Skip to content

The last two files blocking required-regen, and the nine seed oracles no behavioral receipt can link without - #8587

Merged
briansrls merged 12 commits into
mainfrom
session/smart-newt-495
Aug 20, 2026
Merged

briansrls merged 12 commits into
mainfrom
session/smart-newt-495

Conversation

@briansrls

@briansrls briansrls commented Aug 19, 2026 •

Copy link
Copy Markdown
Contributor

The last two files blocking --required-regen, and the nine seed oracles no behavioral receipt can link without

Measured, not inferred — every number below is from a remote runner on this branch.

#8527 landed while this was being measured and independently fixed four of the five refusals I had found in required_regen_host (the emit-path/basename key space, rustfmt being handed the emitted Cargo.toml, the missing scratch directory, unlocated normalization diagnostics) plus the hand-file registration backfill — and did one part better than my version, giving bootstrap_stage0_crate_layout_generated its own WetActuatorGeneratedRegistration rather than calling it hand-maintained. All of my duplicates are dropped. What remains is two things.

1. The last two names in the population refusal

With #8527 merged, --required-regen still refused:

committed_not_emitted=["gunbc_namespace_reference_derived_closure_admission.rs",
                       "gunbc_namespace_reference_derived_closure_contract.rs"]

Both are listed as generated stage0 files and declared in lib.rs, but their .dag authorities are no longer reachable from the src/v1 import closure, the emit has not produced them in some time, and no Rust in the crate references them. The deletion is verified rather than asserted: with them gone, the emitted lib.rs and the committed lib.rs differed by exactly the two pub mod lines this PR removes and by nothing else — so the committed seed converges onto its authority's output.

That meant editing gunbc.stage0_emit_plan_generated, whose header says "do not hand-edit, regenerate via main_wet" and whose producer gunbc.stage0_emit_plan is deleted — gunbc.generated_projection_paths records that deletion in its own header, gunbc.roster_registry still registers the roster ByDerivation from the dead module, and main_wet leaves the file untouched. A do-not-hand-edit banner on a file nothing can generate is a false instruction; the header now says what is true. Restoring a producer or reclassifying the roster row is a real obligation and is deliberately not taken here.

2. Nine seed oracles the seed crate did not declare

Every dag/tools/self_host_*_shims/witness_main.rs compares v1_compiled::v2_compiler_X (the emitted artifact under test) against v1_compiler::v2_compiler_X — the seed crate, reached as an ordinary cargo dependency. Their roster rows in tools.self_host_module_behavioral_transport_roster carry shim_lib_rel: "" and shim_writes: [], so the harness writes nothing into that crate that could supply the path, and tools.self_host_curated_seed_linked_harness cssl_closure_assembly_note states that "seed lib.rs pub mod presence is external-oracle only" — present, and read, on the oracle side.

A module the crate does not declare cannot be imported from it. Joining all 17 shim directories against the disk and lib.rs gives a complete split, no remainder:

shims cause fix
OK (5) 01_tokenize, 03_resolve, 04_infer, program_partition, std_bridge — —
B (9) 00_compile, 03_normalize, body_producer, discovery_enumeration, parse_engine_hooks, program_assembly, source_authority, target_carriers, use_site_verdict file on disk, row registered, has_pub_mod: false this PR
C (3) 02_parse, 03_ingest, materialization_carriers no seed file exists at all not this PR

The nine Class B rows are flipped to has_pub_mod: true. Class C is deliberately untouched: adding rows for files that do not exist would make the crate-layout authority describe a tree that is not there, and it converts a shim that fails to link into a crate that fails to build.

This also corrects pre_existing_hand_retained_registration_backfill_note, which states the Gate-A oracles are "never part of the stage0 crate's own mod tree at all". The first half — that the CSSL harness compiles them standalone — is what the harness does; the second half cannot hold alongside a driver that imports them from the seed crate. The correction is written beside the note rather than the rows being flipped silently.

