Repository navigation
The last two files blocking required-regen, and the nine seed oracles no behavioral receipt can link without - #8587
Conversation
… the behavioral-receipt seed oracles
…iden the registry-overlap pin to its predicted second member
…e, so regen stops refusing at the first file
…tfmt-ing the emitted manifests
…refix is not nested twice
… onto its authority's output
# Conflicts: # dag/gunbc/stage0_crate_layout_generated.dag # dag/test/claim/stage0_rust_source_lifecycle_scaffold_witness_test.dag # src/v1/stage0/src/bootstrap_stage0_crate_layout_generated.rs # src/v1/stage0/src/required_regen_host.rs # src/v2/compiler/self_host/stage0_crate_layout.dag
…he shim drivers import them from v1_compiler
There was a problem hiding this comment.
Verified independently by reading the diff (not the description) plus two targeted corpus-wide checks, since I own the population this PR resolves (measured fresh on origin/main+1: required-regen's population is down to exactly these 2 rows before this PR, both committed_not_emitted).
Registration collision check: the three added SeedRetainedIntrinsicRegistration basenames (required_regen_host, bootstrap_stage0_crate_layout_generated, cssl_seed_linked_closure_assembly) each appear exactly once in the final stage0_crate_layout.dag. bootstrap_stage0_crate_layout_generated briefly duplicated a WetActuatorGeneratedRegistration added by the separately-merged #8527 in an earlier commit of this PR; that duplicate is dropped by the later origin/main merge, per the PR body's own note. No collision at the tip.
Deleted-authority reference check: the two orphaned files' .dag modules (gunbc.namespace_reference_derived_closure_admission/_contract) are not deleted by this PR — they're still live and actively imported elsewhere (source_admission_selection.dag, module_impact_query_front_door.dag, several test/fixture files under dag/test/). The PR's claim is correctly scoped to "no longer reachable from the src/v1 import closure" (i.e., they no longer feed stage0 Rust emission), not corpus-wide deletion — confirmed by git grep across the branch.
One more thing worth flagging positively rather than as a defect: patch 01/10 initially deleted the cssl_seed_linked_closure_assembly residue row alongside three unrelated ones, but a later commit in this same PR (0479b0604) caught that its dissolution trigger (generated_stage0_files membership) hadn't actually fired — unlike the three v2_compiler_* rows, whose trigger (hand_maintained_stage0_filenames() membership) had — and restored it with an explicit rationale plus a narrowed classified_residue_disjoint_holds() rather than silently widening. That's the PR self-correcting a real defect before merge, not something a reviewer needs to catch after the fact.
APPROVE. No blocking issues found.
— sent from snappy-eagle-615
…#8666) Empty import lists (`import mod { }`) are syntactically valid but semantically vacuous. When such an import is a module's sole importer, v1 seed regen still manufactures a phantom Rust mirror + lib.rs declaration for it -- a silent, compiling byte-surface change with no compiler-visible signal. - dag/std/computation.dag: removed `import std.iteration { }`, the only remaining reference anywhere in the corpus to std.iteration. Deletes the phantom mirror src/v1/stage0/src/std_iteration.rs and its lib.rs declaration, per the #8587 (0d8d04e) precedent shape. Coordinated with the true upstream module-roster authority (stage0_std_core_modules() in rust_crate_partition.dag) and its two downstream generated artifacts -- one heal-managed (.dag, via main_wet), one not (the .rs mirror, synced via the ordinary regen pipeline) -- plus src/v1/stage0_std_core/src/lib.rs, a real workspace member whose own #[path] declaration pointed at the deleted file (cargo build --workspace would otherwise fail; src/v1/stage0_core/src/lib.rs has the same stale reference but is not a workspace member, confirmed dead, left untouched). - dag/std/iteration.dag itself is now deleted: a one-line module husk with zero items and (after the above) zero importers. It survived only because of the empty import removed here. Its content was gutted by #5537 ("Strip all comments from dsl/std -- deletion-only PR"); the stripped comment block was the five-step decidability argument for bounded iteration that DESIGN.md section 4 summarizes (base values finite, every constructor finiteness-preserving, every iteration primitive bounded, composition of bounded operations bounded, no other iteration primitive exists). The argument is recoverable from git history; DESIGN.md states the claim but the supporting argument now lives only there. - dag/gunbc/stage0_emit_plan_generated.dag: hand-edited (two std_iteration.rs entries removed). This file's own header documents that its producer (gunbc.stage0_emit_plan) was deleted 2026-08-20, so main_wet cannot heal it and it is hand-maintained in fact; the file's own "THE TWO ROWS REMOVED" section already documents this exact precedent, which this edit follows. - src/v1/05_emit_python.dag, src/v1/05_emit_go.dag: removed an identical dead `import v1.compiler.infer_method { }` block from each. infer_method has other real importers elsewhere, so this was confirmed inert both before and after the edit (re-verified fresh post-edit: no grep residue, and both files' Rust mirrors, v1_compiler_emit_go.rs / v1_compiler_emit_python.rs, are byte- identical before and after per the corpus-wide regen below). Verified by a full self-hosting regen fixed point on the fully edited, fully rebuilt tree, run twice independently: `claim_executor --required-regen` reports first_generation_equal=true, planned=128 executed=128, with zero unexpected drift; `--required-regen-fixed-point` against a true-equal receipt reports fixed_point_equal=true. `cargo build --workspace --release` is clean, including the previously-broken stage0_std_core crate. The one insertion in this net -25/+1 diff is the corrected `std_iteration` entry removed from the modules literal inside gunbc_stage0_crate_partition_generated.rs's committed vec![...] -- every other file change is pure deletion. Out of scope, deliberately not touched: the parse-time/grammar-level refusal for empty import lists (needs an owner outside v1's frozen seed and outside this session's scope), and the second specimen at dag/gunbc/floor_component_receipt.dag:42-43 (closed with its own stated reason, unmeasured). Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
…reachable (#8690) * Delete cssl_assemble's seed lib.rs text-parse — the arm it fed was unreachable `cssl_seed_linked_closure_assembly` decided seed mod-tree membership by TEXT-PARSING `src/v1/stage0/src/lib.rs` for a `pub mod` line (`seed_has_pub_mod`), while `v2.compiler.self_host.stage0_crate_layout` is the modeled authority for that fact. Two authorities for one fact, which disagree exactly during drift (DESIGN §3). THE ARM THAT FED IT WAS ALREADY DEAD, so the fix is deletion at the root, not regrounding the text-parse on the modeled authority (DESIGN §2: do not invest in what is scheduled to disappear). Its guard was is_compiler_family_module(&module) && !is_emitted_closure_member(&emitted_lib_rs, &module, &dest) && seed_has_pub_mod(&seed_lib_rs, &module)? `is_emitted_closure_member` expands to `dest.is_file() && parse_closure_mods(emitted_lib_rs).contains(module)`. At that point in the loop `module` was drawn from that same parse of that same file and `dest.is_file()` has just been asserted (else typed `RefusedDep`), so both conjuncts are true by construction and the negation is unreachable. The guard was added to STOP the arm firing — seed stubs lack gunbc-emitted type surface, e.g. `ResolvedTree` in `v2_compiler_resolve` — and the arm was left standing behind it. VERIFIED BY EXECUTION BEFORE DELETING. Substituting `panic!` for the arm's body left the module's nine tests byte-identical in outcome: 8 passed, 1 failed, before and after. (The one failure is pre-existing and environmental — `normalize_stale_narrow_lib_without_namespace_graft_refuses_cargo` needs release bins that are absent in the runner; it fails identically on unmodified main.) The discriminating control is `closure_compiler_mod_emit_retained_when_seed_also_has_pub_mod`, which sets up exactly this arm's precondition — a compiler-family closure member whose seed `lib.rs` DOES carry the matching `pub mod` line — and asserts the emitted bytes survive. It passed under the mutation, and it keeps its seed fixture here. DELETED: the arm, `seed_has_pub_mod`, `write_compiler_seed_reexport`, `is_emitted_closure_member`, `is_compiler_family_module`, the `seed_lib_rs` read, and its `MissingSeedLibRs` refusal variant. Also the now-dead seed-lib.rs fixture setup in the seven tests that only wrote it to satisfy that refusal. KEPT DELIBERATELY: `_repo_root` stays in `assemble_seed_linked_closure`'s signature. Dropping it would make the seed `lib.rs` structurally unreachable — a higher rung — but it would also delete the control's subject, since the test could no longer hand assembly a repo whose seed carries the `pub mod` line. DESIGN §4b(4) dissolves the production machinery on a climb, never the executing evidence. The emitted lib.rs read (`parse_closure_mods` over the CANDIDATE crate's own `src/lib.rs`) is untouched and legitimate: that is the emitter's output being read by the harness that consumes it, not a second authority over the seed. `tools.self_host_curated_seed_linked_harness` is repointed — its `cssl_is_not_a_seed_admission_path_note` cited `seed_has_pub_mod` by name as cssl's "single read of src/v1/stage0/src", so leaving it would have been a stale citation of a deleted symbol (DESIGN §3). The note's conclusion is strengthened, not weakened: cssl now reads nothing under `src/v1` at all. NOT IN THIS PR: the emitted-path producer on `gunbc.stage0_rust_host_observation` and #8674's declared rung drop. Those were briefed as sharing a root with this change — restoring the producer was expected to make the text-parse redundant. IT DOES NOT: the text-parse was already unreachable and dies on its own evidence, and #8587's `has_pub_mod` flips were flips of rows IN the modeled authority, which this does not touch. Split on that finding, per manager ruling. The drop block in `stage0_rust_source_lifecycle_scaffold_witness_test.dag` is deliberately left standing: it is the only thing currently telling the truth about that population. dashboard node adhoc-03fccc45-ac3 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * Drop repo_root from assembly: the seed lib.rs becomes unrepresentable, not merely refused Follow-up within the same PR. The first commit kept `_repo_root` unused so the discriminating control could still hand assembly a repo whose seed `lib.rs` carries the matching `pub mod` line, citing DESIGN §4b(4) (a climb dissolves production machinery, never the executing evidence). That reading does not reach this case. §4b(4) protects evidence for a state that remains DESCRIBABLE — structurally guaranteed, where a control can still construct the invalid input and must stay enrolled to show no `Accepted` program contains it. Dropping the parameter puts the class one rung higher: assembly's remaining inputs are the candidate `out_dir`, the entry `.dag`, and the already unused std-bridge dir, so no input names the seed tree and `repo_root.join("src/v1/stage0/src/lib.rs")` has no representation to derive. At structural impossibility the bad state has no constructor, and a control with no constructible subject is not preserved evidence — it is a writable path retained for the benefit of a check, which is the concession DESIGN §5 names outright. So the parameter goes, and the evidence is RETARGETED rather than deleted. `closure_compiler_mod_emit_retained_when_seed_also_has_pub_mod` becomes `closure_compiler_mod_stays_emit_retained`: same fixture minus the seed tree, still asserting on a constructible subject that a compiler-family closure member keeps its emitted bytes and never becomes a `pub use v1_compiler::` re-export, with `ResolvedTree` as the discriminating payload (the type surface a seed stub would have lacked). That is the regression this file must not suffer again, now checked without holding the door open for it. `_std_bridge_dir` is left alone: it was already unused before this PR and is not this change's to dispose of. Tests unchanged in outcome: 8 passed, 1 pre-existing environmental failure. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
The last two files blocking
--required-regen, and the nine seed oracles no behavioral receipt can link withoutMeasured, not inferred — every number below is from a remote runner on this branch.
