Repository navigation
Delete the orphan-helper census and the __ filename rule from floor discovery - #8167
Conversation
… pre-plan claim_executor ran discover_floor_witness_roster_with_snapshot once up front, BEFORE resolving the plan, on the stated ground that a naming violation should be "the cheapest possible failure". Measured, that walk is the most expensive phase in the process: 5.9 min of a 56.5-min ordinary floor (run 31477894666), and ~6 min of a ~15-min regen whose plan has exactly two nodes. It is expensive because "naming hygiene" is a misleading label. The four rules in v2.workflow.floor_naming_hygiene are string predicates over file paths and line prefixes, but the roster producer they are reached through also builds module-graph facts, runs a second strict reference-resolution pass, computes path indexes, and runs inert-lens reachability plus the construction- justification census. A two-node regen plan paid all of it to discover a roster it never reads. Hygiene is a property of the witness ROSTER, so it is now paid by the plans that have one: the walk moves to the existing `schedules_discovery` predicate, after the plan's batches settle. The roster is memoized by request digest (IN_PROCESS_ROSTER_BY_REQUEST), so plans that DO schedule discovery pay exactly what they paid before — the corpus batch hits the memo this call fills. Plans that do not schedule discovery pay nothing, and cannot be unhygienic: they have no roster. The walk-attempt id is minted unconditionally as before; it is a tracing coordinate every later phase stamps, and it is not the expensive part. This also closes the PRELUDE COVERAGE HOLE gunbc.ci_spec gunbc_ci_floor_batch_wall_budget_note already names: the walk sat outside every batch budget and could only red at the step cap. It is now inside the region the plan accounts for, or absent. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi
…iew 51099) review 51099 (cursor/composer-2.5, REQUEST_CHANGES) correctly caught that #8140 changed documented CI behavior without updating its authority. DESIGN.md Building & checks stated the opposite of the new code: "the executor runs the zero-enrollment naming walk when no discovery batch is scheduled" That clause is superseded here in gunbc.design_document (DESIGN.md is generated from it; the heal job regenerates the projection). Both of the reviewer's findings are recorded rather than only the first: (a) SCOPE — discovery-free plans no longer run the corpus-wide nameability rules. Declared as a narrowing, with the honest coverage argument: every PR runs the `ci` job, whose plan schedules discovery and walks the full tree, so per-PR coverage is unchanged; what is deleted is a second redundant walk on regen-only and plan-artifact-only runs. Explicitly NOT backstopped by the affected-set falsifier, which has produced no green verdict since 2026-08-03. (b) ORDERING — for plans that DO schedule discovery the walk now runs after plan resolve/eval, so a naming violation pays ~0.5 min of plan resolution before refusing. The reviewer asked whether the trade is intentional: it is, and it is priced — ~0.5 min later on the refusing path against ~6 min saved on every regen. A dissolve-on is recorded: the clause, the separate walk, and the `__`-basename rule all retire when the placement rules move to canonical source ingestion and test identities derive from parser-produced declarations. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi
…51101) review 51101 (cursor/composer-2.5) caught claim_executor.rs:10283 still asserting "The walk still runs before plan evaluation, so a naming violation stays the cheapest failure" — the exact opposite of what this PR does. Non-blocking as a defect, but it is the same class the PR itself is about: a comment standing as authority for behavior the code no longer has. #8140's own receipt was a block comment whose stated premise had been false for months. The paragraph's real subject — install output policy BEFORE the walk so the whole-tree read is funnelled rather than emitting ~2.3k `[file] read` lines — is unchanged and still correct; the walk simply moved further away from it. Rewritten to say that, rather than deleted, so the ordering requirement keeps its rationale. Swept the rest of claim_executor.rs / cli_run.rs for other assertions of the old ordering: the only remaining hits are this PR's own comment describing the prior behavior in the past tense. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi
…ion/eager-cat-841
Two censuses ran inside `discover_floor_witness_roster` — the inert-lens
reach walk and the construction-justification census. Both asked a question
about who authored a lens, and both answered it by acquiring a whole-corpus
module graph. Every discovery run paid that: every PR, regen, and every
coordinated scoped worker, all of which wanted a witness roster and nothing
else. The unit of computation was the world; the unit of fact was one
module's authorship.
