   promotion-receipt framing ("This doc was PROPOSAL until promoted;
   promotion was a single Director-authored cascade PR that did all of the
   following atomically…"); blocking-clause struck through and resolved
   inline. Banner cites PR #782 explicitly.

3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_
   profile excluded (Map<String, AlgebraProfile> body, not list-of-sum;
   needs distinct ValueBody::Map substrate work, tracked separately as a
   future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass
   phase-2 + Engine sharpened-(b) pilot enumeration), both sharing
   list-of-sum substrate work. Lane table, dependency DAG, and capacity
   summary updated for consistency (slot count 9-13, was 10-14).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities

Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade
self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22
explicitly names THESIS.md and "any other authority docs" as required
retraction targets; the prior diff updated ROADMAP + r2-structure + design
docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting-
manager.md pointing at the now-SUPERSEDED ≤5-floor framing.

Files:

- THESIS.md (5 prose blocks updated):
  - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests
    migrate to ExecuteCommand-based .dag TestClaim declarations.
  - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag.
  - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor
    target citing design-pure-bootstrap-zero.md as live authority;
    hand_maintained_src list shrinks to empty set.
  - :301-318 — Tests-are-structural-data block: residual carve-out retracted;
    predicate name pb_rust_tests_outside_residual_zero retained as
    housekeeping (semantically the residual is empty under cascade).

- docs/thesis/compiler-std-consolidation.md (5 references):
  - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes
    design-pure-bootstrap.md (SUPERSEDED).
  - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process
    lane named as the dissolution trigger for bootstrap.rs itself.
  - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md.
  - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority
    re-cited.
  - :185 Related docs link.

- docs/briefs/r1-selfhosting-manager.md (active dispatch brief):
  - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5);
    T-PB-B residual carve-out retracted; predicate names retained for
    housekeeping; cascade-promoted authorities are source of truth.
  - Slice descriptions for T-PB-A / T-PB-B updated inline.
  - Framing-question + ask updated to 0-floor / no-residual framing.
  - Day-1 + up-to-director hand-off bullets updated.
  - Working-state checklist :111 ≤5 → 0 with cite.
  - Decisions log :164 ≤5 → 0-floor target updated.

- docs/r2-structure.md §2 design call (RETRACTED block):
  - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through
    in entirety (both Option A sharpen-and-keep and Option B rename are
    moot under 0-floor). Section preserved as audit-trail historical
    context.
  - Background-doc index: self-hosting anchor updated to
    design-pure-bootstrap-zero.md as live authority.

- docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per
  non-blocking suggestion):
  - Banner cites cascade promotion PR #782 explicitly.
  - New paragraph: "Treat all numeric floors below as retracted" with
    explicit lines named that quote in isolation (table row, body prose
    references). Prevents re-quoting from this doc as live authority.

Cascade is now atomically consistent across:
  THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔
  docs/thesis/compiler-std-consolidation.md ↔
  docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔
  docs/design-pure-bootstrap-zero.md (LIVE) ↔
  docs/design-pure-bootstrap.md (SUPERSEDED).

The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds
genuinely.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): correct ExecuteCommand runner-capability claim

Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation):
TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138
overstated live runner capability — claimed runner support landed in
PR #688/#741 with "emit Rust, invoke rustc on output, check exit code"
as a structurally-equivalent migration path. Verified against live
sources:

- src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema
  exists (declared via PR #678).
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5
  testgen harness allowlists ONLY `command == "true" && args.is_empty()
  && expect_exit == 0`.
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 —
  panics fail-closed on any other shape with explicit "ExecuteCommand
  shell shape is not supported here (runner-owned — do not treat as
  ordinary false)".
- src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no
  match arm for ExecuteCommand; falls through to ClaimResult::
  NotYetImplemented.

Reality: a TestClaim declaring rustc/python/go invocation is
structurally expressible as data today, but executing it is blocked.
Full arbitrary-command runner support is the PB-Runtime lane's
deliverable.

Files updated:

- TESTING.md:195 — capability state callout with file:line citations;
  "Full runner support — arbitrary command + args (rustc/python/go) with
  exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor
  program)." Bullet about migration shape preserved as the cascade-named
  successor pattern, not as a live capability.
- TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane
  lands the ExecuteCommand runner extension" as an explicit precondition.
- docs/design-pure-bootstrap-zero.md:138 — same correction for the
  matching prose, with PB-Runtime named as the runner-extension
  dependency for boundary-test migration.
- ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner
  foundation in #688/#741 with `true`-no-args allowlist only — full
  arbitrary-command runner support deferred to PB-Runtime lane,
  blocking the actual boundary-test migration." Dependencies column
  extended to "DB-15 + T-TestGen + PB-Runtime".

The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still
holds for atomic-cascade-across-authority-docs; this commit closes the
remaining capability/claim mismatch flagged by codex.

(Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still
SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief

Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation).
The prior banner contained:

> "Operationally R1 closure may still ship before the 0-floor is reached
>  — the ratchet ensures the trajectory; the gate's acceptance number is
>  what shifts."

This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0.
Two competing gate semantics in the cascade is exactly what the
atomic-cascade clause forbids.

Replaced with single-authority-honest framing:

> "R1 closure now requires the 0-floor target by gate semantics: T-PB-A
>  and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade
>  promotion changed their acceptance numbers to 0; R1 cannot close
>  while the SG-0 census carries non-zero hand-Rust."

Plus minor sharpening:
- "T-PB-A's non-test target is 0" → "non-test acceptance target is 0
  per ROADMAP.md:67" (cite the authority).
- T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep
  the capability-state honesty consistent with the recent fix wave.
- Predicate-rename housekeeping line moved into banner ("post-cascade
  housekeeping, not a pre-promotion blocker") — was implicit before.

The brief now genuinely inherits the cascade-promoted gate; no
competing release authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 second-wave worker-escalation fixes

Four substantive worker STOP-AND-ESCALATEs from briefs landed in
PR #797. All four worker recommendations correct; each needs a
Director call + brief update.

## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate

Worker correctly identified that brief req 2 (declared-effect carrier
as part of fn type signature, per feedback_no_annotations) requires
net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at
src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots.
Without parser surface, every user function would have
declared_effects = [] while inference returns non-empty — lens fires
EffectLeakageError everywhere on enable. Worker rejected power-through
and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map
parser split).

Director picked split:
- NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md
  Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface
  syntax + lookahead + body parser + lowerer extension + exhaustive-match
  audit + coproduct dissolution receipt.
- MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to
  post-parser-extension scope. Pre-flight check NOT a parser-extension
  step; STOP if parser sub-lane PR not merged.

## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping

Worker found load-bearing evidence at infer.rs:3693-3703: DB-11
deliberately strips refinements at operator dispatch as a designed-in
fix for symmetric-operators failure mode. Brief's "attach where b != 0
as a proof for a / b" directly contradicts this design choice. STOP-3
(where-clause conflict with DB-11) is real; STOP-1 (substrate scope)
needs net-new substrate (per-operator partiality fact + predicate-
entailment check + asymmetric per-operand refinement-honoring) — M+
minimum. ownership_lens precedent in original brief is post-hoc
observability, not proof carrier.

Worker recommended redirect to design/scoping per nested-optional
precedent. Director picked redirect.

Brief fully rewritten as design/scoping with four-question structure:
(1) DB-11 interaction analysis; (2) substrate proposal for proof-or-
totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes
with acceptance-theatre risk on user-defined-total-wrapper-only);
(4) Director-actionable recommendation. Output is doc PR.

## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C)

Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int)
with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136
closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b)
i128 implementation requires either path 1 (hierarchy refactor —
contradicts non-goal) or path 2 (regen lie between substrate and
emit — violates discipline). Worker leaned option (C) re-scope:
land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke)
to a sibling sub-lane that does proper Int128/Word128 substrate work.

Director picked option (C). Brief req 1 re-scoped to drop canonical-
carrier-widening; lane value comes from range facts + reconciliation
narrowing + out-of-range diagnostic against existing i64. Req 4
explicitly deferred with sibling-sub-lane reference. Sibling sub-lane
NOT to be authored or implied in this PR; tracked separately.

## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change)

Worker correctly STOP'd per the brief's own pre-flight check: parser
sub-lane has not landed; SurfaceExpr::Map not on main. Director
authorized cross-lane reassignment: wise-boar-480 takes the parser
sub-lane (t-substrate-valuebody-map-parser-worker.md) since they
already have full investigation context. No brief changes needed; the
routing decision is in the dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope

Resolves codex P2 inline at sha e35103fad on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer
carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still
required widening LiteralBits::Int(i64) to an unbounded carrier and
passing the i64::MIN smoke. Internally unsatisfiable.

Fix:

- Slice section retitled "range facts + reconciliation narrowing
  (against existing i64 carrier)" with explicit note about the
  re-scope.
- Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly
  forbids touching LiteralBits::Int shape, dag_scalar_generated.rs
  regen for that variant, or tokenize i64 parse path.
- Slice steps 2-5 reframed: range facts use i64-representable
  magnitudes; reconciliation narrowing uses existing i64 carrier;
  diagnostic only for i64-representable out-of-range; smoke tests
  for req 5 only (req 4 i64::MIN deferred).
- Acceptance checklist updated:
  - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as
    re-scoped/deferred.
  - LiteralBits::Int(i64) carrier untouched (no widening; no
    parallel; no shape change).
  - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference.
- STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the
  carrier" — explicit STOP if execution surfaces range-fact narrowing
  requiring carrier-widening; that's the boundary the re-scope drew;
  belongs in sibling Int128/Word128 sub-lane.

Brief now consistently treats carrier-widening as out-of-scope across
all sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty

Resolves codex BLOCKING #1 at sha e35103fa on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier
but req 2 required range facts using "the SAME magnitude carrier
as req 1" — meaning i64-typed range bounds. u64's max (2^64-1)
doesn't fit in i64; range fact for u64 would have to truncate,
omit, or mirror in Rust (representation drift). All three options
violate fail-closed declared-facts discipline (P1 / P3).

Fix:

- Req 2 rewritten to specify String-decimal representation:
  range_min_inclusive: String + range_max_inclusive: String fields
  on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127"
  for i8; "0"/"18446744073709551615" for u64).
- Explicit reasoning why String-decimal: u64's max doesn't fit in
  i64; binding range bounds to literal carrier forces truncation/
  omission/mirror-drift; all violate fail-closed declared-facts
  discipline.
- Bridge framing: String-decimal is pending the sibling Int128/
  Word128 sub-lane; both range bounds and literal payload migrate
  to typed carrier when that lands.

- Req 3 updated for String-decimal comparison semantics:
  reconciliation parses both bounds and literal magnitude into a
  common comparison space (i128 host comparison primitive — host
  narrowing, NOT carrier widening). Bounded by what the i64-typed
  literal can express; any i64-representable literal compares
  against any width's String-decimal bound. Carrier discipline
  preserved.

Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral)
is sha-stale — already resolved at 3e142d169.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed

Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback).
Real residual: req 2 specifies String-decimal range bounds (to cover
u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance
bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" /
"i64-representable magnitudes" for the range facts. Two incompatible
authorities for the same range-fact shape — would let a worker satisfy
the slice while truncating/omitting u64 bounds (P3 fail-closed
violation).

Fix:

- Line 31 (req 1 re-scope clarification): updated to explicitly state
  "range facts (req 2) use String-decimal representation (width-
  independent; covers u64::MAX which doesn't fit in i64)". Distinguished
  literal *payload* (stays i64) from range-bound *representation*
  (String) — both serve req 1's "no carrier widening" boundary.
- Line 44 (slice step 2): updated from "Range bounds use i64-
  representable magnitudes" to "Range bounds use String-decimal
  representation per req 2" with concrete example (u64 bounds).
- Acceptance bullet: updated from "Range facts on integer algebras
  (substrate-declared, not Rust-mirrored)" to add "using String-decimal
  representation ... width-independent; u64 bounds expressible without
  truncation."

The brief now consistently treats range bounds as String-decimal
across req 2, req 3, slice, acceptance, and the req 1 clarification —
no remaining authorities saying i64-typed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing

User + PM exchange 2026-04-25 surfaced that the in-flight effects
chain was importing wrong assumptions from external languages
(declared-effects-as-annotation + lens-vs-declaration check). Right
framing under gunbc's closed-system discipline is parallel to
complexity: every effect derives structurally from the composition
of typed primitive operations; nothing can hide because there's no
escape hatch; nothing needs annotation because the structure IS the
registry.

Four doc-only actions:

1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md.
   Frames the closed-system answer with PM's 5-behavior synergy
   table (Value/Transform/Branch/Loop/Bind as universal
   compositional-fold pattern). Four worked examples; aggressive
   reading on redundancy (compile-error-by-construction via
   referential-transparency proof; reread() primitive for legitimate
   cases); implementation-brief shape in §Q6.

2. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md.

3. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md.
   Notes Fn→Arrow refactor brief stays dispatchable as independent
   value.

4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by-
   construction framing replaces lens-detection framing.

Memory file feedback_closed_system_effects.md saved separately;
cross-link added to feedback_construction_over_ratchets.md.

Net cost: doc-level cleanup. Zero substrate code rework. Foundation
(OperationEffect + service-call infrastructure + 5-behavior
substrate) already exists.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect

Per PM convergence review on #808 + user's deeper 2026-04-25 framing:
the closed-system framing landed in #808 retired the user-facing
annotation but kept OperationEffect taxonomy as substrate-level tagging.
User's deeper framing: the taxonomy ITSELF is parallel-representation —
operations are intrinsically read-shaped or write-shaped via their
TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns-
derived-value-only → read). Tagging operations with Read | Upsert |
Create | Append | Delete names what the structure already says.

Three changes:

1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as
   normalized view, or retire as parallel-representation?"
   - Two paths: (i) tags derived from signature shape (acceptable
     normalized view) vs (ii) tags declared per-primitive (parallel-
     representation; retire).
   - Audit-as-existence-check (Q4 req 2 reframed): all effectful
     primitives derive cleanly from signature shape → path (i); any
     primitive needs hand-declared tag → path (ii) by existence proof.
   - Director default: path (ii). Logging primitives that return Unit
     are likely the audit's existence-proof.
   - Two design-question resolutions: (a) external effects not in
     return type → resource-threading discipline (typed param returned
     modified, IO-monad-without-the-monad pattern); (b) transactional
     grouping → derived structural fact from Bind composition + typed
     transaction primitives.

2. Q4 reqs revised: req 2 from "tag every primitive with explicit
   OperationEffect signature" to "audit-as-existence-check that every
   primitive's type signature derives the right effect classification";
   req 3 added (resource-threading discipline); req 6 added
   (transactional-pattern lens). Req 1 (effects lens) anchors on
   operation type-signature shape, not on hand-declared tags.

3. THESIS:345-347 amendment strengthened — "operations are
   intrinsically read-shaped or write-shaped via their type-signature
   shape; consumers walk the signatures directly; there is no parallel
   taxonomy or annotation layer to declare or maintain. Tracking
   effects as a separate enumerated concept IS the bug pattern,
   dissolved by construction." Plus references to resource-threading
   discipline + transactional grouping as derived structural fact.

Memory file feedback_closed_system_effects.md updated to reflect the
deeper framing (type-signature-shape, not taxonomy-tagging) +
resource-threading discipline section + transactional-patterns
section.

Net cost: doc-only delta on top of #808. Substrate retirement
(OperationEffect enum + derive_op_effect + idempotency.dag re-anchor)
deferred to the audit-as-existence-check phase of the implementation
brief; surfaced as Q5.5 OPEN CALL.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage

Resolves codex BLOCKING at sha d49ce79a on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real:
the prior text claimed service primitives "already carry typed effect
signatures" presenting future audit-state as current substrate fact
(P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the
OperationEffect line but left a parallel over-claim on the new
"signature-shape coverage" framing.

Fix: Q4 substrate-state listing rewritten to honestly distinguish:

- Live: Behavior enum + substrate foundation (the principle that
  operations should carry signature shape).
- Incomplete: signature-shape coverage across actual primitives.
  HTTP-derived primitives carry implicit shape via derive_op_effect's
  method-table; logging/mutation primitives that return Unit or don't
  thread their target resource do NOT carry the structural shape that
  would express read-vs-write. Achieving full coverage is required
  work under reqs 2 + 3, not a current fact.
- Pending audit-as-existence-check: OperationEffect + derive_op_effect
  (path (i) vs (ii) per Q5.5).

Honest live-state callout added explicitly: "the closed-system
FOUNDATION (5 behaviors + DAG substrate + the principle that
operations should carry signature-shape) is live. The IMPLEMENTATION
COVERAGE across all effectful primitives is partial. Req 2 + req 3
are the work that closes the gap."

Brief now distinguishes principle-is-live (foundation) from
coverage-is-partial (audit work) without conflating them.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim

Per PM follow-up review on #808 + user's stronger discipline framing
("substrate must make bypass structurally impossible at every layer
of the transport stack"): the closed-system claim is honest only when
typed primitives ARE the path. Today two structural holes exist where
bypasses sidestep the typed-primitive substrate. Both surfaced
explicitly as Q4.5 pre-conditions — load-bearing for the lens's
coverage claim.

Three changes:

1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed-
   system claim)" inserted between Q4 and Q5:

   P1 — Extdeps typed-primitive consumption structurally enforced.
   Substrate must make `messages: Json` impossible to declare in
   service definitions; typed `LlmMessage` / `ContentBlock` /
   `GitHubAuthToken`-with-full-scopes are the only path. Tracked
   debt at ROADMAP.md:153-154 (LLM provider flattening) +
   `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded).
   Required prereq for full lens coverage; lens can land first +
   surface structural-coverage-gap diagnostics on bypass surfaces
   so the gap becomes visible rather than silent.

   P2 — `ExecuteCommand` fully materialized as typed runner
   primitive. TESTING.md (post-#782) committed to 0-residual but
   ExecuteCommand isn't fully materialized; deleting Rust boundary
   tests creates verification gap. Already named under PB-Runtime
   in Zero-Floor; signal pending. Pre-requisite for ANY Rust
   boundary-test deletion.

2. Old leftover duplicate Q5 section deleted (artifact from prior
   Q5/Q5.5 reshape; second copy of asymmetric-tightening text was
   in the file alongside the earlier Q5 instance).

3. Worker-discretion-vs-Director-call section in Q4.5: lens
   implementation worker dispatchable now (reports gaps as
   findings); P1 closure is substantive substrate work touching
   extdeps (dedicated lane); P2 closure is PB-Runtime (signal
   pending).

Net: design doc now honestly distinguishes principle-is-live
(Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs
named explicitly). The closed-system claim has explicit pre-
conditions documented; implementation brief discovers them as
known dependencies, not as STOP-AND-ESCALATEs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default

Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two
real residuals after the Q5.5 reframe:

1. Q6's reqs/STOPs/acceptance still framed under path (i) — said
   "audit + tag std/ primitives — every effectful primitive carries
   an explicit OperationEffect signature." Directly contradicted Q4
   (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment
   ("there is no parallel taxonomy to declare or maintain"). Worker
   reading Q6 in isolation would author the retracted shape.

2. Capacity / sequencing table line about "audit lane (tag std/
   primitives with effect signatures)" carried the same stale
   framing.

3. Q6 STOP "primitive performing side effects without an
   OperationEffect tag" assumed tag-as-authority; under path (ii)
   the STOP shape is "primitive whose signature doesn't structurally
   reveal its effect."

Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale
(already fixed at f073aa95e Q4.5 commit).

## Q6 fixes

- Reqs renumbered + reframed:
  - Req 1 anchors on operation type-signature shape (not hand-declared
    OperationEffect tags); composition reads from signature shape per
    Q2 table.
  - Req 2 changed from "audit + tag every primitive" to
    "audit-as-existence-check" — verify signature-shape coverage; ANY
    primitive needing a hand-declared tag IS the existence-proof for
    path (ii) retirement.
  - Req 3 added: resource-threading discipline applied to existing
    primitives (logging that returns Unit gets reshaped per audit).
  - Req 6 added: transactional-pattern lens (Bind composition +
    Transaction → Transaction').
  - Req 7 added: asymmetric-tightening worked example in PR body
    (per claude review observation; the one place declaration-shaped
    surface re-enters).
  - Req 8 (was 5): tests now reference signature-shape derivation
    explicitly, not tag lookup.
- STOPs reframed:
  - "OperationEffect retirement decision" — audit produces path (i)
    vs (ii) verdict; substrate retirement is its own dedicated
    sub-lane; this lane does NOT absorb it.
  - Pure/impure carrier STOP notes that "pure" should also derive
    from signature shape (pure functions don't return modified
    resources) — so the STOP itself may dissolve under further design.
  - Q4.5 P1 explicitly NOT a STOP — lens reporting structural-
    coverage-gap on extdeps bypass surfaces is the lens delivering
    its foundation-gap-visibility value.
  - Q4.5 P2 explicitly independent — lens doesn't depend on
    ExecuteCommand materialization.
- Acceptance extended: lens reports gap diagnostics on P1 bypass
  surfaces; audit produces existence-proof verdict for Director
  re-decision; asymmetric-tightening worked example in PR body.

## Capacity / sequencing table

Replaced "1 audit lane (tag std/ primitives with effect signatures)"
with "1 audit-as-existence-check lane (verify primitives' signature-
shape coverage; NOT 'tag every primitive') — produces the path (i)
vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2
prereq lanes to the net summary. Closing line: "The taxonomy-
retirement scope (substrate-side) is not in this lane — it's
surfaced by audit and routed to dedicated retirement lane if path
(ii) wins."

Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity
table. Worker reading Q6 in isolation now sees path-(ii)-default
framing matching Q4 + Q5.5 + THESIS amendment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792

Resolves codex inline BLOCKING at sha 191be310 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150.
Real: my Q4.5 P2 framing described ExecuteCommand as still
NotYetImplemented (M1.5 allowlist + Rust TestRunner returning
NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand
extension before this PR's authoring. TESTING.md:195 capability-state
callout confirms:
- Rust TestRunner + M1.5 testgen harness share one std::process path
  for arbitrary command + args + expect_exit_code.
- M1.5 allowlist + fail-closed panic retired.
- Distinguishable ClaimResult::Fail messages for spawn / timeout /
  policy / exit-mismatch.
- Linux unshare(1) namespace isolation on host-allowing systems.
- T-PB-B-1 boundary migration example landed.

Fix:

P2 section rewritten:
- Header retitled "ExecuteCommand runner primitive: LANDED (PR #792);
  residual is bulk-migration."
- Status update naming PR #792 + the post-#792 capability state
  (allowlist retired, etc.).
- Honest acknowledgement: "My earlier P2 framing was stale."
- Residual narrowed to bulk-migration of existing Rust Command::new
  boundary tests (tracked as ROADMAP residual, not lens prereq).
- Sequencing reframed: P2 was always orthogonal to the effects lens
  itself; bulk migration proceeds at its own pace; lens not blocked.

Q4.5 footer updated:
- "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via
  #792; only consumer-side bulk migration remains)"
- Worker-discretion-vs-Director-call P2 line updated: "runner
  primitive landed; only consumer-side bulk migration remains;
  tracked as ROADMAP residual, independent of the lens."

Q6 STOP for P2 updated:
- "the lens itself doesn't depend on P2; only TESTING.md's 0-residual
  claim does" → "runner primitive landed via PR #792 (post-Q4.5-
  authoring update). The lens itself never depended on P2; bulk
  consumer migration is residual ROADMAP work and remains independent
  of this lane."