#8527landed while this was being measured and independently fixed four of the five refusals I had found inrequired_regen_host(the emit-path/basename key space, rustfmt being handed the emittedCargo.toml, the missing scratch directory, unlocated normalization diagnostics) plus the hand-file registration backfill — and did one part better than my version, givingbootstrap_stage0_crate_layout_generatedits ownWetActuatorGeneratedRegistrationrather than calling it hand-maintained. All of my duplicates are dropped. What remains is two things.1. The last two names in the population refusal
With
#8527merged,--required-regenstill refused:Both are listed as generated stage0 files and declared in
lib.rs, but their.dagauthorities are no longer reachable from thesrc/v1import closure, the emit has not produced them in some time, and no Rust in the crate references them. The deletion is verified rather than asserted: with them gone, the emittedlib.rsand the committedlib.rsdiffered by exactly the twopub modlines this PR removes and by nothing else — so the committed seed converges onto its authority's output.That meant editing
gunbc.stage0_emit_plan_generated, whose header says "do not hand-edit, regenerate viamain_wet" and whose producergunbc.stage0_emit_planis deleted —gunbc.generated_projection_pathsrecords that deletion in its own header,gunbc.roster_registrystill registers the rosterByDerivationfrom the dead module, andmain_wetleaves the file untouched. A do-not-hand-edit banner on a file nothing can generate is a false instruction; the header now says what is true. Restoring a producer or reclassifying the roster row is a real obligation and is deliberately not taken here.2. Nine seed oracles the seed crate did not declare
Every
dag/tools/self_host_*_shims/witness_main.rscomparesv1_compiled::v2_compiler_X(the emitted artifact under test) againstv1_compiler::v2_compiler_X— the seed crate, reached as an ordinary cargo dependency. Their roster rows intools.self_host_module_behavioral_transport_rostercarryshim_lib_rel: ""andshim_writes: [], so the harness writes nothing into that crate that could supply the path, andtools.self_host_curated_seed_linked_harnesscssl_closure_assembly_notestates that "seed lib.rs pub mod presence is external-oracle only" — present, and read, on the oracle side.A module the crate does not declare cannot be imported from it. Joining all 17 shim directories against the disk and
lib.rsgives a complete split, no remainder:01_tokenize,03_resolve,04_infer,program_partition,std_bridge00_compile,03_normalize,body_producer,discovery_enumeration,parse_engine_hooks,program_assembly,source_authority,target_carriers,use_site_verdicthas_pub_mod: false02_parse,03_ingest,materialization_carriersThe nine Class B rows are flipped to
has_pub_mod: true. Class C is deliberately untouched: adding rows for files that do not exist would make the crate-layout authority describe a tree that is not there, and it converts a shim that fails to link into a crate that fails to build.This also corrects
pre_existing_hand_retained_registration_backfill_note, which states the Gate-A oracles are "never part of the stage0 crate's own mod tree at all". The first half — that the CSSL harness compiles them standalone — is what the harness does; the second half cannot hold alongside a driver that imports them from the seed crate. The correction is written beside the note rather than the rows being flipped silently.What this does not claim. Declaring the modules is necessary, not sufficient, and it is not a receipt — nothing here executed a behavioral transport. It is also a two-generation change: the emitted
lib.rstakes its pub-mod block from the committedgunbc_stage0_crate_layout_generated.rs, itself one of the drifted files, so these declarations reach the built crate when the seed is regenerated, not when this merges.lib.rsis consequently back in the drift list, and that is the flip being visible rather than a regression.State after this PR
fixed_point_equal=truemeans emission repeatability: the same in-process G0 emits the corpus twice and produces identical bytes.It is NOT a self-host fixed point, and an earlier revision of this body implied it was — corrected here rather than annotated. Despite the flag's name,
run_required_regen_fixed_pointnever builds or invokes a candidate binary: it callscompile_stage0in the same running process that produced pass 1, and pass 1 itself comes from a binary built off the committed seed. So both passes are the same compiler. Reading it as "a compiler built from emitted sources reproduces itself" would be rung inflation (DESIGN §4b) — the claim is real and it is a weaker claim than its flag name suggests. Credit for the correction:stern-tern-636on #8618, which names the same thing about the same function.And a structural finding that is not fixable here, stated because the drift above reads as work someone has not done when it is work nobody currently can do. The regen cut deleted the writer and kept the comparator:
regen_stage0has no bin target and no source file (it survives only as a stale comment insrc/v1/stage0/Cargo.toml), andclaim_executor's two regen flags both compare —--required-regenwrites a candidate undertarget/and never the committed tree. So no mechanism in the tree can bring the committed generated artifacts back into agreement with their authority, andfirst_generation_equalis unreachable by construction rather than by defect. Escalated to the operator with receipts; it is not this PR's to decide.v1 maintenance classification
No
required_regen_hostchange survives in this diff (all dropped in favour of#8527), so nothing here touches the seed's Rust semantics. The remaining changes are a.dagauthority correction, a generated-projection roster correction, and the deletion of two dead files — no new language behavior, no compatibility obligation, no escape hatch or admission row, no seed feature completed, no public surface grown.Not done here, deliberately
CI enrollment of regen and the fixed point.
fixed_point_equalis green andfirst_generation_equalis not, so enrolling--required-regenas required today would red the workflow on a defect this PR does not own — and, per the finding above, on one that currently has no closing move at all. When it lands it goes throughgunbc.witness_floor_workflowand is regenerated, never a hand-authored workflow yaml.