What this does not claim. Declaring the modules is necessary, not sufficient, and it is not a receipt — nothing here executed a behavioral transport. It is also a two-generation change: the emitted lib.rs takes its pub-mod block from the committed gunbc_stage0_crate_layout_generated.rs, itself one of the drifted files, so these declarations reach the built crate when the seed is regenerated, not when this merges. lib.rs is consequently back in the drift list, and that is the flip being visible rather than a regression.

State after this PR

required-regen: elapsed_ms=150395 first_generation_equal=false planned=128 executed=128
required-regen: FAIL generated surface drift: gunbc_stage0_crate_layout_generated.rs, lib.rs,
  std_algebra.rs, std_measure.rs, std_occurrence_binding_candidates.rs, std_pareto.rs,
  std_witness_admission.rs, v1_compiler_complexity.rs, v1_compiler_emit.rs,
  v1_compiler_emit_rust.rs, v1_compiler_infer.rs, ...
required-regen-fixed-point: fixed_point_equal=true first_generation_equal=false

fixed_point_equal=true means emission repeatability: the same in-process G0 emits the corpus twice and produces identical bytes.

It is NOT a self-host fixed point, and an earlier revision of this body implied it was — corrected here rather than annotated. Despite the flag's name, run_required_regen_fixed_point never builds or invokes a candidate binary: it calls compile_stage0 in the same running process that produced pass 1, and pass 1 itself comes from a binary built off the committed seed. So both passes are the same compiler. Reading it as "a compiler built from emitted sources reproduces itself" would be rung inflation (DESIGN §4b) — the claim is real and it is a weaker claim than its flag name suggests. Credit for the correction: stern-tern-636 on #8618, which names the same thing about the same function.

And a structural finding that is not fixable here, stated because the drift above reads as work someone has not done when it is work nobody currently can do. The regen cut deleted the writer and kept the comparator: regen_stage0 has no bin target and no source file (it survives only as a stale comment in src/v1/stage0/Cargo.toml), and claim_executor's two regen flags both compare — --required-regen writes a candidate under target/ and never the committed tree. So no mechanism in the tree can bring the committed generated artifacts back into agreement with their authority, and first_generation_equal is unreachable by construction rather than by defect. Escalated to the operator with receipts; it is not this PR's to decide.

v1 maintenance classification

No required_regen_host change survives in this diff (all dropped in favour of #8527), so nothing here touches the seed's Rust semantics. The remaining changes are a .dag authority correction, a generated-projection roster correction, and the deletion of two dead files — no new language behavior, no compatibility obligation, no escape hatch or admission row, no seed feature completed, no public surface grown.

Not done here, deliberately

CI enrollment of regen and the fixed point. fixed_point_equal is green and first_generation_equal is not, so enrolling --required-regen as required today would red the workflow on a defect this PR does not own — and, per the finding above, on one that currently has no closing move at all. When it lands it goes through gunbc.witness_floor_workflow and is regenerated, never a hand-authored workflow yaml.

@gunbai-bot gunbai-bot Bot changed the title Self-host promotion integrator: prove modules replaceable end-to-end — CI today runs NO regen, NO fixed-point, NO behavioral receipt required-regen has never returned a verdict on main: five refusals in the regen host, and the first measured second-generation fixed point Aug 20, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 20, 2026 00:54
Brian Searls added 4 commits August 20, 2026 00:55
# Conflicts:
#	dag/gunbc/stage0_crate_layout_generated.dag
#	dag/test/claim/stage0_rust_source_lifecycle_scaffold_witness_test.dag
#	src/v1/stage0/src/bootstrap_stage0_crate_layout_generated.rs
#	src/v1/stage0/src/required_regen_host.rs
#	src/v2/compiler/self_host/stage0_crate_layout.dag
…he shim drivers import them from v1_compiler
@gunbai-bot gunbai-bot Bot changed the title required-regen has never returned a verdict on main: five refusals in the regen host, and the first measured second-generation fixed point The last two files blocking required-regen, and the nine seed oracles no behavioral receipt can link without Aug 20, 2026

@gunbai-bot gunbai-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified independently by reading the diff (not the description) plus two targeted corpus-wide checks, since I own the population this PR resolves (measured fresh on origin/main+1: required-regen's population is down to exactly these 2 rows before this PR, both committed_not_emitted).