Brief now reflects live state. The closed-system claim's prereq
landscape is honest:
- P1 (extdeps typed-primitive consumption): real prereq, tracked
  debt at ROADMAP:153-154.
- P2 (ExecuteCommand runner): satisfied via #792; bulk migration is
  consumer-side residual, not foundation work.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale

Resolves codex non-blocking finding at sha bcac41bb on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real
residual: capacity-table line still listed P2 as "`ExecuteCommand`
materialization" prereq + framed both P1 and P2 as "pre-existing
tracked-debt" — but my prior 57a9b1318 fix established that PR #792
already landed the runner primitive, so P2 is no longer a
materialization prereq.

Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq)
from P2 (residual, not prereq):

  - P1: extdeps typed-primitive consumption — pre-existing tracked
    debt at ROADMAP:153-154; load-bearing for the lens's full-coverage
    claim.
  - P2: ExecuteCommand runner primitive landed via PR #792; only
    consumer-side bulk migration of existing Rust Command::new
    boundary tests remains (tracked as ROADMAP residual, independent
    of the lens; not a materialization prereq).

Brief now consistently treats P2 as bulk-migration-residual across:
- §Q4.5 P2 section header (LANDED via PR #792; residual is
  bulk-migration).
- §Q4.5 footer (P2: runner primitive landed; only consumer-side
  bulk migration remains).
- Q6 STOP for P2 (runner primitive landed; bulk migration is
  residual ROADMAP work).
- §Capacity / sequencing impact (P2 as residual, not prereq).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349

Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated
target-grounding prose; the matching extdeps typed-primitive bypass
entries (LLM service flattening, GitHub auth model bypass) live at
ROADMAP.md:348-349.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix third stale ROADMAP citation at line 271

Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence
at line 271 in the §Q4.5 capacity table. Now consistent with lines
139 and 173 (ROADMAP.md:348-349).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity

Codex flagged 'Effect-signature tagging on std/ primitives' as potentially
contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240)
already explicitly say 'NOT tag every primitive' — but the cross-manager
line used sloppy wording. Reworded to make explicit that the audit walks
signature shape; no parallel tag added.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5

- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)

B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).

B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — drop incoherent inner-fallback non-goal

Codex P2: the non-goal line excluding the inner declaration().name
unwrap_or_else fallback contradicted Slice step 2, which replaces the
whole chain with let-Some-else-return. Both fallbacks are in scope by
construction; remove the contradictory non-goal.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives

PM REQUEST_CHANGES: §Frame listed '4 type connectives
(Conjunction | Disjunction | Cardinality | Bit)' which contradicted
the canonical thesis source. Replaced with the canonical 6
(Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per
docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary
closes here'. Also removed 'typed substrate carriers' from the
vocabulary list — substrate carriers are defined using the vocabulary,
not part of it. Added a clarifying note that B4's carriers
(DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are
typed declarations composed from the vocabulary, not vocabulary
extensions.

Per feedback_verify_thesis_claims: brief framings citing thesis
structure must ground in the canonical source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority

Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of
naming the live substrate authority. Two coordinated fixes:

1. §Read first cites src/v3/std/substrate.dag (live .dag substrate
authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel
meta-type — already exists with consumers in verification.dag,
emit_model.dag, python.dag).

2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing
DeclarationRef'. The work is consumer migration + any role-extension
layer the audit reveals, NOT designing or landing the carrier.

Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers)
keep their 'new' framing but explicitly require sub-briefs to grep
src/v3/std/ + src/v3/spec/ for existing authority before authoring
'design and land' framing — per feedback_verify_thesis_claims +
feedback_emitter_workaround_is_gap_symptom.

Acceptance + sub-brief dispatch order updated to reflect B4.1's
consumer-migration shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — tighten Phase 1 umbrella sentence

The umbrella 'Land the typed carriers into src/v3/std/' framing was
stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced
with audit-first wording that covers both the consume-existing case (#1)
and the design-and-land case (#2-#4 if their audits show real gaps).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording

Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands'
which conflicted with the post-reframe reality that B4.1 consumes the
existing DeclarationRef. Updated to 'consumes or lands' with explicit
existing-authority citation and audit-pending caveat for B4.2-B4.4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — soften regression-test requirement (3 worker bounces)

Three consecutive B1 worker dispatches (zesty-crane-890 cursor →
valiant-boar-498 codex → cool-lynx-395 cursor) archived without
opening a PR. Likely friction point: brief Slice step 4 asks for a
unit test that constructs a Dag with an orphan variant declaration,
but emit.rs has zero existing #[test] precedent — emit testing
happens via integration fixtures. Workers see 'build novel test
harness' inside what's billed as an S-scope fix and bounce.

Per feedback_construction_over_ratchets: when a brief has friction,
fix the brief, don't ratchet the worker.

Softened step 4 + acceptance: regression test stays optional. If
test setup requires novel scaffolding, route the gap to follow-up.
The structural fail-closed at step 2 is the load-bearing change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt

PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description'
is too weak; PR descriptions don't survive squash-merge cleanly.

Two coordinated edits:
1. Slice step 4 — explicit substrate-signal framing: skipped test
   means emit-side hermetic-unit-test infrastructure is the missing
   substrate (feedback_emitter_workaround_is_gap_symptom).
2. Acceptance — require ROADMAP debt row (new or existing) with
   named dissolution trigger, referenced in PR body. Converts the
   skip from PR-local note (transient) into tracked debt (durable,
   dispatchable).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124

Codex BLOCKING: my earlier softening claimed emit.rs had no #[test]
precedent — wrong. The module has #[cfg(test)] mod tests at line 3124
with 12+ tests using compile_to_dag(source, filename) as harness
(e.g., go_struct_fields_render_with_separators :3143,
shared_walk_to_disj_finds_match_scrutinee_sum_type :3195).

This is a feedback_verify_thesis_claims violation on Director-side
brief authoring — claim made without grep verification.

Fix: restore step 4 as required, with explicit precedent citation.
Worker constructs the failure case via the existing harness
(direct Dag, fixture string, or BranchPattern exercise; worker's
call on cleanest path). STOP-AND-ESCALATE only if construction
proves materially harder than precedent suggests, in which case
that escalation surfaces a real substrate gap and warrants ROADMAP
debt — but the default is 'add the test.'

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites)

Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but
emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded
to 'several using compile_to_dag'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue

Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this
is Wave 1 of Director's 14-brief authoring queue, covering B4 program
internals.

Authored:
- b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) —
  replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag")
  fold-skip with structural template-formal carrier; mandatory
  authority audit per feedback_audit_adjacent_authority_first.
- b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) —
  replaces §0.6 emit.rs bind/branch.span.file equality with typed
  BindEmitParticipation/BranchEmitParticipation roles populated at
  lowering; aligned with #824 worker's in-flight implementation shape.
- b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4
  of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with
  typed substrate authority; explicit pre-promotion-constraint
  disposition (single-authority vs authority+tracked-debt) addresses
  parallel-representation risk surfaced on #825.
- b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) —
  names B4.5-B4.12 Phase 2 sites with carrier dependencies,
  cross-program coordination notes, and skeleton-brief template;
  full per-site briefs author at dispatch time per #827's
  Substrate Manager ownership.

Cross-cutting discipline applied per inbox #828 reply:
- feedback_audit_adjacent_authority_first (mandatory grep before design)
- feedback_no_textual_enforcement_bridges (no replacement sentinels)
- feedback_parallel_representation_debt (explicit if shape (b))
- feedback_construction_over_ratchets (no parity-by-runtime as primary)
- feedback_coproduct_dissolution (receipts for new variants)

Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling
worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3)

Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue.
Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by
Modeling Manager's Wave 3 worker briefs (gated on these landing).

Authored:
- r2-substrate-cardinality-for-int-lit-subset.md (M) — produces
  magnitude carrier consumed by T-Modeling int-lit. Coordinates with
  PR #806's prior cardinality work; mandatory authority audit guards
  against #796's rejected IntLiteralMagnitude shape resurfacing.
  Open design questions: magnitude representation, reconciliation
  narrowing point, i64::MIN representability.
- r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces
  nominal-opacity carrier consumed by T-Modeling Secret<T>. Open
  design questions: carrier shape (flag/connective/sealed-accessor),
  generic-walk discipline, accessor gating.
- r2-substrate-parametric-algebra-for-dimensions-subset.md (M) —
  produces phantom-parameter carrier consumed by T-Modeling
  Dimension<Carrier>. Open design questions: carrier shape,
  type-equivalence rule, algebra-method dispatch, lifting/coercion.

All three:
- Scoped narrowly to their paired R2 consumer; not full
  substrate-capability lanes.
- Mandatory pre-author authority audit per
  feedback_audit_adjacent_authority_first.
- Cross-program readiness signal pattern from #827's manager rework.
- Coproduct dissolution receipts required for any new variants.
- Open design questions surfaced explicitly so Substrate Manager
  (or Director pre-spin-up) can resolve at dispatch time.

Wave 3 (T-Modeling worker briefs × 4) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4)

Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue.
Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each
gated on a Substrate Manager readiness signal (Wave 2 producers).

Authored:
- r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2
  cardinality-for-int-lit; moves narrowing from tokenizer to
  reconciliation; MagnitudeOutOfRange diagnostic per C-8.
- r2-modeling-secret-graduation-worker.md — gated on Wave 2
  nominal-opaque-for-Secret; authors Secret<T> + gated accessors
  (redact, compare_in_constant_time); C-8 diagnostic on non-gated
  access; signals Impossible-Bugs Manager on close (thesis claim
  covered).
- r2-modeling-dimensions-phantom-worker.md — gated on Wave 2
  parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier>
  + core SI base units + algebra-method dispatch; cross-dimension
  arithmetic produces typed diagnostic; signals Impossible-Bugs
  Manager (thesis claim).
- r2-modeling-tokenizer-charclass-phase2-worker.md — gated on
  T-Substrate ValueBody-list/sum (#790); migrates tokenizer
  consumers to Char/List<Char>/CharClass canonical types; sibling
  consumer to Grounding Manager's Engine sharpened-(b).

All four:
- Explicit gating: 'do not dispatch until producer signal posts.'
- Producer/consumer signal pattern from #827.
- Cross-program signals to R2 Release Manager (Goal 2 closure)
  and Impossible-Bugs Manager (thesis-claim coverage).
- Spoofing regression tests: discipline anchor against
  feedback_no_textual_enforcement_bridges.

Wave 4 (T-ImpossibleBugs worker briefs × 3) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3)

Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue.
Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes,
consuming the existing design/scoping briefs as authority.

Authored:
- r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on
  cardinality refinement substrate (T-Substrate territory adjacent
  to int-lit / DB-11 alias-where). Implementation: structural normalize
  of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T??
  worker decision (reject vs normalize). Cites
  t-impossiblebugs-nested-optional-flatten-design.md as authority.
- r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated
  on Tier 2 substrate (predicate-entailment infrastructure; distinct
  from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes
  predicate entailment, (b) feedback_totality_by_omission dissolves
  partial primitives, (c) park. Worker decides at audit time. Cites
  t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority.
- r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate
  prerequisite per closed-system framing in design doc (#808). Audit-
  as-existence-check + lens implementation as compositional fold over
  5 behaviors; redundancy detection compile-error via referential
  transparency + reread() escape hatch; path (i/ii) decision on
  OperationEffect taxonomy retain-vs-retire (default retire). Cites
  design doc #808 as authority.

Cross-cutting:
- Each cites prior design/scoping brief as authority (the existing
  *-design.md / *-worker.md REFRAMED files).
- Explicit gating per #827 producer/consumer signal pattern; two
  briefs gated on substrate, one NOT gated (closed-system).
- STOP-AND-ESCALATE includes 'design brief assumptions don't hold'
  surfacing per feedback_thesis_gate_state_drift.

Wave 4 complete. Director's 14-brief queue done; awaiting PM portion
(6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4.4 — tighten Slice §3 per PM review on #836

PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b)
(authority + tracked debt parallel-rep) as autonomously acceptable
contradicts feedback_construction_over_ratchets +
feedback_parallel_representation_debt.

Tightened:
- Shape (a) is the only autonomous worker path.
- Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a
  regen-host-loader sub-lane decision; not authorable without explicit
  Substrate Manager approval citation in the PR body.
- Acceptance bullet requires the approval citation when shape (b)
  lands.
- STOP-AND-ESCALATE rephrased to make this explicit; permanent
  parallel-representation re-escalates even with manager approval.

This preserves shape (a) as autonomous; shape (b) becomes a
cross-manager design escalation, not a B4.4 implementation call.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief

Cursor review on #836 flagged the Read-first reference to
.claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md
as machine-specific (outside the repo, not resolvable from a normal
clone). Replaced with in-repo prose pointing at the design doc's
§Q1-Q3 as canonical authority — the discipline lives there in-repo.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs)

Codex flagged: src/v3/std/types.dag does not exist; the canonical
authority is at dsl/std/types.dag. Affected briefs (all from R2
spin-up Wave 2 + Wave 3):

- r2-substrate-cardinality-for-int-lit-subset.md
- r2-substrate-nominal-opaque-for-secret-subset.md
- r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs)
- r2-modeling-dimensions-phantom-worker.md
- r2-modeling-secret-graduation-worker.md

feedback_verify_thesis_claims violation on Director-side brief
authoring — assumed path without grep. Same family of error as
the earlier emit.rs precedent claim. Mass-replaced via perl;
verified no remaining stale refs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant

Codex BLOCKING on #836: my R2 worker brief gated nested-optional on
cardinality refinement substrate, but the design doc verifies v3 is
ALREADY past the cardinality bridge — TypeConnective::Cardinality
is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is
the carrier for Option. The dissolution is an UNGATED implementation
via substrate-constructor invariant.

feedback_verify_thesis_claims violation again — should have read the
design doc fully before assuming the substrate gate.

Rewrote brief to match design doc canonical sketch:
- Single predicate (cardinality_idempotent_target) owns the rule
- Single allocator (alloc_cardinality_decl) is THE substrate-constructor
- API closure on TypeConnective::Cardinality payload (modeling-discipline
  practice 6) — variant cannot be struct-init'd outside the allocator
- 3 hand-Rust + ~22 codegen call sites enumerated per design audit
- infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as
  the killer case for generic-instantiation paths
- Surface-syntax T?? decision left to worker (Director-lean: silent
  normalize)

Brief now dispatchable immediately, no producer signal needed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation

Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment
substrate path, but the design doc §4 explicitly recommends totality-by-
omission as the Director-actionable path. Predicate-entailment is M+ scope
that reopens DB-11's explicitly-closed asymmetric-strip design — design
doc explicitly discards it.

feedback_verify_thesis_claims violation again — same family as nested-
optional reframe. Should have read design doc §4 in full before assuming
the path ordering.

Rewrote brief to match design doc §4 follow-on shape:
- Primary path: per-class totality-by-omission (algebra retype + per-
  target realization migration). For Int/Int: OrderedRing.div retype
  at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 /
  python:486 + python_target.rs:680 helper).
- NOT predicate-entailment (out of scope; M+ + DB-11 reopen).
- NOT NonZero-typed-input (deferred to separate per-operand-variance
  substrate brief; STOP-AND-ESCALATE if chosen).
- Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i]
  indexing, quotient, remainder) queue separately per design doc audit.
- feedback_totality_by_omission discipline anchor explicit.

Brief now matches feedback_totality_by_omission discipline + design doc
recommendation. No substrate prerequisite; dispatchable immediately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure

Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a
pattern: I authored R2 worker briefs without fully reading each design
doc's Director-actionable recommendation. Pre-emptively re-verified
unenumerated-effects against design doc §Q6 to catch the same family
of error before reviewers do.

Findings: brief was substantively close but missing 3 of 8 design-doc
reqs:
- Req 3: Resource-threading discipline applied to existing primitives
- Req 5: reread(key) primitive in std/ as explicit Slice item (was
  only mentioned in tests)
- Req 7: Asymmetric-tightening worked example in PR body

Plus: Slice didn't cite the canonical lens path
src/v3/lenses/effect_enumeration.dag from design doc.

Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6
specifies 4 specific STOPs (path-decision-escalation, pure: Bool
carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP)
that I had elided.

Reframed Slice as 8 numbered reqs matching design doc verbatim;
STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs;
Acceptance enumerated per req.

This is the third reframe in the unhandled-bugs series — same
feedback_verify_thesis_claims violation each time. The pattern
suggests Director-side R2 brief authoring should ALWAYS read each
design doc's §Director-actionable / §Q-recommendation in full first,
not assume.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options

Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)"
listed as a worker-pick option violates THESIS.md substrate-shape
lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality |
Instantiation) are canonical (per #811 thesis additions and #827 PM
review); a 7th is a C1 stop signal requiring failed-dissolution
evidence + Director substrate-design call, not autonomous worker pick.

Removed the "new TypeConnective variant" option; replaced with
`inhabits`-edge-shape carrier as third option (audit-time check). The
explicit STOP-AND-ESCALATE clause now states: 7th connective is the
precondition for failed-dissolution-evidence + Director substrate-design
call, not a worker path.

feedback_verify_thesis_claims still in play — should have grounded
substrate-shape options against the THESIS lock before listing Opaque(T)
as worker-autonomous. Pattern continues; reading source-of-truth before
authoring options is the discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place)

Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter
already exist at dag.rs:186, :217 — explicitly authored for the
R2 Dimensions consumer per the doc comment at dag.rs:148-160.
phantom_unit_mismatch already wired at infer.rs:1057, :1132. The
substrate is fully landed; my brief framing it as 'producer sub-lane
to land carrier' is wrong on the same feedback_audit_adjacent_authority_first
violation that hit nested-optional / unhandled-diagnostic / unenumerated-
effects.

Reframed the substrate-side brief as no-op / closed-by-audit:
- Documents the audit receipt (5 sites confirming substrate exists)
- States the lane is closed
- Routes T-Modeling Dimensions consumer to dispatch immediately
  against the existing carrier
- Records the lesson: 'always grep substrate before authoring
  producer briefs' — discipline doesn't end at brief boundaries.

Updated r2-modeling-dimensions-phantom-worker.md correspondingly:
- Changed gating from 'do not dispatch until producer signal' to
  'NOT GATED — dispatch immediately'
- Read-first updated with concrete dag.rs/infer.rs cites
- Slice §1 changed from 'confirm producer signal' to 'verify
  substrate at HEAD'
- STOP reframed: existing carrier extension would need Substrate
  Manager call, not autonomous worker pick

Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit
both verified — no existing substrate (no is_nominal_opaque /
MagnitudeBound patterns in dag.rs); both still legitimately
producer-side work.

Pattern is now four reframes deep on the R2 spin-up wave. The lesson
saved is structural: read source-of-truth before authoring options.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority

Codex BLOCKING on #836: my new R2 spin-up brief duplicates the
existing t-substrate-cardinality-int-lit-worker.md, which carries
the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64)
stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane).
Single-authority violation per INVARIANTS P2.

Same feedback_audit_adjacent_authority_first failure as parametric-
algebra-for-Dimensions reframe (4 hours ago): assumed substrate
authority didn't exist; should have grepped docs/briefs/ before
authoring. This is the SECOND R2 spin-up substrate brief closed
as redundant — the discipline lesson is structural.

Reframed brief as no-op routing doc (documents the audit receipt;
routes consumers to the existing authority); updated
r2-modeling-int-lit-magnitude-worker.md to cite
t-substrate-cardinality-int-lit-worker.md instead.

Pattern across the R2 spin-up wave reframes (5 now):
1. nested-optional gating-on-substrate (substrate already past
   cardinality bridge)
2. unhandled-diagnostic predicate-entailment default (design doc
   recommends totality-by-omission)
3. unenumerated-effects 8-req design-doc elision
4. parametric-algebra Producer (Declaration.phantom_params already
   authored explicitly for this consumer)
5. cardinality-for-int-lit Producer (existing brief is authority)

All five are 'assumed state without grep before authoring'. Future
R2 subs…
briansrls added a commit that referenced this pull request Apr 29, 2026
…+ reflection completeness + Q6.5 two-layer diagnostic-kind) (#1129)

* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation)

Director-authored amendment following the 2026-04-24 escalation from PR
#693 (sub-child sharp-bear-829 under Surface Manager).

Two edits:

1. New "Class 5 Gap 3 — port-carried field values in data bodies"
   row in the 2026-04-21 post-merge-debt section. The substrate gap was
   documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP
   ledger row for cross-lane visibility. PR #693's execution surfaced it
   as the blocker on sub_charclass_in_std_unicode phase-2.

2. Retract the "ready-to-dispatch (no substrate capability gap)" claim
   on the Character-level row, annotate phase-1 landed via PR #693
   (CharClass vocabulary + Rust-mirror structural scanner path), and
   point phase-2 at the new Class 5 Gap 3 row.

Codifies the audit pattern: "this consumption gap has no substrate
capability gap" claims must be verified by attempting the retype before
the claim lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main

* docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review)

* docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review)

Row title still said 'consumption gap, not substrate gap' while the
body block retracted that claim and cited Class 5 Gap 3 as a substrate
dependency for phase-2. Title now matches body: mixed classification,
consumption for steps 1+3, substrate for step 2.

* docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit)

gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining
gap" description was wrong: field-level shapes (nested records, list
literals, declaration refs, Var refs, sum-variant literals) are
supported today via FieldValue variants + lower_structural_field_value
(dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the
top-level ValueBody boundary (non-scalar, non-record top-level bodies).

The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself
stale: it describes the pre-PR-B-unwind shape where FieldValue was
LiteralBits-only. PR-B's unwind extended FieldValue to carry
Reference / Record / List / Variant, moving the gap to ValueBody.

Two fixes:

1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody
   boundary, point at code paths (dag.rs, lower.rs) as live authority,
   flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass
   blocker classification to "provisional pending reproduction."

2. Update the Character-level row's phase-2 block to name that the
   specific shape of the CharClass failure needs concrete reproduction
   from the escalating sub-child before the blocker is finalized.

Recursive audit-pattern instance: the row I wrote to codify "verify
live state before claiming substrate gap" itself failed to verify live
state. Both incidents (2026-04-23 original row + 2026-04-24 my
retraction row) are now cited in the audit-pattern sub-note as
examples of the same discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33

Three substantive fixes addressing internal-consistency gaps in the cascade
promotion PR caught by codex review at sha 0d6e7c33:

1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane
   acceptance bullets and Hand-Rust census paragraph in line with the
   updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero
   (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is
   retracted under 0-floor with explicit migration to ExecuteCommand-based
   .dag TestClaim declarations.

2. docs/design-pure-bootstrap-zero.md promotion section — converted from
   future-tense ("This doc is PROPOSAL until promoted… promotion is a
   single Director-authored cascade PR…") to historical past-tense
   promotion-receipt framing ("This doc was PROPOSAL until promoted;
   promotion was a single Director-authored cascade PR that did all of the
   following atomically…"); blocking-clause struck through and resolved
   inline. Banner cites PR #782 explicitly.

3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_
   profile excluded (Map<String, AlgebraProfile> body, not list-of-sum;
   needs distinct ValueBody::Map substrate work, tracked separately as a
   future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass
   phase-2 + Engine sharpened-(b) pilot enumeration), both sharing
   list-of-sum substrate work. Lane table, dependency DAG, and capacity
   summary updated for consistency (slot count 9-13, was 10-14).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities

Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade
self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22
explicitly names THESIS.md and "any other authority docs" as required
retraction targets; the prior diff updated ROADMAP + r2-structure + design
docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting-
manager.md pointing at the now-SUPERSEDED ≤5-floor framing.

Files:

- THESIS.md (5 prose blocks updated):
  - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests
    migrate to ExecuteCommand-based .dag TestClaim declarations.
  - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag.
  - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor
    target citing design-pure-bootstrap-zero.md as live authority;
    hand_maintained_src list shrinks to empty set.
  - :301-318 — Tests-are-structural-data block: residual carve-out retracted;
    predicate name pb_rust_tests_outside_residual_zero retained as
    housekeeping (semantically the residual is empty under cascade).

- docs/thesis/compiler-std-consolidation.md (5 references):
  - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes
    design-pure-bootstrap.md (SUPERSEDED).
  - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process
    lane named as the dissolution trigger for bootstrap.rs itself.
  - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md.
  - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority
    re-cited.
  - :185 Related docs link.

- docs/briefs/r1-selfhosting-manager.md (active dispatch brief):
  - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5);
    T-PB-B residual carve-out retracted; predicate names retained for
    housekeeping; cascade-promoted authorities are source of truth.
  - Slice descriptions for T-PB-A / T-PB-B updated inline.
  - Framing-question + ask updated to 0-floor / no-residual framing.
  - Day-1 + up-to-director hand-off bullets updated.
  - Working-state checklist :111 ≤5 → 0 with cite.
  - Decisions log :164 ≤5 → 0-floor target updated.

- docs/r2-structure.md §2 design call (RETRACTED block):
  - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through
    in entirety (both Option A sharpen-and-keep and Option B rename are
    moot under 0-floor). Section preserved as audit-trail historical
    context.
  - Background-doc index: self-hosting anchor updated to
    design-pure-bootstrap-zero.md as live authority.

- docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per
  non-blocking suggestion):
  - Banner cites cascade promotion PR #782 explicitly.
  - New paragraph: "Treat all numeric floors below as retracted" with
    explicit lines named that quote in isolation (table row, body prose
    references). Prevents re-quoting from this doc as live authority.

Cascade is now atomically consistent across:
  THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔
  docs/thesis/compiler-std-consolidation.md ↔
  docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔
  docs/design-pure-bootstrap-zero.md (LIVE) ↔
  docs/design-pure-bootstrap.md (SUPERSEDED).

The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds
genuinely.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): correct ExecuteCommand runner-capability claim

Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation):
TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138
overstated live runner capability — claimed runner support landed in
PR #688/#741 with "emit Rust, invoke rustc on output, check exit code"
as a structurally-equivalent migration path. Verified against live
sources:

- src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema
  exists (declared via PR #678).
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5
  testgen harness allowlists ONLY `command == "true" && args.is_empty()
  && expect_exit == 0`.
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 —
  panics fail-closed on any other shape with explicit "ExecuteCommand
  shell shape is not supported here (runner-owned — do not treat as
  ordinary false)".
- src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no
  match arm for ExecuteCommand; falls through to ClaimResult::
  NotYetImplemented.

Reality: a TestClaim declaring rustc/python/go invocation is
structurally expressible as data today, but executing it is blocked.
Full arbitrary-command runner support is the PB-Runtime lane's
deliverable.

Files updated:

- TESTING.md:195 — capability state callout with file:line citations;
  "Full runner support — arbitrary command + args (rustc/python/go) with
  exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor
  program)." Bullet about migration shape preserved as the cascade-named
  successor pattern, not as a live capability.
- TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane
  lands the ExecuteCommand runner extension" as an explicit precondition.
- docs/design-pure-bootstrap-zero.md:138 — same correction for the
  matching prose, with PB-Runtime named as the runner-extension
  dependency for boundary-test migration.
- ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner
  foundation in #688/#741 with `true`-no-args allowlist only — full
  arbitrary-command runner support deferred to PB-Runtime lane,
  blocking the actual boundary-test migration." Dependencies column
  extended to "DB-15 + T-TestGen + PB-Runtime".

The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still
holds for atomic-cascade-across-authority-docs; this commit closes the
remaining capability/claim mismatch flagged by codex.

(Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still
SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief

Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation).
The prior banner contained:

> "Operationally R1 closure may still ship before the 0-floor is reached
>  — the ratchet ensures the trajectory; the gate's acceptance number is
>  what shifts."

This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0.
Two competing gate semantics in the cascade is exactly what the
atomic-cascade clause forbids.

Replaced with single-authority-honest framing:

> "R1 closure now requires the 0-floor target by gate semantics: T-PB-A
>  and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade
>  promotion changed their acceptance numbers to 0; R1 cannot close
>  while the SG-0 census carries non-zero hand-Rust."

Plus minor sharpening:
- "T-PB-A's non-test target is 0" → "non-test acceptance target is 0
  per ROADMAP.md:67" (cite the authority).
- T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep
  the capability-state honesty consistent with the recent fix wave.
- Predicate-rename housekeeping line moved into banner ("post-cascade
  housekeeping, not a pre-promotion blocker") — was implicit before.

The brief now genuinely inherits the cascade-promoted gate; no
competing release authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 second-wave worker-escalation fixes

Four substantive worker STOP-AND-ESCALATEs from briefs landed in
PR #797. All four worker recommendations correct; each needs a
Director call + brief update.

## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate

Worker correctly identified that brief req 2 (declared-effect carrier
as part of fn type signature, per feedback_no_annotations) requires
net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at
src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots.
Without parser surface, every user function would have
declared_effects = [] while inference returns non-empty — lens fires
EffectLeakageError everywhere on enable. Worker rejected power-through
and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map
parser split).

Director picked split:
- NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md
  Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface
  syntax + lookahead + body parser + lowerer extension + exhaustive-match
  audit + coproduct dissolution receipt.
- MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to
  post-parser-extension scope. Pre-flight check NOT a parser-extension
  step; STOP if parser sub-lane PR not merged.

## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping

Worker found load-bearing evidence at infer.rs:3693-3703: DB-11
deliberately strips refinements at operator dispatch as a designed-in
fix for symmetric-operators failure mode. Brief's "attach where b != 0
as a proof for a / b" directly contradicts this design choice. STOP-3
(where-clause conflict with DB-11) is real; STOP-1 (substrate scope)
needs net-new substrate (per-operator partiality fact + predicate-
entailment check + asymmetric per-operand refinement-honoring) — M+
minimum. ownership_lens precedent in original brief is post-hoc
observability, not proof carrier.

Worker recommended redirect to design/scoping per nested-optional
precedent. Director picked redirect.

Brief fully rewritten as design/scoping with four-question structure:
(1) DB-11 interaction analysis; (2) substrate proposal for proof-or-
totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes
with acceptance-theatre risk on user-defined-total-wrapper-only);
(4) Director-actionable recommendation. Output is doc PR.

## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C)

Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int)
with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136
closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b)
i128 implementation requires either path 1 (hierarchy refactor —
contradicts non-goal) or path 2 (regen lie between substrate and
emit — violates discipline). Worker leaned option (C) re-scope:
land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke)
to a sibling sub-lane that does proper Int128/Word128 substrate work.

Director picked option (C). Brief req 1 re-scoped to drop canonical-
carrier-widening; lane value comes from range facts + reconciliation
narrowing + out-of-range diagnostic against existing i64. Req 4
explicitly deferred with sibling-sub-lane reference. Sibling sub-lane
NOT to be authored or implied in this PR; tracked separately.

## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change)

Worker correctly STOP'd per the brief's own pre-flight check: parser
sub-lane has not landed; SurfaceExpr::Map not on main. Director
authorized cross-lane reassignment: wise-boar-480 takes the parser
sub-lane (t-substrate-valuebody-map-parser-worker.md) since they
already have full investigation context. No brief changes needed; the
routing decision is in the dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope

Resolves codex P2 inline at sha e35103fad on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer
carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still
required widening LiteralBits::Int(i64) to an unbounded carrier and
passing the i64::MIN smoke. Internally unsatisfiable.

Fix:

- Slice section retitled "range facts + reconciliation narrowing
  (against existing i64 carrier)" with explicit note about the
  re-scope.
- Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly
  forbids touching LiteralBits::Int shape, dag_scalar_generated.rs
  regen for that variant, or tokenize i64 parse path.
- Slice steps 2-5 reframed: range facts use i64-representable
  magnitudes; reconciliation narrowing uses existing i64 carrier;
  diagnostic only for i64-representable out-of-range; smoke tests
  for req 5 only (req 4 i64::MIN deferred).
- Acceptance checklist updated:
  - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as
    re-scoped/deferred.
  - LiteralBits::Int(i64) carrier untouched (no widening; no
    parallel; no shape change).
  - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference.
- STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the
  carrier" — explicit STOP if execution surfaces range-fact narrowing
  requiring carrier-widening; that's the boundary the re-scope drew;
  belongs in sibling Int128/Word128 sub-lane.

Brief now consistently treats carrier-widening as out-of-scope across
all sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty

Resolves codex BLOCKING #1 at sha e35103fa on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier
but req 2 required range facts using "the SAME magnitude carrier
as req 1" — meaning i64-typed range bounds. u64's max (2^64-1)
doesn't fit in i64; range fact for u64 would have to truncate,
omit, or mirror in Rust (representation drift). All three options
violate fail-closed declared-facts discipline (P1 / P3).

Fix:

- Req 2 rewritten to specify String-decimal representation:
  range_min_inclusive: String + range_max_inclusive: String fields
  on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127"
  for i8; "0"/"18446744073709551615" for u64).
- Explicit reasoning why String-decimal: u64's max doesn't fit in
  i64; binding range bounds to literal carrier forces truncation/
  omission/mirror-drift; all violate fail-closed declared-facts
  discipline.
- Bridge framing: String-decimal is pending the sibling Int128/
  Word128 sub-lane; both range bounds and literal payload migrate
  to typed carrier when that lands.

- Req 3 updated for String-decimal comparison semantics:
  reconciliation parses both bounds and literal magnitude into a
  common comparison space (i128 host comparison primitive — host
  narrowing, NOT carrier widening). Bounded by what the i64-typed
  literal can express; any i64-representable literal compares
  against any width's String-decimal bound. Carrier discipline
  preserved.

Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral)
is sha-stale — already resolved at 3e142d169.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed

Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback).
Real residual: req 2 specifies String-decimal range bounds (to cover
u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance
bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" /
"i64-representable magnitudes" for the range facts. Two incompatible
authorities for the same range-fact shape — would let a worker satisfy
the slice while truncating/omitting u64 bounds (P3 fail-closed
violation).

Fix:

- Line 31 (req 1 re-scope clarification): updated to explicitly state
  "range facts (req 2) use String-decimal representation (width-
  independent; covers u64::MAX which doesn't fit in i64)". Distinguished
  literal *payload* (stays i64) from range-bound *representation*
  (String) — both serve req 1's "no carrier widening" boundary.
- Line 44 (slice step 2): updated from "Range bounds use i64-
  representable magnitudes" to "Range bounds use String-decimal
  representation per req 2" with concrete example (u64 bounds).
- Acceptance bullet: updated from "Range facts on integer algebras
  (substrate-declared, not Rust-mirrored)" to add "using String-decimal
  representation ... width-independent; u64 bounds expressible without
  truncation."

The brief now consistently treats range bounds as String-decimal
across req 2, req 3, slice, acceptance, and the req 1 clarification —
no remaining authorities saying i64-typed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing

User + PM exchange 2026-04-25 surfaced that the in-flight effects
chain was importing wrong assumptions from external languages
(declared-effects-as-annotation + lens-vs-declaration check). Right
framing under gunbc's closed-system discipline is parallel to
complexity: every effect derives structurally from the composition
of typed primitive operations; nothing can hide because there's no
escape hatch; nothing needs annotation because the structure IS the
registry.

Four doc-only actions:

1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md.
   Frames the closed-system answer with PM's 5-behavior synergy
   table (Value/Transform/Branch/Loop/Bind as universal
   compositional-fold pattern). Four worked examples; aggressive
   reading on redundancy (compile-error-by-construction via
   referential-transparency proof; reread() primitive for legitimate
   cases); implementation-brief shape in §Q6.

2. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md.

3. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md.
   Notes Fn→Arrow refactor brief stays dispatchable as independent
   value.

4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by-
   construction framing replaces lens-detection framing.

Memory file feedback_closed_system_effects.md saved separately;
cross-link added to feedback_construction_over_ratchets.md.

Net cost: doc-level cleanup. Zero substrate code rework. Foundation
(OperationEffect + service-call infrastructure + 5-behavior
substrate) already exists.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect

Per PM convergence review on #808 + user's deeper 2026-04-25 framing:
the closed-system framing landed in #808 retired the user-facing
annotation but kept OperationEffect taxonomy as substrate-level tagging.
User's deeper framing: the taxonomy ITSELF is parallel-representation —
operations are intrinsically read-shaped or write-shaped via their
TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns-
derived-value-only → read). Tagging operations with Read | Upsert |
Create | Append | Delete names what the structure already says.

Three changes:

1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as
   normalized view, or retire as parallel-representation?"
   - Two paths: (i) tags derived from signature shape (acceptable
     normalized view) vs (ii) tags declared per-primitive (parallel-
     representation; retire).
   - Audit-as-existence-check (Q4 req 2 reframed): all effectful
     primitives derive cleanly from signature shape → path (i); any
     primitive needs hand-declared tag → path (ii) by existence proof.
   - Director default: path (ii). Logging primitives that return Unit
     are likely the audit's existence-proof.
   - Two design-question resolutions: (a) external effects not in
     return type → resource-threading discipline (typed param returned
     modified, IO-monad-without-the-monad pattern); (b) transactional
     grouping → derived structural fact from Bind composition + typed
     transaction primitives.

2. Q4 reqs revised: req 2 from "tag every primitive with explicit
   OperationEffect signature" to "audit-as-existence-check that every
   primitive's type signature derives the right effect classification";
   req 3 added (resource-threading discipline); req 6 added
   (transactional-pattern lens). Req 1 (effects lens) anchors on
   operation type-signature shape, not on hand-declared tags.

3. THESIS:345-347 amendment strengthened — "operations are
   intrinsically read-shaped or write-shaped via their type-signature
   shape; consumers walk the signatures directly; there is no parallel
   taxonomy or annotation layer to declare or maintain. Tracking
   effects as a separate enumerated concept IS the bug pattern,
   dissolved by construction." Plus references to resource-threading
   discipline + transactional grouping as derived structural fact.

Memory file feedback_closed_system_effects.md updated to reflect the
deeper framing (type-signature-shape, not taxonomy-tagging) +
resource-threading discipline section + transactional-patterns
section.

Net cost: doc-only delta on top of #808. Substrate retirement
(OperationEffect enum + derive_op_effect + idempotency.dag re-anchor)
deferred to the audit-as-existence-check phase of the implementation
brief; surfaced as Q5.5 OPEN CALL.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage

Resolves codex BLOCKING at sha d49ce79a on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real:
the prior text claimed service primitives "already carry typed effect
signatures" presenting future audit-state as current substrate fact
(P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the
OperationEffect line but left a parallel over-claim on the new
"signature-shape coverage" framing.

Fix: Q4 substrate-state listing rewritten to honestly distinguish:

- Live: Behavior enum + substrate foundation (the principle that
  operations should carry signature shape).
- Incomplete: signature-shape coverage across actual primitives.
  HTTP-derived primitives carry implicit shape via derive_op_effect's
  method-table; logging/mutation primitives that return Unit or don't
  thread their target resource do NOT carry the structural shape that
  would express read-vs-write. Achieving full coverage is required
  work under reqs 2 + 3, not a current fact.
- Pending audit-as-existence-check: OperationEffect + derive_op_effect
  (path (i) vs (ii) per Q5.5).

Honest live-state callout added explicitly: "the closed-system
FOUNDATION (5 behaviors + DAG substrate + the principle that
operations should carry signature-shape) is live. The IMPLEMENTATION
COVERAGE across all effectful primitives is partial. Req 2 + req 3
are the work that closes the gap."

Brief now distinguishes principle-is-live (foundation) from
coverage-is-partial (audit work) without conflating them.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim

Per PM follow-up review on #808 + user's stronger discipline framing
("substrate must make bypass structurally impossible at every layer
of the transport stack"): the closed-system claim is honest only when
typed primitives ARE the path. Today two structural holes exist where
bypasses sidestep the typed-primitive substrate. Both surfaced
explicitly as Q4.5 pre-conditions — load-bearing for the lens's
coverage claim.

Three changes:

1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed-
   system claim)" inserted between Q4 and Q5:

   P1 — Extdeps typed-primitive consumption structurally enforced.
   Substrate must make `messages: Json` impossible to declare in
   service definitions; typed `LlmMessage` / `ContentBlock` /
   `GitHubAuthToken`-with-full-scopes are the only path. Tracked
   debt at ROADMAP.md:153-154 (LLM provider flattening) +
   `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded).
   Required prereq for full lens coverage; lens can land first +
   surface structural-coverage-gap diagnostics on bypass surfaces
   so the gap becomes visible rather than silent.

   P2 — `ExecuteCommand` fully materialized as typed runner
   primitive. TESTING.md (post-#782) committed to 0-residual but
   ExecuteCommand isn't fully materialized; deleting Rust boundary
   tests creates verification gap. Already named under PB-Runtime
   in Zero-Floor; signal pending. Pre-requisite for ANY Rust
   boundary-test deletion.

2. Old leftover duplicate Q5 section deleted (artifact from prior
   Q5/Q5.5 reshape; second copy of asymmetric-tightening text was
   in the file alongside the earlier Q5 instance).

3. Worker-discretion-vs-Director-call section in Q4.5: lens
   implementation worker dispatchable now (reports gaps as
   findings); P1 closure is substantive substrate work touching
   extdeps (dedicated lane); P2 closure is PB-Runtime (signal
   pending).

Net: design doc now honestly distinguishes principle-is-live
(Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs
named explicitly). The closed-system claim has explicit pre-
conditions documented; implementation brief discovers them as
known dependencies, not as STOP-AND-ESCALATEs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default

Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two
real residuals after the Q5.5 reframe:

1. Q6's reqs/STOPs/acceptance still framed under path (i) — said
   "audit + tag std/ primitives — every effectful primitive carries
   an explicit OperationEffect signature." Directly contradicted Q4
   (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment
   ("there is no parallel taxonomy to declare or maintain"). Worker
   reading Q6 in isolation would author the retracted shape.

2. Capacity / sequencing table line about "audit lane (tag std/
   primitives with effect signatures)" carried the same stale
   framing.

3. Q6 STOP "primitive performing side effects without an
   OperationEffect tag" assumed tag-as-authority; under path (ii)
   the STOP shape is "primitive whose signature doesn't structurally
   reveal its effect."

Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale
(already fixed at f073aa95e Q4.5 commit).

## Q6 fixes

- Reqs renumbered + reframed:
  - Req 1 anchors on operation type-signature shape (not hand-declared
    OperationEffect tags); composition reads from signature shape per
    Q2 table.
  - Req 2 changed from "audit + tag every primitive" to
    "audit-as-existence-check" — verify signature-shape coverage; ANY
    primitive needing a hand-declared tag IS the existence-proof for
    path (ii) retirement.
  - Req 3 added: resource-threading discipline applied to existing
    primitives (logging that returns Unit gets reshaped per audit).
  - Req 6 added: transactional-pattern lens (Bind composition +
    Transaction → Transaction').
  - Req 7 added: asymmetric-tightening worked example in PR body
    (per claude review observation; the one place declaration-shaped
    surface re-enters).
  - Req 8 (was 5): tests now reference signature-shape derivation
    explicitly, not tag lookup.
- STOPs reframed:
  - "OperationEffect retirement decision" — audit produces path (i)
    vs (ii) verdict; substrate retirement is its own dedicated
    sub-lane; this lane does NOT absorb it.
  - Pure/impure carrier STOP notes that "pure" should also derive
    from signature shape (pure functions don't return modified
    resources) — so the STOP itself may dissolve under further design.
  - Q4.5 P1 explicitly NOT a STOP — lens reporting structural-
    coverage-gap on extdeps bypass surfaces is the lens delivering
    its foundation-gap-visibility value.
  - Q4.5 P2 explicitly independent — lens doesn't depend on
    ExecuteCommand materialization.
- Acceptance extended: lens reports gap diagnostics on P1 bypass
  surfaces; audit produces existence-proof verdict for Director
  re-decision; asymmetric-tightening worked example in PR body.

## Capacity / sequencing table

Replaced "1 audit lane (tag std/ primitives with effect signatures)"
with "1 audit-as-existence-check lane (verify primitives' signature-
shape coverage; NOT 'tag every primitive') — produces the path (i)
vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2
prereq lanes to the net summary. Closing line: "The taxonomy-
retirement scope (substrate-side) is not in this lane — it's
surfaced by audit and routed to dedicated retirement lane if path
(ii) wins."

Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity
table. Worker reading Q6 in isolation now sees path-(ii)-default
framing matching Q4 + Q5.5 + THESIS amendment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792

Resolves codex inline BLOCKING at sha 191be310 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150.
Real: my Q4.5 P2 framing described ExecuteCommand as still
NotYetImplemented (M1.5 allowlist + Rust TestRunner returning
NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand
extension before this PR's authoring. TESTING.md:195 capability-state
callout confirms:
- Rust TestRunner + M1.5 testgen harness share one std::process path
  for arbitrary command + args + expect_exit_code.
- M1.5 allowlist + fail-closed panic retired.
- Distinguishable ClaimResult::Fail messages for spawn / timeout /
  policy / exit-mismatch.
- Linux unshare(1) namespace isolation on host-allowing systems.
- T-PB-B-1 boundary migration example landed.

Fix:

P2 section rewritten:
- Header retitled "ExecuteCommand runner primitive: LANDED (PR #792);
  residual is bulk-migration."
- Status update naming PR #792 + the post-#792 capability state
  (allowlist retired, etc.).
- Honest acknowledgement: "My earlier P2 framing was stale."
- Residual narrowed to bulk-migration of existing Rust Command::new
  boundary tests (tracked as ROADMAP residual, not lens prereq).
- Sequencing reframed: P2 was always orthogonal to the effects lens
  itself; bulk migration proceeds at its own pace; lens not blocked.

Q4.5 footer updated:
- "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via
  #792; only consumer-side bulk migration remains)"
- Worker-discretion-vs-Director-call P2 line updated: "runner
  primitive landed; only consumer-side bulk migration remains;
  tracked as ROADMAP residual, independent of the lens."

Q6 STOP for P2 updated:
- "the lens itself doesn't depend on P2; only TESTING.md's 0-residual
  claim does" → "runner primitive landed via PR #792 (post-Q4.5-
  authoring update). The lens itself never depended on P2; bulk
  consumer migration is residual ROADMAP work and remains independent
  of this lane."

Brief now reflects live state. The closed-system claim's prereq
landscape is honest:
- P1 (extdeps typed-primitive consumption): real prereq, tracked
  debt at ROADMAP:153-154.
- P2 (ExecuteCommand runner): satisfied via #792; bulk migration is
  consumer-side residual, not foundation work.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale

Resolves codex non-blocking finding at sha bcac41bb on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real
residual: capacity-table line still listed P2 as "`ExecuteCommand`
materialization" prereq + framed both P1 and P2 as "pre-existing
tracked-debt" — but my prior 57a9b1318 fix established that PR #792
already landed the runner primitive, so P2 is no longer a
materialization prereq.

Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq)
from P2 (residual, not prereq):

  - P1: extdeps typed-primitive consumption — pre-existing tracked
    debt at ROADMAP:153-154; load-bearing for the lens's full-coverage
    claim.
  - P2: ExecuteCommand runner primitive landed via PR #792; only
    consumer-side bulk migration of existing Rust Command::new
    boundary tests remains (tracked as ROADMAP residual, independent
    of the lens; not a materialization prereq).

Brief now consistently treats P2 as bulk-migration-residual across:
- §Q4.5 P2 section header (LANDED via PR #792; residual is
  bulk-migration).
- §Q4.5 footer (P2: runner primitive landed; only consumer-side
  bulk migration remains).
- Q6 STOP for P2 (runner primitive landed; bulk migration is
  residual ROADMAP work).
- §Capacity / sequencing impact (P2 as residual, not prereq).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349

Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated
target-grounding prose; the matching extdeps typed-primitive bypass
entries (LLM service flattening, GitHub auth model bypass) live at
ROADMAP.md:348-349.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix third stale ROADMAP citation at line 271

Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence
at line 271 in the §Q4.5 capacity table. Now consistent with lines
139 and 173 (ROADMAP.md:348-349).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity

Codex flagged 'Effect-signature tagging on std/ primitives' as potentially
contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240)
already explicitly say 'NOT tag every primitive' — but the cross-manager
line used sloppy wording. Reworded to make explicit that the audit walks
signature shape; no parallel tag added.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5

- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)

B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).

B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — drop incoherent inner-fallback non-goal

Codex P2: the non-goal line excluding the inner declaration().name
unwrap_or_else fallback contradicted Slice step 2, which replaces the
whole chain with let-Some-else-return. Both fallbacks are in scope by
construction; remove the contradictory non-goal.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives

PM REQUEST_CHANGES: §Frame listed '4 type connectives
(Conjunction | Disjunction | Cardinality | Bit)' which contradicted
the canonical thesis source. Replaced with the canonical 6
(Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per
docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary
closes here'. Also removed 'typed substrate carriers' from the
vocabulary list — substrate carriers are defined using the vocabulary,
not part of it. Added a clarifying note that B4's carriers
(DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are
typed declarations composed from the vocabulary, not vocabulary
extensions.

Per feedback_verify_thesis_claims: brief framings citing thesis
structure must ground in the canonical source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority

Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of
naming the live substrate authority. Two coordinated fixes:

1. §Read first cites src/v3/std/substrate.dag (live .dag substrate
authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel
meta-type — already exists with consumers in verification.dag,
emit_model.dag, python.dag).

2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing
DeclarationRef'. The work is consumer migration + any role-extension
layer the audit reveals, NOT designing or landing the carrier.

Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers)
keep their 'new' framing but explicitly require sub-briefs to grep
src/v3/std/ + src/v3/spec/ for existing authority before authoring
'design and land' framing — per feedback_verify_thesis_claims +
feedback_emitter_workaround_is_gap_symptom.

Acceptance + sub-brief dispatch order updated to reflect B4.1's
consumer-migration shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — tighten Phase 1 umbrella sentence

The umbrella 'Land the typed carriers into src/v3/std/' framing was
stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced
with audit-first wording that covers both the consume-existing case (#1)
and the design-and-land case (#2-#4 if their audits show real gaps).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording

Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands'
which conflicted with the post-reframe reality that B4.1 consumes the
existing DeclarationRef. Updated to 'consumes or lands' with explicit
existing-authority citation and audit-pending caveat for B4.2-B4.4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — soften regression-test requirement (3 worker bounces)

Three consecutive B1 worker dispatches (zesty-crane-890 cursor →
valiant-boar-498 codex → cool-lynx-395 cursor) archived without
opening a PR. Likely friction point: brief Slice step 4 asks for a
unit test that constructs a Dag with an orphan variant declaration,
but emit.rs has zero existing #[test] precedent — emit testing
happens via integration fixtures. Workers see 'build novel test
harness' inside what's billed as an S-scope fix and bounce.

Per feedback_construction_over_ratchets: when a brief has friction,
fix the brief, don't ratchet the worker.

Softened step 4 + acceptance: regression test stays optional. If
test setup requires novel scaffolding, route the gap to follow-up.
The structural fail-closed at step 2 is the load-bearing change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt

PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description'
is too weak; PR descriptions don't survive squash-merge cleanly.

Two coordinated edits:
1. Slice step 4 — explicit substrate-signal framing: skipped test
   means emit-side hermetic-unit-test infrastructure is the missing
   substrate (feedback_emitter_workaround_is_gap_symptom).
2. Acceptance — require ROADMAP debt row (new or existing) with
   named dissolution trigger, referenced in PR body. Converts the
   skip from PR-local note (transient) into tracked debt (durable,
   dispatchable).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124

Codex BLOCKING: my earlier softening claimed emit.rs had no #[test]
precedent — wrong. The module has #[cfg(test)] mod tests at line 3124
with 12+ tests using compile_to_dag(source, filename) as harness
(e.g., go_struct_fields_render_with_separators :3143,
shared_walk_to_disj_finds_match_scrutinee_sum_type :3195).

This is a feedback_verify_thesis_claims violation on Director-side
brief authoring — claim made without grep verification.

Fix: restore step 4 as required, with explicit precedent citation.
Worker constructs the failure case via the existing harness
(direct Dag, fixture string, or BranchPattern exercise; worker's
call on cleanest path). STOP-AND-ESCALATE only if construction
proves materially harder than precedent suggests, in which case
that escalation surfaces a real substrate gap and warrants ROADMAP
debt — but the default is 'add the test.'

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites)

Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but
emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded
to 'several using compile_to_dag'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue

Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this
is Wave 1 of Director's 14-brief authoring queue, covering B4 program
internals.

Authored:
- b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) —
  replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag")
  fold-skip with structural template-formal carrier; mandatory
  authority audit per feedback_audit_adjacent_authority_first.
- b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) —
  replaces §0.6 emit.rs bind/branch.span.file equality with typed
  BindEmitParticipation/BranchEmitParticipation roles populated at
  lowering; aligned with #824 worker's in-flight implementation shape.
- b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4
  of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with
  typed substrate authority; explicit pre-promotion-constraint
  disposition (single-authority vs authority+tracked-debt) addresses
  parallel-representation risk surfaced on #825.
- b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) —
  names B4.5-B4.12 Phase 2 sites with carrier dependencies,
  cross-program coordination notes, and skeleton-brief template;
  full per-site briefs author at dispatch time per #827's
  Substrate Manager ownership.

Cross-cutting discipline applied per inbox #828 reply:
- feedback_audit_adjacent_authority_first (mandatory grep before design)
- feedback_no_textual_enforcement_bridges (no replacement sentinels)
- feedback_parallel_representation_debt (explicit if shape (b))
- feedback_construction_over_ratchets (no parity-by-runtime as primary)
- feedback_coproduct_dissolution (receipts for new variants)

Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling
worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3)

Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue.
Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by
Modeling Manager's Wave 3 worker briefs (gated on these landing).

Authored:
- r2-substrate-cardinality-for-int-lit-subset.md (M) — produces
  magnitude carrier consumed by T-Modeling int-lit. Coordinates with
  PR #806's prior cardinality work; mandatory authority audit guards
  against #796's rejected IntLiteralMagnitude shape resurfacing.
  Open design questions: magnitude representation, reconciliation
  narrowing point, i64::MIN representability.
- r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces
  nominal-opacity carrier consumed by T-Modeling Secret<T>. Open
  design questions: carrier shape (flag/connective/sealed-accessor),
  generic-walk discipline, accessor gating.
- r2-substrate-parametric-algebra-for-dimensions-subset.md (M) —
  produces phantom-parameter carrier consumed by T-Modeling
  Dimension<Carrier>. Open design questions: carrier shape,
  type-equivalence rule, algebra-method dispatch, lifting/coercion.

All three:
- Scoped narrowly to their paired R2 consumer; not full
  substrate-capability lanes.
- Mandatory pre-author authority audit per
  feedback_audit_adjacent_authority_first.
- Cross-program readiness signal pattern from #827's manager rework.
- Coproduct dissolution receipts required for any new variants.
- Open design questions surfaced explicitly so Substrate Manager
  (or Director pre-spin-up) can resolve at dispatch time.

Wave 3 (T-Modeling worker briefs × 4) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4)

Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue.
Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each
gated on a Substrate Manager readiness signal (Wave 2 producers).

Authored:
- r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2
  cardinality-for-int-lit; moves narrowing from tokenizer to
  reconciliation; MagnitudeOutOfRange diagnostic per C-8.
- r2-modeling-secret-graduation-worker.md — gated on Wave 2
  nominal-opaque-for-Secret; authors Secret<T> + gated accessors
  (redact, compare_in_constant_time); C-8 diagnostic on non-gated
  access; signals Impossible-Bugs Manager on close (thesis claim
  covered).
- r2-modeling-dimensions-phantom-worker.md — gated on Wave 2
  parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier>
  + core SI base units + algebra-method dispatch; cross-dimension
  arithmetic produces typed diagnostic; signals Impossible-Bugs
  Manager (thesis claim).
- r2-modeling-tokenizer-charclass-phase2-worker.md — gated on
  T-Substrate ValueBody-list/sum (#790); migrates tokenizer
  consumers to Char/List<Char>/CharClass canonical types; sibling
  consumer to Grounding Manager's Engine sharpened-(b).

All four:
- Explicit gating: 'do not dispatch until producer signal posts.'
- Producer/consumer signal pattern from #827.
- Cross-program signals to R2 Release Manager (Goal 2 closure)
  and Impossible-Bugs Manager (thesis-claim coverage).
- Spoofing regression tests: discipline anchor against
  feedback_no_textual_enforcement_bridges.

Wave 4 (T-ImpossibleBugs worker briefs × 3) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3)

Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue.
Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes,
consuming the existing design/scoping briefs as authority.

Authored:
- r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on
  cardinality refinement substrate (T-Substrate territory adjacent
  to int-lit / DB-11 alias-where). Implementation: structural normalize
  of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T??
  worker decision (reject vs normalize). Cites
  t-impossiblebugs-nested-optional-flatten-design.md as authority.
- r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated
  on Tier 2 substrate (predicate-entailment infrastructure; distinct
  from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes
  predicate entailment, (b) feedback_totality_by_omission dissolves
  partial primitives, (c) park. Worker decides at audit time. Cites
  t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority.
- r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate
  prerequisite per closed-system framing in design doc (#808). Audit-
  as-existence-check + lens implementation as compositional fold over
  5 behaviors; redundancy detection compile-error via referential
  transparency + reread() escape hatch; path (i/ii) decision on
  OperationEffect taxonomy retain-vs-retire (default retire). Cites
  design doc #808 as authority.

Cross-cutting:
- Each cites prior design/scoping brief as authority (the existing
  *-design.md / *-worker.md REFRAMED files).
- Explicit gating per #827 producer/consumer signal pattern; two
  briefs gated on substrate, one NOT gated (closed-system).
- STOP-AND-ESCALATE includes 'design brief assumptions don't hold'
  surfacing per feedback_thesis_gate_state_drift.

Wave 4 complete. Director's 14-brief queue done; awaiting PM portion
(6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4.4 — tighten Slice §3 per PM review on #836

PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b)
(authority + tracked debt parallel-rep) as autonomously acceptable
contradicts feedback_construction_over_ratchets +
feedback_parallel_representation_debt.

Tightened:
- Shape (a) is the only autonomous worker path.
- Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a
  regen-host-loader sub-lane decision; not authorable without explicit
  Substrate Manager approval citation in the PR body.
- Acceptance bullet requires the approval citation when shape (b)
  lands.
- STOP-AND-ESCALATE rephrased to make this explicit; permanent
  parallel-representation re-escalates even with manager approval.

This preserves shape (a) as autonomous; shape (b) becomes a
cross-manager design escalation, not a B4.4 implementation call.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief

Cursor review on #836 flagged the Read-first reference to
.claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md
as machine-specific (outside the repo, not resolvable from a normal
clone). Replaced with in-repo prose pointing at the design doc's
§Q1-Q3 as canonical authority — the discipline lives there in-repo.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs)

Codex flagged: src/v3/std/types.dag does not exist; the canonical
authority is at dsl/std/types.dag. Affected briefs (all from R2
spin-up Wave 2 + Wave 3):

- r2-substrate-cardinality-for-int-lit-subset.md
- r2-substrate-nominal-opaque-for-secret-subset.md
- r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs)
- r2-modeling-dimensions-phantom-worker.md
- r2-modeling-secret-graduation-worker.md

feedback_verify_thesis_claims violation on Director-side brief
authoring — assumed path without grep. Same family of error as
the earlier emit.rs precedent claim. Mass-replaced via perl;
verified no remaining stale refs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant

Codex BLOCKING on #836: my R2 worker brief gated nested-optional on
cardinality refinement substrate, but the design doc verifies v3 is
ALREADY past the cardinality bridge — TypeConnective::Cardinality
is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is
the carrier for Option. The dissolution is an UNGATED implementation
via substrate-constructor invariant.

feedback_verify_thesis_claims violation again — should have read the
design doc fully before assuming the substrate gate.

Rewrote brief to match design doc canonical sketch:
- Single predicate (cardinality_idempotent_target) owns the rule
- Single allocator (alloc_cardinality_decl) is THE substrate-constructor
- API closure on TypeConnective::Cardinality payload (modeling-discipline
  practice 6) — variant cannot be struct-init'd outside the allocator
- 3 hand-Rust + ~22 codegen call sites enumerated per design audit
- infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as
  the killer case for generic-instantiation paths
- Surface-syntax T?? decision left to worker (Director-lean: silent
  normalize)

Brief now dispatchable immediately, no producer signal needed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation

Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment
substrate path, but the design doc §4 explicitly recommends totality-by-
omission as the Director-actionable path. Predicate-entailment is M+ scope
that reopens DB-11's explicitly-closed asymmetric-strip design — design
doc explicitly discards it.

feedback_verify_thesis_claims violation again — same family as nested-
optional reframe. Should have read design doc §4 in full before assuming
the path ordering.

Rewrote brief to match design doc §4 follow-on shape:
- Primary path: per-class totality-by-omission (algebra retype + per-
  target realization migration). For Int/Int: OrderedRing.div retype
  at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 /
  python:486 + python_target.rs:680 helper).
- NOT predicate-entailment (out of scope; M+ + DB-11 reopen).
- NOT NonZero-typed-input (deferred to separate per-operand-variance
  substrate brief; STOP-AND-ESCALATE if chosen).
- Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i]
  indexing, quotient, remainder) queue separately per design doc audit.
- feedback_totality_by_omission discipline anchor explicit.

Brief now matches feedback_totality_by_omission discipline + design doc
recommendation. No substrate prerequisite; dispatchable immediately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure

Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a
pattern: I authored R2 worker briefs without fully reading each design
doc's Director-actionable recommendation. Pre-emptively re-verified
unenumerated-effects against design doc §Q6 to catch the same family
of error before reviewers do.

Findings: brief was substantively close but missing 3 of 8 design-doc
reqs:
- Req 3: Resource-threading discipline applied to existing primitives
- Req 5: reread(key) primitive in std/ as explicit Slice item (was
  only mentioned in tests)
- Req 7: Asymmetric-tightening worked example in PR body

Plus: Slice didn't cite the canonical lens path
src/v3/lenses/effect_enumeration.dag from design doc.

Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6
specifies 4 specific STOPs (path-decision-escalation, pure: Bool
carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP)
that I had elided.

Reframed Slice as 8 numbered reqs matching design doc verbatim;
STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs;
Acceptance enumerated per req.

This is the third reframe in the unhandled-bugs series — same
feedback_verify_thesis_claims violation each time. The pattern
suggests Director-side R2 brief authoring should ALWAYS read each
design doc's §Director-actionable / §Q-recommendation in full first,
not assume.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options

Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)"
listed as a worker-pick option violates THESIS.md substrate-shape
lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality |
Instantiation) are canonical (per #811 thesis additions and #827 PM
review); a 7th is a C1 stop signal requiring failed-dissolution
evidence + Director substrate-design call, not autonomous worker pick.

Removed the "new TypeConnective variant" option; replaced with
`inhabits`-edge-shape carrier as third option (audit-time check). The
explicit STOP-AND-ESCALATE clause now states: 7th connective is the
precondition for failed-dissolution-evidence + Director substrate-design
call, not a worker path.

feedback_verify_thesis_claims still in play — should have grounded
substrate-shape options against the THESIS lock before listing Opaque(T)
as worker-autonomous. Pattern continues; reading source-of-truth before
authoring options is the discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place)

Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter
already exist at dag.rs:186, :217 — explicitly authored for the
R2 Dimensions consumer per the doc comment at dag.rs:148-160.
phantom_unit_mismatch already wired at infer.rs:1057, :1132. The
substrate is fully landed; my brief framing it as 'producer sub-lane
to land carrier' is wrong on the same feedback_audit_adjacent_authority_first
violation that hit nested-optional / unhandled-diagnostic / unenumerated-
effects.

Reframed the substrate-side brief as no-op / closed-by-audit:
- Documents the audit receipt (5 sites confirming substrate exists)
- States the lane is closed
- Routes T-Modeling Dimensions consumer to dispatch immediately
  against the existing carrier
- Records the lesson: 'always grep substrate before authoring
  producer briefs' — discipline doesn't end at brief boundaries.

Updated r2-modeling-dimensions-phantom-worker.md correspondingly:
- Changed gating from 'do not dispatch until producer signal' to
  'NOT GATED — dispatch immediately'
- Read-first updated with concrete dag.rs/infer.rs cites
- Slice §1 changed from 'confirm producer signal' to 'verify
  substrate at HEAD'
- STOP reframed: existing carrier extension would need Substrate
  Manager call, not autonomous worker pick

Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit
both verified — no existing substrate (no is_nominal_opaque /
MagnitudeBound patterns in dag.rs); both still legitimately
producer-side work.

Pattern is now four reframes deep on the R2 spin-up wave. The lesson
saved is structural: read source-of-truth before authoring options.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority

Codex BLOCKING on #836: my new R2 spin-up brief duplicates the
existing t-substrate-cardinality-int-lit-worker.md, which carries
the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64)
stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane).
Single-authority violation per INVARIANTS P2.

Same feedback_audit_adjacent_authority_first failure as parametric-
algebra-for-Dimensions reframe (4 hours ago): assumed substrate
authority didn't exist; should have grepped docs/briefs/ before
authoring. This is the SECOND R2 spin-up substrate brief closed
as redundant — the discipline lesson is structural.

Reframed brief as no-op routing doc (documents the audit receipt;
routes consumers to the existing authority); updated
r2-modeling-int-lit-magnitude-worker.md to cite
t-substrate-cardinality-int-lit-worker.md instead.

Pattern across the R2 spin-up wave reframes (5 now):
1. nested-optional gating-on-substrate (substrate already past
   cardinality bridge)
2. unhandled-diagnostic predicate-entailment default (design doc
   recommends totality-by-omission)
3. unenumerated-effects 8-req design-doc elision
4. parametric-algebra Producer (Declaration.phantom_params already
   authored explicitly for this consumer)
5. cardinality-for-int-lit…
briansrls added a commit that referenced this pull request Apr 29, 2026
…gpt-5-5-pro post-merge follow-up) (#1162)

* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation)

Director-authored amendment following the 2026-04-24 escalation from PR
#693 (sub-child sharp-bear-829 under Surface Manager).

Two edits:

1. New "Class 5 Gap 3 — port-carried field values in data bodies"
   row in the 2026-04-21 post-merge-debt section. The substrate gap was
   documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP
   ledger row for cross-lane visibility. PR #693's execution surfaced it
   as the blocker on sub_charclass_in_std_unicode phase-2.

2. Retract the "ready-to-dispatch (no substrate capability gap)" claim
   on the Character-level row, annotate phase-1 landed via PR #693
   (CharClass vocabulary + Rust-mirror structural scanner path), and
   point phase-2 at the new Class 5 Gap 3 row.

Codifies the audit pattern: "this consumption gap has no substrate
capability gap" claims must be verified by attempting the retype before
the claim lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main

* docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review)

* docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review)

Row title still said 'consumption gap, not substrate gap' while the
body block retracted that claim and cited Class 5 Gap 3 as a substrate
dependency for phase-2. Title now matches body: mixed classification,
consumption for steps 1+3, substrate for step 2.

* docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit)

gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining
gap" description was wrong: field-level shapes (nested records, list
literals, declaration refs, Var refs, sum-variant literals) are
supported today via FieldValue variants + lower_structural_field_value
(dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the
top-level ValueBody boundary (non-scalar, non-record top-level bodies).

The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself
stale: it describes the pre-PR-B-unwind shape where FieldValue was
LiteralBits-only. PR-B's unwind extended FieldValue to carry
Reference / Record / List / Variant, moving the gap to ValueBody.

Two fixes:

1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody
   boundary, point at code paths (dag.rs, lower.rs) as live authority,
   flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass
   blocker classification to "provisional pending reproduction."

2. Update the Character-level row's phase-2 block to name that the
   specific shape of the CharClass failure needs concrete reproduction
   from the escalating sub-child before the blocker is finalized.

Recursive audit-pattern instance: the row I wrote to codify "verify
live state before claiming substrate gap" itself failed to verify live
state. Both incidents (2026-04-23 original row + 2026-04-24 my
retraction row) are now cited in the audit-pattern sub-note as
examples of the same discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33

Three substantive fixes addressing internal-consistency gaps in the cascade
promotion PR caught by codex review at sha 0d6e7c33:

1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane
   acceptance bullets and Hand-Rust census paragraph in line with the
   updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero
   (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is
   retracted under 0-floor with explicit migration to ExecuteCommand-based
   .dag TestClaim declarations.

2. docs/design-pure-bootstrap-zero.md promotion section — converted from
   future-tense ("This doc is PROPOSAL until promoted… promotion is a
   single Director-authored cascade PR…") to historical past-tense
   promotion-receipt framing ("This doc was PROPOSAL until promoted;
   promotion was a single Director-authored cascade PR that did all of the
   following atomically…"); blocking-clause struck through and resolved
   inline. Banner cites PR #782 explicitly.

3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_
   profile excluded (Map<String, AlgebraProfile> body, not list-of-sum;
   needs distinct ValueBody::Map substrate work, tracked separately as a
   future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass
   phase-2 + Engine sharpened-(b) pilot enumeration), both sharing
   list-of-sum substrate work. Lane table, dependency DAG, and capacity
   summary updated for consistency (slot count 9-13, was 10-14).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities

Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade
self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22
explicitly names THESIS.md and "any other authority docs" as required
retraction targets; the prior diff updated ROADMAP + r2-structure + design
docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting-
manager.md pointing at the now-SUPERSEDED ≤5-floor framing.

Files:

- THESIS.md (5 prose blocks updated):
  - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests
    migrate to ExecuteCommand-based .dag TestClaim declarations.
  - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag.
  - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor
    target citing design-pure-bootstrap-zero.md as live authority;
    hand_maintained_src list shrinks to empty set.
  - :301-318 — Tests-are-structural-data block: residual carve-out retracted;
    predicate name pb_rust_tests_outside_residual_zero retained as
    housekeeping (semantically the residual is empty under cascade).

- docs/thesis/compiler-std-consolidation.md (5 references):
  - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes
    design-pure-bootstrap.md (SUPERSEDED).
  - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process
    lane named as the dissolution trigger for bootstrap.rs itself.
  - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md.
  - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority
    re-cited.
  - :185 Related docs link.

- docs/briefs/r1-selfhosting-manager.md (active dispatch brief):
  - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5);
    T-PB-B residual carve-out retracted; predicate names retained for
    housekeeping; cascade-promoted authorities are source of truth.
  - Slice descriptions for T-PB-A / T-PB-B updated inline.
  - Framing-question + ask updated to 0-floor / no-residual framing.
  - Day-1 + up-to-director hand-off bullets updated.
  - Working-state checklist :111 ≤5 → 0 with cite.
  - Decisions log :164 ≤5 → 0-floor target updated.

- docs/r2-structure.md §2 design call (RETRACTED block):
  - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through
    in entirety (both Option A sharpen-and-keep and Option B rename are
    moot under 0-floor). Section preserved as audit-trail historical
    context.
  - Background-doc index: self-hosting anchor updated to
    design-pure-bootstrap-zero.md as live authority.

- docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per
  non-blocking suggestion):
  - Banner cites cascade promotion PR #782 explicitly.
  - New paragraph: "Treat all numeric floors below as retracted" with
    explicit lines named that quote in isolation (table row, body prose
    references). Prevents re-quoting from this doc as live authority.

Cascade is now atomically consistent across:
  THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔
  docs/thesis/compiler-std-consolidation.md ↔
  docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔
  docs/design-pure-bootstrap-zero.md (LIVE) ↔
  docs/design-pure-bootstrap.md (SUPERSEDED).

The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds
genuinely.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): correct ExecuteCommand runner-capability claim

Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation):
TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138
overstated live runner capability — claimed runner support landed in
PR #688/#741 with "emit Rust, invoke rustc on output, check exit code"
as a structurally-equivalent migration path. Verified against live
sources:

- src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema
  exists (declared via PR #678).
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5
  testgen harness allowlists ONLY `command == "true" && args.is_empty()
  && expect_exit == 0`.
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 —
  panics fail-closed on any other shape with explicit "ExecuteCommand
  shell shape is not supported here (runner-owned — do not treat as
  ordinary false)".
- src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no
  match arm for ExecuteCommand; falls through to ClaimResult::
  NotYetImplemented.

Reality: a TestClaim declaring rustc/python/go invocation is
structurally expressible as data today, but executing it is blocked.
Full arbitrary-command runner support is the PB-Runtime lane's
deliverable.

Files updated:

- TESTING.md:195 — capability state callout with file:line citations;
  "Full runner support — arbitrary command + args (rustc/python/go) with
  exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor
  program)." Bullet about migration shape preserved as the cascade-named
  successor pattern, not as a live capability.
- TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane
  lands the ExecuteCommand runner extension" as an explicit precondition.
- docs/design-pure-bootstrap-zero.md:138 — same correction for the
  matching prose, with PB-Runtime named as the runner-extension
  dependency for boundary-test migration.
- ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner
  foundation in #688/#741 with `true`-no-args allowlist only — full
  arbitrary-command runner support deferred to PB-Runtime lane,
  blocking the actual boundary-test migration." Dependencies column
  extended to "DB-15 + T-TestGen + PB-Runtime".

The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still
holds for atomic-cascade-across-authority-docs; this commit closes the
remaining capability/claim mismatch flagged by codex.

(Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still
SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief

Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation).
The prior banner contained:

> "Operationally R1 closure may still ship before the 0-floor is reached
>  — the ratchet ensures the trajectory; the gate's acceptance number is
>  what shifts."

This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0.
Two competing gate semantics in the cascade is exactly what the
atomic-cascade clause forbids.

Replaced with single-authority-honest framing:

> "R1 closure now requires the 0-floor target by gate semantics: T-PB-A
>  and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade
>  promotion changed their acceptance numbers to 0; R1 cannot close
>  while the SG-0 census carries non-zero hand-Rust."

Plus minor sharpening:
- "T-PB-A's non-test target is 0" → "non-test acceptance target is 0
  per ROADMAP.md:67" (cite the authority).
- T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep
  the capability-state honesty consistent with the recent fix wave.
- Predicate-rename housekeeping line moved into banner ("post-cascade
  housekeeping, not a pre-promotion blocker") — was implicit before.

The brief now genuinely inherits the cascade-promoted gate; no
competing release authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 second-wave worker-escalation fixes

Four substantive worker STOP-AND-ESCALATEs from briefs landed in
PR #797. All four worker recommendations correct; each needs a
Director call + brief update.

## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate

Worker correctly identified that brief req 2 (declared-effect carrier
as part of fn type signature, per feedback_no_annotations) requires
net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at
src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots.
Without parser surface, every user function would have
declared_effects = [] while inference returns non-empty — lens fires
EffectLeakageError everywhere on enable. Worker rejected power-through
and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map
parser split).

Director picked split:
- NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md
  Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface
  syntax + lookahead + body parser + lowerer extension + exhaustive-match
  audit + coproduct dissolution receipt.
- MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to
  post-parser-extension scope. Pre-flight check NOT a parser-extension
  step; STOP if parser sub-lane PR not merged.

## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping

Worker found load-bearing evidence at infer.rs:3693-3703: DB-11
deliberately strips refinements at operator dispatch as a designed-in
fix for symmetric-operators failure mode. Brief's "attach where b != 0
as a proof for a / b" directly contradicts this design choice. STOP-3
(where-clause conflict with DB-11) is real; STOP-1 (substrate scope)
needs net-new substrate (per-operator partiality fact + predicate-
entailment check + asymmetric per-operand refinement-honoring) — M+
minimum. ownership_lens precedent in original brief is post-hoc
observability, not proof carrier.

Worker recommended redirect to design/scoping per nested-optional
precedent. Director picked redirect.

Brief fully rewritten as design/scoping with four-question structure:
(1) DB-11 interaction analysis; (2) substrate proposal for proof-or-
totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes
with acceptance-theatre risk on user-defined-total-wrapper-only);
(4) Director-actionable recommendation. Output is doc PR.

## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C)

Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int)
with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136
closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b)
i128 implementation requires either path 1 (hierarchy refactor —
contradicts non-goal) or path 2 (regen lie between substrate and
emit — violates discipline). Worker leaned option (C) re-scope:
land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke)
to a sibling sub-lane that does proper Int128/Word128 substrate work.

Director picked option (C). Brief req 1 re-scoped to drop canonical-
carrier-widening; lane value comes from range facts + reconciliation
narrowing + out-of-range diagnostic against existing i64. Req 4
explicitly deferred with sibling-sub-lane reference. Sibling sub-lane
NOT to be authored or implied in this PR; tracked separately.

## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change)

Worker correctly STOP'd per the brief's own pre-flight check: parser
sub-lane has not landed; SurfaceExpr::Map not on main. Director
authorized cross-lane reassignment: wise-boar-480 takes the parser
sub-lane (t-substrate-valuebody-map-parser-worker.md) since they
already have full investigation context. No brief changes needed; the
routing decision is in the dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope

Resolves codex P2 inline at sha e35103fad on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer
carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still
required widening LiteralBits::Int(i64) to an unbounded carrier and
passing the i64::MIN smoke. Internally unsatisfiable.

Fix:

- Slice section retitled "range facts + reconciliation narrowing
  (against existing i64 carrier)" with explicit note about the
  re-scope.
- Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly
  forbids touching LiteralBits::Int shape, dag_scalar_generated.rs
  regen for that variant, or tokenize i64 parse path.
- Slice steps 2-5 reframed: range facts use i64-representable
  magnitudes; reconciliation narrowing uses existing i64 carrier;
  diagnostic only for i64-representable out-of-range; smoke tests
  for req 5 only (req 4 i64::MIN deferred).
- Acceptance checklist updated:
  - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as
    re-scoped/deferred.
  - LiteralBits::Int(i64) carrier untouched (no widening; no
    parallel; no shape change).
  - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference.
- STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the
  carrier" — explicit STOP if execution surfaces range-fact narrowing
  requiring carrier-widening; that's the boundary the re-scope drew;
  belongs in sibling Int128/Word128 sub-lane.

Brief now consistently treats carrier-widening as out-of-scope across
all sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty

Resolves codex BLOCKING #1 at sha e35103fa on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier
but req 2 required range facts using "the SAME magnitude carrier
as req 1" — meaning i64-typed range bounds. u64's max (2^64-1)
doesn't fit in i64; range fact for u64 would have to truncate,
omit, or mirror in Rust (representation drift). All three options
violate fail-closed declared-facts discipline (P1 / P3).

Fix:

- Req 2 rewritten to specify String-decimal representation:
  range_min_inclusive: String + range_max_inclusive: String fields
  on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127"
  for i8; "0"/"18446744073709551615" for u64).
- Explicit reasoning why String-decimal: u64's max doesn't fit in
  i64; binding range bounds to literal carrier forces truncation/
  omission/mirror-drift; all violate fail-closed declared-facts
  discipline.
- Bridge framing: String-decimal is pending the sibling Int128/
  Word128 sub-lane; both range bounds and literal payload migrate
  to typed carrier when that lands.

- Req 3 updated for String-decimal comparison semantics:
  reconciliation parses both bounds and literal magnitude into a
  common comparison space (i128 host comparison primitive — host
  narrowing, NOT carrier widening). Bounded by what the i64-typed
  literal can express; any i64-representable literal compares
  against any width's String-decimal bound. Carrier discipline
  preserved.

Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral)
is sha-stale — already resolved at 3e142d169.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed

Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback).
Real residual: req 2 specifies String-decimal range bounds (to cover
u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance
bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" /
"i64-representable magnitudes" for the range facts. Two incompatible
authorities for the same range-fact shape — would let a worker satisfy
the slice while truncating/omitting u64 bounds (P3 fail-closed
violation).

Fix:

- Line 31 (req 1 re-scope clarification): updated to explicitly state
  "range facts (req 2) use String-decimal representation (width-
  independent; covers u64::MAX which doesn't fit in i64)". Distinguished
  literal *payload* (stays i64) from range-bound *representation*
  (String) — both serve req 1's "no carrier widening" boundary.
- Line 44 (slice step 2): updated from "Range bounds use i64-
  representable magnitudes" to "Range bounds use String-decimal
  representation per req 2" with concrete example (u64 bounds).
- Acceptance bullet: updated from "Range facts on integer algebras
  (substrate-declared, not Rust-mirrored)" to add "using String-decimal
  representation ... width-independent; u64 bounds expressible without
  truncation."

The brief now consistently treats range bounds as String-decimal
across req 2, req 3, slice, acceptance, and the req 1 clarification —
no remaining authorities saying i64-typed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing

User + PM exchange 2026-04-25 surfaced that the in-flight effects
chain was importing wrong assumptions from external languages
(declared-effects-as-annotation + lens-vs-declaration check). Right
framing under gunbc's closed-system discipline is parallel to
complexity: every effect derives structurally from the composition
of typed primitive operations; nothing can hide because there's no
escape hatch; nothing needs annotation because the structure IS the
registry.

Four doc-only actions:

1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md.
   Frames the closed-system answer with PM's 5-behavior synergy
   table (Value/Transform/Branch/Loop/Bind as universal
   compositional-fold pattern). Four worked examples; aggressive
   reading on redundancy (compile-error-by-construction via
   referential-transparency proof; reread() primitive for legitimate
   cases); implementation-brief shape in §Q6.

2. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md.

3. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md.
   Notes Fn→Arrow refactor brief stays dispatchable as independent
   value.

4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by-
   construction framing replaces lens-detection framing.

Memory file feedback_closed_system_effects.md saved separately;
cross-link added to feedback_construction_over_ratchets.md.

Net cost: doc-level cleanup. Zero substrate code rework. Foundation
(OperationEffect + service-call infrastructure + 5-behavior
substrate) already exists.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect

Per PM convergence review on #808 + user's deeper 2026-04-25 framing:
the closed-system framing landed in #808 retired the user-facing
annotation but kept OperationEffect taxonomy as substrate-level tagging.
User's deeper framing: the taxonomy ITSELF is parallel-representation —
operations are intrinsically read-shaped or write-shaped via their
TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns-
derived-value-only → read). Tagging operations with Read | Upsert |
Create | Append | Delete names what the structure already says.

Three changes:

1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as
   normalized view, or retire as parallel-representation?"
   - Two paths: (i) tags derived from signature shape (acceptable
     normalized view) vs (ii) tags declared per-primitive (parallel-
     representation; retire).
   - Audit-as-existence-check (Q4 req 2 reframed): all effectful
     primitives derive cleanly from signature shape → path (i); any
     primitive needs hand-declared tag → path (ii) by existence proof.
   - Director default: path (ii). Logging primitives that return Unit
     are likely the audit's existence-proof.
   - Two design-question resolutions: (a) external effects not in
     return type → resource-threading discipline (typed param returned
     modified, IO-monad-without-the-monad pattern); (b) transactional
     grouping → derived structural fact from Bind composition + typed
     transaction primitives.

2. Q4 reqs revised: req 2 from "tag every primitive with explicit
   OperationEffect signature" to "audit-as-existence-check that every
   primitive's type signature derives the right effect classification";
   req 3 added (resource-threading discipline); req 6 added
   (transactional-pattern lens). Req 1 (effects lens) anchors on
   operation type-signature shape, not on hand-declared tags.

3. THESIS:345-347 amendment strengthened — "operations are
   intrinsically read-shaped or write-shaped via their type-signature
   shape; consumers walk the signatures directly; there is no parallel
   taxonomy or annotation layer to declare or maintain. Tracking
   effects as a separate enumerated concept IS the bug pattern,
   dissolved by construction." Plus references to resource-threading
   discipline + transactional grouping as derived structural fact.

Memory file feedback_closed_system_effects.md updated to reflect the
deeper framing (type-signature-shape, not taxonomy-tagging) +
resource-threading discipline section + transactional-patterns
section.

Net cost: doc-only delta on top of #808. Substrate retirement
(OperationEffect enum + derive_op_effect + idempotency.dag re-anchor)
deferred to the audit-as-existence-check phase of the implementation
brief; surfaced as Q5.5 OPEN CALL.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage

Resolves codex BLOCKING at sha d49ce79a on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real:
the prior text claimed service primitives "already carry typed effect
signatures" presenting future audit-state as current substrate fact
(P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the
OperationEffect line but left a parallel over-claim on the new
"signature-shape coverage" framing.

Fix: Q4 substrate-state listing rewritten to honestly distinguish:

- Live: Behavior enum + substrate foundation (the principle that
  operations should carry signature shape).
- Incomplete: signature-shape coverage across actual primitives.
  HTTP-derived primitives carry implicit shape via derive_op_effect's
  method-table; logging/mutation primitives that return Unit or don't
  thread their target resource do NOT carry the structural shape that
  would express read-vs-write. Achieving full coverage is required
  work under reqs 2 + 3, not a current fact.
- Pending audit-as-existence-check: OperationEffect + derive_op_effect
  (path (i) vs (ii) per Q5.5).

Honest live-state callout added explicitly: "the closed-system
FOUNDATION (5 behaviors + DAG substrate + the principle that
operations should carry signature-shape) is live. The IMPLEMENTATION
COVERAGE across all effectful primitives is partial. Req 2 + req 3
are the work that closes the gap."

Brief now distinguishes principle-is-live (foundation) from
coverage-is-partial (audit work) without conflating them.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim

Per PM follow-up review on #808 + user's stronger discipline framing
("substrate must make bypass structurally impossible at every layer
of the transport stack"): the closed-system claim is honest only when
typed primitives ARE the path. Today two structural holes exist where
bypasses sidestep the typed-primitive substrate. Both surfaced
explicitly as Q4.5 pre-conditions — load-bearing for the lens's
coverage claim.

Three changes:

1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed-
   system claim)" inserted between Q4 and Q5:

   P1 — Extdeps typed-primitive consumption structurally enforced.
   Substrate must make `messages: Json` impossible to declare in
   service definitions; typed `LlmMessage` / `ContentBlock` /
   `GitHubAuthToken`-with-full-scopes are the only path. Tracked
   debt at ROADMAP.md:153-154 (LLM provider flattening) +
   `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded).
   Required prereq for full lens coverage; lens can land first +
   surface structural-coverage-gap diagnostics on bypass surfaces
   so the gap becomes visible rather than silent.

   P2 — `ExecuteCommand` fully materialized as typed runner
   primitive. TESTING.md (post-#782) committed to 0-residual but
   ExecuteCommand isn't fully materialized; deleting Rust boundary
   tests creates verification gap. Already named under PB-Runtime
   in Zero-Floor; signal pending. Pre-requisite for ANY Rust
   boundary-test deletion.

2. Old leftover duplicate Q5 section deleted (artifact from prior
   Q5/Q5.5 reshape; second copy of asymmetric-tightening text was
   in the file alongside the earlier Q5 instance).

3. Worker-discretion-vs-Director-call section in Q4.5: lens
   implementation worker dispatchable now (reports gaps as
   findings); P1 closure is substantive substrate work touching
   extdeps (dedicated lane); P2 closure is PB-Runtime (signal
   pending).

Net: design doc now honestly distinguishes principle-is-live
(Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs
named explicitly). The closed-system claim has explicit pre-
conditions documented; implementation brief discovers them as
known dependencies, not as STOP-AND-ESCALATEs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default

Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two
real residuals after the Q5.5 reframe:

1. Q6's reqs/STOPs/acceptance still framed under path (i) — said
   "audit + tag std/ primitives — every effectful primitive carries
   an explicit OperationEffect signature." Directly contradicted Q4
   (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment
   ("there is no parallel taxonomy to declare or maintain"). Worker
   reading Q6 in isolation would author the retracted shape.

2. Capacity / sequencing table line about "audit lane (tag std/
   primitives with effect signatures)" carried the same stale
   framing.

3. Q6 STOP "primitive performing side effects without an
   OperationEffect tag" assumed tag-as-authority; under path (ii)
   the STOP shape is "primitive whose signature doesn't structurally
   reveal its effect."

Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale
(already fixed at f073aa95e Q4.5 commit).

## Q6 fixes

- Reqs renumbered + reframed:
  - Req 1 anchors on operation type-signature shape (not hand-declared
    OperationEffect tags); composition reads from signature shape per
    Q2 table.
  - Req 2 changed from "audit + tag every primitive" to
    "audit-as-existence-check" — verify signature-shape coverage; ANY
    primitive needing a hand-declared tag IS the existence-proof for
    path (ii) retirement.
  - Req 3 added: resource-threading discipline applied to existing
    primitives (logging that returns Unit gets reshaped per audit).
  - Req 6 added: transactional-pattern lens (Bind composition +
    Transaction → Transaction').
  - Req 7 added: asymmetric-tightening worked example in PR body
    (per claude review observation; the one place declaration-shaped
    surface re-enters).
  - Req 8 (was 5): tests now reference signature-shape derivation
    explicitly, not tag lookup.
- STOPs reframed:
  - "OperationEffect retirement decision" — audit produces path (i)
    vs (ii) verdict; substrate retirement is its own dedicated
    sub-lane; this lane does NOT absorb it.
  - Pure/impure carrier STOP notes that "pure" should also derive
    from signature shape (pure functions don't return modified
    resources) — so the STOP itself may dissolve under further design.
  - Q4.5 P1 explicitly NOT a STOP — lens reporting structural-
    coverage-gap on extdeps bypass surfaces is the lens delivering
    its foundation-gap-visibility value.
  - Q4.5 P2 explicitly independent — lens doesn't depend on
    ExecuteCommand materialization.
- Acceptance extended: lens reports gap diagnostics on P1 bypass
  surfaces; audit produces existence-proof verdict for Director
  re-decision; asymmetric-tightening worked example in PR body.

## Capacity / sequencing table

Replaced "1 audit lane (tag std/ primitives with effect signatures)"
with "1 audit-as-existence-check lane (verify primitives' signature-
shape coverage; NOT 'tag every primitive') — produces the path (i)
vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2
prereq lanes to the net summary. Closing line: "The taxonomy-
retirement scope (substrate-side) is not in this lane — it's
surfaced by audit and routed to dedicated retirement lane if path
(ii) wins."

Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity
table. Worker reading Q6 in isolation now sees path-(ii)-default
framing matching Q4 + Q5.5 + THESIS amendment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792

Resolves codex inline BLOCKING at sha 191be310 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150.
Real: my Q4.5 P2 framing described ExecuteCommand as still
NotYetImplemented (M1.5 allowlist + Rust TestRunner returning
NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand
extension before this PR's authoring. TESTING.md:195 capability-state
callout confirms:
- Rust TestRunner + M1.5 testgen harness share one std::process path
  for arbitrary command + args + expect_exit_code.
- M1.5 allowlist + fail-closed panic retired.
- Distinguishable ClaimResult::Fail messages for spawn / timeout /
  policy / exit-mismatch.
- Linux unshare(1) namespace isolation on host-allowing systems.
- T-PB-B-1 boundary migration example landed.

Fix:

P2 section rewritten:
- Header retitled "ExecuteCommand runner primitive: LANDED (PR #792);
  residual is bulk-migration."
- Status update naming PR #792 + the post-#792 capability state
  (allowlist retired, etc.).
- Honest acknowledgement: "My earlier P2 framing was stale."
- Residual narrowed to bulk-migration of existing Rust Command::new
  boundary tests (tracked as ROADMAP residual, not lens prereq).
- Sequencing reframed: P2 was always orthogonal to the effects lens
  itself; bulk migration proceeds at its own pace; lens not blocked.

Q4.5 footer updated:
- "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via
  #792; only consumer-side bulk migration remains)"
- Worker-discretion-vs-Director-call P2 line updated: "runner
  primitive landed; only consumer-side bulk migration remains;
  tracked as ROADMAP residual, independent of the lens."

Q6 STOP for P2 updated:
- "the lens itself doesn't depend on P2; only TESTING.md's 0-residual
  claim does" → "runner primitive landed via PR #792 (post-Q4.5-
  authoring update). The lens itself never depended on P2; bulk
  consumer migration is residual ROADMAP work and remains independent
  of this lane."

Brief now reflects live state. The closed-system claim's prereq
landscape is honest:
- P1 (extdeps typed-primitive consumption): real prereq, tracked
  debt at ROADMAP:153-154.
- P2 (ExecuteCommand runner): satisfied via #792; bulk migration is
  consumer-side residual, not foundation work.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale

Resolves codex non-blocking finding at sha bcac41bb on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real
residual: capacity-table line still listed P2 as "`ExecuteCommand`
materialization" prereq + framed both P1 and P2 as "pre-existing
tracked-debt" — but my prior 57a9b1318 fix established that PR #792
already landed the runner primitive, so P2 is no longer a
materialization prereq.

Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq)
from P2 (residual, not prereq):

  - P1: extdeps typed-primitive consumption — pre-existing tracked
    debt at ROADMAP:153-154; load-bearing for the lens's full-coverage
    claim.
  - P2: ExecuteCommand runner primitive landed via PR #792; only
    consumer-side bulk migration of existing Rust Command::new
    boundary tests remains (tracked as ROADMAP residual, independent
    of the lens; not a materialization prereq).

Brief now consistently treats P2 as bulk-migration-residual across:
- §Q4.5 P2 section header (LANDED via PR #792; residual is
  bulk-migration).
- §Q4.5 footer (P2: runner primitive landed; only consumer-side
  bulk migration remains).
- Q6 STOP for P2 (runner primitive landed; bulk migration is
  residual ROADMAP work).
- §Capacity / sequencing impact (P2 as residual, not prereq).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349

Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated
target-grounding prose; the matching extdeps typed-primitive bypass
entries (LLM service flattening, GitHub auth model bypass) live at
ROADMAP.md:348-349.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix third stale ROADMAP citation at line 271

Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence
at line 271 in the §Q4.5 capacity table. Now consistent with lines
139 and 173 (ROADMAP.md:348-349).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity

Codex flagged 'Effect-signature tagging on std/ primitives' as potentially
contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240)
already explicitly say 'NOT tag every primitive' — but the cross-manager
line used sloppy wording. Reworded to make explicit that the audit walks
signature shape; no parallel tag added.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5

- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)

B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).

B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — drop incoherent inner-fallback non-goal

Codex P2: the non-goal line excluding the inner declaration().name
unwrap_or_else fallback contradicted Slice step 2, which replaces the
whole chain with let-Some-else-return. Both fallbacks are in scope by
construction; remove the contradictory non-goal.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives

PM REQUEST_CHANGES: §Frame listed '4 type connectives
(Conjunction | Disjunction | Cardinality | Bit)' which contradicted
the canonical thesis source. Replaced with the canonical 6
(Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per
docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary
closes here'. Also removed 'typed substrate carriers' from the
vocabulary list — substrate carriers are defined using the vocabulary,
not part of it. Added a clarifying note that B4's carriers
(DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are
typed declarations composed from the vocabulary, not vocabulary
extensions.

Per feedback_verify_thesis_claims: brief framings citing thesis
structure must ground in the canonical source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority

Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of
naming the live substrate authority. Two coordinated fixes:

1. §Read first cites src/v3/std/substrate.dag (live .dag substrate
authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel
meta-type — already exists with consumers in verification.dag,
emit_model.dag, python.dag).

2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing
DeclarationRef'. The work is consumer migration + any role-extension
layer the audit reveals, NOT designing or landing the carrier.

Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers)
keep their 'new' framing but explicitly require sub-briefs to grep
src/v3/std/ + src/v3/spec/ for existing authority before authoring
'design and land' framing — per feedback_verify_thesis_claims +
feedback_emitter_workaround_is_gap_symptom.

Acceptance + sub-brief dispatch order updated to reflect B4.1's
consumer-migration shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — tighten Phase 1 umbrella sentence

The umbrella 'Land the typed carriers into src/v3/std/' framing was
stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced
with audit-first wording that covers both the consume-existing case (#1)
and the design-and-land case (#2-#4 if their audits show real gaps).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording

Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands'
which conflicted with the post-reframe reality that B4.1 consumes the
existing DeclarationRef. Updated to 'consumes or lands' with explicit
existing-authority citation and audit-pending caveat for B4.2-B4.4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — soften regression-test requirement (3 worker bounces)

Three consecutive B1 worker dispatches (zesty-crane-890 cursor →
valiant-boar-498 codex → cool-lynx-395 cursor) archived without
opening a PR. Likely friction point: brief Slice step 4 asks for a
unit test that constructs a Dag with an orphan variant declaration,
but emit.rs has zero existing #[test] precedent — emit testing
happens via integration fixtures. Workers see 'build novel test
harness' inside what's billed as an S-scope fix and bounce.

Per feedback_construction_over_ratchets: when a brief has friction,
fix the brief, don't ratchet the worker.

Softened step 4 + acceptance: regression test stays optional. If
test setup requires novel scaffolding, route the gap to follow-up.
The structural fail-closed at step 2 is the load-bearing change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt

PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description'
is too weak; PR descriptions don't survive squash-merge cleanly.

Two coordinated edits:
1. Slice step 4 — explicit substrate-signal framing: skipped test
   means emit-side hermetic-unit-test infrastructure is the missing
   substrate (feedback_emitter_workaround_is_gap_symptom).
2. Acceptance — require ROADMAP debt row (new or existing) with
   named dissolution trigger, referenced in PR body. Converts the
   skip from PR-local note (transient) into tracked debt (durable,
   dispatchable).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124

Codex BLOCKING: my earlier softening claimed emit.rs had no #[test]
precedent — wrong. The module has #[cfg(test)] mod tests at line 3124
with 12+ tests using compile_to_dag(source, filename) as harness
(e.g., go_struct_fields_render_with_separators :3143,
shared_walk_to_disj_finds_match_scrutinee_sum_type :3195).

This is a feedback_verify_thesis_claims violation on Director-side
brief authoring — claim made without grep verification.

Fix: restore step 4 as required, with explicit precedent citation.
Worker constructs the failure case via the existing harness
(direct Dag, fixture string, or BranchPattern exercise; worker's
call on cleanest path). STOP-AND-ESCALATE only if construction
proves materially harder than precedent suggests, in which case
that escalation surfaces a real substrate gap and warrants ROADMAP
debt — but the default is 'add the test.'

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites)

Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but
emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded
to 'several using compile_to_dag'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue

Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this
is Wave 1 of Director's 14-brief authoring queue, covering B4 program
internals.

Authored:
- b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) —
  replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag")
  fold-skip with structural template-formal carrier; mandatory
  authority audit per feedback_audit_adjacent_authority_first.
- b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) —
  replaces §0.6 emit.rs bind/branch.span.file equality with typed
  BindEmitParticipation/BranchEmitParticipation roles populated at
  lowering; aligned with #824 worker's in-flight implementation shape.
- b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4
  of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with
  typed substrate authority; explicit pre-promotion-constraint
  disposition (single-authority vs authority+tracked-debt) addresses
  parallel-representation risk surfaced on #825.
- b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) —
  names B4.5-B4.12 Phase 2 sites with carrier dependencies,
  cross-program coordination notes, and skeleton-brief template;
  full per-site briefs author at dispatch time per #827's
  Substrate Manager ownership.

Cross-cutting discipline applied per inbox #828 reply:
- feedback_audit_adjacent_authority_first (mandatory grep before design)
- feedback_no_textual_enforcement_bridges (no replacement sentinels)
- feedback_parallel_representation_debt (explicit if shape (b))
- feedback_construction_over_ratchets (no parity-by-runtime as primary)
- feedback_coproduct_dissolution (receipts for new variants)

Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling
worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3)

Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue.
Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by
Modeling Manager's Wave 3 worker briefs (gated on these landing).

Authored:
- r2-substrate-cardinality-for-int-lit-subset.md (M) — produces
  magnitude carrier consumed by T-Modeling int-lit. Coordinates with
  PR #806's prior cardinality work; mandatory authority audit guards
  against #796's rejected IntLiteralMagnitude shape resurfacing.
  Open design questions: magnitude representation, reconciliation
  narrowing point, i64::MIN representability.
- r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces
  nominal-opacity carrier consumed by T-Modeling Secret<T>. Open
  design questions: carrier shape (flag/connective/sealed-accessor),
  generic-walk discipline, accessor gating.
- r2-substrate-parametric-algebra-for-dimensions-subset.md (M) —
  produces phantom-parameter carrier consumed by T-Modeling
  Dimension<Carrier>. Open design questions: carrier shape,
  type-equivalence rule, algebra-method dispatch, lifting/coercion.

All three:
- Scoped narrowly to their paired R2 consumer; not full
  substrate-capability lanes.
- Mandatory pre-author authority audit per
  feedback_audit_adjacent_authority_first.
- Cross-program readiness signal pattern from #827's manager rework.
- Coproduct dissolution receipts required for any new variants.
- Open design questions surfaced explicitly so Substrate Manager
  (or Director pre-spin-up) can resolve at dispatch time.

Wave 3 (T-Modeling worker briefs × 4) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4)

Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue.
Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each
gated on a Substrate Manager readiness signal (Wave 2 producers).

Authored:
- r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2
  cardinality-for-int-lit; moves narrowing from tokenizer to
  reconciliation; MagnitudeOutOfRange diagnostic per C-8.
- r2-modeling-secret-graduation-worker.md — gated on Wave 2
  nominal-opaque-for-Secret; authors Secret<T> + gated accessors
  (redact, compare_in_constant_time); C-8 diagnostic on non-gated
  access; signals Impossible-Bugs Manager on close (thesis claim
  covered).
- r2-modeling-dimensions-phantom-worker.md — gated on Wave 2
  parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier>
  + core SI base units + algebra-method dispatch; cross-dimension
  arithmetic produces typed diagnostic; signals Impossible-Bugs
  Manager (thesis claim).
- r2-modeling-tokenizer-charclass-phase2-worker.md — gated on
  T-Substrate ValueBody-list/sum (#790); migrates tokenizer
  consumers to Char/List<Char>/CharClass canonical types; sibling
  consumer to Grounding Manager's Engine sharpened-(b).

All four:
- Explicit gating: 'do not dispatch until producer signal posts.'
- Producer/consumer signal pattern from #827.
- Cross-program signals to R2 Release Manager (Goal 2 closure)
  and Impossible-Bugs Manager (thesis-claim coverage).
- Spoofing regression tests: discipline anchor against
  feedback_no_textual_enforcement_bridges.

Wave 4 (T-ImpossibleBugs worker briefs × 3) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3)

Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue.
Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes,
consuming the existing design/scoping briefs as authority.

Authored:
- r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on
  cardinality refinement substrate (T-Substrate territory adjacent
  to int-lit / DB-11 alias-where). Implementation: structural normalize
  of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T??
  worker decision (reject vs normalize). Cites
  t-impossiblebugs-nested-optional-flatten-design.md as authority.
- r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated
  on Tier 2 substrate (predicate-entailment infrastructure; distinct
  from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes
  predicate entailment, (b) feedback_totality_by_omission dissolves
  partial primitives, (c) park. Worker decides at audit time. Cites
  t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority.
- r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate
  prerequisite per closed-system framing in design doc (#808). Audit-
  as-existence-check + lens implementation as compositional fold over
  5 behaviors; redundancy detection compile-error via referential
  transparency + reread() escape hatch; path (i/ii) decision on
  OperationEffect taxonomy retain-vs-retire (default retire). Cites
  design doc #808 as authority.

Cross-cutting:
- Each cites prior design/scoping brief as authority (the existing
  *-design.md / *-worker.md REFRAMED files).
- Explicit gating per #827 producer/consumer signal pattern; two
  briefs gated on substrate, one NOT gated (closed-system).
- STOP-AND-ESCALATE includes 'design brief assumptions don't hold'
  surfacing per feedback_thesis_gate_state_drift.

Wave 4 complete. Director's 14-brief queue done; awaiting PM portion
(6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4.4 — tighten Slice §3 per PM review on #836

PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b)
(authority + tracked debt parallel-rep) as autonomously acceptable
contradicts feedback_construction_over_ratchets +
feedback_parallel_representation_debt.

Tightened:
- Shape (a) is the only autonomous worker path.
- Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a
  regen-host-loader sub-lane decision; not authorable without explicit
  Substrate Manager approval citation in the PR body.
- Acceptance bullet requires the approval citation when shape (b)
  lands.
- STOP-AND-ESCALATE rephrased to make this explicit; permanent
  parallel-representation re-escalates even with manager approval.

This preserves shape (a) as autonomous; shape (b) becomes a
cross-manager design escalation, not a B4.4 implementation call.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief

Cursor review on #836 flagged the Read-first reference to
.claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md
as machine-specific (outside the repo, not resolvable from a normal
clone). Replaced with in-repo prose pointing at the design doc's
§Q1-Q3 as canonical authority — the discipline lives there in-repo.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs)

Codex flagged: src/v3/std/types.dag does not exist; the canonical
authority is at dsl/std/types.dag. Affected briefs (all from R2
spin-up Wave 2 + Wave 3):

- r2-substrate-cardinality-for-int-lit-subset.md
- r2-substrate-nominal-opaque-for-secret-subset.md
- r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs)
- r2-modeling-dimensions-phantom-worker.md
- r2-modeling-secret-graduation-worker.md

feedback_verify_thesis_claims violation on Director-side brief
authoring — assumed path without grep. Same family of error as
the earlier emit.rs precedent claim. Mass-replaced via perl;
verified no remaining stale refs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant

Codex BLOCKING on #836: my R2 worker brief gated nested-optional on
cardinality refinement substrate, but the design doc verifies v3 is
ALREADY past the cardinality bridge — TypeConnective::Cardinality
is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is
the carrier for Option. The dissolution is an UNGATED implementation
via substrate-constructor invariant.

feedback_verify_thesis_claims violation again — should have read the
design doc fully before assuming the substrate gate.

Rewrote brief to match design doc canonical sketch:
- Single predicate (cardinality_idempotent_target) owns the rule
- Single allocator (alloc_cardinality_decl) is THE substrate-constructor
- API closure on TypeConnective::Cardinality payload (modeling-discipline
  practice 6) — variant cannot be struct-init'd outside the allocator
- 3 hand-Rust + ~22 codegen call sites enumerated per design audit
- infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as
  the killer case for generic-instantiation paths
- Surface-syntax T?? decision left to worker (Director-lean: silent
  normalize)

Brief now dispatchable immediately, no producer signal needed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation

Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment
substrate path, but the design doc §4 explicitly recommends totality-by-
omission as the Director-actionable path. Predicate-entailment is M+ scope
that reopens DB-11's explicitly-closed asymmetric-strip design — design
doc explicitly discards it.

feedback_verify_thesis_claims violation again — same family as nested-
optional reframe. Should have read design doc §4 in full before assuming
the path ordering.

Rewrote brief to match design doc §4 follow-on shape:
- Primary path: per-class totality-by-omission (algebra retype + per-
  target realization migration). For Int/Int: OrderedRing.div retype
  at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 /
  python:486 + python_target.rs:680 helper).
- NOT predicate-entailment (out of scope; M+ + DB-11 reopen).
- NOT NonZero-typed-input (deferred to separate per-operand-variance
  substrate brief; STOP-AND-ESCALATE if chosen).
- Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i]
  indexing, quotient, remainder) queue separately per design doc audit.
- feedback_totality_by_omission discipline anchor explicit.

Brief now matches feedback_totality_by_omission discipline + design doc
recommendation. No substrate prerequisite; dispatchable immediately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure

Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a
pattern: I authored R2 worker briefs without fully reading each design
doc's Director-actionable recommendation. Pre-emptively re-verified
unenumerated-effects against design doc §Q6 to catch the same family
of error before reviewers do.

Findings: brief was substantively close but missing 3 of 8 design-doc
reqs:
- Req 3: Resource-threading discipline applied to existing primitives
- Req 5: reread(key) primitive in std/ as explicit Slice item (was
  only mentioned in tests)
- Req 7: Asymmetric-tightening worked example in PR body

Plus: Slice didn't cite the canonical lens path
src/v3/lenses/effect_enumeration.dag from design doc.

Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6
specifies 4 specific STOPs (path-decision-escalation, pure: Bool
carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP)
that I had elided.

Reframed Slice as 8 numbered reqs matching design doc verbatim;
STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs;
Acceptance enumerated per req.

This is the third reframe in the unhandled-bugs series — same
feedback_verify_thesis_claims violation each time. The pattern
suggests Director-side R2 brief authoring should ALWAYS read each
design doc's §Director-actionable / §Q-recommendation in full first,
not assume.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options

Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)"
listed as a worker-pick option violates THESIS.md substrate-shape
lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality |
Instantiation) are canonical (per #811 thesis additions and #827 PM
review); a 7th is a C1 stop signal requiring failed-dissolution
evidence + Director substrate-design call, not autonomous worker pick.

Removed the "new TypeConnective variant" option; replaced with
`inhabits`-edge-shape carrier as third option (audit-time check). The
explicit STOP-AND-ESCALATE clause now states: 7th connective is the
precondition for failed-dissolution-evidence + Director substrate-design
call, not a worker path.

feedback_verify_thesis_claims still in play — should have grounded
substrate-shape options against the THESIS lock before listing Opaque(T)
as worker-autonomous. Pattern continues; reading source-of-truth before
authoring options is the discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place)

Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter
already exist at dag.rs:186, :217 — explicitly authored for the
R2 Dimensions consumer per the doc comment at dag.rs:148-160.
phantom_unit_mismatch already wired at infer.rs:1057, :1132. The
substrate is fully landed; my brief framing it as 'producer sub-lane
to land carrier' is wrong on the same feedback_audit_adjacent_authority_first
violation that hit nested-optional / unhandled-diagnostic / unenumerated-
effects.

Reframed the substrate-side brief as no-op / closed-by-audit:
- Documents the audit receipt (5 sites confirming substrate exists)
- States the lane is closed
- Routes T-Modeling Dimensions consumer to dispatch immediately
  against the existing carrier
- Records the lesson: 'always grep substrate before authoring
  producer briefs' — discipline doesn't end at brief boundaries.

Updated r2-modeling-dimensions-phantom-worker.md correspondingly:
- Changed gating from 'do not dispatch until producer signal' to
  'NOT GATED — dispatch immediately'
- Read-first updated with concrete dag.rs/infer.rs cites
- Slice §1 changed from 'confirm producer signal' to 'verify
  substrate at HEAD'
- STOP reframed: existing carrier extension would need Substrate
  Manager call, not autonomous worker pick

Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit
both verified — no existing substrate (no is_nominal_opaque /
MagnitudeBound patterns in dag.rs); both still legitimately
producer-side work.

Pattern is now four reframes deep on the R2 spin-up wave. The lesson
saved is structural: read source-of-truth before authoring options.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority

Codex BLOCKING on #836: my new R2 spin-up brief duplicates the
existing t-substrate-cardinality-int-lit-worker.md, which carries
the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64)
stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane).
Single-authority violation per INVARIANTS P2.

Same feedback_audit_adjacent_authority_first failure as parametric-
algebra-for-Dimensions reframe (4 hours ago): assumed substrate
authority didn't exist; should have grepped docs/briefs/ before
authoring. This is the SECOND R2 spin-up substrate brief closed
as redundant — the discipline lesson is structural.

Reframed brief as no-op routing doc (documents the audit receipt;
routes consumers to the existing authority); updated
r2-modeling-int-lit-magnitude-worker.md to cite
t-substrate-cardinality-int-lit-worker.md instead.

Pattern across the R2 spin-up wave reframes (5 now):
1. nested-optional gating-on-substrate (substrate already past
   cardinality bridge)
2. unhandled-diagnostic predicate-entailment default (design doc
   recommends totality-by-omission)
3. unenumerated-effects 8-req design-doc elision
4. parametric-algebra Producer (Declaration.phantom_params already
   authored explicitly for this consumer)
5. cardinality-for-int-lit Producer (existing brief …
briansrls added a commit that referenced this pull request Apr 29, 2026
… + bin-shim emit pattern) (#1176)

* docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation)

Director-authored amendment following the 2026-04-24 escalation from PR
#693 (sub-child sharp-bear-829 under Surface Manager).

Two edits:

1. New "Class 5 Gap 3 — port-carried field values in data bodies"
   row in the 2026-04-21 post-merge-debt section. The substrate gap was
   documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP
   ledger row for cross-lane visibility. PR #693's execution surfaced it
   as the blocker on sub_charclass_in_std_unicode phase-2.

2. Retract the "ready-to-dispatch (no substrate capability gap)" claim
   on the Character-level row, annotate phase-1 landed via PR #693
   (CharClass vocabulary + Rust-mirror structural scanner path), and
   point phase-2 at the new Class 5 Gap 3 row.

Codifies the audit pattern: "this consumption gap has no substrate
capability gap" claims must be verified by attempting the retype before
the claim lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main

* docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review)

* docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review)

Row title still said 'consumption gap, not substrate gap' while the
body block retracted that claim and cited Class 5 Gap 3 as a substrate
dependency for phase-2. Title now matches body: mixed classification,
consumption for steps 1+3, substrate for step 2.

* docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit)

gpt-5.4's review on 706 @ 71f46afe caught that the row's "remaining
gap" description was wrong: field-level shapes (nested records, list
literals, declaration refs, Var refs, sum-variant literals) are
supported today via FieldValue variants + lower_structural_field_value
(dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the
top-level ValueBody boundary (non-scalar, non-record top-level bodies).

The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself
stale: it describes the pre-PR-B-unwind shape where FieldValue was
LiteralBits-only. PR-B's unwind extended FieldValue to carry
Reference / Record / List / Variant, moving the gap to ValueBody.

Two fixes:

1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody
   boundary, point at code paths (dag.rs, lower.rs) as live authority,
   flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass
   blocker classification to "provisional pending reproduction."

2. Update the Character-level row's phase-2 block to name that the
   specific shape of the CharClass failure needs concrete reproduction
   from the escalating sub-child before the blocker is finalized.

Recursive audit-pattern instance: the row I wrote to codify "verify
live state before claiming substrate gap" itself failed to verify live
state. Both incidents (2026-04-23 original row + 2026-04-24 my
retraction row) are now cited in the audit-pattern sub-note as
examples of the same discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* WIP: gunbc Director

* docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c33

Three substantive fixes addressing internal-consistency gaps in the cascade
promotion PR caught by codex review at sha 0d6e7c33:

1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane
   acceptance bullets and Hand-Rust census paragraph in line with the
   updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero
   (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is
   retracted under 0-floor with explicit migration to ExecuteCommand-based
   .dag TestClaim declarations.

2. docs/design-pure-bootstrap-zero.md promotion section — converted from
   future-tense ("This doc is PROPOSAL until promoted… promotion is a
   single Director-authored cascade PR…") to historical past-tense
   promotion-receipt framing ("This doc was PROPOSAL until promoted;
   promotion was a single Director-authored cascade PR that did all of the
   following atomically…"); blocking-clause struck through and resolved
   inline. Banner cites PR #782 explicitly.

3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_
   profile excluded (Map<String, AlgebraProfile> body, not list-of-sum;
   needs distinct ValueBody::Map substrate work, tracked separately as a
   future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass
   phase-2 + Engine sharpened-(b) pilot enumeration), both sharing
   list-of-sum substrate work. Lane table, dependency DAG, and capacity
   summary updated for consistency (slot count 9-13, was 10-14).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities

Resolves claude REQUEST_CHANGES at sha fed6b032 — atomic-cascade
self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22
explicitly names THESIS.md and "any other authority docs" as required
retraction targets; the prior diff updated ROADMAP + r2-structure + design
docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting-
manager.md pointing at the now-SUPERSEDED ≤5-floor framing.

Files:

- THESIS.md (5 prose blocks updated):
  - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests
    migrate to ExecuteCommand-based .dag TestClaim declarations.
  - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag.
  - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor
    target citing design-pure-bootstrap-zero.md as live authority;
    hand_maintained_src list shrinks to empty set.
  - :301-318 — Tests-are-structural-data block: residual carve-out retracted;
    predicate name pb_rust_tests_outside_residual_zero retained as
    housekeeping (semantically the residual is empty under cascade).

- docs/thesis/compiler-std-consolidation.md (5 references):
  - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes
    design-pure-bootstrap.md (SUPERSEDED).
  - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process
    lane named as the dissolution trigger for bootstrap.rs itself.
  - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md.
  - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority
    re-cited.
  - :185 Related docs link.

- docs/briefs/r1-selfhosting-manager.md (active dispatch brief):
  - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5);
    T-PB-B residual carve-out retracted; predicate names retained for
    housekeeping; cascade-promoted authorities are source of truth.
  - Slice descriptions for T-PB-A / T-PB-B updated inline.
  - Framing-question + ask updated to 0-floor / no-residual framing.
  - Day-1 + up-to-director hand-off bullets updated.
  - Working-state checklist :111 ≤5 → 0 with cite.
  - Decisions log :164 ≤5 → 0-floor target updated.

- docs/r2-structure.md §2 design call (RETRACTED block):
  - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through
    in entirety (both Option A sharpen-and-keep and Option B rename are
    moot under 0-floor). Section preserved as audit-trail historical
    context.
  - Background-doc index: self-hosting anchor updated to
    design-pure-bootstrap-zero.md as live authority.

- docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per
  non-blocking suggestion):
  - Banner cites cascade promotion PR #782 explicitly.
  - New paragraph: "Treat all numeric floors below as retracted" with
    explicit lines named that quote in isolation (table row, body prose
    references). Prevents re-quoting from this doc as live authority.

Cascade is now atomically consistent across:
  THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔
  docs/thesis/compiler-std-consolidation.md ↔
  docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔
  docs/design-pure-bootstrap-zero.md (LIVE) ↔
  docs/design-pure-bootstrap.md (SUPERSEDED).

The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds
genuinely.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): correct ExecuteCommand runner-capability claim

Resolves codex BLOCKING #1 at sha fed6b032 (P1 live-state violation):
TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138
overstated live runner capability — claimed runner support landed in
PR #688/#741 with "emit Rust, invoke rustc on output, check exit code"
as a structurally-equivalent migration path. Verified against live
sources:

- src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema
  exists (declared via PR #678).
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5
  testgen harness allowlists ONLY `command == "true" && args.is_empty()
  && expect_exit == 0`.
- src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 —
  panics fail-closed on any other shape with explicit "ExecuteCommand
  shell shape is not supported here (runner-owned — do not treat as
  ordinary false)".
- src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no
  match arm for ExecuteCommand; falls through to ClaimResult::
  NotYetImplemented.

Reality: a TestClaim declaring rustc/python/go invocation is
structurally expressible as data today, but executing it is blocked.
Full arbitrary-command runner support is the PB-Runtime lane's
deliverable.

Files updated:

- TESTING.md:195 — capability state callout with file:line citations;
  "Full runner support — arbitrary command + args (rustc/python/go) with
  exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor
  program)." Bullet about migration shape preserved as the cascade-named
  successor pattern, not as a live capability.
- TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane
  lands the ExecuteCommand runner extension" as an explicit precondition.
- docs/design-pure-bootstrap-zero.md:138 — same correction for the
  matching prose, with PB-Runtime named as the runner-extension
  dependency for boundary-test migration.
- ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner
  foundation in #688/#741 with `true`-no-args allowlist only — full
  arbitrary-command runner support deferred to PB-Runtime lane,
  blocking the actual boundary-test migration." Dependencies column
  extended to "DB-15 + T-TestGen + PB-Runtime".

The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still
holds for atomic-cascade-across-authority-docs; this commit closes the
remaining capability/claim mismatch flagged by codex.

(Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still
SUPERSEDED-pointing — was sha-stale; resolved in c85e6916d.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief

Resolves codex BLOCKING at sha 0fb223a1 (P2 single-authority violation).
The prior banner contained:

> "Operationally R1 closure may still ship before the 0-floor is reached
>  — the ratchet ensures the trajectory; the gate's acceptance number is
>  what shifts."

This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0.
Two competing gate semantics in the cascade is exactly what the
atomic-cascade clause forbids.

Replaced with single-authority-honest framing:

> "R1 closure now requires the 0-floor target by gate semantics: T-PB-A
>  and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade
>  promotion changed their acceptance numbers to 0; R1 cannot close
>  while the SG-0 census carries non-zero hand-Rust."

Plus minor sharpening:
- "T-PB-A's non-test target is 0" → "non-test acceptance target is 0
  per ROADMAP.md:67" (cite the authority).
- T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep
  the capability-state honesty consistent with the recent fix wave.
- Predicate-rename housekeeping line moved into banner ("post-cascade
  housekeeping, not a pre-promotion blocker") — was implicit before.

The brief now genuinely inherits the cascade-promoted gate; no
competing release authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 second-wave worker-escalation fixes

Four substantive worker STOP-AND-ESCALATEs from briefs landed in
PR #797. All four worker recommendations correct; each needs a
Director call + brief update.

## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate

Worker correctly identified that brief req 2 (declared-effect carrier
as part of fn type signature, per feedback_no_annotations) requires
net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at
src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots.
Without parser surface, every user function would have
declared_effects = [] while inference returns non-empty — lens fires
EffectLeakageError everywhere on enable. Worker rejected power-through
and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map
parser split).

Director picked split:
- NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md
  Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface
  syntax + lookahead + body parser + lowerer extension + exhaustive-match
  audit + coproduct dissolution receipt.
- MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to
  post-parser-extension scope. Pre-flight check NOT a parser-extension
  step; STOP if parser sub-lane PR not merged.

## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping

Worker found load-bearing evidence at infer.rs:3693-3703: DB-11
deliberately strips refinements at operator dispatch as a designed-in
fix for symmetric-operators failure mode. Brief's "attach where b != 0
as a proof for a / b" directly contradicts this design choice. STOP-3
(where-clause conflict with DB-11) is real; STOP-1 (substrate scope)
needs net-new substrate (per-operator partiality fact + predicate-
entailment check + asymmetric per-operand refinement-honoring) — M+
minimum. ownership_lens precedent in original brief is post-hoc
observability, not proof carrier.

Worker recommended redirect to design/scoping per nested-optional
precedent. Director picked redirect.

Brief fully rewritten as design/scoping with four-question structure:
(1) DB-11 interaction analysis; (2) substrate proposal for proof-or-
totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes
with acceptance-theatre risk on user-defined-total-wrapper-only);
(4) Director-actionable recommendation. Output is doc PR.

## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C)

Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int)
with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136
closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b)
i128 implementation requires either path 1 (hierarchy refactor —
contradicts non-goal) or path 2 (regen lie between substrate and
emit — violates discipline). Worker leaned option (C) re-scope:
land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke)
to a sibling sub-lane that does proper Int128/Word128 substrate work.

Director picked option (C). Brief req 1 re-scoped to drop canonical-
carrier-widening; lane value comes from range facts + reconciliation
narrowing + out-of-range diagnostic against existing i64. Req 4
explicitly deferred with sibling-sub-lane reference. Sibling sub-lane
NOT to be authored or implied in this PR; tracked separately.

## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change)

Worker correctly STOP'd per the brief's own pre-flight check: parser
sub-lane has not landed; SurfaceExpr::Map not on main. Director
authorized cross-lane reassignment: wise-boar-480 takes the parser
sub-lane (t-substrate-valuebody-map-parser-worker.md) since they
already have full investigation context. No brief changes needed; the
routing decision is in the dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope

Resolves codex P2 inline at sha e35103fad on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer
carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still
required widening LiteralBits::Int(i64) to an unbounded carrier and
passing the i64::MIN smoke. Internally unsatisfiable.

Fix:

- Slice section retitled "range facts + reconciliation narrowing
  (against existing i64 carrier)" with explicit note about the
  re-scope.
- Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly
  forbids touching LiteralBits::Int shape, dag_scalar_generated.rs
  regen for that variant, or tokenize i64 parse path.
- Slice steps 2-5 reframed: range facts use i64-representable
  magnitudes; reconciliation narrowing uses existing i64 carrier;
  diagnostic only for i64-representable out-of-range; smoke tests
  for req 5 only (req 4 i64::MIN deferred).
- Acceptance checklist updated:
  - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as
    re-scoped/deferred.
  - LiteralBits::Int(i64) carrier untouched (no widening; no
    parallel; no shape change).
  - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference.
- STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the
  carrier" — explicit STOP if execution surfaces range-fact narrowing
  requiring carrier-widening; that's the boundary the re-scope drew;
  belongs in sibling Int128/Word128 sub-lane.

Brief now consistently treats carrier-widening as out-of-scope across
all sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty

Resolves codex BLOCKING #1 at sha e35103fa on
docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real:
the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier
but req 2 required range facts using "the SAME magnitude carrier
as req 1" — meaning i64-typed range bounds. u64's max (2^64-1)
doesn't fit in i64; range fact for u64 would have to truncate,
omit, or mirror in Rust (representation drift). All three options
violate fail-closed declared-facts discipline (P1 / P3).

Fix:

- Req 2 rewritten to specify String-decimal representation:
  range_min_inclusive: String + range_max_inclusive: String fields
  on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127"
  for i8; "0"/"18446744073709551615" for u64).
- Explicit reasoning why String-decimal: u64's max doesn't fit in
  i64; binding range bounds to literal carrier forces truncation/
  omission/mirror-drift; all violate fail-closed declared-facts
  discipline.
- Bridge framing: String-decimal is pending the sibling Int128/
  Word128 sub-lane; both range bounds and literal payload migrate
  to typed carrier when that lands.

- Req 3 updated for String-decimal comparison semantics:
  reconciliation parses both bounds and literal magnitude into a
  common comparison space (i128 host comparison primitive — host
  narrowing, NOT carrier widening). Bounded by what the i64-typed
  literal can express; any i64-representable literal compares
  against any width's String-decimal bound. Carrier discipline
  preserved.

Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral)
is sha-stale — already resolved at 3e142d169.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed

Resolves codex BLOCKING at sha 0815189a (post-#799-merge feedback).
Real residual: req 2 specifies String-decimal range bounds (to cover
u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance
bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" /
"i64-representable magnitudes" for the range facts. Two incompatible
authorities for the same range-fact shape — would let a worker satisfy
the slice while truncating/omitting u64 bounds (P3 fail-closed
violation).

Fix:

- Line 31 (req 1 re-scope clarification): updated to explicitly state
  "range facts (req 2) use String-decimal representation (width-
  independent; covers u64::MAX which doesn't fit in i64)". Distinguished
  literal *payload* (stays i64) from range-bound *representation*
  (String) — both serve req 1's "no carrier widening" boundary.
- Line 44 (slice step 2): updated from "Range bounds use i64-
  representable magnitudes" to "Range bounds use String-decimal
  representation per req 2" with concrete example (u64 bounds).
- Acceptance bullet: updated from "Range facts on integer algebras
  (substrate-declared, not Rust-mirrored)" to add "using String-decimal
  representation ... width-independent; u64 bounds expressible without
  truncation."

The brief now consistently treats range bounds as String-decimal
across req 2, req 3, slice, acceptance, and the req 1 clarification —
no remaining authorities saying i64-typed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing

User + PM exchange 2026-04-25 surfaced that the in-flight effects
chain was importing wrong assumptions from external languages
(declared-effects-as-annotation + lens-vs-declaration check). Right
framing under gunbc's closed-system discipline is parallel to
complexity: every effect derives structurally from the composition
of typed primitive operations; nothing can hide because there's no
escape hatch; nothing needs annotation because the structure IS the
registry.

Four doc-only actions:

1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md.
   Frames the closed-system answer with PM's 5-behavior synergy
   table (Value/Transform/Branch/Loop/Bind as universal
   compositional-fold pattern). Four worked examples; aggressive
   reading on redundancy (compile-error-by-construction via
   referential-transparency proof; reread() primitive for legitimate
   cases); implementation-brief shape in §Q6.

2. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md.

3. SUPERSEDED banner on
   docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md.
   Notes Fn→Arrow refactor brief stays dispatchable as independent
   value.

4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by-
   construction framing replaces lens-detection framing.

Memory file feedback_closed_system_effects.md saved separately;
cross-link added to feedback_construction_over_ratchets.md.

Net cost: doc-level cleanup. Zero substrate code rework. Foundation
(OperationEffect + service-call infrastructure + 5-behavior
substrate) already exists.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect

Per PM convergence review on #808 + user's deeper 2026-04-25 framing:
the closed-system framing landed in #808 retired the user-facing
annotation but kept OperationEffect taxonomy as substrate-level tagging.
User's deeper framing: the taxonomy ITSELF is parallel-representation —
operations are intrinsically read-shaped or write-shaped via their
TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns-
derived-value-only → read). Tagging operations with Read | Upsert |
Create | Append | Delete names what the structure already says.

Three changes:

1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as
   normalized view, or retire as parallel-representation?"
   - Two paths: (i) tags derived from signature shape (acceptable
     normalized view) vs (ii) tags declared per-primitive (parallel-
     representation; retire).
   - Audit-as-existence-check (Q4 req 2 reframed): all effectful
     primitives derive cleanly from signature shape → path (i); any
     primitive needs hand-declared tag → path (ii) by existence proof.
   - Director default: path (ii). Logging primitives that return Unit
     are likely the audit's existence-proof.
   - Two design-question resolutions: (a) external effects not in
     return type → resource-threading discipline (typed param returned
     modified, IO-monad-without-the-monad pattern); (b) transactional
     grouping → derived structural fact from Bind composition + typed
     transaction primitives.

2. Q4 reqs revised: req 2 from "tag every primitive with explicit
   OperationEffect signature" to "audit-as-existence-check that every
   primitive's type signature derives the right effect classification";
   req 3 added (resource-threading discipline); req 6 added
   (transactional-pattern lens). Req 1 (effects lens) anchors on
   operation type-signature shape, not on hand-declared tags.

3. THESIS:345-347 amendment strengthened — "operations are
   intrinsically read-shaped or write-shaped via their type-signature
   shape; consumers walk the signatures directly; there is no parallel
   taxonomy or annotation layer to declare or maintain. Tracking
   effects as a separate enumerated concept IS the bug pattern,
   dissolved by construction." Plus references to resource-threading
   discipline + transactional grouping as derived structural fact.

Memory file feedback_closed_system_effects.md updated to reflect the
deeper framing (type-signature-shape, not taxonomy-tagging) +
resource-threading discipline section + transactional-patterns
section.

Net cost: doc-only delta on top of #808. Substrate retirement
(OperationEffect enum + derive_op_effect + idempotency.dag re-anchor)
deferred to the audit-as-existence-check phase of the implementation
brief; surfaced as Q5.5 OPEN CALL.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage

Resolves codex BLOCKING at sha d49ce79a on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real:
the prior text claimed service primitives "already carry typed effect
signatures" presenting future audit-state as current substrate fact
(P1 violation). My Q5.5 amendment at 2dc656bbe partially fixed the
OperationEffect line but left a parallel over-claim on the new
"signature-shape coverage" framing.

Fix: Q4 substrate-state listing rewritten to honestly distinguish:

- Live: Behavior enum + substrate foundation (the principle that
  operations should carry signature shape).
- Incomplete: signature-shape coverage across actual primitives.
  HTTP-derived primitives carry implicit shape via derive_op_effect's
  method-table; logging/mutation primitives that return Unit or don't
  thread their target resource do NOT carry the structural shape that
  would express read-vs-write. Achieving full coverage is required
  work under reqs 2 + 3, not a current fact.
- Pending audit-as-existence-check: OperationEffect + derive_op_effect
  (path (i) vs (ii) per Q5.5).

Honest live-state callout added explicitly: "the closed-system
FOUNDATION (5 behaviors + DAG substrate + the principle that
operations should carry signature-shape) is live. The IMPLEMENTATION
COVERAGE across all effectful primitives is partial. Req 2 + req 3
are the work that closes the gap."

Brief now distinguishes principle-is-live (foundation) from
coverage-is-partial (audit work) without conflating them.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim

Per PM follow-up review on #808 + user's stronger discipline framing
("substrate must make bypass structurally impossible at every layer
of the transport stack"): the closed-system claim is honest only when
typed primitives ARE the path. Today two structural holes exist where
bypasses sidestep the typed-primitive substrate. Both surfaced
explicitly as Q4.5 pre-conditions — load-bearing for the lens's
coverage claim.

Three changes:

1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed-
   system claim)" inserted between Q4 and Q5:

   P1 — Extdeps typed-primitive consumption structurally enforced.
   Substrate must make `messages: Json` impossible to declare in
   service definitions; typed `LlmMessage` / `ContentBlock` /
   `GitHubAuthToken`-with-full-scopes are the only path. Tracked
   debt at ROADMAP.md:153-154 (LLM provider flattening) +
   `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded).
   Required prereq for full lens coverage; lens can land first +
   surface structural-coverage-gap diagnostics on bypass surfaces
   so the gap becomes visible rather than silent.

   P2 — `ExecuteCommand` fully materialized as typed runner
   primitive. TESTING.md (post-#782) committed to 0-residual but
   ExecuteCommand isn't fully materialized; deleting Rust boundary
   tests creates verification gap. Already named under PB-Runtime
   in Zero-Floor; signal pending. Pre-requisite for ANY Rust
   boundary-test deletion.

2. Old leftover duplicate Q5 section deleted (artifact from prior
   Q5/Q5.5 reshape; second copy of asymmetric-tightening text was
   in the file alongside the earlier Q5 instance).

3. Worker-discretion-vs-Director-call section in Q4.5: lens
   implementation worker dispatchable now (reports gaps as
   findings); P1 closure is substantive substrate work touching
   extdeps (dedicated lane); P2 closure is PB-Runtime (signal
   pending).

Net: design doc now honestly distinguishes principle-is-live
(Q4 rewrite at 191be310b) from coverage-is-partial (Q4.5 prereqs
named explicitly). The closed-system claim has explicit pre-
conditions documented; implementation brief discovers them as
known dependencies, not as STOP-AND-ESCALATEs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default

Resolves claude APPROVE_WITH_COMMENTS at sha 191be310 on #808. Two
real residuals after the Q5.5 reframe:

1. Q6's reqs/STOPs/acceptance still framed under path (i) — said
   "audit + tag std/ primitives — every effectful primitive carries
   an explicit OperationEffect signature." Directly contradicted Q4
   (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment
   ("there is no parallel taxonomy to declare or maintain"). Worker
   reading Q6 in isolation would author the retracted shape.

2. Capacity / sequencing table line about "audit lane (tag std/
   primitives with effect signatures)" carried the same stale
   framing.

3. Q6 STOP "primitive performing side effects without an
   OperationEffect tag" assumed tag-as-authority; under path (ii)
   the STOP shape is "primitive whose signature doesn't structurally
   reveal its effect."

Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale
(already fixed at f073aa95e Q4.5 commit).

## Q6 fixes

- Reqs renumbered + reframed:
  - Req 1 anchors on operation type-signature shape (not hand-declared
    OperationEffect tags); composition reads from signature shape per
    Q2 table.
  - Req 2 changed from "audit + tag every primitive" to
    "audit-as-existence-check" — verify signature-shape coverage; ANY
    primitive needing a hand-declared tag IS the existence-proof for
    path (ii) retirement.
  - Req 3 added: resource-threading discipline applied to existing
    primitives (logging that returns Unit gets reshaped per audit).
  - Req 6 added: transactional-pattern lens (Bind composition +
    Transaction → Transaction').
  - Req 7 added: asymmetric-tightening worked example in PR body
    (per claude review observation; the one place declaration-shaped
    surface re-enters).
  - Req 8 (was 5): tests now reference signature-shape derivation
    explicitly, not tag lookup.
- STOPs reframed:
  - "OperationEffect retirement decision" — audit produces path (i)
    vs (ii) verdict; substrate retirement is its own dedicated
    sub-lane; this lane does NOT absorb it.
  - Pure/impure carrier STOP notes that "pure" should also derive
    from signature shape (pure functions don't return modified
    resources) — so the STOP itself may dissolve under further design.
  - Q4.5 P1 explicitly NOT a STOP — lens reporting structural-
    coverage-gap on extdeps bypass surfaces is the lens delivering
    its foundation-gap-visibility value.
  - Q4.5 P2 explicitly independent — lens doesn't depend on
    ExecuteCommand materialization.
- Acceptance extended: lens reports gap diagnostics on P1 bypass
  surfaces; audit produces existence-proof verdict for Director
  re-decision; asymmetric-tightening worked example in PR body.

## Capacity / sequencing table

Replaced "1 audit lane (tag std/ primitives with effect signatures)"
with "1 audit-as-existence-check lane (verify primitives' signature-
shape coverage; NOT 'tag every primitive') — produces the path (i)
vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2
prereq lanes to the net summary. Closing line: "The taxonomy-
retirement scope (substrate-side) is not in this lane — it's
surfaced by audit and routed to dedicated retirement lane if path
(ii) wins."

Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity
table. Worker reading Q6 in isolation now sees path-(ii)-default
framing matching Q4 + Q5.5 + THESIS amendment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792

Resolves codex inline BLOCKING at sha 191be310 on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150.
Real: my Q4.5 P2 framing described ExecuteCommand as still
NotYetImplemented (M1.5 allowlist + Rust TestRunner returning
NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand
extension before this PR's authoring. TESTING.md:195 capability-state
callout confirms:
- Rust TestRunner + M1.5 testgen harness share one std::process path
  for arbitrary command + args + expect_exit_code.
- M1.5 allowlist + fail-closed panic retired.
- Distinguishable ClaimResult::Fail messages for spawn / timeout /
  policy / exit-mismatch.
- Linux unshare(1) namespace isolation on host-allowing systems.
- T-PB-B-1 boundary migration example landed.

Fix:

P2 section rewritten:
- Header retitled "ExecuteCommand runner primitive: LANDED (PR #792);
  residual is bulk-migration."
- Status update naming PR #792 + the post-#792 capability state
  (allowlist retired, etc.).
- Honest acknowledgement: "My earlier P2 framing was stale."
- Residual narrowed to bulk-migration of existing Rust Command::new
  boundary tests (tracked as ROADMAP residual, not lens prereq).
- Sequencing reframed: P2 was always orthogonal to the effects lens
  itself; bulk migration proceeds at its own pace; lens not blocked.

Q4.5 footer updated:
- "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via
  #792; only consumer-side bulk migration remains)"
- Worker-discretion-vs-Director-call P2 line updated: "runner
  primitive landed; only consumer-side bulk migration remains;
  tracked as ROADMAP residual, independent of the lens."

Q6 STOP for P2 updated:
- "the lens itself doesn't depend on P2; only TESTING.md's 0-residual
  claim does" → "runner primitive landed via PR #792 (post-Q4.5-
  authoring update). The lens itself never depended on P2; bulk
  consumer migration is residual ROADMAP work and remains independent
  of this lane."

Brief now reflects live state. The closed-system claim's prereq
landscape is honest:
- P1 (extdeps typed-primitive consumption): real prereq, tracked
  debt at ROADMAP:153-154.
- P2 (ExecuteCommand runner): satisfied via #792; bulk migration is
  consumer-side residual, not foundation work.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale

Resolves codex non-blocking finding at sha bcac41bb on
docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real
residual: capacity-table line still listed P2 as "`ExecuteCommand`
materialization" prereq + framed both P1 and P2 as "pre-existing
tracked-debt" — but my prior 57a9b1318 fix established that PR #792
already landed the runner primitive, so P2 is no longer a
materialization prereq.

Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq)
from P2 (residual, not prereq):

  - P1: extdeps typed-primitive consumption — pre-existing tracked
    debt at ROADMAP:153-154; load-bearing for the lens's full-coverage
    claim.
  - P2: ExecuteCommand runner primitive landed via PR #792; only
    consumer-side bulk migration of existing Rust Command::new
    boundary tests remains (tracked as ROADMAP residual, independent
    of the lens; not a materialization prereq).