Deleted end-to-end, not merely unwired:
- `v2.lens.inert_lens` (its `.dag` surface was two self-recursive stubs,
`fn f() { f() }`, reachable only because the interpreter intercepted them)
- its two host builtins, both interpreter dispatch registrations, the
generated bridge family, the `04_method` type-table entries and the
`std.primitives` roster rows
- the `InertLens` registry variant, its registry row, contract row and
`lens_module_gate` invariant surface
- `inert_lens_modules`, `inert_lens_modules_legacy`, `lens_justification_census`,
`unjustified_lens_modules`, `declares_construction_justification` and both
floor refusal arms (`cli_run.rs` and `floor_discovery_snapshot.rs`)
- the long witness and its frozen deferral row (shrink logged)
`build_module_graph_facts_live` still runs on this path and this change does
not claim otherwise: effect-reach derivation and the cross-worker snapshot
transport both consume it. `refuse_on_module_graph_read_refusals` and its two
red controls are retained and re-homed, since the fail-closed arm now guards
those consumers rather than the deleted censuses.
This is a scope narrowing, not a climb. A new lens with no witness, and a lens
recording no `construction_justification`, are both writable again and nothing
detects either. Declared in DESIGN §6 with its next-rung trigger: authorship
belongs on the module's own declaration, checked where the module is already
parsed, rather than reconstructed corpus-wide by a consumer that wanted a
roster.
Two citations repaired rather than left stale (§3): the roadmap acceptance note
cited a shadow witness this change renames and weakens, and `source_authority`
cited the inert-lens stubs as its example of host interception.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi
…ement Review 51113 (cursor/composer-2.5) found two second authorities still claiming enforcement the code no longer performs — DESIGN §3 dual representation and §4b rung honesty. Both confirmed against the current head, both fixed. `gunbc.plans.construction_justification_rule` said the presence check "run[s] in `discover_floor_corpus_rows`" and listed it as current status. Its retirement condition also named that check as its trigger, so after the deletion the condition could never fire — an unreachable lifecycle claim that structurally cannot report itself satisfied. The plan now leads with a supersession notice, §2/§3/§4 are marked historical rather than reworded, and a new §5 records what was deleted, what it costs (a lens added tomorrow with no justification lands green; the 35-module classification in §4 is a historical measurement, not a maintained invariant), and the next-rung trigger. The retirement condition is replaced with a reachable one and says why. `floor_discovery_snapshot.rs`'s consumer census still listed the two gates and still called the roster walk "pre-plan", which #8140 already made false. Swept the rest rather than fixing only what was reported: eight comments in `cli_run.rs` and one in `claim_executor.rs` named the inert-lens reach as a live consumer of the observation rows, the reference-edge producer, and the selection tier. Repointed to the consumers that remain. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi
…ion/eager-cat-841
Two bounded review corrections. `is_top_level_lens_module` survived the census deletion with no remaining caller — only its own definition. It compiled clean because the crate carries a blanket allow, which is exactly why the residue needed finding by reading rather than by warning. Deleted; the PR's bar is end-to-end with zero residue, and a dead classifier left behind is the pattern this change exists to close. The new DESIGN paragraph asserted the censuses charged "every discovery run — on every PR, on regen, in every coordinated worker". True before #8140, false on this PR's base: #8140 made the roster walk demand-directed, so a discovery-free plan such as regen already stopped paying. Both DESIGN and the plan carrier now split the claim by era — unconditional before #8140, regen exempt after it, the censuses burdening every remaining discovery-bearing execution until this deletion. A change removing stale supply-side enforcement must not land a fresh stale assertion in the same diff. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi
… census Review 51154 caught a consistency failure in my own work: I applied the stale-authority fix to `construction_justification_rule.dag` and then judged `inert_layer_lens.dag` "historical prose" without running the same test on it. It fails that test. It is a registered plan whose §3 tells a future worker that Tier 1 is "buildable now (reuse #5433)" and to extend `inert_lens_modules` — a function this PR deletes — and §7 goes further, advising them to extend it behind a flag rather than fork it. Someone following that plan would go looking for machinery that is gone. Four rows repointed rather than deleted, since the design reasoning survives even though its cited mechanism does not: - §3 Tier 1 now leads with the supersession, names `v2.lens.module_graph` as the surviving reachability authority, and says plainly that "reuse the existing walk" now means "build the walk", which is a larger job than the paragraph reads. - §6's reuse map repoints the transitive-reachability-BFS row off `cli_run.rs:2558-2606` — a positional citation into a file that has since moved several thousand lines, which is the §3 rot mode exactly. - §7's seed caveat drops the extend-behind-a-flag advice and states the real constraint: whatever Tier 1 becomes must not reintroduce a corpus-wide walk inside floor discovery, because the placement was the defect, not the walk. - §5's "fail closed exactly as #5433 does" moves to past tense; no lens-inertness gate runs today. Also marked the two remaining historical citations, in the same plan's landed doc-graph receipt and in `axiom_syllogism_lens.dag`'s precedent table, so every surviving mention of a deleted symbol carries its deletion beside it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi
The floor finally evaluated this branch — main was red before, then an upstream
timeout cascaded — and found exactly one red witness in 8757:
`v1_interpreter_primitive_dispatch_authority_acceptance_contract_holds`.
It is genuinely this PR's. Deleting `v2.lens.inert_lens` removed the last two
rows carrying `EvalCallBridgeFamilySite { module: v2.lens.inert_lens }`, so the
distinct bridge-family count went 9 -> 8 and
distinct_bridge_family_site_count() == 9
redded. The literal was a population pin — the exact class DESIGN §5 rejects,
and the exact class #7615 removed from this same carrier's census witnesses.
The file's own `closing_contract_note` opens by claiming "The checks here are
structural properties that survive roster growth -- not population pins", so
the clause contradicted its own contract and my deletion is what surfaced it.
Decrementing 9 to 8 would restore green while preserving the defect, so the
control is derived instead: the number of distinct emit-site keys must equal the
number of distinct modules the bridge rows themselves name, and exceed one.
That is not a tautology, because the two sides come from different places — the
left from `dispatch_emit_site_key`'s keying, the right from each row's own
`module` field. Collapsing the families back onto one shared key (the defect the
clause is named for) reds it, 1 != N. Adding or removing a family does not.
The clause now measures what its name claims, in both directions.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi
… discovery Two more required-path phases whose cost was denominated in the corpus and whose answer nobody consumed. Net −1446/+39. **The `__`-basename rule.** A census found ZERO offending basenames in the tree and no stated rationale anywhere for the ban — it guarded an empty population. It was not free: reaching the predicate meant collecting every `.dag` path in the corpus and then resolving a SEPARATE `.dag` entry (`FLOOR_NAMING_HYGIENE_ENTRY` -> `floor_filename_hygiene_refusal_via_producer`) on every discovery-bearing run, so a zero-population style rule cost a whole-tree walk plus an entry resolve. Both are gone, along with the snapshot's `naming_hygiene_refusal` field and the two witness controls. **The orphan-helper census.** It walked every `*_test.dag`, parsed each one, projected `DeclSurface`/`ModuleSurface` values, resolved a second interpreter context, and ran a fuelled reachability fixpoint against a hand-authored cross-module export exception roster — to decide whether a plain helper in a test file was referenced. An unreferenced test helper is dead-code hygiene. It is not evidence that the compiler or the tests are correct, and it did not justify a recurring whole-corpus traversal on a required path. `gunbc.test_module_hygiene` goes 661 -> 106 lines, the Rust bridge 835 -> ~320, and `test_module_hygiene_scaffold.dag` deletes whole (its dissolution obligation is discharged by the deletion, not carried forward). **Scope narrowing, declared rather than implied.** An unreferenced test helper and a `__` basename are both writable again and nothing detects either. The orphan class had fourteen enrolled witnesses and they are deleted with it — §4b permits that only because the class is ABANDONED, not climbing: there is no higher rung for the evidence to guard, and keeping fixtures for a fold nothing calls would be specification-without-execution one level up. Recorded in DESIGN, in the module authority note, and in the witness file that used to hold them. **What survives, and why:** the `test fn` placement rule, the file-grain expand half, and `failure_receipt_companion` — the naming convention `claim_executor` actually invokes. That last one was only ever exercised through the census's whole-corpus walk, so it would have silently lost its executing consumer; it gains direct unit and `.dag` witnesses here instead. **Not in scope, deliberately:** the line-scanned test-identity derivation. That is the second parser, and replacing it needs the canonical parser to retain the `test` marker — which `drop_leading_test_marker` discards, because `test` is a live module-path segment (`test.claim.*`, `extdeps.test.*`) and cannot be lexed as a keyword. `realization_attempt.dag` already names the prerequisite: a contextual-keyword terminal in `GrammarExpr`, which does not exist yet. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi
Review 51262 found `floor_naming_hygiene_note` still asserting, in a file this PR edits, that the module sits where it does so "orphan/filename hygiene resolve stays free of the Filesystem service closure" and that it dissolves the hand-Rust mirror `check_floor_filename_hygiene`. Neither survives the deletion: there is no orphan census and no filename-hygiene resolve left to keep free of anything, and the filename half of that dissolution obligation is discharged by deletion rather than by dissolution — no equivalence receipt was ever owed for a rule with a zero-row population. The note now states what remains true instead, including the part worth carrying: the test-decl line scan is still a second parser, and replacing it is not a refactor of this module — it needs the canonical parser to retain the `test` marker, which `drop_leading_test_marker` discards, and `test` cannot become a lex keyword because it is a live module-path segment. Swept for the same class rather than fixing only what was reported: `floor_discovery_dissolve_trigger` still described "the producer and filename-hygiene entries" as two typed entry values resolved through `resolve_workspace_entry`. There is one now. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi
Finding 2 fixed and swept; finding 1 is the designed flow, not a defect2 — stale authority prose: fixed (
|
Resolving the falsifier I set on finding 1I claimed
And the projection now carries the authority's text — grepping the healed So authority and projection are in sync, by the mechanism this repository uses for every generated artifact, one CI commit after the authoring push. No hand edit to Recording it here rather than letting the green drift gate speak for itself, because a prediction is only worth making if its failure would have been reported with the same prominence. — sent from eager-cat-841 |
…prose data row `prose_row_introduction_gate` refused this change: `test_module_hygiene_orphan_witness_deletion_note` is a `data NAME_note: String` declaration introduced under `dag/test/claim/test_module_hygiene_hand_rust_equivalence_witness_test.dag`, a path already on `gunbc.prose_row_frontier` `prose_row_migration_scope`. DESIGN §4c: prose is not forbidden, unclassified prose is, and a `String` declaration whose sole purpose is commentary is misplaced data. The rationale is irreducible — it records why fourteen witnesses were deleted with the machinery they tested, and why §4b's dissolution-on-climb rule does not save them (the class is abandoned, not climbed) — so it becomes a leading `//` block attached to the declaration below it. The PR-number and section references in the prose are dropped rather than carried across: those are exactly the machine-consumed facts §4c says belong in a typed carrier, not in commentary. The two other in-scope rows this change touches (`test_module_hygiene_authority_note`, `failure_receipt_companion_note`) are pre-existing declaration names whose content was rewritten, not introductions, and the gate does not refuse them. They are left as rows rather than swept here. Green by execution: the edited witness parses and `test_module_hygiene_file_grain_empty_function_holds` returns `true`. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi
Brings in the ArtifactIdentity collision repair (#8177 + #8187) that main's whole-tree compile-clean was red on, plus the intervening merges. This PR's red was that inherited defect, not its own content: the identical five `unresolved type 'ArtifactIdentity'` errors appeared on a sibling PR containing no `.dag` change at all, and then on main itself at #8146. DESIGN.md was the only conflict, and it is resolved to main's copy deliberately: it is a PROJECTION of `dag/gunbc/design_document.dag`, which merged cleanly. Hand -merging a generated artifact would author bytes no authority produced; the `heal_generated_artifacts` job re-projects it from the merged authority, as it already did on this branch in f7ddaef. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi
Review 51377: the paragraph describing the naming-hygiene walk's measured cost still said the roster producer "runs inert-lens reachability plus the construction-justification census" — present tense, about two censuses gunbc#8141 deleted. `claim_executor` already says "(until gunbc#8141 deleted them)" and the §6 bullet in this same document records the deletion in past tense, so the canonical authority contradicted both. The measurement itself stands: those censuses WERE part of what made the walk the most expensive phase when it was measured. What was wrong is the tense, which asserts a superseded population as the present one — and doing that inside a deletion diff is the exact failure #8141's own review caught, recorded a few paragraphs above in this file. Reworded to "and — until gunbc#8141 deleted them — ran", preserving the cost claim as the historical fact it is. Swept for other occurrences: the §6 bullet is already past tense; this was the only stale one. DESIGN.md is a projection of this authority and is regenerated by `heal_generated_artifacts`, so it is not hand-edited here. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi
…ion/eager-cat-841