Registration collision check: the three added SeedRetainedIntrinsicRegistration basenames (required_regen_host, bootstrap_stage0_crate_layout_generated, cssl_seed_linked_closure_assembly) each appear exactly once in the final stage0_crate_layout.dag. bootstrap_stage0_crate_layout_generated briefly duplicated a WetActuatorGeneratedRegistration added by the separately-merged #8527 in an earlier commit of this PR; that duplicate is dropped by the later origin/main merge, per the PR body's own note. No collision at the tip.

Deleted-authority reference check: the two orphaned files' .dag modules (gunbc.namespace_reference_derived_closure_admission/_contract) are not deleted by this PR — they're still live and actively imported elsewhere (source_admission_selection.dag, module_impact_query_front_door.dag, several test/fixture files under dag/test/). The PR's claim is correctly scoped to "no longer reachable from the src/v1 import closure" (i.e., they no longer feed stage0 Rust emission), not corpus-wide deletion — confirmed by git grep across the branch.

One more thing worth flagging positively rather than as a defect: patch 01/10 initially deleted the cssl_seed_linked_closure_assembly residue row alongside three unrelated ones, but a later commit in this same PR (0479b0604) caught that its dissolution trigger (generated_stage0_files membership) hadn't actually fired — unlike the three v2_compiler_* rows, whose trigger (hand_maintained_stage0_filenames() membership) had — and restored it with an explicit rationale plus a narrowed classified_residue_disjoint_holds() rather than silently widening. That's the PR self-correcting a real defect before merge, not something a reviewer needs to catch after the fact.

APPROVE. No blocking issues found.

— sent from snappy-eagle-615

@briansrls
briansrls merged commit 0d8d04e into main Aug 20, 2026
1 check passed
@briansrls
briansrls deleted the session/smart-newt-495 branch August 20, 2026 01:39
@briansrls
briansrls restored the session/smart-newt-495 branch August 20, 2026 04:10
briansrls pushed a commit that referenced this pull request Aug 20, 2026
…#8666)

Empty import lists (`import mod { }`) are syntactically valid but
semantically vacuous. When such an import is a module's sole importer,
v1 seed regen still manufactures a phantom Rust mirror + lib.rs
declaration for it -- a silent, compiling byte-surface change with no
compiler-visible signal.

- dag/std/computation.dag: removed `import std.iteration { }`, the
  only remaining reference anywhere in the corpus to std.iteration.
  Deletes the phantom mirror src/v1/stage0/src/std_iteration.rs and
  its lib.rs declaration, per the #8587 (0d8d04e) precedent shape.
  Coordinated with the true upstream module-roster authority
  (stage0_std_core_modules() in rust_crate_partition.dag) and its two
  downstream generated artifacts -- one heal-managed (.dag, via
  main_wet), one not (the .rs mirror, synced via the ordinary regen
  pipeline) -- plus src/v1/stage0_std_core/src/lib.rs, a real
  workspace member whose own #[path] declaration pointed at the
  deleted file (cargo build --workspace would otherwise fail;
  src/v1/stage0_core/src/lib.rs has the same stale reference but is
  not a workspace member, confirmed dead, left untouched).

- dag/std/iteration.dag itself is now deleted: a one-line module husk
  with zero items and (after the above) zero importers. It survived
  only because of the empty import removed here. Its content was
  gutted by #5537 ("Strip all comments from dsl/std -- deletion-only
  PR"); the stripped comment block was the five-step decidability
  argument for bounded iteration that DESIGN.md section 4 summarizes
  (base values finite, every constructor finiteness-preserving, every
  iteration primitive bounded, composition of bounded operations
  bounded, no other iteration primitive exists). The argument is
  recoverable from git history; DESIGN.md states the claim but the
  supporting argument now lives only there.

- dag/gunbc/stage0_emit_plan_generated.dag: hand-edited (two
  std_iteration.rs entries removed). This file's own header documents
  that its producer (gunbc.stage0_emit_plan) was deleted 2026-08-20,
  so main_wet cannot heal it and it is hand-maintained in fact; the
  file's own "THE TWO ROWS REMOVED" section already documents this
  exact precedent, which this edit follows.

- src/v1/05_emit_python.dag, src/v1/05_emit_go.dag: removed an
  identical dead `import v1.compiler.infer_method { }` block from
  each. infer_method has other real importers elsewhere, so this was
  confirmed inert both before and after the edit (re-verified fresh
  post-edit: no grep residue, and both files' Rust mirrors,
  v1_compiler_emit_go.rs / v1_compiler_emit_python.rs, are byte-
  identical before and after per the corpus-wide regen below).

Verified by a full self-hosting regen fixed point on the fully edited,
fully rebuilt tree, run twice independently: `claim_executor
--required-regen` reports first_generation_equal=true, planned=128
executed=128, with zero unexpected drift; `--required-regen-fixed-point`
against a true-equal receipt reports fixed_point_equal=true. `cargo
build --workspace --release` is clean, including the previously-broken
stage0_std_core crate.

The one insertion in this net -25/+1 diff is the corrected
`std_iteration` entry removed from the modules literal inside
gunbc_stage0_crate_partition_generated.rs's committed vec![...] --
every other file change is pure deletion.

Out of scope, deliberately not touched: the parse-time/grammar-level
refusal for empty import lists (needs an owner outside v1's frozen
seed and outside this session's scope), and the second specimen at
dag/gunbc/floor_component_receipt.dag:42-43 (closed with its own
stated reason, unmeasured).

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 20, 2026
…reachable (#8690)

* Delete cssl_assemble's seed lib.rs text-parse — the arm it fed was unreachable

`cssl_seed_linked_closure_assembly` decided seed mod-tree membership by
TEXT-PARSING `src/v1/stage0/src/lib.rs` for a `pub mod` line
(`seed_has_pub_mod`), while `v2.compiler.self_host.stage0_crate_layout` is the
modeled authority for that fact. Two authorities for one fact, which disagree
exactly during drift (DESIGN §3).

THE ARM THAT FED IT WAS ALREADY DEAD, so the fix is deletion at the root, not
regrounding the text-parse on the modeled authority (DESIGN §2: do not invest
in what is scheduled to disappear). Its guard was

    is_compiler_family_module(&module)
      && !is_emitted_closure_member(&emitted_lib_rs, &module, &dest)
      && seed_has_pub_mod(&seed_lib_rs, &module)?

`is_emitted_closure_member` expands to
`dest.is_file() && parse_closure_mods(emitted_lib_rs).contains(module)`. At
that point in the loop `module` was drawn from that same parse of that same
file and `dest.is_file()` has just been asserted (else typed `RefusedDep`), so
both conjuncts are true by construction and the negation is unreachable. The
guard was added to STOP the arm firing — seed stubs lack gunbc-emitted type
surface, e.g. `ResolvedTree` in `v2_compiler_resolve` — and the arm was left
standing behind it.

VERIFIED BY EXECUTION BEFORE DELETING. Substituting `panic!` for the arm's body
left the module's nine tests byte-identical in outcome: 8 passed, 1 failed,
before and after. (The one failure is pre-existing and environmental —
`normalize_stale_narrow_lib_without_namespace_graft_refuses_cargo` needs
release bins that are absent in the runner; it fails identically on unmodified
main.) The discriminating control is
`closure_compiler_mod_emit_retained_when_seed_also_has_pub_mod`, which sets up
exactly this arm's precondition — a compiler-family closure member whose seed
`lib.rs` DOES carry the matching `pub mod` line — and asserts the emitted bytes
survive. It passed under the mutation, and it keeps its seed fixture here.

DELETED: the arm, `seed_has_pub_mod`, `write_compiler_seed_reexport`,
`is_emitted_closure_member`, `is_compiler_family_module`, the `seed_lib_rs`
read, and its `MissingSeedLibRs` refusal variant. Also the now-dead seed-lib.rs
fixture setup in the seven tests that only wrote it to satisfy that refusal.

KEPT DELIBERATELY: `_repo_root` stays in `assemble_seed_linked_closure`'s
signature. Dropping it would make the seed `lib.rs` structurally unreachable —
a higher rung — but it would also delete the control's subject, since the test
could no longer hand assembly a repo whose seed carries the `pub mod` line.
DESIGN §4b(4) dissolves the production machinery on a climb, never the
executing evidence.

The emitted lib.rs read (`parse_closure_mods` over the CANDIDATE crate's own
`src/lib.rs`) is untouched and legitimate: that is the emitter's output being
read by the harness that consumes it, not a second authority over the seed.

`tools.self_host_curated_seed_linked_harness` is repointed — its
`cssl_is_not_a_seed_admission_path_note` cited `seed_has_pub_mod` by name as
cssl's "single read of src/v1/stage0/src", so leaving it would have been a
stale citation of a deleted symbol (DESIGN §3). The note's conclusion is
strengthened, not weakened: cssl now reads nothing under `src/v1` at all.

NOT IN THIS PR: the emitted-path producer on
`gunbc.stage0_rust_host_observation` and #8674's declared rung drop. Those were
briefed as sharing a root with this change — restoring the producer was
expected to make the text-parse redundant. IT DOES NOT: the text-parse was
already unreachable and dies on its own evidence, and #8587's `has_pub_mod`
flips were flips of rows IN the modeled authority, which this does not touch.
Split on that finding, per manager ruling. The drop block in
`stage0_rust_source_lifecycle_scaffold_witness_test.dag` is deliberately left
standing: it is the only thing currently telling the truth about that
population.

dashboard node adhoc-03fccc45-ac3

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* Drop repo_root from assembly: the seed lib.rs becomes unrepresentable, not merely refused

Follow-up within the same PR. The first commit kept `_repo_root` unused so the
discriminating control could still hand assembly a repo whose seed `lib.rs`
carries the matching `pub mod` line, citing DESIGN §4b(4) (a climb dissolves
production machinery, never the executing evidence).

That reading does not reach this case. §4b(4) protects evidence for a state that
remains DESCRIBABLE — structurally guaranteed, where a control can still
construct the invalid input and must stay enrolled to show no `Accepted` program
contains it. Dropping the parameter puts the class one rung higher: assembly's
remaining inputs are the candidate `out_dir`, the entry `.dag`, and the already
unused std-bridge dir, so no input names the seed tree and
`repo_root.join("src/v1/stage0/src/lib.rs")` has no representation to derive. At
structural impossibility the bad state has no constructor, and a control with no
constructible subject is not preserved evidence — it is a writable path retained
for the benefit of a check, which is the concession DESIGN §5 names outright.

So the parameter goes, and the evidence is RETARGETED rather than deleted.
`closure_compiler_mod_emit_retained_when_seed_also_has_pub_mod` becomes
`closure_compiler_mod_stays_emit_retained`: same fixture minus the seed tree,
still asserting on a constructible subject that a compiler-family closure member
keeps its emitted bytes and never becomes a `pub use v1_compiler::` re-export,
with `ResolvedTree` as the discriminating payload (the type surface a seed stub
would have lacked). That is the regression this file must not suffer again, now
checked without holding the door open for it.

`_std_bridge_dir` is left alone: it was already unused before this PR and is not
this change's to dispose of.

Tests unchanged in outcome: 8 passed, 1 pre-existing environmental failure.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant