Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
18 commits
Select commit Hold shift + click to select a range
4422638
Make the witness-roster walk demand-directed instead of unconditional…
Aug 11, 2026
ff43f42
Update the design authority for the demand-directed hygiene walk (rev…
Aug 11, 2026
dfefcc4
chore: regenerate drifted generated artifacts (ci auto-heal)
Aug 11, 2026
b6c50f2
Repair the stale output-policy comment left by the walk move (review …
Aug 11, 2026
932778a
Merge remote-tracking branch 'origin/session/eager-cat-841' into sess…
Aug 11, 2026
d497cbd
Merge remote-tracking branch 'origin/main' into session/eager-cat-841
Aug 11, 2026
47584ea
Delete supply-side lens enforcement from floor discovery
Aug 11, 2026
0c044d1
Merge 47584ea8c8ab9dba707b1f75dde0ae268f998432 into 341d3203bc2be4f3d…
gunbai-bot[bot] Aug 11, 2026
2d5306d
chore: regenerate drifted generated artifacts (ci auto-heal)
Aug 11, 2026
ca2d3b4
Reconcile the plan carrier and stale comments with the deleted enforc…
Aug 11, 2026
06424e3
Merge remote-tracking branch 'origin/session/eager-cat-841' into sess…
Aug 11, 2026
9b7626f
Delete the dead lens classifier and date-scope the cost claim
Aug 11, 2026
e585778
chore: regenerate drifted generated artifacts (ci auto-heal)
Aug 11, 2026
da4b7fd
Merge remote-tracking branch 'origin/main' into session/eager-cat-841
Aug 11, 2026
a6e55e5
Repoint the sibling plan authorities that still advertise the deleted…
Aug 11, 2026
a911593
chore: regenerate drifted generated artifacts (ci auto-heal)
Aug 11, 2026
6364020
Derive the bridge-family split control instead of pinning its population
Aug 11, 2026
78bfd93
Merge remote-tracking branch 'origin/main' into session/eager-cat-841
Aug 11, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion DESIGN.md
Original file line number Diff line number Diff line change
Expand Up @@ -114,7 +114,7 @@ The same arm exists at authoring time: **the workaround — an absorbing fallbac
- **Model:** DFS the concept DAG before inventing vocabulary; fact-bundle modeling (invent or reuse on proven coincidence, never bare-alias); a finished stage is one fold (any non-fold residue is either a named irreducible kernel or un-migrated modeling — there is no third); model just-in-time and let the mark on the carrier be the authority (no parallel-ledger docs); **no scaffold lands by author declaration alone** — every net-new scaffold is represented by one exact dissolution obligation, joined to an external operator verdict on the current head, and refused in its absence (§5); reviewers independently search for undeclared scaffolds, so the author's classification is evidence to inspect, never the denominator.
- **Intellectual sustainability:** don't spend future author, reviewer, operator or maintainer time to buy present convenience. Work expected to be thrown away is *presumed redundant* (§2), so back up and complete the construction that will survive; use a temporary one only after the operator explicitly chooses that future cost. The reviewer's independent test, applied whether or not the author labelled anything: **will this artifact survive the terminal architecture substantially unchanged, and be consumed by it?** If no, presume scaffold and stop the merge until the final construction lands or the operator approves the exact exception. A *missing* dissolution condition makes the finding **more** severe, not less — the response is to name the undeclared dissolvable concept, request the final architecture, and require the exact obligation model if the author believes an exception is warranted; adding a trigger after review does not resolve the objection, it only makes the proposal eligible for a decision. Automated detection can never be the whole policy, because temporary work can be authored without using any of the names a gate matches on. Tells, each carrying a presumption: a hand-authored workflow, deployment script, migration script or operational command (out-of-band actuation); a second path beside an existing modeled route (parallel authority); "bridge", "shim", "compatibility", "for now", "temporary", "until", "later" (deferred refactor); a model to be deleted whole when the real one lands (throwaway model); a hand-authored projection the model should generate (manual application committed as source); raw shell implementing semantics already expressible in `.dag` (unmodeled realization); a broad wrapper around a type or modeling deficit (workaround hiding substrate work); a condition whose terminal is "rewrite this properly" (the proper work was not done); a new artifact with no final consumer (experimental residue). If dissolution approvals become frequent, that is not a process cost to optimize away — it is evidence the repository is routinely borrowing future intellectual labor to ship present convenience.
- **Prioritize holistically, not by the bottleneck:** balance the quantitative and the qualitative — don't anchor on one KPI (you'll hit it at a cost) or on pure taste. Map the cause→effect across sections; a 5ms step doesn't get a pass for not being the 80s one (it might be a 5ns step). One consequence is a standing rule, **bare minimum cost** (operator ruling 2026-07-10): a proven cost-shape defect — a copied accumulator, a quadratic fold — is *always fixed*, regardless of the realized n. "n is small here" is not a time-stable fact (§1/A3 — reuse changes n), and pricing per-site exceptions is itself redundant work (§2); the humility is not trusting your own "negligible here." Root-cause to the language layer and fix related systems *together* — a local subsystem patch is the forked-logic trap. **Denominate the benefit:** the deliverable is a *displaced cost* (§1's time — a pain someone pays to remove); the lens/substrate is the *mechanism* (the moat), not the product. A lens — or any construction wall — is on-dial exactly insofar as it is the cheapest path to such a pain. Priced in elegance instead, the work is self-referential and unbounded (the purity trap — the economic twin of "never" in §5; an extensible substrate's infinite improvability dissolving its own bound).
- **Enforce with lenses,** not grep — but **construction first** (§5): a lens is *validation* (it concedes the bad state is writable), so make the class unwritable by single authority where you can and reserve the lens for the unstructurable residue. As a residue mechanism it earns its keep: a pure reader over the same `Node` tree, storing nothing, so a new analysis costs zero substrate edits. Beware the tier where the machinery exists but nothing gates on it — coverage by illusion; an inert lens is itself a lie, so an **executable** hygiene check must keep every lens either wired (a discovered fail-closed witness) or deleted — that backstop runs over the corpus and is *not* superseded by the authoring-time construction-justification judgment, which layers on top of it.
- **Enforce with lenses,** not grep — but **construction first** (§5): a lens is *validation* (it concedes the bad state is writable), so make the class unwritable by single authority where you can and reserve the lens for the unstructurable residue. As a residue mechanism it earns its keep: a pure reader over the same `Node` tree, storing nothing, so a new analysis costs zero substrate edits. Beware the tier where the machinery exists but nothing gates on it — coverage by illusion; an inert lens is itself a lie. **The corpus-wide backstops that used to police this are DELETED (2026-08-11), and the reason is the rule that replaces them:** the inert-lens reach census and the construction-justification census both ran inside floor witness discovery, so *every* discovery run — on every PR, on regen, in every coordinated worker — had to acquire a whole-corpus module graph in order to answer a question about who authored a lens. That is the §6 cost-shape defect at its purest: the unit of computation was the world, the unit of fact was one module's authorship, and the price was paid by every consumer that wanted a witness roster and nothing else. **Who paid it, split by era, because this document must not assert a superseded population as the present one:** before #8140 the walk was unconditional, so ordinary CI, regen, the falsifier cadence and every coordinated worker all paid; #8140 made it demand-directed, so a discovery-free plan such as regen stopped paying; from #8140 to this deletion the two censuses burdened every remaining discovery-bearing execution. The correction is recorded rather than reworded because a change deleting stale supply-side enforcement must not land a fresh stale assertion in the same diff (review on #8141). Neither census had a consumer that justified the acquisition; the inert-lens half additionally reported through two host builtins whose `.dag` surface was a pair of self-recursive stubs (`fn f() { f() }`) reachable only because the interpreter intercepted them. **What is NOT claimed:** this is a real scope narrowing, not a climb. A newly authored lens with no witness, and a lens recording no `construction_justification`, are both writable again and nothing detects either. The obligation survives as review diligence, which is strictly weaker. **Next-rung trigger:** an authorship fact belongs on the module's own declaration, checked at ingestion where the module is parsed anyway — one module's facts from one module's source — rather than reconstructed corpus-wide by a consumer that wanted something else. Until that lands the class sits at *mitigatable*, declared here rather than left to be rediscovered.
- *e.g.* one catamorphism `fold_node` is reused by all 7 v2 stages; #4699 dissolved `06_translate` 4,912→3,973 lines (`_go` accumulators 35→0); a 6-line `merge_envs` root fix cut reconcile from 81% of the pipeline to 6% (~2× self-compile) — the symptom recurs wherever the root is unfixed (v2 still hand-rolls `ParseTable` because the Realization carrier is staged, not inhabited).

## 7. Self-hosting (the principles applied to the compiler itself)
Expand Down
48 changes: 2 additions & 46 deletions dag/gunbc/cli_run_floor_lens_oracle_scaffold.dag
Original file line number Diff line number Diff line change
Expand Up @@ -3,44 +3,6 @@ module gunbc.cli_run_floor_lens_oracle_scaffold
import std.dissolution { DissolutionCondition, dissolution_description, unbound_dissolution }


data cli_run_floor_lens_legacy_graph_oracle_scaffold: Disposition = Scaffold {
dissolves_to: SingleAuthority,
bind: DeclarationRef {
module_path: "v1_compiler.cli_run",
decl_name: "floor_lens_graph_legacy",
field: WholeDeclaration
}
}

data cli_run_floor_lens_legacy_walk_oracle_scaffold: Disposition = Scaffold {
dissolves_to: SingleAuthority,
bind: DeclarationRef {
module_path: "v1_compiler.cli_run",
decl_name: "inert_lens_modules_legacy",
field: WholeDeclaration
}
}

data cli_run_floor_lens_oracle_dissolve_trigger: DissolutionCondition = unbound_dissolution(description: "🟡 dissolve-on: floor_lens_graph_legacy + inert_lens_modules_legacy — the 6A repoint's TEST-SIDE equality oracle (the deleted build_floor_lens_import_graph corpus scan and module-name-grain walk, retained only inside cli_run.rs inert_lens_hygiene_tests as the executing equivalence receipt, the same shape as resolve_transitively_bfs_legacy). DELETES WHEN the legacy-oracle class dissolves (the queued resolve_transitively_bfs_legacy triage deletion) OR cli_run.rs Chunk F retires the HAND census entirely (docs/plans/cli-run-reconcile-defork.md)")

data cli_run_floor_lens_census_walk_hand_rust_scaffold: Disposition = Scaffold {
dissolves_to: SingleAuthority,
bind: DeclarationRef {
module_path: "v1_compiler.cli_run",
decl_name: "inert_lens_modules",
field: WholeDeclaration
}
}

data cli_run_floor_lens_justification_hand_rust_scaffold: Disposition = Scaffold {
dissolves_to: SingleAuthority,
bind: DeclarationRef {
module_path: "v1_compiler.cli_run",
decl_name: "lens_justification_census",
field: WholeDeclaration
}
}

data cli_run_floor_lens_read_refusal_hand_rust_scaffold: Disposition = Scaffold {
dissolves_to: SingleAuthority,
bind: DeclarationRef {
Expand All @@ -59,18 +21,12 @@ data cli_run_floor_lens_observation_hand_rust_scaffold: Disposition = Scaffold {
}
}

data cli_run_floor_lens_hand_rust_dissolve_trigger: DissolutionCondition = unbound_dissolution(description: "🟡 dissolve-on: inert_lens_modules + lens_justification_census + refuse_on_module_graph_read_refusals + import_resolution_facts_with_observation — the 6A repoint's PRODUCTION census walk, justification census, typed read-refusal arm, and observation projection in HAND-Rust (counted interim seed growth, net +22 production LOC at landing; the host realization of the v2.lens.module_graph selection-tier reach until the census emits from workflow dag). DISSOLVES WHEN cli_run.rs Chunk F lands (docs/plans/cli-run-reconcile-defork.md — the census emits from workflow dag over v2.lens.module_graph and the HAND arms delete) OR ROADMAP 5-dissolve-patches (gunbc.roadmap_authority ticket) retires the HAND census entirely")

data cli_run_floor_lens_hand_rust_loc_delta_net: Int = 22
data cli_run_floor_lens_hand_rust_dissolve_trigger: DissolutionCondition = unbound_dissolution(description: "🟡 dissolve-on: refuse_on_module_graph_read_refusals + import_resolution_facts_with_observation — the typed read-refusal arm and the observation projection in HAND-Rust (the host realization of the v2.lens.module_graph fact production until it emits from workflow dag). The census walk and justification census this carrier also tracked are DELETED, not dissolved: the supply-side lens enforcement they served made every floor discovery run acquire a whole-corpus world to answer a question about lens authorship, and the answer had no consumer that justified the acquisition. DISSOLVES WHEN cli_run.rs Chunk F lands (docs/plans/cli-run-reconcile-defork.md) OR ROADMAP 5-dissolve-patches (gunbc.roadmap_authority ticket) retires the HAND fact production entirely")

data cli_run_floor_lens_scaffold_shape_red_control: Disposition = Terminal {
reason: "RED CONTROL for the scaffold-shape cells in dag/test/claim/cli_run_floor_lens_oracle_witness_test.dag: a Terminal disposition, so the canonical reader v2.lens.disposition_redundancy.disposition_is_terminal must answer true for it while answering false for every Scaffold row above. Without this row the shape assertions could pass on a reader that answered false unconditionally; with it, the reader is proven to discriminate. Not a disposition ABOUT any declaration — it is test data declared beside the rows it controls."
}

data cli_run_floor_lens_oracle_receipt_plan_anchor: String = "docs/plans/cli-run-reconcile-defork.md"

data cli_run_floor_lens_oracle_equality_receipt_test: String = "facts_walk_matches_legacy_floor_lens_graph_on_live_corpus"

data cli_run_floor_lens_oracle_build_count_receipt_test: String = "lens_census_single_facts_build_receipt"

data cli_run_floor_lens_oracle_read_refusal_receipt_test: String = "unreadable_lens_is_a_read_refusal_not_an_absence"
data cli_run_floor_lens_oracle_read_refusal_receipt_test: String = "unreadable_source_is_a_read_refusal_not_an_absence"
Loading
Loading