Review 51382: the module header still listed "Naming hygiene, orphan/helpers" as what the demand-directed roster walk reads, in a file this PR edits. The orphan-helper census and the `__`-basename rule are deleted here, so the row named work that no longer happens — doc drift inside the diff that removed the subject. The row now names what the walk actually still does: `test fn` placement hygiene, producer roster, module-graph facts, effect-reach derivation, with the deletion noted so a reader is not left wondering where the other two went. The same review's DESIGN.md finding is real and is NOT fixed by hand: DESIGN.md is a generated projection of `dag/gunbc/design_document.dag`, whose wording was corrected in 69009a3. Editing the projection directly would author bytes no authority produced, and `heal_generated_artifacts` reverts exactly that. Heal last ran against the previous head (a5b441b, before the authority fix); its run on this head re-projects the corrected sentence. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi
Review on gunbc#8191 (cursor/composer-2.5, review 51383) was right: the PR enrolled a new gate while pinning only the backstop sum. Arithmetic over timeouts establishes nothing about what the gate EMITS, which is DESIGN 5 specification-without-execution for an enrolled gate. Seven witnesses, mirroring test.claim.ci_stage0_partition_compile_gate_witness: emitted argv, extra_args equality, scaffold disposition, dissolve marker, the exact plan-plus-marker composition, build-job enrollment, and a RED refusal through a bogus operation name. The argv is pinned TOKEN-BY-TOKEN rather than as one string because the three tokens rot independently. `check` -> `test` would silently convert this into the execution gate the standing nextest ruling rejects. Widening `-p v1-compiler` would re-check what the partition gate already covers. And dropping `--all-targets` is the quiet one: the step still passes, still looks enrolled, and covers exactly the population that was uncovered before this gate existed -- the case a single-string assertion would miss most easily. Green by execution, all seven: PASS w_v1_compiler_test_targets_gate_script_carries_check_scope_and_all_targets PASS w_v1_compiler_test_targets_gate_extra_args_are_exactly_scope_then_all_targets PASS w_v1_compiler_test_targets_gate_shell_emit_is_scaffold_holds PASS w_v1_compiler_test_targets_gate_emit_carries_dissolve_marker_holds PASS w_v1_compiler_test_targets_gate_script_is_typed_plan_plus_marker PASS w_build_job_enrolls_v1_compiler_test_targets_compile_gate_holds PASS w_v1_compiler_test_targets_gate_RED_missing_operation_refuses The review's other finding — that merging reds the build job on the current tree — is factually correct and now enforced rather than described: #8167 and #8173 are still open, cli_run.rs:29991 still calls with_env_test_lock without the import, so the PR is converted to DRAFT until that repair lands. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XxLzhuMisV3GAPpP2mBtSG
Review 51390: a comment justifying why a wiring test calls the producer seam argued by contrast with `floor_filename_hygiene_refusal_for_paths` — which this PR deletes. The live half of the argument still holds (the seam is where a wire-contract violation is observable, and the rule itself is owned content-side by `floor_discovery_equivalence_misplaced_wire_contract_refuses_holds`, so re-deriving it here would be a second representation). Only the contrast was dangling. Rewritten to state the positive reason, with the retired comparison noted as history rather than silently dropped: a reader who remembers the old sentence should find out where it went, not wonder whether the argument changed. No code, assertion, or behavior change. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi
…ion/eager-cat-841
…iled (#8191) * Compile v1-compiler's test targets in CI: the population no gate compiled MEASURED HOLE. v1-compiler carries 24 files with cfg(test) modules and nothing in CI compiled any of them, so a test module referencing helpers it cannot see sits on main with every gate green. Today's specimen, still live on main at b33a9c0: cargo check -p v1-compiler --all-targets -> exit 101 error[E0425]: cannot find function `with_env_test_lock` error[E0433]: unresolved module or unlinked crate `floor_discovery_snapshot` error[E0433]: undeclared type `EnvGuard` error[E0425]: cannot find value `FLOOR_DISCOVERY_CONSUMER_ENV` error: could not compile `v1-compiler` (lib test) due to 4 previous errors Why the three existing gates structurally cannot see it: the release build compiles binaries, not test targets; ci_stage0_partition_compile_gate checks the seven generated partition crates without test targets (and all seven carry zero cfg(test) files, measured); and the v1-compiler-tests gate compiles and runs a DIFFERENT workspace crate. NOT a nextest re-enrollment. gunbc.commit_workflow commit_gate_rust_suite_removed_disposition rejects that, and every rationale in it is a fact about EXECUTION -- ~37 GiB, red on main, seed runtime, ~42min. This is cargo.Build.Check, compile-only, and runs no test. Same separable-fact argument that re-enrolled fmt (2026-07-15) and the v1-compiler-tests compile half (2026-07-31). Scoped to -p v1-compiler, not --workspace: partition crates are already Check-ed and have no test targets to miss, and v1-compiler-tests has its own gate, so a workspace-wide check would re-check covered lib targets for no gain (DESIGN 2). --all-targets is supplied by the WORKFLOW layer through extra_args, exactly as ci_stage0_partition_compile_gate_extra_args supplies -p. DESIGN 3 names a bare --all-targets in an extdeps argv as the policy-leak tell and v2.lens.extdeps_shape_transport_policy reds on it; that reading is respected rather than evaded -- extdeps.cargo_build keeps the agnostic shape. Cost: 99s measured (b33a9c0, cargo check --workspace --all-targets, cold, remote), an upper bound for this single-package step. Budget 10m, deliberately below the 15m the sibling gates carry on an unmeasured cold envelope. Placed after the release build so it reuses the release-profile v1-compiler artifact. Evidence: emitted -> ci.yml:142, "$CARGO_BIN" 'check' '-p' 'v1-compiler' '--all-targets' witness -> PASS ci_build_job_backstop_is_step_sum_plus_prelude red ctrl -> the gate's exact argv reproduces all 4 errors on main WHAT THIS DOES NOT DO: it does not execute those tests. Compiling a test module proves its references resolve, never that its assertions hold. The 24 files still have no executing consumer on any CI path -- including the five union_dedup_import_facts_law tests gunbc#8162 added to the very file this specimen came from. Execution cost is left UNMEASURED on purpose: main's lib test target does not currently compile, so the number can only be taken on a green tree. SEQUENCING: this cannot go green until the 4 errors are fixed by #8167 / #8173, which carry that repair. Merge those first; this gate then prevents the recurrence. The fix is deliberately not duplicated here. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XxLzhuMisV3GAPpP2mBtSG * Pin the test-targets compile gate the way its siblings are pinned Review on gunbc#8191 (cursor/composer-2.5, review 51383) was right: the PR enrolled a new gate while pinning only the backstop sum. Arithmetic over timeouts establishes nothing about what the gate EMITS, which is DESIGN 5 specification-without-execution for an enrolled gate. Seven witnesses, mirroring test.claim.ci_stage0_partition_compile_gate_witness: emitted argv, extra_args equality, scaffold disposition, dissolve marker, the exact plan-plus-marker composition, build-job enrollment, and a RED refusal through a bogus operation name. The argv is pinned TOKEN-BY-TOKEN rather than as one string because the three tokens rot independently. `check` -> `test` would silently convert this into the execution gate the standing nextest ruling rejects. Widening `-p v1-compiler` would re-check what the partition gate already covers. And dropping `--all-targets` is the quiet one: the step still passes, still looks enrolled, and covers exactly the population that was uncovered before this gate existed -- the case a single-string assertion would miss most easily. Green by execution, all seven: PASS w_v1_compiler_test_targets_gate_script_carries_check_scope_and_all_targets PASS w_v1_compiler_test_targets_gate_extra_args_are_exactly_scope_then_all_targets PASS w_v1_compiler_test_targets_gate_shell_emit_is_scaffold_holds PASS w_v1_compiler_test_targets_gate_emit_carries_dissolve_marker_holds PASS w_v1_compiler_test_targets_gate_script_is_typed_plan_plus_marker PASS w_build_job_enrolls_v1_compiler_test_targets_compile_gate_holds PASS w_v1_compiler_test_targets_gate_RED_missing_operation_refuses The review's other finding — that merging reds the build job on the current tree — is factually correct and now enforced rather than described: #8167 and #8173 are still open, cli_run.rs:29991 still calls with_env_test_lock without the import, so the PR is converted to DRAFT until that repair lands. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XxLzhuMisV3GAPpP2mBtSG * Replace the bounded cost figure with the measured one, and record both controls The blocker landed: gunbc#8167 (2d68b63) and gunbc#8173 (865d8f6) merged 2026-08-12T15:24Z, repairing v1-compiler's lib-test compile errors. main is integrated here by merge commit, and the gate now has both directions on the REAL specimen rather than one direction plus an argument: pre-fix main b33a9c0 -> exit 101, 4 errors (E0425/E0433) post-fix (this tree) -> exit 0, 0 errors, 67s cold The green half is deliberately taken from the landed repair rather than from a locally reimplemented one, so it is evidence about the tree CI will see. Cost notes corrected. Both carried 99s, which was cargo check --workspace --all-targets -- an upper BOUND measured while main's lib test target did not compile, because that was all a broken tree allowed. This step's exact argv is 67s. The bound is SUPERSEDED, not kept beside the measurement: a note carrying a looser figure than the available evidence is the stale-citation shape, and this one is load-bearing for the 10m budget. Verified on the merged tree, not assumed from the merge: ci.yml regenerates with NO drift, and the step is still emitted all 7 gate witnesses PASS, including build-job enrollment Enrollment is checked separately from the check passing, because main advanced by many commits and a reordered steps list would leave a gate that compiles cleanly and guards nothing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XxLzhuMisV3GAPpP2mBtSG * Fix the two defects the new gate found in never-compiled targets The gate's first CI execution redded, and it was right both times. Neither defect is in a test module -- they are in target classes nothing compiled: p1_cohort_probe (a BIN): function item cast straight to integer, x2. The release build builds only claim_executor and gunbc, so this bin had no compiling consumer at all. Fixed with the compiler's own suggestion, `as *const () as usize`. serve_budget_e2e (an INTEGRATION TEST): ServeProcess.port never read. Deleted the field and its initializer -- it has zero read sites, so it is dead data. Deliberately NOT #[allow(dead_code)]: annotating it would keep the thing the lint correctly found and hide the finding. MY GREEN CONTROL WAS MEASURED IN THE WRONG ENVIRONMENT, which is why this surfaced in CI rather than before the push. CI sets RUSTFLAGS=-D warnings at the job level; my earlier remote check did not, so it exercised a laxer compiler than the one that decides and produced a green that could not transfer. Both errors are LINTS promoted to errors, not compile failures -- invisible without the flag. The control now replicates CI's env. WHY -D warnings IS KEPT RATHER THAN CARVED OUT FOR THIS STEP: the population was measured before deciding, not fixed one error at a time. With --keep-going the entire -D warnings population across every v1-compiler target is ONE target with ONE lint, so there is no sprawl to scope around. Overriding RUSTFLAGS here would have smuggled a lint-policy carve-out into a compile gate and left the step inconsistent with its own job env; a 32-target population would have justified separating the two facts, and one does not. Green control, CI env exactly, --keep-going so nothing hides behind a first failure: exit 0, 0 errors, 1m10s. Three uncovered categories found by this gate so far, none visible to any gate that ran before it: a test module that did not compile (repaired by gunbc#8167 / gunbc#8173), a bin that did not compile, and an integration test carrying dead code. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XxLzhuMisV3GAPpP2mBtSG * Correct the execution-gap note: it is a standing program, not a pending measurement The note said execution cost was "UNMEASURED and is now measurable, since the compile fix landed", which reads as though enrolling execution is one measurement away. That misreads the repository, and the request this gate answers was "compile + test", so the reason the test half is absent has to be the real one rather than a softer one. MEASURED 2026-08-13: cargo test -p v1-compiler --lib -- --list reports 537 tests, and test.retirement.model retained_legacy_rust_test_modules governs src/v1/tests/src ONLY -- every row is a bare filename in the v1-compiler-tests crate and ZERO rows name src/v1/stage0/src. Those 537 are outside the retirement program: not retained, not deleted, not classified. So execution is not a gap for this gate to close. That model's declared direction is that a Rust test module may REMAIN only when explicitly retained and the complement disappears with the seed; the kernel was deliberately cut to 9 modules / 30 tests from 98 / 740; and nextest was removed precisely to stop executing seed tests. Enrolling execution would run the population the DESIGN 7 burn-down exists to delete and partially undo that cutover -- an operator decision, not a step I should add quietly. ALSO RECORDED, because it is a hole in the retention wall and it is mine: the model reds a new Rust test FILE added without a retention row, but discovers only src/v1/tests/src, so cfg(test) tests added INLINE to an existing src/v1/stage0/src file bypass it. gunbc#8162's five union_dedup_import_facts_law tests in cli_run.rs entered the unclassified 537 exactly that way -- no retention row, no executing consumer, slated to vanish with the seed. They belonged in the retained crate or should have been accepted as throwaway. Verified after the edit rather than assumed: ci.yml regenerates with no drift and the four emission/enrollment witnesses still PASS -- the note shares a module with the emit, and the plan-plus-marker witness compares exact strings. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XxLzhuMisV3GAPpP2mBtSG --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
What
Two more required-path phases whose cost was denominated in the corpus and whose answer nobody consumed. −1446 / +39.
The
__-basename ruleA census found zero offending basenames in the tree, and no stated rationale for the ban exists anywhere in it. It guarded an empty population.
It was not free. Reaching that one predicate meant collecting every
.dagpath in the corpus and then resolving a separate.dagentry —FLOOR_NAMING_HYGIENE_ENTRY→floor_filename_hygiene_refusal_via_producer→ a fresh eval context — on every discovery-bearing run. A zero-population style rule cost a whole-tree walk plus an entry resolve.Deleted: the rule, the Rust bridge, the entry constant, the snapshot's
naming_hygiene_refusalfield, and the two witness controls.The orphan-helper census
It walked every
*_test.dag, parsed each one, projectedDeclSurface/ModuleSurfacevalues, resolved a second interpreter context, and ran a fuelled reachability fixpoint against a hand-authored cross-module export exception roster — to decide whether a plain helper in a test file was referenced.An unreferenced test helper is dead-code hygiene. It is not evidence that the compiler or the tests are correct, and it did not justify a recurring whole-corpus traversal on a required path.
gunbc.test_module_hygienetest_module_hygiene_bridge.rstest_module_hygiene_scaffold.dagThe scaffold's dissolution obligation is discharged by the deletion, not carried forward.
Scope narrowing — declared, not implied
An unreferenced test helper and a
__basename are both writable again, and nothing detects either.The orphan class had fourteen enrolled witnesses and they are deleted with it. DESIGN §4b normally forbids deleting a class's evidence, but that rule governs a class that climbs — the proof replaces the validator, so the RED stays enrolled to prove the higher rung is real. This class is abandoned, not climbed: there is no higher rung for the evidence to guard, and retaining fixtures for a fold nothing calls would be specification-without-execution one level up. Recorded in DESIGN, in the module authority note, and in the witness file that used to hold them.
What survives, and why
The
test fnplacement rule, the file-grain expand half, andfailure_receipt_companion— the naming conventionclaim_executoractually invokes.That last one is worth calling out: it was only ever exercised through the census's whole-corpus walk, so deleting the walk would have silently stripped its executing consumer while leaving the function in place. It gains a direct Rust unit test and two
.dagwitnesses here instead.Not in scope, deliberately
The line-scanned test-identity derivation — the second parser — stays. Replacing it requires the canonical parser to retain the
testmarker, anddrop_leading_test_markerdiscards it. That is not an oversight:testis a live module-path segment (test.claim.*,extdeps.test.*) so it cannot be lexed as a keyword, andv2.workflow.realization_attempttest_marker_capture_notealready names the prerequisite — a contextual-keyword terminal inGrammarExpr, which does not exist yet. That is a grammar extension, not a field addition, and it gates 100% of test files.Also untouched:
build_module_graph_facts_live, theModuleGraphFactsSnapshotfields,snapshot_to_facts, affected-set selection, and Batch 3 assembly.Verification
cargo check -p v1-compiler --all-targetsclean;cargo fmt --all --checkclean via hooks. A corpus sweep finds no live reference to any deleted symbol. The.dagcorpus compile and the witness corpus run in CI.🤖 Generated with Claude Code
https://claude.ai/code/session_018ZrxLJrt8ASGLegiK72fAi