Brief now consistently treats P2 as bulk-migration-residual across:
- §Q4.5 P2 section header (LANDED via PR #792; residual is
  bulk-migration).
- §Q4.5 footer (P2: runner primitive landed; only consumer-side
  bulk migration remains).
- Q6 STOP for P2 (runner primitive landed; bulk migration is
  residual ROADMAP work).
- §Capacity / sequencing impact (P2 as residual, not prereq).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349

Codex finding on PR #808 sha ece964e9: lines 153-154 are unrelated
target-grounding prose; the matching extdeps typed-primitive bypass
entries (LLM service flattening, GitHub auth model bypass) live at
ROADMAP.md:348-349.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): fix third stale ROADMAP citation at line 271

Codex follow-up on sha 2552ca3b: prior fix missed a third occurrence
at line 271 in the §Q4.5 capacity table. Now consistent with lines
139 and 173 (ROADMAP.md:348-349).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity

Codex flagged 'Effect-signature tagging on std/ primitives' as potentially
contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240)
already explicitly say 'NOT tag every primitive' — but the cross-manager
line used sloppy wording. Reworded to make explicit that the audit walks
signature shape; no parallel tag added.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5

- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound
- B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause
- B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge
- B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation)

B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25):
language vocabulary is primitives + namespacing only; no escape syntax;
the §0 sentinels are the compiler itself failing to use primitives +
namespacing internally. Eight surface sites dissolve via four
substrate carriers (DeclarationRef, structural fold-shape carrier,
structural emit-helper carrier, structural extdeps-fixture-set
carrier).

B1-B3 are independent; dispatch in parallel. B4 is sequential program
work; sub-brief dispatch (B4.1-B4.12) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — drop incoherent inner-fallback non-goal

Codex P2: the non-goal line excluding the inner declaration().name
unwrap_or_else fallback contradicted Slice step 2, which replaces the
whole chain with let-Some-else-return. Both fallbacks are in scope by
construction; remove the contradictory non-goal.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives

PM REQUEST_CHANGES: §Frame listed '4 type connectives
(Conjunction | Disjunction | Cardinality | Bit)' which contradicted
the canonical thesis source. Replaced with the canonical 6
(Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per
docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary
closes here'. Also removed 'typed substrate carriers' from the
vocabulary list — substrate carriers are defined using the vocabulary,
not part of it. Added a clarifying note that B4's carriers
(DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are
typed declarations composed from the vocabulary, not vocabulary
extensions.

Per feedback_verify_thesis_claims: brief framings citing thesis
structure must ground in the canonical source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority

Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of
naming the live substrate authority. Two coordinated fixes:

1. §Read first cites src/v3/std/substrate.dag (live .dag substrate
authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel
meta-type — already exists with consumers in verification.dag,
emit_model.dag, python.dag).

2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing
DeclarationRef'. The work is consumer migration + any role-extension
layer the audit reveals, NOT designing or landing the carrier.

Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers)
keep their 'new' framing but explicitly require sub-briefs to grep
src/v3/std/ + src/v3/spec/ for existing authority before authoring
'design and land' framing — per feedback_verify_thesis_claims +
feedback_emitter_workaround_is_gap_symptom.

Acceptance + sub-brief dispatch order updated to reflect B4.1's
consumer-migration shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — tighten Phase 1 umbrella sentence

The umbrella 'Land the typed carriers into src/v3/std/' framing was
stale after f52e2cea7's reframe of #1 to consumer-migration. Replaced
with audit-first wording that covers both the consume-existing case (#1)
and the design-and-land case (#2-#4 if their audits show real gaps).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording

Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands'
which conflicted with the post-reframe reality that B4.1 consumes the
existing DeclarationRef. Updated to 'consumes or lands' with explicit
existing-authority citation and audit-pending caveat for B4.2-B4.4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — soften regression-test requirement (3 worker bounces)

Three consecutive B1 worker dispatches (zesty-crane-890 cursor →
valiant-boar-498 codex → cool-lynx-395 cursor) archived without
opening a PR. Likely friction point: brief Slice step 4 asks for a
unit test that constructs a Dag with an orphan variant declaration,
but emit.rs has zero existing #[test] precedent — emit testing
happens via integration fixtures. Workers see 'build novel test
harness' inside what's billed as an S-scope fix and bounce.

Per feedback_construction_over_ratchets: when a brief has friction,
fix the brief, don't ratchet the worker.

Softened step 4 + acceptance: regression test stays optional. If
test setup requires novel scaffolding, route the gap to follow-up.
The structural fail-closed at step 2 is the load-bearing change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — convert deferred-test skip into tracked ROADMAP debt

PM APPROVE_WITH_COMMENTS on #818: 'skip and note in PR description'
is too weak; PR descriptions don't survive squash-merge cleanly.

Two coordinated edits:
1. Slice step 4 — explicit substrate-signal framing: skipped test
   means emit-side hermetic-unit-test infrastructure is the missing
   substrate (feedback_emitter_workaround_is_gap_symptom).
2. Acceptance — require ROADMAP debt row (new or existing) with
   named dissolution trigger, referenced in PR body. Converts the
   skip from PR-local note (transient) into tracked debt (durable,
   dispatchable).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — restore test requirement; precedent verified at emit.rs:3124

Codex BLOCKING: my earlier softening claimed emit.rs had no #[test]
precedent — wrong. The module has #[cfg(test)] mod tests at line 3124
with 12+ tests using compile_to_dag(source, filename) as harness
(e.g., go_struct_fields_render_with_separators :3143,
shared_walk_to_disj_finds_match_scrutinee_sum_type :3195).

This is a feedback_verify_thesis_claims violation on Director-side
brief authoring — claim made without grep verification.

Fix: restore step 4 as required, with explicit precedent citation.
Worker constructs the failure case via the existing harness
(direct Dag, fixture string, or BranchPattern exercise; worker's
call on cleanest path). STOP-AND-ESCALATE only if construction
proves materially harder than precedent suggests, in which case
that escalation surfaces a real substrate gap and warrants ROADMAP
debt — but the default is 'add the test.'

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B1 — fix test count accuracy (12 tests, 8 compile_to_dag sites)

Codex P1 live-doc accuracy: said '12+ tests using compile_to_dag' but
emit.rs has 12 tests total with 8 compile_to_dag call sites. Reworded
to 'several using compile_to_dag'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 1 — B4.2/B4.3/B4.4 worker briefs + Phase 2 queue

Per inbox issue #828 (PM/Director split for R2 spin-up readiness): this
is Wave 1 of Director's 14-brief authoring queue, covering B4 program
internals.

Authored:
- b4-2-structural-fold-shape-carrier-worker.md (Phase 1 #2 of 4) —
  replaces §0.4 lens_apply.rs span.file.ends_with("std/algebra.dag")
  fold-skip with structural template-formal carrier; mandatory
  authority audit per feedback_audit_adjacent_authority_first.
- b4-3-structural-emit-helper-carrier-worker.md (Phase 1 #3 of 4) —
  replaces §0.6 emit.rs bind/branch.span.file equality with typed
  BindEmitParticipation/BranchEmitParticipation roles populated at
  lowering; aligned with #824 worker's in-flight implementation shape.
- b4-4-structural-extdeps-fixture-set-carrier-worker.md (Phase 1 #4
  of 4) — replaces §0.8 EXTDEPS_BOOTSTRAP_FIXTURES Rust constant with
  typed substrate authority; explicit pre-promotion-constraint
  disposition (single-authority vs authority+tracked-debt) addresses
  parallel-representation risk surfaced on #825.
- b4-phase-2-site-dissolution-queue.md (skeleton tracking doc) —
  names B4.5-B4.12 Phase 2 sites with carrier dependencies,
  cross-program coordination notes, and skeleton-brief template;
  full per-site briefs author at dispatch time per #827's
  Substrate Manager ownership.

Cross-cutting discipline applied per inbox #828 reply:
- feedback_audit_adjacent_authority_first (mandatory grep before design)
- feedback_no_textual_enforcement_bridges (no replacement sentinels)
- feedback_parallel_representation_debt (explicit if shape (b))
- feedback_construction_over_ratchets (no parity-by-runtime as primary)
- feedback_coproduct_dissolution (receipts for new variants)

Wave 2 (T-Substrate sub-lane scoping briefs × 3) + Wave 3 (T-Modeling
worker briefs × 4) + Wave 4 (T-ImpossibleBugs worker briefs × 3) follow.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(briefs): R2 spin-up Wave 2 — T-Substrate sub-lane scoping briefs (3)

Per inbox issue #828: Wave 2 of Director's R2 spin-up authoring queue.
Substrate-producer briefs for the 3 T-Substrate sub-lanes consumed by
Modeling Manager's Wave 3 worker briefs (gated on these landing).

Authored:
- r2-substrate-cardinality-for-int-lit-subset.md (M) — produces
  magnitude carrier consumed by T-Modeling int-lit. Coordinates with
  PR #806's prior cardinality work; mandatory authority audit guards
  against #796's rejected IntLiteralMagnitude shape resurfacing.
  Open design questions: magnitude representation, reconciliation
  narrowing point, i64::MIN representability.
- r2-substrate-nominal-opaque-for-secret-subset.md (M) — produces
  nominal-opacity carrier consumed by T-Modeling Secret<T>. Open
  design questions: carrier shape (flag/connective/sealed-accessor),
  generic-walk discipline, accessor gating.
- r2-substrate-parametric-algebra-for-dimensions-subset.md (M) —
  produces phantom-parameter carrier consumed by T-Modeling
  Dimension<Carrier>. Open design questions: carrier shape,
  type-equivalence rule, algebra-method dispatch, lifting/coercion.

All three:
- Scoped narrowly to their paired R2 consumer; not full
  substrate-capability lanes.
- Mandatory pre-author authority audit per
  feedback_audit_adjacent_authority_first.
- Cross-program readiness signal pattern from #827's manager rework.
- Coproduct dissolution receipts required for any new variants.
- Open design questions surfaced explicitly so Substrate Manager
  (or Director pre-spin-up) can resolve at dispatch time.

Wave 3 (T-Modeling worker briefs × 4) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 3 — T-Modeling worker briefs (4)

Per inbox issue #828: Wave 3 of Director's R2 spin-up authoring queue.
Consumer-side worker briefs for the 4 T-Modeling Goal 2 items, each
gated on a Substrate Manager readiness signal (Wave 2 producers).

Authored:
- r2-modeling-int-lit-magnitude-worker.md — gated on Wave 2
  cardinality-for-int-lit; moves narrowing from tokenizer to
  reconciliation; MagnitudeOutOfRange diagnostic per C-8.
- r2-modeling-secret-graduation-worker.md — gated on Wave 2
  nominal-opaque-for-Secret; authors Secret<T> + gated accessors
  (redact, compare_in_constant_time); C-8 diagnostic on non-gated
  access; signals Impossible-Bugs Manager on close (thesis claim
  covered).
- r2-modeling-dimensions-phantom-worker.md — gated on Wave 2
  parametric-algebra-for-Dimensions; authors Dimension<Unit, Carrier>
  + core SI base units + algebra-method dispatch; cross-dimension
  arithmetic produces typed diagnostic; signals Impossible-Bugs
  Manager (thesis claim).
- r2-modeling-tokenizer-charclass-phase2-worker.md — gated on
  T-Substrate ValueBody-list/sum (#790); migrates tokenizer
  consumers to Char/List<Char>/CharClass canonical types; sibling
  consumer to Grounding Manager's Engine sharpened-(b).

All four:
- Explicit gating: 'do not dispatch until producer signal posts.'
- Producer/consumer signal pattern from #827.
- Cross-program signals to R2 Release Manager (Goal 2 closure)
  and Impossible-Bugs Manager (thesis-claim coverage).
- Spoofing regression tests: discipline anchor against
  feedback_no_textual_enforcement_bridges.

Wave 4 (T-ImpossibleBugs worker briefs × 3) follows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): R2 spin-up Wave 4 — T-ImpossibleBugs worker briefs (3)

Per inbox issue #828: Wave 4 of Director's R2 spin-up authoring queue.
Implementation worker briefs for the 3 T-ImpossibleBugs Goal 4 classes,
consuming the existing design/scoping briefs as authority.

Authored:
- r2-impossible-bugs-nested-optional-flatten-worker.md (M) — gated on
  cardinality refinement substrate (T-Substrate territory adjacent
  to int-lit / DB-11 alias-where). Implementation: structural normalize
  of OptionalOf<OptionalOf<T>> at type-checker; surface-syntax T??
  worker decision (reject vs normalize). Cites
  t-impossiblebugs-nested-optional-flatten-design.md as authority.
- r2-impossible-bugs-unhandled-diagnostic-paths-worker.md (M) — gated
  on Tier 2 substrate (predicate-entailment infrastructure; distinct
  from Wave 2 sub-lanes). Three paths: (a) operator dispatch consumes
  predicate entailment, (b) feedback_totality_by_omission dissolves
  partial primitives, (c) park. Worker decides at audit time. Cites
  t-impossiblebugs-unhandled-diagnostic-paths-design.md as authority.
- r2-impossible-bugs-unenumerated-effects-worker.md (M) — NO substrate
  prerequisite per closed-system framing in design doc (#808). Audit-
  as-existence-check + lens implementation as compositional fold over
  5 behaviors; redundancy detection compile-error via referential
  transparency + reread() escape hatch; path (i/ii) decision on
  OperationEffect taxonomy retain-vs-retire (default retire). Cites
  design doc #808 as authority.

Cross-cutting:
- Each cites prior design/scoping brief as authority (the existing
  *-design.md / *-worker.md REFRAMED files).
- Explicit gating per #827 producer/consumer signal pattern; two
  briefs gated on substrate, one NOT gated (closed-system).
- STOP-AND-ESCALATE includes 'design brief assumptions don't hold'
  surfacing per feedback_thesis_gate_state_drift.

Wave 4 complete. Director's 14-brief queue done; awaiting PM portion
(6 manager briefs + §6a + B5/B6/B7) for full R2 spin-up readiness.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): B4.4 — tighten Slice §3 per PM review on #836

PM APPROVE_WITH_COMMENTS on #836: Slice §3's framing of shape (b)
(authority + tracked debt parallel-rep) as autonomously acceptable
contradicts feedback_construction_over_ratchets +
feedback_parallel_representation_debt.

Tightened:
- Shape (a) is the only autonomous worker path.
- Shape (b) requires STOP-AND-ESCALATE to Substrate Manager for a
  regen-host-loader sub-lane decision; not authorable without explicit
  Substrate Manager approval citation in the PR body.
- Acceptance bullet requires the approval citation when shape (b)
  lands.
- STOP-AND-ESCALATE rephrased to make this explicit; permanent
  parallel-representation re-escalates even with manager approval.

This preserves shape (a) as autonomous; shape (b) becomes a
cross-manager design escalation, not a B4.4 implementation call.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix machine-specific .claude path in unenumerated-effects worker brief

Cursor review on #836 flagged the Read-first reference to
.claude/projects/-Users-briansrls-gunbc/memory/feedback_closed_system_effects.md
as machine-specific (outside the repo, not resolvable from a normal
clone). Replaced with in-repo prose pointing at the design doc's
§Q1-Q3 as canonical authority — the discipline lives there in-repo.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix stale src/v3/std/types.dag → dsl/std/types.dag (6 refs across 5 briefs)

Codex flagged: src/v3/std/types.dag does not exist; the canonical
authority is at dsl/std/types.dag. Affected briefs (all from R2
spin-up Wave 2 + Wave 3):

- r2-substrate-cardinality-for-int-lit-subset.md
- r2-substrate-nominal-opaque-for-secret-subset.md
- r2-substrate-parametric-algebra-for-dimensions-subset.md (2 refs)
- r2-modeling-dimensions-phantom-worker.md
- r2-modeling-secret-graduation-worker.md

feedback_verify_thesis_claims violation on Director-side brief
authoring — assumed path without grep. Same family of error as
the earlier emit.rs precedent claim. Mass-replaced via perl;
verified no remaining stale refs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nested-optional — UNGATE per design doc; substrate-constructor invariant

Codex BLOCKING on #836: my R2 worker brief gated nested-optional on
cardinality refinement substrate, but the design doc verifies v3 is
ALREADY past the cardinality bridge — TypeConnective::Cardinality
is first-class at dag.rs:395-398; CardinalityBound::AtMostOne is
the carrier for Option. The dissolution is an UNGATED implementation
via substrate-constructor invariant.

feedback_verify_thesis_claims violation again — should have read the
design doc fully before assuming the substrate gate.

Rewrote brief to match design doc canonical sketch:
- Single predicate (cardinality_idempotent_target) owns the rule
- Single allocator (alloc_cardinality_decl) is THE substrate-constructor
- API closure on TypeConnective::Cardinality payload (modeling-discipline
  practice 6) — variant cannot be struct-init'd outside the allocator
- 3 hand-Rust + ~22 codegen call sites enumerated per design audit
- infer.rs:2902 (concretize_decl_with_subst) explicitly flagged as
  the killer case for generic-instantiation paths
- Surface-syntax T?? decision left to worker (Director-lean: silent
  normalize)

Brief now dispatchable immediately, no producer signal needed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unhandled-diagnostic — switch to totality-by-omission per design doc §4 recommendation

Codex BLOCKING on #836: my R2 worker brief defaulted to predicate-entailment
substrate path, but the design doc §4 explicitly recommends totality-by-
omission as the Director-actionable path. Predicate-entailment is M+ scope
that reopens DB-11's explicitly-closed asymmetric-strip design — design
doc explicitly discards it.

feedback_verify_thesis_claims violation again — same family as nested-
optional reframe. Should have read design doc §4 in full before assuming
the path ordering.

Rewrote brief to match design doc §4 follow-on shape:
- Primary path: per-class totality-by-omission (algebra retype + per-
  target realization migration). For Int/Int: OrderedRing.div retype
  at algebra.dag:182; 3 realizations migrated (rust:816 / go:742 /
  python:486 + python_target.rs:680 helper).
- NOT predicate-entailment (out of scope; M+ + DB-11 reopen).
- NOT NonZero-typed-input (deferred to separate per-operand-variance
  substrate brief; STOP-AND-ESCALATE if chosen).
- Per-class sub-lane shape: this PR closes Int/Int only; siblings ([i]
  indexing, quotient, remainder) queue separately per design doc audit.
- feedback_totality_by_omission discipline anchor explicit.

Brief now matches feedback_totality_by_omission discipline + design doc
recommendation. No substrate prerequisite; dispatchable immediately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): unenumerated-effects — align with design doc Q6 8-req structure

Codex BLOCKINGs on nested-optional + unhandled-diagnostic exposed a
pattern: I authored R2 worker briefs without fully reading each design
doc's Director-actionable recommendation. Pre-emptively re-verified
unenumerated-effects against design doc §Q6 to catch the same family
of error before reviewers do.

Findings: brief was substantively close but missing 3 of 8 design-doc
reqs:
- Req 3: Resource-threading discipline applied to existing primitives
- Req 5: reread(key) primitive in std/ as explicit Slice item (was
  only mentioned in tests)
- Req 7: Asymmetric-tightening worked example in PR body

Plus: Slice didn't cite the canonical lens path
src/v3/lenses/effect_enumeration.dag from design doc.

Plus: STOP-AND-ESCALATE only had 4 generic STOPs; design doc Q6
specifies 4 specific STOPs (path-decision-escalation, pure: Bool
carrier, asymmetric-tightening structural gap, Q4.5 P1 NOT a STOP)
that I had elided.

Reframed Slice as 8 numbered reqs matching design doc verbatim;
STOP-AND-ESCALATE rewritten to match design doc Q6 STOPs;
Acceptance enumerated per req.

This is the third reframe in the unhandled-bugs series — same
feedback_verify_thesis_claims violation each time. The pattern
suggests Director-side R2 brief authoring should ALWAYS read each
design doc's §Director-actionable / §Q-recommendation in full first,
not assume.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): nominal-opaque-for-Secret — remove 7th-connective from worker-autonomous options

Codex BLOCKING on #836: "New TypeConnective variant — e.g., Opaque(T)"
listed as a worker-pick option violates THESIS.md substrate-shape
lock. The 6 connectives (Atom | Conj | Disj | Arrow | Cardinality |
Instantiation) are canonical (per #811 thesis additions and #827 PM
review); a 7th is a C1 stop signal requiring failed-dissolution
evidence + Director substrate-design call, not autonomous worker pick.

Removed the "new TypeConnective variant" option; replaced with
`inhabits`-edge-shape carrier as third option (audit-time check). The
explicit STOP-AND-ESCALATE clause now states: 7th connective is the
precondition for failed-dissolution-evidence + Director substrate-design
call, not a worker path.

feedback_verify_thesis_claims still in play — should have grounded
substrate-shape options against the THESIS lock before listing Opaque(T)
as worker-autonomous. Pattern continues; reading source-of-truth before
authoring options is the discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): parametric-algebra-for-Dimensions — close as no-op (substrate already in place)

Codex BLOCKING on #836: Declaration.phantom_params and PhantomParameter
already exist at dag.rs:186, :217 — explicitly authored for the
R2 Dimensions consumer per the doc comment at dag.rs:148-160.
phantom_unit_mismatch already wired at infer.rs:1057, :1132. The
substrate is fully landed; my brief framing it as 'producer sub-lane
to land carrier' is wrong on the same feedback_audit_adjacent_authority_first
violation that hit nested-optional / unhandled-diagnostic / unenumerated-
effects.

Reframed the substrate-side brief as no-op / closed-by-audit:
- Documents the audit receipt (5 sites confirming substrate exists)
- States the lane is closed
- Routes T-Modeling Dimensions consumer to dispatch immediately
  against the existing carrier
- Records the lesson: 'always grep substrate before authoring
  producer briefs' — discipline doesn't end at brief boundaries.

Updated r2-modeling-dimensions-phantom-worker.md correspondingly:
- Changed gating from 'do not dispatch until producer signal' to
  'NOT GATED — dispatch immediately'
- Read-first updated with concrete dag.rs/infer.rs cites
- Slice §1 changed from 'confirm producer signal' to 'verify
  substrate at HEAD'
- STOP reframed: existing carrier extension would need Substrate
  Manager call, not autonomous worker pick

Audited siblings: nominal-opaque-for-Secret + cardinality-for-int-lit
both verified — no existing substrate (no is_nominal_opaque /
MagnitudeBound patterns in dag.rs); both still legitimately
producer-side work.

Pattern is now four reframes deep on the R2 spin-up wave. The lesson
saved is structural: read source-of-truth before authoring options.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): cardinality-for-int-lit — close as redundant; existing t-substrate-cardinality-int-lit-worker.md is authority

Codex BLOCKING on #836: my new R2 spin-up brief duplicates the
existing t-substrate-cardinality-int-lit-worker.md, which carries
the canonical post-wise-pike-578 re-scope decisions (LiteralBits::Int(i64)
stays; String-decimal range facts; i64::MIN deferred to sibling sub-lane).
Single-authority violation per INVARIANTS P2.

Same feedback_audit_adjacent_authority_first failure as parametric-
algebra-for-Dimensions reframe (4 hours ago): assumed substrate
authority didn't exist; should have grepped docs/briefs/ before
authoring. This is the SECOND R2 spin-up substrate brief closed
as redundant — the discipline lesson is structural.

Reframed brief as no-op routing doc (documents the audit receipt;
routes consumers to the existing authority); updated
r2-modeling-int-lit-magnitude-worker.md to cite
t-substrate-cardinality-int-lit-worker.md instead.

Pattern across the R2 spin-up wave reframes (5 now):
1. nested-optional gating-on-substrate (substrate already past
   cardinality bridge)
2. unhandled-diagnostic predicate-entailment default (design doc
   recommends totality-by-omission)
3. unenumerated-effects 8-req design-doc elision
4. parametric-algebra Producer (Declaration.phantom_params already
   authored explicitly for this consumer)
5. cardinality-for-int-lit Producer (existing brief is autho…
@briansrls briansrls mentioned this pull request Jun 1, 2026
@briansrls
briansrls deleted the session/keen-wren-319 branch June 1, 2026 18:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant