Skip to content

BT1: SDLC pipeline compiles with unit_test profile - #86

Closed
briansrls wants to merge 1 commit into
mainfrom
claude/blue-team-bt1
Closed

briansrls wants to merge 1 commit into
mainfrom
claude/blue-team-bt1

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Three fixes to get build_dsl_graph_with_profile("pipelines/sdlc.dag", "unit_test") working:

  1. Transport blocks for services: Added transport rest { ... } to github/pull_request.dag (7 ops) and llm/openai.dag (2 ops). These services are directly imported by the SDLC pipeline and need transport specs for the lowerer to generate prepare/execute/parse triplets.

  2. Profile-scoped module loading: include_profile_modules() now only loads implementation modules for the active profile, not all profiles. Previously, compiling with unit_test would also load codex_agent_provider, github_issue_provider, etc. from the local/cloud_run profiles.

  3. InterfaceStub for service implementations: Services using service Foo : BarInterface syntax (implementing an interface) with no transport block now get InterfaceStub transport class instead of Unknown. This lets stub providers compile without explicit transport declarations.

Scouted: github/issues.dag also lacks transport blocks (needed for BT6/local profile).

Three fixes to get `build_dsl_graph_with_profile("pipelines/sdlc.dag", "unit_test")` working:

1. **Transport blocks for services**: Added `transport rest { ... }` to
   github/pull_request.dag (7 ops) and llm/openai.dag (2 ops). These
   services are directly imported by the SDLC pipeline and need transport
   specs for the lowerer to generate prepare/execute/parse triplets.

2. **Profile-scoped module loading**: `include_profile_modules()` now only
   loads implementation modules for the active profile, not all profiles.
   Previously, compiling with unit_test would also load codex_agent_provider,
   github_issue_provider, etc. from the local/cloud_run profiles.

3. **InterfaceStub for service implementations**: Services using
   `service Foo : BarInterface` syntax (implementing an interface) with no
   transport block now get InterfaceStub transport class instead of Unknown.
   This lets stub providers compile without explicit transport declarations.

Scouted: github/issues.dag also lacks transport blocks (needed for BT6/local profile).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@briansrls briansrls closed this Feb 27, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: edaf817143

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

// Only include implementation modules for the active profile,
// not all profiles. This avoids loading transport-incomplete
// providers that aren't used by the active profile.
if active_profile != Some(def.name.as_str()) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Match active profile against fully qualified names

include_profile_modules now filters binds with active_profile != Some(def.name.as_str()), which only matches profile aliases (e.g. local) and never matches fully qualified names (e.g. profiles.sdlc.local). This regresses the disambiguation path used when aliases collide: in this repo both dsl/profiles/gist.dag and dsl/profiles/sdlc.dag define profile local, and lowerer diagnostics explicitly require fully qualified names for ambiguous aliases. With a fully qualified --profile, this filter skips the active profile's implementation modules, so bound service endpoints are not loaded and profile compilation fails for valid profiles.

Useful? React with 👍 / 👎.

briansrls added a commit that referenced this pull request May 6, 2026
…arkers)

Per gunbc PM review on PR #1879 (deep-wolf-155, 2026-05-06T20:46:43Z):
within each layer-block the CENTER mixed three origin classes — direct
mirror of .dag, user-authored .dag logic, and fold-rule auto-emit —
all sharing one tint. Applying the recommended Path A: light-touch
inline markers that flag the auto-emit lines, plus a load-bearing
qualifier on the TESTS panel.

Changes:
- TESTS panel header: "// tests — R3 DELIVERABLE (T-Tests-As-Data
  lane; not emitted today)". Legend tests row updated to match. The
  panel previously claimed behavior that doesn't exist yet — verified
  by the PM that gunbc emits 0 #[cfg(test)] markers today and that R3
  closure gates #74/#84/#85/#86/#87 will deliver this.
- Inline "// auto — fold rule" annotations (italic gray, via tspan)
  on the three impl blocks that the structural fold emits without
  authored source: impl<A,B> Sum<A,B> (constructors + predicates),
  impl HttpError (new), impl LoginRequest (new).
- Subtitle updated so the auto-marker convention is explained at the
  top of the diagram.

Not applied (intentional, lighter touch):
- #[derive(...)] left as plain code — deriving is universally
  understood as mechanical, the layer comment + auto-marker on the
  impl block is enough signal.
- unimplemented!() left as plain code — body filler is obviously
  placeholder; over-marking would clutter.
- Within-helpers fact-vs-logic split (Result alias vs map/and_then)
  not visually separated — the helpers layer comment will gain a
  small clarifier in a follow-up if it reads ambiguous.
briansrls added a commit that referenced this pull request May 9, 2026
…rrier-shape (codex BLOCKING)

codex inline BLOCKING @ docs/audit/r3-cluster-m-sequencing-plan-2026-05-09.md:92:
"§3 reopens #85/#86 carrier-shape and Director-ratification questions
even though docs/design-tests-as-data-completeness.md already
canonically defines ProgramGenerator/Quantifier/QuantifiedTestClaim
and says no Director ratification is required before lane dispatch,
creating a second authority for the lane plan (INVARIANTS P2 single
authority)."

Verified: docs/design-tests-as-data-completeness.md exists on main
(blob ff49723). §1 Authority discipline says "All §8 design
questions resolved in-doc per feedback_design_before_implement — no
Director ratification required before lane dispatch (only standard
cascade gates: R2-Evaluator landed; existing TestClaim infrastructure
from DB-15 R2)." §2.1 canonically defines ProgramGenerator;
§2.2 canonically defines Quantifier (closed two-variant ForAll/Exists
sum) + QuantifiedTestClaim with Rust signatures.

My §3.1/§3.2 framing as "substrate canvas needed; Director
ratification needed before brief authoring" was a duplicate-authority
anti-pattern — should have grep-verified locked design before
authoring canvas-tier framing per `feedback_grep_verify_locked_design_before_ratification`.

Fix-forward across:
- §3 header + intro (line 71): citation to locked design + authority
  correction explaining the prior duplicate-authority error
- §3.1/§3.2 (lines 79/85): rewrite from "substrate canvas needed +
  Director ratifies" → "carrier landing per locked design § ; no
  Director ratification needed; standard cascade gates only"
- §2 Lane-Mgr partition table (lines 64/65): authoring scope cites
  locked design instead of "need substrate canvas first"
- §2 closing prose (line 69): "no canvas-tier ratification — design-doc
  resolves shape per §1 Authority discipline"
- §4 (line 91): "carrier landings per locked design not blocking"
  instead of "substrate canvases for #85/#86 not blocking"
- §6 velocity projection (line 126): "carrier landings per locked
  design" instead of "substrate canvas + carrier authoring"
- §6 risk (line 132): replaced "canvas-tier ratification adds 1-3 days"
  with "STOP-and-PING via Substrate Mgr inbox if migration shape
  surprises arise per feedback_construction_over_ratchets"

Single canonical authority restored: locked design
docs/design-tests-as-data-completeness.md §2.1/§2.2 owns
ProgramGenerator/Quantifier/QuantifiedTestClaim shape; this sequencing
plan owns Cluster M phase ordering only.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 9, 2026
… option-(c) discipline + SG-0 tracker (#2361)

* docs(r3): PB-0 remediation program — Cluster M sequencing + §10 RED + option-(c) discipline + SG-0 tracker

Director-greenlit partner work (gunbc#846 #issuecomment-4412008376) for the Pure-Bootstrap-Zero remediation program. Operator directive 2026-05-09: "course correct; existing plan stays canonical; staffing is not a concern; this is planning/correction." Branch-A from framing question: PB-0 by R3 close stays load-bearing.

Bundles 5 partner-work artifacts:

1. **`docs/audit/r3-cluster-m-sequencing-plan-2026-05-09.md`** (Task 1) — 3-phase sequencing plan for Cluster M (T-Tests-As-Data-Completeness gates #84/#85/#86/#87) with lane-Mgr partition (Substrate authors #85/#86 substrate canvases; Verification authors #87 cementing-test discipline + #84 bulk-port). 4-8 week velocity projection fits 8-12 week R3 window with parallel dispatch.

2. **`docs/audit/r3-sg0-trajectory-tracker.md`** (Task 5) — daily-cadence schema + first 5-row history table; 3 threshold alarms; data source for new R3-close progress bars.

3. **`docs/r3-program-plan.md` §10.3 amendments** (Task 4) — adds Q-PB0-Trajectory-Risk5 + Q-PB0-ClusterM-Cold-Risk6 + Q-Cluster-M-Reclassification rows (RATIFIED 2026-05-09 per Director acknowledgment).

4. **`ROADMAP.md`:177 amendment + `scripts/check-pr-sg0-net-shrink-discipline.sh` tightening** (Task 3) — option-(c) deferrals now require concrete dispatch evidence (gunbc#NNNN issue ref OR docs/briefs/*.md path), not just "named follow-up dispatch" word. Closes the +30/9days option-(c) paper-trail leak. Self-tests pass.

5. **§8 dispatch readiness checklist** in sequencing plan — surfaces Director ratification needed on dispatch shape (single-coordinator vs 4-parallel-worker vs hybrid); cites existing PRE-AUTH DISPATCH-READY brief at `docs/briefs/r3-v-tests-as-data-v1-worker.md` (tier-1 queue #1859).

PM-tier authoring; Director ratifies before dispatch. Pre-authored worker briefs (Task 2 sub-task) await Director's choice of dispatch shape per §8.1; current PR scopes to plan + amendments + tightening + tracker.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): asks 6 + 9 — TC1 #11 plan-language sync + gate-count canonicalization (Director scope expansion)

Director scope expansion at gunbc#846 #issuecomment-4412017502 (parallel Director audit findings, 2026-05-09). First wave of 6 NEW asks (6-11) bundled into existing remediation PR per Director sequencing recommendation.

**Ask 6 — TC1 §1.8 row #11 plan-language sync**:
Row #11 prior text claimed "flips DECLARED → CONSUMER_LANDED → PASSING in one move on Evaluator E3.c (#1970) merge." This contradicts ratified Director (a)-disposition (#828 decision id `473b99fb...` 2026-05-09) where TC1 stays DECLARED through R3 (gate #11 cannot reach PASSING absent #1972 substrate canvas-tier work, which is HELD-CANVAS-DEFERRED past R3 per Substrate Mgr Path-A confirmation 2026-05-08). Amended row #11 to reflect honest sub-status; prior phrasing superseded.

**Ask 9 — gate-count canonicalization (94 vs 95 ambiguity)**:
Added explicit canonical breakdown: `97 enumerated - 3 R4-carved (#81/#82/#95) = 94 R3-load-bearing`. Gate #97 IS part of the 94 set (not additive). Future closure-arithmetic citations must use {97 enumerated, 94 load-bearing, 81 lane-aligned} canonical numbers to avoid +/-1 drift.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(r3): §1.5 arithmetic vs row #11 + SG-0 tracker fragments scope (openai-pro REQUEST_CHANGES)

openai-pro review on PR #2361 sha 6efde88: 2 valid findings.

**Finding 1 BLOCKING — §1.5 arithmetic vs row #11 contradiction**:
§1.5 said "97 - 3 R4-carved = 94 R3-load-bearing; #97 IS part of 94" while row #11 said "stays DECLARED through R3; not load-bearing for R3-thesis honest-close arithmetic." Two authorities for what counts as R3-load-bearing.

Fix: refined §1.5 canonical breakdown to {97 enumerated → 94 post-R4-carve → 93 post-canvas-deferral}. Gate #11 added to "post-R3-canvas-deferred" category alongside R4-carved set; effectively removed from R3-thesis-honest-load-bearing arithmetic per Director (a)-disposition. Both 94 and 93 are canonical for different purposes:
- 94 = post-R4-carve enumeration count (R4 boundary discussions)
- 93 = R3-thesis-honest-close conjunction count (actual R3 close gate-count requirement)

**Finding 2 NON-BLOCKING — SG-0 tracker fragments scope**:
Tracker procedure extracted only `EXPECTED_HAND_AUTHORED_NON_TEST` + `EXPECTED_HAND_AUTHORED_TEST`, but ROADMAP.md:177 names the SG-0 delta surface as `EXPECTED_HAND_AUTHORED_*` ∪ fragments. Tracker undercounted live debt.

Fix: added `fragments` column to tracker schema + procedure; updated history table with retroactive `fragments=1` (per `parse_parser_body.txt`). New total formula: `non_test + test + fragments`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(r3): §1.5 + tracker + script — full canonicalization round (openai-pro REQUEST_CHANGES round 2)

openai-pro review on PR #2361 sha 5b10ed2 found 3 remaining inconsistencies after round 1 fix:

**Finding 1 — §1.5 still said "94 R3 thesis-load-bearing" alongside new "93 honest-load-bearing"**:
Refactored §1.5 opening to enumerate three canonical numbers explicitly: 97 enumerated / 94 post-R4-carve enumerated / 93 R3-thesis-honest-load-bearing. Removed legacy "94 are R3 thesis-load-bearing" framing in favor of the unambiguous breakdown.

**Finding 2 — SG-0 tracker §4 used 149 + "0+0" while §3 schema/history says 150 + "0+0+0"**:
Updated §4 to match: "150 entries (48 non_test + 101 test + 1 fragments)" + "0 + 0 + 0" target. Updated §7 progress-bar guidance: "150 → 0".

**Finding 3 — script regex didn't accept full GitHub issue URLs (ROADMAP says URL form is acceptable)**:
Expanded regex to accept `https?://github.com/.../issues/NNNN` form alongside gunbc#NNNN + docs/briefs/*.md. Updated error message + comment block. Added passing self-test for full GitHub URL form. Self-tests pass.

Boundary contract between ROADMAP option-(c) language and script regex now aligned; canonical R3 closure arithmetic single-authoritied; SG-0 tracker fully consistent across schema / current-state / progress-bar guidance.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(r3): close-condition strictness + brief-path file existence + Risk5 fragments-inclusive numbers (codex BLOCKING)

codex BLOCKING review on PR #2361 sha b925b17 + 1 non-blocking. All 3 findings addressed.

**Finding 1 BLOCKING — temporary exception handling folded into close condition**:
Cluster M plan §1.3 #84 close criterion previously said "count = 0 (or carries only Director-allocated exceptions)" — folding exceptions into close. Codex correct: this leaves PB-zero ratchet escapable. Tightened to strict zero; Director-allocated timed-carries (e.g., Option 2 cross_target_coverage_carrier_test.rs) are now blockers/non-close-risk until they migrate to testgen-coverage. R3-honest-close requires actual zero, not "zero-except-exceptions". §5.1 receipt language matched.

**Finding 2 BLOCKING — script reduces dispatch evidence to string pattern**:
Brief paths cited in option-(c) pairings now require file existence verification at $ROOT/$path. String-pattern match alone was escapable (cite a fictional brief path, satisfy regex). Issue refs / GitHub URLs are external and not file-checkable here, so they pass through pattern check only. Updated script self-tests to use existing brief path (docs/briefs/r3-v-tests-as-data-v1-worker.md); added new fail case for nonexistent brief path. Self-tests pass.

**Finding 3 NON-BLOCKING — Risk5 numbers misaligned with fragments-inclusive surface**:
§10.3 Risk5 cited 119→149; tracker + ROADMAP surface (post-fragments-inclusion) is 120→150. Updated Risk5 row to fragments-inclusive numbers; cited tightening provenance.

Boundary contract now consistent: close-condition matches "actual zero" semantics; script enforces file-existence for brief-path evidence; Risk5 numbers match canonical surface.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(audit): §9.3 — close stale open question that contradicts §1.3/§5.1 strict zero (codex inline BLOCKING)

codex inline BLOCKING @ docs/audit/r3-cluster-m-sequencing-plan-2026-05-09.md:174: §9 question 3 ("does Phase 3 close fold Director-allocated exceptions") was left open after §1.3 + §5.1 were tightened to strict-zero. Inconsistent close-authority within same doc.

Fix: marked §9.3 RESOLVED with cross-reference to §1.3/§5.1 canonical close-condition language. Strict-zero adopted; Option 2 timed-carries are blockers, not closure-allowed exceptions. Question is no longer open.

Internal close-authority now consistent across §1.3 (canonical close-condition) + §5.1 (Phase 3 receipt) + §9.3 (resolved-not-open).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(sg-0): brief-path canonicality + path-traversal rejection (codex BLOCKING)

codex inline BLOCKING @ scripts/check-pr-sg0-net-shrink-discipline.sh:119: existence check alone insufficient — regex permits docs/briefs/../*.md which could resolve to non-brief files outside docs/briefs/.

Fix: added path-traversal rejection (any `..` segment fails) + canonical-prefix check (resolved path must remain under docs/briefs/). Existence check retained.

New self-test: "(c) cited brief path with path-traversal (.. segment)" expects fail. Prior self-tests still pass.

Defense-in-depth ordering:
1. Reject `..` segments (path-traversal)
2. Reject paths not under docs/briefs/ (canonical-prefix; redundant with regex but guards future regex relaxation)
3. Verify file exists at $ROOT/$p

Brief-path option-(c) discipline now enforces (a) prefix-locked, (b) path-traversal-free, (c) file-existing — three orthogonal checks closing the prior escape paths.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §1.5 gate-count framing — carve-promotion-aware (Director amendment ask)

Per Director amendment ask at gunbc#846 #issuecomment-4412343280: replace prior "97 - 3 R4-carved = 94 R3-load-bearing" framing with carve-promotion-aware "97 R3-load-bearing gates green, no carves" forward-looking framing.

Per Director ratification 2026-05-09 at gunbc#846 c#4412330468 (operator framing "0 hand-Rust including tests AND stage0; bootstrap is data + self-generated"): R4 carves C1 / C2 / C3 (gates #81 / #82 / #95) are PROMOTED-IN-R3 as lens-producer-retirement work folded into Cluster F.

Updated canonical breakdown:
- 97 enumerated total
- 0 R4-carved at R3 close (carves dissolved per c#4412330468)
- 1 post-R3-canvas-deferred {#11} (TC1 V1 strict-fire; #1972 substrate canvas-tier deferred past R3)
- 96 R3-thesis-load-bearing = 97 − 1 = 96

R3 close target = 96 R3-load-bearing gates GREEN (was 93 prior round; was 94 before that). Forward-looking framing avoids the drift instance per PR #2358 §8 meta-finding (publishing "94" or "93" now would drift within hours of Director ratifying carve-promotion).

This change dissolves expansion Ask 10 (gate #95 carve cross-ref) — Cluster F carve-promotion follow-up PR handles r4-carve-out-routing.md amendment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(r3): §1.5 intro arithmetic single-authority — remove stale 94/93 framing (codex BLOCKING)

codex inline BLOCKING @ docs/r3-program-plan.md:86: §1.5 intro paragraph retained "97 enumerated / 94 post-R4-carve / 93 R3-thesis-honest-load-bearing" framing while the canonicalization block below said "0 R4-carved / 96 R3-thesis-load-bearing." Two competing authorities for R3 gate arithmetic (P2 single-authority violation).

The 94/93 framing was stale post-Director carve-promotion-IN-R3 ratification at gunbc#846 c#4412330468 — should have been removed when canonicalization block was added but I missed the intro paragraph.

Fix: §1.5 intro now says "97 enumerated / 96 R3-thesis-load-bearing (no carves; only #11 canvas-deferral subtracted)." Single authority for R3 gate arithmetic. Carve-promotion citation in intro matches canonicalization block.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(sg-0): option-(c) regex — require qualified gunbc# prefix; reject bare #NNNN gate-numbers (codex BLOCKING)

codex inline BLOCKING @ scripts/check-pr-sg0-net-shrink-discipline.sh:119: regex `[[:space:]]#)[0-9]+` matched bare #NNNN tokens in prose like "dispatch for gate #84" — gate numbers (#84, #85, etc. are R3 gate IDs cited in §1.8 ledger), not issue refs. This let option-(c) deferrals pass with what looks like a tracker reference but is actually just a gate number mentioned in passing.

Fix: regex tightened to require qualified `gunbc#NNNN` or `gunb-ai/gunbc#NNNN` form (or full GitHub URL). Bare `#NNNN` no longer accepted. Self-test added: "(c) bare #NNNN gate-number-in-prose" expects fail.

Error message updated to make the distinction explicit: "qualified tracker issue ref (gunbc#NNNN or gunb-ai/gunbc#NNNN). Bare #NNNN refs (which could be gate numbers in prose) no longer accepted."

Self-tests pass.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(sg-0): error message backtick → single-quote (openai-pro APPROVE_WITH_COMMENTS)

openai-pro review on PR #2361 sha 3673f1c: shell-backticks around `..` in path-traversal error message at line 137 are command-substitution, not literal-text quoting. Shell tries to execute `..` as command before printing the GitHub Actions error, producing avoidable shell noise.

Fix: replaced backtick-quoted `..` with single-quoted '..' in error message. Branch still returns failure cleanly; no shell side-effects on diagnostic path. Self-tests pass.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(r3): Cluster M docs hygiene + SG-0 (c) comment alignment (codex non-blocking)

codex review on PR #2361 sha ba18ef8: 0 BLOCKING + 2 non-blocking
hygiene findings.

**Non-blocking #1 — Cluster M parent-doc anchors**

THESIS.md:298 + ROADMAP.md:88 line citations don't precisely point
to "zero-Rust-tests" authority — THESIS:298 says "0 hand-maintained"
(broader scope including non-test); ROADMAP:88 IS the T-PB-B row but
line numbers drift. Per `feedback_section_anchors_over_line_numbers`,
switched to structural references: THESIS.md "Pure Bootstrap to Zero"
framing + ROADMAP.md T-PB-B lane row (`pb_rust_tests_outside_residual_zero`
predicate explicitly named).

**Non-blocking #2 — SG-0 (c) comment vs regex divergence**

Comment at line 113 said "(c) now requires ... an issue ref (gunbc#NNNN
or #NNNN)" but regex on line 119 + error message on line 120 reject
bare #NNNN (gate-number-in-prose risk). Comment was stale relative to
2026-05-09 codex BLOCKING tightening (commit later in this PR).

Fix: aligned comment to regex — "(gunbc#NNNN or gunb-ai/gunbc#NNNN)";
explicitly noted "Bare #NNNN refs (could be gate-numbers in prose)
are NOT accepted" matching the error message language.

Self-test case at line 343 already validates the rejection
("(c) bare #NNNN gate-number-in-prose"); behavior unchanged, only
comment alignment.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(script): SG-0 (c) URL regex tightened to gunb-ai/gunbc tracker only (openai-pro REQUEST_CHANGES)

openai-pro REQUEST_CHANGES on PR #2361 sha ba18ef8: option-(c) full-URL
alternative accepted any GitHub issue URL via
`https?://github\.com/[[:alnum:]_./-]+/issues/[0-9]+`. This let unrelated
external repos (github.com/other/repo/issues/1234) satisfy the SG-0
deferral gate, undermining the "tracked dispatch" single-authority
contract. ROADMAP option (c) is "dispatch-tracker issue URL", which
implicitly means the gunbc tracker.

Fix:
- Tightened URL regex to `https?://github\.com/gunb-ai/gunbc/issues/[0-9]+`
- Updated error message to name "gunb-ai/gunbc issue URL" explicitly
- Added negative self-test case for external-repo URL rejection
  (matches openai-pro's request: "an external repo URL such as
  https://github.com/other/repo/issues/1234 should fail")

Self-test passes after change. Behavior:
- gunbc#NNNN: pass (unchanged)
- gunb-ai/gunbc#NNNN: pass (unchanged)
- https://github.com/gunb-ai/gunbc/issues/NNNN: pass (positive case at line 346)
- https://github.com/other-org/other-repo/issues/NNNN: fail (NEW negative case at line 351)
- docs/briefs/*.md (existing canonical path): pass (unchanged)
- bare #NNNN: fail (unchanged)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(r3): r3-program-plan post-carve-promotion reconciliation (codex BLOCKING on PR #2361)

codex inline BLOCKING @ docs/r3-program-plan.md:99: "the new 96/no-carves
close target is not propagated to the later §1.8 close formula or the
referenced r3-structure/r4-carve authorities that still mark #81/#82/#95
carved, leaving two R3 close authorities (INVARIANTS P2 single
authority)."

PR #2361's §1.5 canonicalization block (added at sha 2e782f2) introduced
"96 R3-load-bearing / 0 carves" framing but didn't reconcile parallel-
authority references elsewhere. Same drift PR #2364 had (fixed at sha
bc45e59 on that branch). PR #2361 needs the same comprehensive
reconciliation to be self-consistent on its own merit.

Fix-forward across:
- §1 top "R3 close" definition (line 8) — replace stale "97/CARVED to R4 / option (b)" with carve-promotion-aware framing
- §1.5 §1.5 canonicalization sub-bullets (lines 86, 95, 96) — clean fabricated `473b99fb...` placeholder hash, update r4-carve-out-routing.md cross-ref to PR #2364 (actual carve-promotion PR, not PR #2363 which is the substrate-readiness audit)
- §1.5 R4-carved §1.8 rows paragraph (line 109) — DISSOLVED note + carve-promotion citations + cross-ref to PR #2364
- §1 Pass-surface bullets (lines 112, 115) — 94 → 96
- §1.7 R3 close criteria implies (line 107) — "all non-carved" → "all 96 R3-load-bearing"
- §1.6 lane gate row T-Lens-Behavioral-Parity (line 187) — all 4 lenses R3-load-bearing
- §1.8 row #11 (line 229) — clean `473b99fb...` placeholder
- §1.8 row #73 status (line 291) — all 4 lenses post-promotion framing
- §1.8 row #81/#82/#83 (lines 299/300/301) — R3-LOAD-BEARING carve-promoted within Cluster F
- §1.8 row #95 (line 313) — R3-LOAD-BEARING carve-promoted; cascade prereqs
- §1.8 epilogue (line 320) — 94 → 96
- §5/6 R3 close (line 607) — 94 → 96
- §10.3 Q-LBP-R3-Closeability (line 1040) — appended 2026-05-09 AMENDED note dissolving option (b) carve-narrowing

Single canonical authority: 97 enumerated → 96 R3-load-bearing
(only #11 canvas-deferred; 0 R4 carves at R3 close per Director
ratification 2026-05-09 c#4412330468). Cited consistently across
§1 / §1.5 / §1.6 / §1.7 / §1.8 / §3 / §5 / §10.3.

Note on PR #2364 overlap: PR #2364's bc45e59 lands the same
reconciliation. This PR makes #2361 self-consistent independent of
merge ordering — squash-merge resolves overlapping content cleanly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(audit): Cluster M §3 — cite locked design instead of reopening carrier-shape (codex BLOCKING)

codex inline BLOCKING @ docs/audit/r3-cluster-m-sequencing-plan-2026-05-09.md:92:
"§3 reopens #85/#86 carrier-shape and Director-ratification questions
even though docs/design-tests-as-data-completeness.md already
canonically defines ProgramGenerator/Quantifier/QuantifiedTestClaim
and says no Director ratification is required before lane dispatch,
creating a second authority for the lane plan (INVARIANTS P2 single
authority)."

Verified: docs/design-tests-as-data-completeness.md exists on main
(blob ff49723). §1 Authority discipline says "All §8 design
questions resolved in-doc per feedback_design_before_implement — no
Director ratification required before lane dispatch (only standard
cascade gates: R2-Evaluator landed; existing TestClaim infrastructure
from DB-15 R2)." §2.1 canonically defines ProgramGenerator;
§2.2 canonically defines Quantifier (closed two-variant ForAll/Exists
sum) + QuantifiedTestClaim with Rust signatures.

My §3.1/§3.2 framing as "substrate canvas needed; Director
ratification needed before brief authoring" was a duplicate-authority
anti-pattern — should have grep-verified locked design before
authoring canvas-tier framing per `feedback_grep_verify_locked_design_before_ratification`.

Fix-forward across:
- §3 header + intro (line 71): citation to locked design + authority
  correction explaining the prior duplicate-authority error
- §3.1/§3.2 (lines 79/85): rewrite from "substrate canvas needed +
  Director ratifies" → "carrier landing per locked design § ; no
  Director ratification needed; standard cascade gates only"
- §2 Lane-Mgr partition table (lines 64/65): authoring scope cites
  locked design instead of "need substrate canvas first"
- §2 closing prose (line 69): "no canvas-tier ratification — design-doc
  resolves shape per §1 Authority discipline"
- §4 (line 91): "carrier landings per locked design not blocking"
  instead of "substrate canvases for #85/#86 not blocking"
- §6 velocity projection (line 126): "carrier landings per locked
  design" instead of "substrate canvas + carrier authoring"
- §6 risk (line 132): replaced "canvas-tier ratification adds 1-3 days"
  with "STOP-and-PING via Substrate Mgr inbox if migration shape
  surprises arise per feedback_construction_over_ratchets"

Single canonical authority restored: locked design
docs/design-tests-as-data-completeness.md §2.1/§2.2 owns
ProgramGenerator/Quantifier/QuantifiedTestClaim shape; this sequencing
plan owns Cluster M phase ordering only.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 9, 2026
…rid ratification) (#2362)

* docs(briefs): R3 Cluster M dispatch briefs — Task 2 per Director (γ) hybrid ratification

Per Director ratification at gunbc#846 #issuecomment-4412309986: 4 asks answered + Task 2 dispatch shape locked at (γ) hybrid (Substrate canvases #85/#86 → Verification discipline #87 → Verification bulk-port coordinator #84).

3 light-touch dispatch briefs authored:

1. **`r3-cluster-m-dispatch-substrate-canvas-asks-2026-05-09.md`** — Substrate Mgr (warm-wolf-698) dispatch surface for #85 ForAll/Exists quantifier substrate canvas + #86 ProgramGenerator carrier canvas. Standing-authority canvas-drafting; Director ratifies surfaced shape questions. Pattern precedent: T-WAD Slice 2.

2. **`r3-cluster-m-dispatch-verification-discipline-87-2026-05-09.md`** — Verification Mgr (wise-bear-525) dispatch for #87 cementing-test discipline pattern. Cites existing PRE-AUTH `r3-v-tests-as-data-v1-worker.md` (tier-1 queue gunbc#1859) as substrate-of-truth; this brief is the (γ)-hybrid coordination overlay.

3. **`r3-cluster-m-dispatch-verification-bulkport-84-2026-05-09.md`** — Verification Mgr coordinator role for #84 bulk-port. Strict-zero close-condition per Director Ask 4 (no Director-allocated exception fold; bulk-port scope = all 102 entries; testgen must cover). Per-class brief queue + lane-Mgr signoff workflow.

All 3 briefs cite-and-execute against the structural authority at `docs/audit/r3-cluster-m-sequencing-plan-2026-05-09.md` per Director's "Sequencing-plan doc carries the structural authority; briefs cite-and-execute" guidance.

Director will dispatch lane Mgrs (Substrate Mgr canvas authoring + Verification Mgr discipline + bulk-port coordinator) on this brief PR ratification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(briefs): Cluster M Phase 1 dispatch brief — cite locked design instead of canvas-asks (codex BLOCKING cascade)

Cascade fix from codex BLOCKING on PR #2361 sha c6c3fb9 (sequencing
plan §3 reopened carrier-shape questions despite locked design
resolving them at docs/design-tests-as-data-completeness.md §2.1/§2.2).

This brief had the same anti-pattern: framed as "Substrate Canvas
Dispatch Asks" + "Surface for Director ratification" sub-bullets that
duplicated the locked design's canonical carrier definitions.

Fix: comprehensive rewrite as "Substrate Carrier Landing Asks":
- Title: "Substrate Canvas Dispatch Asks" → "Substrate Carrier
  Landing Asks"
- §0 Scope: list specific carriers (Quantifier + QuantifiedTestClaim
  + ProgramGenerator) instead of "substrate canvas authoring"
- §1: NEW Authority correction section citing codex BLOCKING +
  locked-design §1 ("no Director ratification required before lane
  dispatch") + INVARIANTS P2 single-authority
- §2 Dispatch disposition: pattern explicitly distinguishes
  "substrate-shape canvases for novel substrate (e.g., T-WAD Slice 2)"
  from "migration / locked-design carrier landings dispatch directly"
- §3 (was §2) Substantive guidance: removed "surface for Director
  ratification" bullets; replaced with verbatim locked design carrier
  shapes (Quantifier closed sum; QuantifiedTestClaim/ProgramGenerator
  Rust signatures). Worker scope cites locked design §2.1/§2.2 directly.
- §4 NEW STOP-and-PING posture: if unexpected shape question arises,
  surface via Substrate Mgr inbox (per feedback_construction_over_ratchets)
  rather than authoring canvas mid-port
- §5/§6/§7 dispatch trigger / receipt / velocity unchanged in
  substantive content; cleaned up framing references

Single canonical authority restored: locked design
docs/design-tests-as-data-completeness.md §2.1/§2.2 owns shape;
this brief owns dispatch coordination only.

Cross-PR alignment: PR #2361 sha 697a125 has the parallel fix on
the sequencing plan; this PR's brief is now consistent with that.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(briefs): Cluster M dispatch briefs — codex BLOCKING (4) addressed

codex inline BLOCKINGs on PR #2362 sha a88e816 (4 findings):

1. **Sequencing plan path neither in PR diff nor in repo** (line 4 of all 3 briefs)
   Verified: `docs/audit/r3-cluster-m-sequencing-plan-2026-05-09.md` is
   in-flight on concurrent PR #2361 (not on main yet). Same in-flight
   authority pattern as PR #2363 audit.
   Fix: each brief's authority line now notes "in-flight via concurrent
   PR #2361" + "this brief is the dispatch overlay — substantive content
   here is self-contained and grounded in [locked-design / live-ledger]
   authorities below." Self-containment preserved; no merge-order trap.

2. **`r3-v-tests-as-data-v1-worker.md` cited as substrate-of-truth but absent** (discipline-87 line 14)
   Verified: file EXISTS on main (blob `4ff9abcb1b8b` per `git ls-tree
   origin/main`). Tree-visibility false positive (codex bot's repeated
   pattern this cycle).
   Fix: added explicit `git ls-tree origin/main` cite + locked-design
   authority `docs/design-tests-as-data-completeness.md` §C5 in §1
   substrate section.

3. **Hard-coding "102" duplicates SG-0 census authority** (bulkport-84 line 18)
   Real finding: brief said "all 102 entries" duplicating the live
   `EXPECTED_HAND_AUTHORED_TEST` count.
   Fix: scope reframed to "all entries in EXPECTED_HAND_AUTHORED_TEST
   at PR-merge time (live authority: src/v3/compiler/tests/integration/
   sg0_census_test.rs; count is wc -l-derivable from the array literal —
   not hardcoded here to avoid duplicate-authority drift)."

4. **First cementing migration uses wrong predicate** (discipline-87 line 34)
   Real finding: brief said "frozen `BinaryDimensionReportEquals`
   snapshot" but locked design `docs/design-tests-as-data-completeness.md`
   §C5 says cementing v2-oracle ports use `DifferentialEquals` or
   `LensOutputEquals` (same-source comparison axis).
   `BinaryDimensionReportEquals` is for Pattern-A DimensionReport
   comparisons (TC1/TC2/TC3 family) — different axis.
   Fix: predicate corrected with explicit cite to locked design §C5
   row + §"C5: Cementing (v2 oracle)" + clarification of why
   `BinaryDimensionReportEquals` is the wrong predicate.

5. **Velocity context citing "102"** (discipline-87 line 45)
   Cascade fix: replaced "102 hand-Rust test entries" with reference
   to `EXPECTED_HAND_AUTHORED_TEST` (live count authoritative at
   sg0_census_test.rs).

Cross-PR alignment: PR #2361 sha 697a125 has the parallel locked-
design citations on the sequencing plan; this PR's briefs now
consistent.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 9, 2026
…conflation (codex BLOCKING post-merge) (#2365)

Follow-up correction PR for codex BLOCKING (4) on merged PR #2362 sha
6027978 (per-finding analysis at #2362 issuecomment-4412858415).

PRs #2361 + #2362 + #2363 + #2364 already merged 15:14-15:20Z 2026-05-09;
this PR corrects 2 substantive bugs that landed in the merged briefs +
sequencing plan.

**Bug #1: Phase 1 substrate carrier set incomplete (3 of 5)**

Locked design `docs/design-tests-as-data-completeness.md` §6 line 344
says Phase 1 introduces 5 carriers: ProgramGenerator, ProgramShape,
Quantifier, QuantifiedTestClaim, SuiteClaim. Merged briefs only listed
3 (Quantifier, QuantifiedTestClaim, ProgramGenerator); missed
ProgramShape (element type of ProgramGenerator's body) + SuiteClaim
(wrapper sum with Enumerated/Quantified variants for TestSuite.claims
migration per design §6 line 344). Workers reading the briefs would
close #85/#86 without full substrate surface — INVARIANTS P2 boundary
sufficiency.

Fix:
- substrate-canvas-asks brief §0 Scope: 5 carriers split across #85
  (Quantifier+QuantifiedTestClaim+SuiteClaim per §2.2) and #86
  (ProgramGenerator+ProgramShape per §2.1)
- substrate-canvas-asks brief §3.1: add SuiteClaim with verbatim
  variant signature + TestSuite.claims migration note
- substrate-canvas-asks brief §3.2: add ProgramShape with verbatim
  signature + LiteralProgram bootstrap variant per §8.2
- sequencing plan §1.2 dependency structure: 5-carrier split across
  Phase 1 (#85+#86); #87 reframed as "uses existing DB-15 TestClaim +
  DifferentialEquals/LensOutputEquals (terminal predicates)" rather
  than "consumes #85/#86 carriers"
- sequencing plan §2 Lane-Mgr partition: 5-carrier authoring scope
  with `SuiteClaim` (#85) + `ProgramShape` (#86) added

**Bug #2: #87 conflated with #85/#86 dependencies (real bug)**

Discipline-87 brief said "every .dag lens has at least one cementing
test in .dag form using #85 Quantifier + QuantifiedTestClaim carriers
+ #86 ProgramGenerator carrier" — but cementing uses LensRegistry
projection ratchet with DifferentialEquals/LensOutputEquals
TestClaims per locked design §C5. ProgramGenerator ranges over
ProgramShape (program family axis), NOT over LensRegistry rows.
The conflation would make ProgramGenerator a closed roster over lens
rows — exactly the anti-pattern flagged in lens-library-design.md
§1.5 that ProgramGenerator was specifically designed to avoid.

Fix:
- discipline-87 brief §2 Dispatch trigger: rewrote — #87 dispatches
  independently of #85/#86 at predicate level. Existing DB-15
  TestClaim + DifferentialEquals/LensOutputEquals (TERMINAL
  predicates available on main today) are the cementing axis. Phase
  1 → #87 coupling exists at SuiteClaim wrapper level only
  (mechanical post-#85 wrap, backward-compatible).
- discipline-87 brief §3 Authoring scope: rewrote — discipline
  pattern uses existing DB-15 + DifferentialEquals/LensOutputEquals
  per design §C5. Cementing axis (per-LensRegistry-row v2-vs-v3
  same-source) explicitly distinguished from property-based axis
  (program-family claims via ProgramGenerator).
- sequencing plan §1.2/§1.3 dependency structure: #87 reframed as
  independent of #85/#86 at predicate level; SuiteClaim wrapper
  coupling only.
- sequencing plan §2 Lane-Mgr partition: #87 partner column scoped
  to "SuiteClaim wrapper migration only post-#85" rather than
  "Substrate (#85/#86 consumer)".
- sequencing plan §8.2 Dispatch sequence: removed "Director
  ratifies" canvas-tier-ratification anti-pattern from #85/#86
  carrier landings (per locked design §1: "no Director ratification
  required before lane dispatch"); #87 dispatch independent of
  #85/#86 timing.
- sequencing plan §9 Open questions: marked all 3 RESOLVED with
  citations.

**Impact**

Workers reading the corrected briefs + plan now have:
- Correct full carrier set per locked design §6 line 344
- Correct cementing axis (DifferentialEquals/LensOutputEquals via
  existing DB-15 infrastructure, NOT property-based ProgramGenerator)
- Correct dispatch independence (#87 doesn't gate on #85/#86)
- No canvas-tier-ratification anti-pattern

Per Brian operator authorization 2026-05-09 ~15:30Z ("can you make
the followups directly to main").

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 10, 2026
Q-PB0-ClusterM-Cold-Risk6: #86 is CONSUMER_LANDED+PASSING (PR #2645); #84/#85
still DECLARED.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 12, 2026
Addresses briansrls BLOCKING inline at L66 on PR #2748: coercion table
omitted live §1.8 composite forms like 'CONSUMER_LANDED + PASSING'
(~25 instances in the ledger, including candidate Cluster M constituent
#86 program_generator_carrier_landed).

Added:
- Explicit row for 'CONSUMER_LANDED + PASSING' → PASSING
- General composite rule '<earlier> + <later>' → coerce to <later>
  (rightmost component; conjunction-of-progression-stages semantics);
  covers future composite forms not enumerated.

This makes #86 view-ready under the precondition rule (coerces cleanly
to PASSING).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
* docs(r3): expand R3 lanes to 12 + lens-framework invariant + analysis findings

User directive 2026-04-30: "nothing can be deferred past R3 - we have to
readjust R3 if something is missing." PM-driven audit + Director ratification.

R3 lane expansion (10 → 12):
- T-V2-Retirement (NEW; PB Manager continuation): src/v2/ retirement
  cascades from T-FixedPoint + T-LensProducer-Retirement; structurally
  cheap to pull in. Gates: v2_oracle_no_remaining_test_consumers +
  v2_directory_deleted.
- T-Free-Consequences-Demonstration (NEW; Verification Manager): 10-gate
  TestClaim suite operationalizing thesis "free consequences" framing.
  Auto-parallelism + auto-memoization + cross-target opt + space-bound CX.
  Loop-iteration parallelism: sequential default + opt-in via
  Lens<Iteration-Independence> (zero-heuristic; same shape as
  Lens<Bind-Independence>).

Priority corrections folded into existing lanes (no new lanes):
- C1 (T-Tier3-Dissolution sub-gate): tier3_mirror_dissolution_perf_within_budget
  with thresholds <=2x median, <=5x p99 (cargo bench fixtures per retired
  mirror).
- C2 (Substrate continuation, T-Anthropic-Wire scope expansion):
  ProviderTypedWire<P> carrier extracted IN R3 (path (a) commit; drops the
  prior 6-month elapsed-time check exactly per user directive).

design-lens-framework.md amendment:
- Lens.read MUST depend only on (Node, Behavior) pair, not external state.
- Locks memoizable shape; runtime memoization becomes auto-memoization free
  consequence instance (T-Free-Consequences-Demonstration).

ROADMAP.md additions (### Post-merge debt (2026-04-30 analyses)):
- 4 novel findings from paired exploratory + reflective analyses
  (gpt-5-5-pro 991114f / gpt-5-5-thinking ad016c5):
  * Duplicate record-literal fields silently dropped (highest-value bug)
  * ValueBody Rust<->.dag mirror drift; no isomorphism gate
  * FieldMap duplicate-free invariant lost in .dag mirror
  * Operator inference fabricates (T,T)->T for non-algebra LHS
- 8 reflective-analysis priority corrections folded into R3 trajectory
- 2 stale rows marked RESOLVED (repeat_string + lower_fn_body re-derive)

Routed to R3 Mgrs via inbox dispatches (#1130 / #1131 / #1133 / #1276 / #846).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): reframe Rust<->.dag isomorphism as producer-first

cool-crab-614 PR #1324 research reframed the proposal: missing substrate
is a reflected-Dag query/report PRODUCER (Lens<DagShapeReport>), not a
new predicate variant. RustDagIsomorphism becomes a CONSUMER (TestClaim
comparing two DagShapeReport outputs via BinaryDimensionReportEquals),
eliminating parallel-authority risk.

Reflection-aware modifiers for unified BinaryDimensionReportEquals now
cover 4 surfaces: TC1 eta-equivalence + TC2 strategy-order + TC3
evaluation-step + shape-report (reflected-Dag query).

Single substrate-introduction; multiple consumers via reflection-aware
modifiers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): fix lower_fn_body row citation per #1319 review

PR #1319 review (cursor 9d2dffb) flagged that the RESOLVED note cited
`src/v3/compiler/src/lower.rs:61670-61688` but lower.rs is only 7919
lines. Original line citations referenced the analysis snapshot's
aggregate-numbering scheme, not live file.

Verified live state: `lower_fn_body_into_existing_decl` symbol does NOT
exist in current lower.rs; equivalent path is `lower_fn_item_expr_body`
(:4410+); non-Arrow arm at :4433-4451 reports
`Diagnostic::ResolveError` with explicit invariant-violation message
("violated lowering invariant: seed_function_signatures_phase did not
produce an Arrow connective for this Fn") and returns outer_scope.
That IS the fail-closed shape the original row asked for; resolution
note now correctly cites live behavior.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): resolve v2-retirement contradiction per #1319 review

PR #1319 review (codex a9a9894) flagged contradiction: T-V2-Retirement
added as R3 lane (line 100) but Compromises table (line 165) still
listed v2 retirement as Post-R3 operational cleanup. INVARIANTS P1
"Documentation Describes Live State" violation.

Fix: strikethrough the post-R3 entry; explicitly note migration into
R3 as T-V2-Retirement lane per 2026-04-30 user directive "nothing can
be deferred past R3." Single authoritative placement; cross-link to
Lane structure §11.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* docs(r3): aggregator pattern — coercion table + precondition + exclusion rules

Addresses BLOCKING #2748 (briansrls inline at L71): live §1.8 uses 7 status
values, not 3 (PASSING, SATISFIED-BY-CONSTRUCTION, CONSUMER_LANDED, DECLARED,
R3-LOAD-BEARING, HELD-CANVAS-DEFERRED, DEFERRED). The 3-value lattice meet
was not machine-checkable as written.

- Coercion table: SATISFIED-BY-CONSTRUCTION → PASSING; INTEGRATION_RECEIPT
  partial-slice → CONSUMER_LANDED; identity for the 3 lattice values.
- Precondition rule: bare R3-LOAD-BEARING is scope-metadata, not closure
  progress; constituents with that status are not aggregator-ready until
  cell inlines closure-progress (e.g., 'R3-LOAD-BEARING — DECLARED').
- Exclusion rule: DEFERRED + HELD-CANVAS-DEFERRED MUST NOT appear in any
  aggregator's depends_on: per §1.5 honest-close arithmetic.
- Cluster F candidate reframed: NOT aggregator-ready at HEAD because rows
  #81/#82/#83/#95 carry bare R3-LOAD-BEARING; precondition fix required
  before pilot. Cluster M / K / V2-Retirement candidates similarly subject
  to precondition check at pilot time.
- Invariants P2 cleanliness note: coercion table + precondition + exclusion
  are themselves a single derivation authority; no parallel authority for
  closure progress.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): cascade ci_yml_deleted → ci_yml_hand_authority_dissolved rename

Per PM cascade (PR #2744 commit 19a1d8d absorbing briansrls BLOCKING
on line 32): file artifact presence is orthogonal to hand-authority
dissolution. YamlStatic / BinaryShim / PythonShim all require some
.github/workflows/ci.yml for GH Actions trigger discovery; P5 / Pure
Bootstrap dissolves authority, not file presence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): relocate aggregator pattern from §1.8 to §1.9 per codex P2 finding

Addresses codex REQUEST_CHANGES /api/reviews/9982 on PR #2748: putting
aggregator rows directly in §1.8 alongside their constituents violated
INVARIANTS P2 single-authority — even with "derived not hand-set" prose,
the row shape didn't structurally prevent treatment as a closure
obligation, and the side-taxonomy of "does not participate in §1.7
corpus rules" was a P2 boundary-discipline violation inside the
canonical ledger.

Restructured:
- Aggregators relocated to a NEW §1.9 section (separate table)
- Distinct ID namespace: V1, V2, ... (NOT numeric §1.8 row IDs)
- Different table columns (View ID / View Name / Cluster Lane /
  depends_on: / Derived Status / Notes) to make visual distinction
  obvious
- depends_on: references §1.8 row #s by foreign-key style
- Derived Status rendered as <DERIVED> in committed text; never stored
  as snapshot (per feedback_no_snapshot_integers_in_briefs)
- §1.8 "97 enumerated / 96 R3-load-bearing" arithmetic preserved
  unchanged; §1.9 entries do not appear in that arithmetic
- Coercion table + precondition + exclusion rules carried forward
- Cluster F precondition catch (rows #81/#82/#83/#95 carry bare
  R3-LOAD-BEARING) preserved

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): annotate R4-carve citation with supersession marker

Fixes CI failure on PR #2748: scripts/check-r4-carve-dissolution-discipline.sh
flagged the coercion-table row for R3-LOAD-BEARING which mentioned 'R4-carved'
without a supersession annotation. Reframed to cite carve-promotion-IN-R3
2026-05-09 + DISSOLVED status per Director ratification gunbc#846.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): correct #83 characterization + add filename note

Per cursor APPROVE_WITH_COMMENTS /api/reviews/10000 on PR #2748:

- Row #83 (lens_capability_register_zero_proxy_zero_stub) was incorrectly
  listed alongside #81/#82/#95 as carrying "bare R3-LOAD-BEARING". The
  authoritative ledger has #83 reading "DECLARED — full scope IN R3
  (carve-promotion-IN-R3 2026-05-09)", which inlines closure-progress
  alongside scope-metadata and already coerces to DECLARED under the
  precondition rule. Reframed #83 as a positive counter-example showing
  the inline-pattern #81/#82/#95 still need to adopt.

- Added top-of-doc filename note explaining the §1.8 vs §1.9 mismatch:
  filename retained for review-thread anchor stability; substantive
  section is §1.9.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add sunset condition for aggregator pattern pilot doc

Per cursor /api/reviews/10013 optional tighten: PILOT scaffold needs a
single checkable sunset to satisfy P5 scaffold-posture discipline.
Sunset: doc retires when docs/r3-program-plan.md contains §1.9 per the
specified table shape AND at least one §1.9 view entry is live in the
ledger.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add composite-status coercion rule (CONSUMER_LANDED + PASSING)

Addresses briansrls BLOCKING inline at L66 on PR #2748: coercion table
omitted live §1.8 composite forms like 'CONSUMER_LANDED + PASSING'
(~25 instances in the ledger, including candidate Cluster M constituent
#86 program_generator_carrier_landed).

Added:
- Explicit row for 'CONSUMER_LANDED + PASSING' → PASSING
- General composite rule '<earlier> + <later>' → coerce to <later>
  (rightmost component; conjunction-of-progression-stages semantics);
  covers future composite forms not enumerated.

This makes #86 view-ready under the precondition rule (coerces cleanly
to PASSING).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
* docs(r3): flip §1.8 #85 forall_exists_quantifier_substrate_landed to CONSUMER_LANDED + PASSING

PR #2647 (vivid-dove-106 / Cluster M Phase 1a) merged carriers into src/v3/std/verification.dag at HEAD; ledger row was drifted DECLARED. Per post-merge ledger-receipt sync discipline (Director-ratified at gunbc#828 c#4415884211).

Caught by Debt-Paydown PM ledger-sync check — thanks silent-ram-834.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): downgrade §1.8 #85 to DECLARED per codex BLOCKING + row #17 precedent

Prior CONSUMER_LANDED + PASSING flip overstated the gate per INVARIANTS §P2 strict reading: carriers + hand-written ratchet ≠ generated consumer proof. Mirrors row #17 (numeric_abstract_carriers_landed) shape: carrier substrate landed, hand-written ratchet noted, CONSUMER_LANDED deferred to generated consumer + SuiteClaim wrapper migration + V Mgr #87 runner consumer.

Sibling row #86 carries same overclaim risk via PR #2645 precedent — separate amendment if Director rules.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: T-WAD substrate-shape comparison canvas (gate #56)

Mgr-tier comparison canvas surfacing three substrate-shape options for
gate #56 ci_workflow_modeled_as_dag under FULL R3-close elevation:

- (a) PR #2736 provider-neutral CIWorkflowDag (semantic-only)
- (b) WI-1 PR #2746 actions.dag-concrete + EmissionTarget? (transport-only)
- (c) Hybrid — CIWorkflowDag as semantic source + Workflow.emission_target
  as transport-artifact selector + projection function project_github_actions:
  CIWorkflowDag -> Workflow as the structural fold connecting them

§0 grep-verifies PR #2736 body claim ("hand-authored GitHub Actions transport
copy was removed") against actual diff: actions.dag Workflow/Job/Step
carriers at :21/:110/:147 intact; PR adds CIWorkflowDag without removing
actions.dag carriers, leaving dual-authority unresolved at HEAD.

§5 recommends option (c) for Director ratification on:
- single-authority per concept layer (gate-dependency at gunbc.ci;
  transport at extdeps.github.actions) per MODELING.md M9
- decoupled cost-of-change axes (new provider vs new emission target)
- preserves both already-authored PRs' substrate contributions
- aligns with docs/design-emission-model.md single-emitter discipline

Authority: PM relay msg_a945b141 (deep-wolf-155) routing Director
msg_34e9a381 substrate-shape question per
feedback_substrate_shape_belongs_in_mgr_canvas.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7 addendum — INVARIANTS P1 reframes (c) to (c-refined)

BLOCKING inline review on PR #2746 (briansrls c#4427988541) flagged
that adding EmissionTarget to dsl/extdeps/github/actions.dag puts a
gunbc emission-policy fact into the GitHub Actions platform model,
violating extdeps fidelity and INVARIANTS P1.

§7 accepts the finding (structurally correct per actions.dag header
:1-12 platform-vs-CI-logic discriminator), disqualifies §1 option (b)
as-authored, partially invalidates §1 option (c) as-authored (the
two-layer concept-layering argument STILL holds; only the EmissionTarget
placement on extdeps fails P1).

§7.3 surfaces option (c-refined): EmissionTarget lives in gunbc/ci.dag
as a sum type + parameter to project_github_actions(ci_workflow_dag,
target) -> Workflow. extdeps.github.actions.Workflow is unmodified.
Pinned Workflow values for emission validation live in gunbc namespace.

§7.5 revises ratification asks: PR #2746 disposition shifts from
"framing-narrowing" to substantive substrate retraction on the field-
placement decision (sum-type shape stands; placement relocates).

§7.6 distinguishes (c-refined) from PM-proposed alternatives:
- not PM(b) [EmissionTarget on CIPipeline] — same M9 join-cost as
  PR #2746 §3 Option B
- not PM(c) [WorkflowEmission wrapper] — same sibling-decision cost
  PR #2746 §3 Option C already rejected
(c-refined) expresses emission-target choice at the projection
invocation (per docs/design-emission-model.md: emission is structural
projection, choice is property of the call not the value).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §8 retraction — derive Workflow from projection, not separate authority

codex REQUEST_CHANGES on PR #2749 (review 9970) flagged that option (c)
as authored proposed both a projection function CIWorkflowDag -> Workflow
AND a separately hand-declared Workflow value the emitter "validates
against" as a pinned target — INVARIANTS P2 / modeling-discipline.md
Practice 5 dual-authority condition.

Finding accepted. §8 retracts the pinned-Workflow-as-modeled-authority
framing; in-place edits applied to §1 (option (c) intro), §4 (S0
sequencing), §5 (ratification ask #5), §7.3 (WI-2 placement), §7.5
(revised recommendation).

Replacement framing: the only Workflow value in modeled authority is
the projection function output, structurally derived from a single
source. WI-2's gunbc_ci_yml_workflow becomes a name binding to the
derived result (data gunbc_ci_yml_workflow: Workflow =
project_github_actions(ci_workflow_dag, YamlStatic)), not an
independent declaration. Byte-level regression fixtures live in
tests/, not dsl/, and are not part of modeled authority.

Layering argument unchanged: gate-dependency at gunbc.ci.CIWorkflowDag;
platform transport at extdeps.github.actions.Workflow (unmodified);
emission policy in gunbc namespace; artifact derived from single source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: cite feedback_extdeps_header_discriminator_before_field_placement

Per PM relay msg_72e2ab50: Director memorialized actions.dag:1-12
discriminator rule as feedback_extdeps_header_discriminator_before_field_placement.
Add citation in §7's discriminator block for audit trail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: cite P2 (Boundary Discipline) not P1 for single-authority

gpt-5.5-pro APPROVE_WITH_COMMENTS review 9972 caught that the
single-authority / "every fact lives in exactly one place" principle
is INVARIANTS.md P2 Boundary Discipline, not P1. P1 is Modeling
Faithfulness.

Operator BLOCKING quote at §7 invoked "P1" verbatim; both principles
are in play:
- P2 because emission-policy authority must live in exactly one place
  (gunbc/ci.dag), not split across extdeps and gunbc
- P1 because placing gunbc-policy state on an extdeps carrier makes
  the carrier no longer faithful to its header's "platform facts
  only" claim

§7.1 prose updated to explicitly distinguish the two principles and
note that subsequent single-authority references cite P2.
§7.4 table row relabeled "INVARIANTS P2 (Boundary Discipline / single
authority)".
§7.5 ratification ask #2 cites P2 + P1.
§7 heading updated to "INVARIANTS P2/P1 BLOCKING reframes (c)".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: classify EmissionTarget coproduct per Practice 4 (§7.3.1)

BLOCKING inline review on PR #2749 at line :573 (briansrls
2026-05-12T07:04:15Z): proposed EmissionTarget 4-variant coproduct
landed without 🟢/🟡/🔴 dissolution classification, violating
modeling-discipline.md Practice 4 (coproduct dissolution).

Finding accepted. §7.3.1 added classifying EmissionTarget as
🟡 YELLOW (scaffold) with full reasoning across all four dissolution
patterns:
- Pattern 1 (fact placement): N/A — empty payloads
- Pattern 2 (variant-is-data): blocked by closed-set guardrail
- Pattern 3 (algebraic form): N/A — not std/ algebraic operations
- Pattern 4 (dimensional): live dissolution path; ~2-3 axes
  (target_language, requires_shim, runtime_executes) plausible but
  not yet forced at four variants

YELLOW not GREEN: Pattern 4 plausibly works; closing the door would
be wrong. YELLOW not RED: dissolving prematurely without consumer-
side pressure risks landing wrong axes (requires_shim partially
redundant with target_language at current variants).

Named dissolution trigger (per YELLOW requirements): (a) fifth
target landing that breaks the four-way axis, OR (b) consumer needing
single-dimension pattern-match, OR (c) Slice 4/5 implementation
surfacing an unpredicted axis. Any forces dimensional record shape.

Ledger note: classification is canvas-level; implementing PR (WI-2
re-brief per §5/§7.5 ask #4) MUST carry the same classification +
trigger as a // 🟡 YELLOW (scaffold) comment on the type declaration
citing this canvas §7.3.1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: canvas RATIFIED — §9 ratification dispositions

Director (zesty-bear-812) ratified option (c-refined) at
2026-05-12T07:04:18Z per PR #2749 comment (session msg_4f7f536d
to PM deep-wolf-155). Updates:

- Status header changed to RATIFIED with ratification authority
  citation
- §9 added with all 5 ratification asks dispositioned:
  - (c-refined) substrate-shape: RATIFIED
  - PR #2746: AMEND (4 specific changes for still-heron-763)
  - PR #2736 body: SATISFIED prior
  - PR #2745 WI-2: SCOPE EXPANSION APPROVED, PM authors re-brief
  - S1 projection function: NEW §1.8 GATE (project_github_actions_landed,
    substrate-shape family); aggregator pilot row #56+4→#56+5
- Downstream cascade documented per Director directive

Director attributed feedback_extdeps_header_discriminator_before_field_placement
discipline rule to the §7+§8 self-correction trajectory.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: inline SUPERSEDED banners on §1(c)/§2.3/§3/§4/§5

codex BLOCKING review 9986 at sha 38c28cd flagged that §2.3/§3/§5
still contain the now-overturned option-(c)-as-authored framing
(EmissionTarget on extdeps.Workflow + hand-declared pinned Workflow).
For a RATIFIED canvas, leaving those sections unmarked materially
states the wrong substrate shape — readers would have to read through
to §7/§8/§9 to discover the supersession.

Finding accepted. Inline SUPERSEDED banners added at the top of:
- §1 Option (c) sub-section: points to §7.3/§7.4/§8/§9 for current shape
- §2.3 Option (c) evaluation: flags the "emission validates declared
  Workflow against projection" sentence as the dual-authority condition
  §8 retracts
- §3 WI-1 assumption-breakage: OVERTURNED bullets explicitly listed
  (placement, "Workflow chooses target" framing, framing-narrowing
  disposition)
- §4 Slice sequencing under (c): SUPERSEDED in part — structure
  remains valid under (c-refined); placement-specific descriptions
  overturned by §7/§8; WI-2 scope larger than §5.4 implied per §9 ask #4
- §5 Recommendation: all three positions (extdeps placement,
  framing-narrowing PR #2746 disposition, pinned-Workflow validation
  target) OVERTURNED; current recommendation is (c-refined) per §7.5+§9

Earlier framings preserved as canvas-evolution record (showing
self-correction trajectory through §7+§8), but each affected section
now flags its own superseded status without requiring a full-doc read.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §6 Q#2 RESOLVED banner — overturned superseded Workflow framing

cursor APPROVE_WITH_COMMENTS review 10001 (non-blocking) noted that §6
open question #2 still partly explained the projected signature via
"PR #2746 places the field on Workflow", which contradicts §7.3
(c-refined) where extdeps.github.actions.Workflow is frozen unmodified.

Fix: add inline RESOLVED banner at §6 head pointing to §7.3 + §9; rewrite
Q#2 entry to flag the superseded framing inline — the parametric
signature was the right answer regardless of placement, but the rationale
over-attributed to a placement that no longer stands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: inline 🟡 YELLOW checkpoint at §7.3 EmissionTarget declaration

Operator BLOCKING inline review on PR #2749 at :657 (briansrls
2026-05-12T07:58:34Z): the §7.3 code block declaring type
EmissionTarget lacked the inline 🟢/🟡/🔴 classification annotation
required by modeling-discipline.md Practice 4 "any new enum with
N ≥ 2 variants must have a checkpoint comment naming its classification."

The classification reasoning exists in §7.3.1 prose section, but the
declaration site itself was missing the checkpoint comment, which is
the form Practice 4 requires.

Fix: add inline 🟡 YELLOW (scaffold) comment block above the type
declaration citing §7.3.1 for full reasoning + the three-condition
dissolution trigger + likely Pattern 4 dissolution path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7.3.2 Shape A/B clarification — EmissionTarget names realization modes

Operator BLOCKING inline review on PR #2749 at :657 (briansrls
2026-05-12T07:58:35Z): YamlStatic variant of EmissionTarget would
"make a Shape B CI YAML artifact mode an emission target despite
THESIS Shape A/B requiring YAML artifacts to be generated by .dag
user programs, not compiler emission targets."

Per THESIS:215-216, Shape A = compiler language targets (compiler
emits directly); Shape B = user-program artifacts (YAML, Terraform,
K8s, etc. — emitted by .dag programs walking typed values, NOT
compiler render targets). YAML for ci.yml is Shape B; gunbc
doesn't have a YAML emission target.

Finding accepted as naming-and-framing concern, not substrate-shape
concern. Added §7.3.2 clarifying:

- EmissionTarget names a REALIZATION MODE selector, not a parallel
  compiler emission target
- YamlStatic = Shape B (.dag program renders YAML from Workflow)
- BinaryShim = Shape A binary + Shape B YAML shim wrapper
- PythonShim = Shape A Python + Shape B YAML shim wrapper
- InlineGunbc = Shape A (gunbc runtime as host)

No substrate retraction: variants, YELLOW classification, dissolution
trigger, gunbc-namespace placement, parametric signature all stand.
Naming consideration noted (WorkflowRealizationMode would carry less
Shape-A baggage), but renaming forces re-ratification without
corresponding substrate change — keep name, document the mapping at
declaration site per §7.5 ask #4 implementation PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: fix §9 ask #5 slice/gate name — Slice 8 ci_yml_dissolved, not Slice 5 ci_yml_deleted

gpt-5.5-pro REQUEST_CHANGES on PR #2749 sha f5b57e7 (review 10037)
caught that §9 ratification ask #5 wrote the projection-function gate
as "discrete from Slice 5 (ci_yml_deleted, state-check)", but per the
canvas's own §1 (Director-ratified gate-set) and §4 Slice sequencing:
- Slice 5 = BinaryShim emitter (workflow_emission_target_toggle_proven)
- Slice 8 = ci.yml dissolution (gate name: ci_yml_dissolved)

The conflation could mislead workers updating PR #2748 to wire the new
project_github_actions_landed gate against the wrong slice/gate.

Fix: §9 ask #5 now reads "discrete from Slice 8 ci_yml_dissolved",
matching the canvas's earlier authoritative gate-set + §4 sequencing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
* docs(r3): expand R3 lanes to 12 + lens-framework invariant + analysis findings

User directive 2026-04-30: "nothing can be deferred past R3 - we have to
readjust R3 if something is missing." PM-driven audit + Director ratification.

R3 lane expansion (10 → 12):
- T-V2-Retirement (NEW; PB Manager continuation): src/v2/ retirement
  cascades from T-FixedPoint + T-LensProducer-Retirement; structurally
  cheap to pull in. Gates: v2_oracle_no_remaining_test_consumers +
  v2_directory_deleted.
- T-Free-Consequences-Demonstration (NEW; Verification Manager): 10-gate
  TestClaim suite operationalizing thesis "free consequences" framing.
  Auto-parallelism + auto-memoization + cross-target opt + space-bound CX.
  Loop-iteration parallelism: sequential default + opt-in via
  Lens<Iteration-Independence> (zero-heuristic; same shape as
  Lens<Bind-Independence>).

Priority corrections folded into existing lanes (no new lanes):
- C1 (T-Tier3-Dissolution sub-gate): tier3_mirror_dissolution_perf_within_budget
  with thresholds <=2x median, <=5x p99 (cargo bench fixtures per retired
  mirror).
- C2 (Substrate continuation, T-Anthropic-Wire scope expansion):
  ProviderTypedWire<P> carrier extracted IN R3 (path (a) commit; drops the
  prior 6-month elapsed-time check exactly per user directive).

design-lens-framework.md amendment:
- Lens.read MUST depend only on (Node, Behavior) pair, not external state.
- Locks memoizable shape; runtime memoization becomes auto-memoization free
  consequence instance (T-Free-Consequences-Demonstration).

ROADMAP.md additions (### Post-merge debt (2026-04-30 analyses)):
- 4 novel findings from paired exploratory + reflective analyses
  (gpt-5-5-pro 991114f / gpt-5-5-thinking ad016c5):
  * Duplicate record-literal fields silently dropped (highest-value bug)
  * ValueBody Rust<->.dag mirror drift; no isomorphism gate
  * FieldMap duplicate-free invariant lost in .dag mirror
  * Operator inference fabricates (T,T)->T for non-algebra LHS
- 8 reflective-analysis priority corrections folded into R3 trajectory
- 2 stale rows marked RESOLVED (repeat_string + lower_fn_body re-derive)

Routed to R3 Mgrs via inbox dispatches (#1130 / #1131 / #1133 / #1276 / #846).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): reframe Rust<->.dag isomorphism as producer-first

cool-crab-614 PR #1324 research reframed the proposal: missing substrate
is a reflected-Dag query/report PRODUCER (Lens<DagShapeReport>), not a
new predicate variant. RustDagIsomorphism becomes a CONSUMER (TestClaim
comparing two DagShapeReport outputs via BinaryDimensionReportEquals),
eliminating parallel-authority risk.

Reflection-aware modifiers for unified BinaryDimensionReportEquals now
cover 4 surfaces: TC1 eta-equivalence + TC2 strategy-order + TC3
evaluation-step + shape-report (reflected-Dag query).

Single substrate-introduction; multiple consumers via reflection-aware
modifiers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): fix lower_fn_body row citation per #1319 review

PR #1319 review (cursor 9d2dffb) flagged that the RESOLVED note cited
`src/v3/compiler/src/lower.rs:61670-61688` but lower.rs is only 7919
lines. Original line citations referenced the analysis snapshot's
aggregate-numbering scheme, not live file.

Verified live state: `lower_fn_body_into_existing_decl` symbol does NOT
exist in current lower.rs; equivalent path is `lower_fn_item_expr_body`
(:4410+); non-Arrow arm at :4433-4451 reports
`Diagnostic::ResolveError` with explicit invariant-violation message
("violated lowering invariant: seed_function_signatures_phase did not
produce an Arrow connective for this Fn") and returns outer_scope.
That IS the fail-closed shape the original row asked for; resolution
note now correctly cites live behavior.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): resolve v2-retirement contradiction per #1319 review

PR #1319 review (codex a9a9894) flagged contradiction: T-V2-Retirement
added as R3 lane (line 100) but Compromises table (line 165) still
listed v2 retirement as Post-R3 operational cleanup. INVARIANTS P1
"Documentation Describes Live State" violation.

Fix: strikethrough the post-R3 entry; explicitly note migration into
R3 as T-V2-Retirement lane per 2026-04-30 user directive "nothing can
be deferred past R3." Single authoritative placement; cross-link to
Lane structure §11.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* docs(r3): aggregator pattern — coercion table + precondition + exclusion rules

Addresses BLOCKING #2748 (briansrls inline at L71): live §1.8 uses 7 status
values, not 3 (PASSING, SATISFIED-BY-CONSTRUCTION, CONSUMER_LANDED, DECLARED,
R3-LOAD-BEARING, HELD-CANVAS-DEFERRED, DEFERRED). The 3-value lattice meet
was not machine-checkable as written.

- Coercion table: SATISFIED-BY-CONSTRUCTION → PASSING; INTEGRATION_RECEIPT
  partial-slice → CONSUMER_LANDED; identity for the 3 lattice values.
- Precondition rule: bare R3-LOAD-BEARING is scope-metadata, not closure
  progress; constituents with that status are not aggregator-ready until
  cell inlines closure-progress (e.g., 'R3-LOAD-BEARING — DECLARED').
- Exclusion rule: DEFERRED + HELD-CANVAS-DEFERRED MUST NOT appear in any
  aggregator's depends_on: per §1.5 honest-close arithmetic.
- Cluster F candidate reframed: NOT aggregator-ready at HEAD because rows
  #81/#82/#83/#95 carry bare R3-LOAD-BEARING; precondition fix required
  before pilot. Cluster M / K / V2-Retirement candidates similarly subject
  to precondition check at pilot time.
- Invariants P2 cleanliness note: coercion table + precondition + exclusion
  are themselves a single derivation authority; no parallel authority for
  closure progress.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): cascade ci_yml_deleted → ci_yml_hand_authority_dissolved rename

Per PM cascade (PR #2744 commit 19a1d8d absorbing briansrls BLOCKING
on line 32): file artifact presence is orthogonal to hand-authority
dissolution. YamlStatic / BinaryShim / PythonShim all require some
.github/workflows/ci.yml for GH Actions trigger discovery; P5 / Pure
Bootstrap dissolves authority, not file presence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): relocate aggregator pattern from §1.8 to §1.9 per codex P2 finding

Addresses codex REQUEST_CHANGES /api/reviews/9982 on PR #2748: putting
aggregator rows directly in §1.8 alongside their constituents violated
INVARIANTS P2 single-authority — even with "derived not hand-set" prose,
the row shape didn't structurally prevent treatment as a closure
obligation, and the side-taxonomy of "does not participate in §1.7
corpus rules" was a P2 boundary-discipline violation inside the
canonical ledger.

Restructured:
- Aggregators relocated to a NEW §1.9 section (separate table)
- Distinct ID namespace: V1, V2, ... (NOT numeric §1.8 row IDs)
- Different table columns (View ID / View Name / Cluster Lane /
  depends_on: / Derived Status / Notes) to make visual distinction
  obvious
- depends_on: references §1.8 row #s by foreign-key style
- Derived Status rendered as <DERIVED> in committed text; never stored
  as snapshot (per feedback_no_snapshot_integers_in_briefs)
- §1.8 "97 enumerated / 96 R3-load-bearing" arithmetic preserved
  unchanged; §1.9 entries do not appear in that arithmetic
- Coercion table + precondition + exclusion rules carried forward
- Cluster F precondition catch (rows #81/#82/#83/#95 carry bare
  R3-LOAD-BEARING) preserved

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): annotate R4-carve citation with supersession marker

Fixes CI failure on PR #2748: scripts/check-r4-carve-dissolution-discipline.sh
flagged the coercion-table row for R3-LOAD-BEARING which mentioned 'R4-carved'
without a supersession annotation. Reframed to cite carve-promotion-IN-R3
2026-05-09 + DISSOLVED status per Director ratification gunbc#846.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): correct #83 characterization + add filename note

Per cursor APPROVE_WITH_COMMENTS /api/reviews/10000 on PR #2748:

- Row #83 (lens_capability_register_zero_proxy_zero_stub) was incorrectly
  listed alongside #81/#82/#95 as carrying "bare R3-LOAD-BEARING". The
  authoritative ledger has #83 reading "DECLARED — full scope IN R3
  (carve-promotion-IN-R3 2026-05-09)", which inlines closure-progress
  alongside scope-metadata and already coerces to DECLARED under the
  precondition rule. Reframed #83 as a positive counter-example showing
  the inline-pattern #81/#82/#95 still need to adopt.

- Added top-of-doc filename note explaining the §1.8 vs §1.9 mismatch:
  filename retained for review-thread anchor stability; substantive
  section is §1.9.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add sunset condition for aggregator pattern pilot doc

Per cursor /api/reviews/10013 optional tighten: PILOT scaffold needs a
single checkable sunset to satisfy P5 scaffold-posture discipline.
Sunset: doc retires when docs/r3-program-plan.md contains §1.9 per the
specified table shape AND at least one §1.9 view entry is live in the
ledger.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add composite-status coercion rule (CONSUMER_LANDED + PASSING)

Addresses briansrls BLOCKING inline at L66 on PR #2748: coercion table
omitted live §1.8 composite forms like 'CONSUMER_LANDED + PASSING'
(~25 instances in the ledger, including candidate Cluster M constituent
#86 program_generator_carrier_landed).

Added:
- Explicit row for 'CONSUMER_LANDED + PASSING' → PASSING
- General composite rule '<earlier> + <later>' → coerce to <later>
  (rightmost component; conjunction-of-progression-stages semantics);
  covers future composite forms not enumerated.

This makes #86 view-ready under the precondition rule (coerces cleanly
to PASSING).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
* docs(r3): flip §1.8 #85 forall_exists_quantifier_substrate_landed to CONSUMER_LANDED + PASSING

PR #2647 (vivid-dove-106 / Cluster M Phase 1a) merged carriers into src/v3/std/verification.dag at HEAD; ledger row was drifted DECLARED. Per post-merge ledger-receipt sync discipline (Director-ratified at gunbc#828 c#4415884211).

Caught by Debt-Paydown PM ledger-sync check — thanks silent-ram-834.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): downgrade §1.8 #85 to DECLARED per codex BLOCKING + row #17 precedent

Prior CONSUMER_LANDED + PASSING flip overstated the gate per INVARIANTS §P2 strict reading: carriers + hand-written ratchet ≠ generated consumer proof. Mirrors row #17 (numeric_abstract_carriers_landed) shape: carrier substrate landed, hand-written ratchet noted, CONSUMER_LANDED deferred to generated consumer + SuiteClaim wrapper migration + V Mgr #87 runner consumer.

Sibling row #86 carries same overclaim risk via PR #2645 precedent — separate amendment if Director rules.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: T-WAD substrate-shape comparison canvas (gate #56)

Mgr-tier comparison canvas surfacing three substrate-shape options for
gate #56 ci_workflow_modeled_as_dag under FULL R3-close elevation:

- (a) PR #2736 provider-neutral CIWorkflowDag (semantic-only)
- (b) WI-1 PR #2746 actions.dag-concrete + EmissionTarget? (transport-only)
- (c) Hybrid — CIWorkflowDag as semantic source + Workflow.emission_target
  as transport-artifact selector + projection function project_github_actions:
  CIWorkflowDag -> Workflow as the structural fold connecting them

§0 grep-verifies PR #2736 body claim ("hand-authored GitHub Actions transport
copy was removed") against actual diff: actions.dag Workflow/Job/Step
carriers at :21/:110/:147 intact; PR adds CIWorkflowDag without removing
actions.dag carriers, leaving dual-authority unresolved at HEAD.

§5 recommends option (c) for Director ratification on:
- single-authority per concept layer (gate-dependency at gunbc.ci;
  transport at extdeps.github.actions) per MODELING.md M9
- decoupled cost-of-change axes (new provider vs new emission target)
- preserves both already-authored PRs' substrate contributions
- aligns with docs/design-emission-model.md single-emitter discipline

Authority: PM relay msg_a945b141 (deep-wolf-155) routing Director
msg_34e9a381 substrate-shape question per
feedback_substrate_shape_belongs_in_mgr_canvas.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7 addendum — INVARIANTS P1 reframes (c) to (c-refined)

BLOCKING inline review on PR #2746 (briansrls c#4427988541) flagged
that adding EmissionTarget to dsl/extdeps/github/actions.dag puts a
gunbc emission-policy fact into the GitHub Actions platform model,
violating extdeps fidelity and INVARIANTS P1.

§7 accepts the finding (structurally correct per actions.dag header
:1-12 platform-vs-CI-logic discriminator), disqualifies §1 option (b)
as-authored, partially invalidates §1 option (c) as-authored (the
two-layer concept-layering argument STILL holds; only the EmissionTarget
placement on extdeps fails P1).

§7.3 surfaces option (c-refined): EmissionTarget lives in gunbc/ci.dag
as a sum type + parameter to project_github_actions(ci_workflow_dag,
target) -> Workflow. extdeps.github.actions.Workflow is unmodified.
Pinned Workflow values for emission validation live in gunbc namespace.

§7.5 revises ratification asks: PR #2746 disposition shifts from
"framing-narrowing" to substantive substrate retraction on the field-
placement decision (sum-type shape stands; placement relocates).

§7.6 distinguishes (c-refined) from PM-proposed alternatives:
- not PM(b) [EmissionTarget on CIPipeline] — same M9 join-cost as
  PR #2746 §3 Option B
- not PM(c) [WorkflowEmission wrapper] — same sibling-decision cost
  PR #2746 §3 Option C already rejected
(c-refined) expresses emission-target choice at the projection
invocation (per docs/design-emission-model.md: emission is structural
projection, choice is property of the call not the value).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §8 retraction — derive Workflow from projection, not separate authority

codex REQUEST_CHANGES on PR #2749 (review 9970) flagged that option (c)
as authored proposed both a projection function CIWorkflowDag -> Workflow
AND a separately hand-declared Workflow value the emitter "validates
against" as a pinned target — INVARIANTS P2 / modeling-discipline.md
Practice 5 dual-authority condition.

Finding accepted. §8 retracts the pinned-Workflow-as-modeled-authority
framing; in-place edits applied to §1 (option (c) intro), §4 (S0
sequencing), §5 (ratification ask #5), §7.3 (WI-2 placement), §7.5
(revised recommendation).

Replacement framing: the only Workflow value in modeled authority is
the projection function output, structurally derived from a single
source. WI-2's gunbc_ci_yml_workflow becomes a name binding to the
derived result (data gunbc_ci_yml_workflow: Workflow =
project_github_actions(ci_workflow_dag, YamlStatic)), not an
independent declaration. Byte-level regression fixtures live in
tests/, not dsl/, and are not part of modeled authority.

Layering argument unchanged: gate-dependency at gunbc.ci.CIWorkflowDag;
platform transport at extdeps.github.actions.Workflow (unmodified);
emission policy in gunbc namespace; artifact derived from single source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: cite feedback_extdeps_header_discriminator_before_field_placement

Per PM relay msg_72e2ab50: Director memorialized actions.dag:1-12
discriminator rule as feedback_extdeps_header_discriminator_before_field_placement.
Add citation in §7's discriminator block for audit trail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: cite P2 (Boundary Discipline) not P1 for single-authority

gpt-5.5-pro APPROVE_WITH_COMMENTS review 9972 caught that the
single-authority / "every fact lives in exactly one place" principle
is INVARIANTS.md P2 Boundary Discipline, not P1. P1 is Modeling
Faithfulness.

Operator BLOCKING quote at §7 invoked "P1" verbatim; both principles
are in play:
- P2 because emission-policy authority must live in exactly one place
  (gunbc/ci.dag), not split across extdeps and gunbc
- P1 because placing gunbc-policy state on an extdeps carrier makes
  the carrier no longer faithful to its header's "platform facts
  only" claim

§7.1 prose updated to explicitly distinguish the two principles and
note that subsequent single-authority references cite P2.
§7.4 table row relabeled "INVARIANTS P2 (Boundary Discipline / single
authority)".
§7.5 ratification ask #2 cites P2 + P1.
§7 heading updated to "INVARIANTS P2/P1 BLOCKING reframes (c)".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: classify EmissionTarget coproduct per Practice 4 (§7.3.1)

BLOCKING inline review on PR #2749 at line :573 (briansrls
2026-05-12T07:04:15Z): proposed EmissionTarget 4-variant coproduct
landed without 🟢/🟡/🔴 dissolution classification, violating
modeling-discipline.md Practice 4 (coproduct dissolution).

Finding accepted. §7.3.1 added classifying EmissionTarget as
🟡 YELLOW (scaffold) with full reasoning across all four dissolution
patterns:
- Pattern 1 (fact placement): N/A — empty payloads
- Pattern 2 (variant-is-data): blocked by closed-set guardrail
- Pattern 3 (algebraic form): N/A — not std/ algebraic operations
- Pattern 4 (dimensional): live dissolution path; ~2-3 axes
  (target_language, requires_shim, runtime_executes) plausible but
  not yet forced at four variants

YELLOW not GREEN: Pattern 4 plausibly works; closing the door would
be wrong. YELLOW not RED: dissolving prematurely without consumer-
side pressure risks landing wrong axes (requires_shim partially
redundant with target_language at current variants).

Named dissolution trigger (per YELLOW requirements): (a) fifth
target landing that breaks the four-way axis, OR (b) consumer needing
single-dimension pattern-match, OR (c) Slice 4/5 implementation
surfacing an unpredicted axis. Any forces dimensional record shape.

Ledger note: classification is canvas-level; implementing PR (WI-2
re-brief per §5/§7.5 ask #4) MUST carry the same classification +
trigger as a // 🟡 YELLOW (scaffold) comment on the type declaration
citing this canvas §7.3.1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: canvas RATIFIED — §9 ratification dispositions

Director (zesty-bear-812) ratified option (c-refined) at
2026-05-12T07:04:18Z per PR #2749 comment (session msg_4f7f536d
to PM deep-wolf-155). Updates:

- Status header changed to RATIFIED with ratification authority
  citation
- §9 added with all 5 ratification asks dispositioned:
  - (c-refined) substrate-shape: RATIFIED
  - PR #2746: AMEND (4 specific changes for still-heron-763)
  - PR #2736 body: SATISFIED prior
  - PR #2745 WI-2: SCOPE EXPANSION APPROVED, PM authors re-brief
  - S1 projection function: NEW §1.8 GATE (project_github_actions_landed,
    substrate-shape family); aggregator pilot row #56+4→#56+5
- Downstream cascade documented per Director directive

Director attributed feedback_extdeps_header_discriminator_before_field_placement
discipline rule to the §7+§8 self-correction trajectory.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: inline SUPERSEDED banners on §1(c)/§2.3/§3/§4/§5

codex BLOCKING review 9986 at sha 38c28cd flagged that §2.3/§3/§5
still contain the now-overturned option-(c)-as-authored framing
(EmissionTarget on extdeps.Workflow + hand-declared pinned Workflow).
For a RATIFIED canvas, leaving those sections unmarked materially
states the wrong substrate shape — readers would have to read through
to §7/§8/§9 to discover the supersession.

Finding accepted. Inline SUPERSEDED banners added at the top of:
- §1 Option (c) sub-section: points to §7.3/§7.4/§8/§9 for current shape
- §2.3 Option (c) evaluation: flags the "emission validates declared
  Workflow against projection" sentence as the dual-authority condition
  §8 retracts
- §3 WI-1 assumption-breakage: OVERTURNED bullets explicitly listed
  (placement, "Workflow chooses target" framing, framing-narrowing
  disposition)
- §4 Slice sequencing under (c): SUPERSEDED in part — structure
  remains valid under (c-refined); placement-specific descriptions
  overturned by §7/§8; WI-2 scope larger than §5.4 implied per §9 ask #4
- §5 Recommendation: all three positions (extdeps placement,
  framing-narrowing PR #2746 disposition, pinned-Workflow validation
  target) OVERTURNED; current recommendation is (c-refined) per §7.5+§9

Earlier framings preserved as canvas-evolution record (showing
self-correction trajectory through §7+§8), but each affected section
now flags its own superseded status without requiring a full-doc read.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §6 Q#2 RESOLVED banner — overturned superseded Workflow framing

cursor APPROVE_WITH_COMMENTS review 10001 (non-blocking) noted that §6
open question #2 still partly explained the projected signature via
"PR #2746 places the field on Workflow", which contradicts §7.3
(c-refined) where extdeps.github.actions.Workflow is frozen unmodified.

Fix: add inline RESOLVED banner at §6 head pointing to §7.3 + §9; rewrite
Q#2 entry to flag the superseded framing inline — the parametric
signature was the right answer regardless of placement, but the rationale
over-attributed to a placement that no longer stands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: inline 🟡 YELLOW checkpoint at §7.3 EmissionTarget declaration

Operator BLOCKING inline review on PR #2749 at :657 (briansrls
2026-05-12T07:58:34Z): the §7.3 code block declaring type
EmissionTarget lacked the inline 🟢/🟡/🔴 classification annotation
required by modeling-discipline.md Practice 4 "any new enum with
N ≥ 2 variants must have a checkpoint comment naming its classification."

The classification reasoning exists in §7.3.1 prose section, but the
declaration site itself was missing the checkpoint comment, which is
the form Practice 4 requires.

Fix: add inline 🟡 YELLOW (scaffold) comment block above the type
declaration citing §7.3.1 for full reasoning + the three-condition
dissolution trigger + likely Pattern 4 dissolution path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7.3.2 Shape A/B clarification — EmissionTarget names realization modes

Operator BLOCKING inline review on PR #2749 at :657 (briansrls
2026-05-12T07:58:35Z): YamlStatic variant of EmissionTarget would
"make a Shape B CI YAML artifact mode an emission target despite
THESIS Shape A/B requiring YAML artifacts to be generated by .dag
user programs, not compiler emission targets."

Per THESIS:215-216, Shape A = compiler language targets (compiler
emits directly); Shape B = user-program artifacts (YAML, Terraform,
K8s, etc. — emitted by .dag programs walking typed values, NOT
compiler render targets). YAML for ci.yml is Shape B; gunbc
doesn't have a YAML emission target.

Finding accepted as naming-and-framing concern, not substrate-shape
concern. Added §7.3.2 clarifying:

- EmissionTarget names a REALIZATION MODE selector, not a parallel
  compiler emission target
- YamlStatic = Shape B (.dag program renders YAML from Workflow)
- BinaryShim = Shape A binary + Shape B YAML shim wrapper
- PythonShim = Shape A Python + Shape B YAML shim wrapper
- InlineGunbc = Shape A (gunbc runtime as host)

No substrate retraction: variants, YELLOW classification, dissolution
trigger, gunbc-namespace placement, parametric signature all stand.
Naming consideration noted (WorkflowRealizationMode would carry less
Shape-A baggage), but renaming forces re-ratification without
corresponding substrate change — keep name, document the mapping at
declaration site per §7.5 ask #4 implementation PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: fix §9 ask #5 slice/gate name — Slice 8 ci_yml_dissolved, not Slice 5 ci_yml_deleted

gpt-5.5-pro REQUEST_CHANGES on PR #2749 sha f5b57e7 (review 10037)
caught that §9 ratification ask #5 wrote the projection-function gate
as "discrete from Slice 5 (ci_yml_deleted, state-check)", but per the
canvas's own §1 (Director-ratified gate-set) and §4 Slice sequencing:
- Slice 5 = BinaryShim emitter (workflow_emission_target_toggle_proven)
- Slice 8 = ci.yml dissolution (gate name: ci_yml_dissolved)

The conflation could mislead workers updating PR #2748 to wire the new
project_github_actions_landed gate against the wrong slice/gate.

Fix: §9 ask #5 now reads "discrete from Slice 8 ci_yml_dissolved",
matching the canvas's earlier authoritative gate-set + §4 sequencing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…on 🟡 YELLOW (#2751)

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: canvas RATIFIED — §7 ratification dispositions

Director (zesty-bear-812) ratified option (c) at 2026-05-12T07:39:44Z
per PR #2751 comment (session msg_168005e1 to PM deep-wolf-155).

- Status header updated to RATIFIED
- §7 added with 4 ratification points + cascade implications:
  1. Expression sum-type at dsl/extdeps/github/actions.dag: RATIFIED
  2. Single OpaqueString variant + 🟡 YELLOW: RATIFIED
  3. Three-condition dissolution trigger: RATIFIED
  4. 5-site uniform migration: RATIFIED
- Cascade documented: cool-carp-720 (WI-2) Expression wrapping;
  stern-stag-854 (Slice 4-5) emit logic stays trivial; PR #2746 can
  reference ratified Expression substrate

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: site-count correction — 5→7 expression sites in actions.dag

Operator BLOCKING inline review on PR #2751 at :34 (briansrls
2026-05-12T07:45:24Z) flagged that actions.dag has Job.if_condition
+ RunStep.if_condition + UsesStep.if_condition (3 if_condition sites),
not 1. Same expansion applies to env: RunStep.env + UsesStep.env (2
sites), not 1.

Finding accepted. Actual migration scope is 7 sites total:
- Job.if_condition (:117)
- RunStep.if_condition (:154)
- UsesStep.if_condition (:163)
- RunnerSpec (new ExpressionRunner variant)
- ConcurrencySpec.group (:?)
- Step.with[k] (UsesStep:160)
- RunStep.env (:151) + UsesStep.env (:162)

Updates:
- §1 table: if_condition row shows 3 sites; env row shows 2 sites
- §1 narrative: "seven expression sites" with enumeration
- §2 (a/b/c) code samples: all 7 sites in option (c) sketch; Step
  carrier modeled with RunStep/UsesStep variants properly
- §3 reasoning point #1: explicit P2/P5 framing — leaving any
  if_condition/env site un-migrated creates hidden parallel authority
  (typed at one site, opaque at others) blocking P5 dissolution at
  un-migrated sites
- §5 / §6 / §7 site-count refs updated
- §7 site-count correction note: framing the expansion as
  site-count correction, NOT substrate-shape correction — ratification
  point #4's "single-authority for expression substrate" already covered
  ALL expression sites in actions.dag uniformly; 7-site scope is
  implementing-PR responsibility

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §4 dissolution target — template-string layer for extdeps fidelity

Operator BLOCKING #2 on PR #2751 at :214 (briansrls 2026-05-12T07:45:24Z):
the §4 dissolution target sketched a pure Expression AST, but GH Actions
expression-bearing scalars are template strings with alternating literal-
text and ${{...}} segments (e.g., concurrency.group:
${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}).
A pure-AST terminal shape under-models what the platform actually parses,
violating INVARIANTS.md P1 (modeling faithfulness).

Finding accepted. §4 dissolution target corrected to two-layer shape:

  Expression
    = OpaqueString(String)
    | Template(List<TemplateSegment>)

  TemplateSegment
    = TextSegment(String)
    | ExpressionSegment(ExpressionAst)

  ExpressionAst = Literal | Var | BinOp | Func | Index (etc.)

This is extdeps-faithful: mirrors the platform's actual parse structure
(template-string layer over expression-AST layer). Pure-literal /
pure-expression / mixed scalars all collapse cleanly into the segment
list.

Original sketch preserved as authoring-evolution record; corrected shape
supersedes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §6 Q#1 RESOLVED — sum form, not record (per BLOCKING at :258)

Operator BLOCKING #3 on PR #2751 at :258 (briansrls 2026-05-12T07:45:24Z):
§6 open question #1 incorrectly treated record form and one-arm sum as
equivalent. A record form (type Expression { value: String }) does NOT
preserve:
- Single-arm pattern-match property on consumers (record access
  projects to .value as String; no tag to match)
- Single-edit second-variant dissolution path (record → sum is a
  carrier-shape change, not a one-line declaration edit; every
  consumer must be rewritten to switch from .value access to
  pattern-match)

This breaks Practice 4 (coproduct dissolution) and P5 (Progress Is
Dissolution) — the dissolution receipt the YELLOW classification
relies on assumes the dissolution is cheap; record form makes it
expensive.

Q#1 resolved inline: Expression lands as a one-arm sum
(type Expression = OpaqueString(String)), NOT a record. This was
implied by §3 reasoning point #4 ("Pre-empts the type-alias trap")
which applies equally to record-form aliases, but the §6 framing
treated both as admissible — corrected.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: add CI workflow emitter-dispatch canvas (#2746)

* docs: add CI workflow emitter-dispatch canvas

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs: align workflow emitter canvas with substrate comparison

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs: keep InlineGunbc out of initial target enum

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs(r3): §1.8 acceptance-aggregator pattern scaffold (pilot) (#2748)

* docs(r3): expand R3 lanes to 12 + lens-framework invariant + analysis findings

User directive 2026-04-30: "nothing can be deferred past R3 - we have to
readjust R3 if something is missing." PM-driven audit + Director ratification.

R3 lane expansion (10 → 12):
- T-V2-Retirement (NEW; PB Manager continuation): src/v2/ retirement
  cascades from T-FixedPoint + T-LensProducer-Retirement; structurally
  cheap to pull in. Gates: v2_oracle_no_remaining_test_consumers +
  v2_directory_deleted.
- T-Free-Consequences-Demonstration (NEW; Verification Manager): 10-gate
  TestClaim suite operationalizing thesis "free consequences" framing.
  Auto-parallelism + auto-memoization + cross-target opt + space-bound CX.
  Loop-iteration parallelism: sequential default + opt-in via
  Lens<Iteration-Independence> (zero-heuristic; same shape as
  Lens<Bind-Independence>).

Priority corrections folded into existing lanes (no new lanes):
- C1 (T-Tier3-Dissolution sub-gate): tier3_mirror_dissolution_perf_within_budget
  with thresholds <=2x median, <=5x p99 (cargo bench fixtures per retired
  mirror).
- C2 (Substrate continuation, T-Anthropic-Wire scope expansion):
  ProviderTypedWire<P> carrier extracted IN R3 (path (a) commit; drops the
  prior 6-month elapsed-time check exactly per user directive).

design-lens-framework.md amendment:
- Lens.read MUST depend only on (Node, Behavior) pair, not external state.
- Locks memoizable shape; runtime memoization becomes auto-memoization free
  consequence instance (T-Free-Consequences-Demonstration).

ROADMAP.md additions (### Post-merge debt (2026-04-30 analyses)):
- 4 novel findings from paired exploratory + reflective analyses
  (gpt-5-5-pro 991114f / gpt-5-5-thinking ad016c5):
  * Duplicate record-literal fields silently dropped (highest-value bug)
  * ValueBody Rust<->.dag mirror drift; no isomorphism gate
  * FieldMap duplicate-free invariant lost in .dag mirror
  * Operator inference fabricates (T,T)->T for non-algebra LHS
- 8 reflective-analysis priority corrections folded into R3 trajectory
- 2 stale rows marked RESOLVED (repeat_string + lower_fn_body re-derive)

Routed to R3 Mgrs via inbox dispatches (#1130 / #1131 / #1133 / #1276 / #846).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): reframe Rust<->.dag isomorphism as producer-first

cool-crab-614 PR #1324 research reframed the proposal: missing substrate
is a reflected-Dag query/report PRODUCER (Lens<DagShapeReport>), not a
new predicate variant. RustDagIsomorphism becomes a CONSUMER (TestClaim
comparing two DagShapeReport outputs via BinaryDimensionReportEquals),
eliminating parallel-authority risk.

Reflection-aware modifiers for unified BinaryDimensionReportEquals now
cover 4 surfaces: TC1 eta-equivalence + TC2 strategy-order + TC3
evaluation-step + shape-report (reflected-Dag query).

Single substrate-introduction; multiple consumers via reflection-aware
modifiers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): fix lower_fn_body row citation per #1319 review

PR #1319 review (cursor 9d2dffb) flagged that the RESOLVED note cited
`src/v3/compiler/src/lower.rs:61670-61688` but lower.rs is only 7919
lines. Original line citations referenced the analysis snapshot's
aggregate-numbering scheme, not live file.

Verified live state: `lower_fn_body_into_existing_decl` symbol does NOT
exist in current lower.rs; equivalent path is `lower_fn_item_expr_body`
(:4410+); non-Arrow arm at :4433-4451 reports
`Diagnostic::ResolveError` with explicit invariant-violation message
("violated lowering invariant: seed_function_signatures_phase did not
produce an Arrow connective for this Fn") and returns outer_scope.
That IS the fail-closed shape the original row asked for; resolution
note now correctly cites live behavior.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): resolve v2-retirement contradiction per #1319 review

PR #1319 review (codex a9a9894) flagged contradiction: T-V2-Retirement
added as R3 lane (line 100) but Compromises table (line 165) still
listed v2 retirement as Post-R3 operational cleanup. INVARIANTS P1
"Documentation Describes Live State" violation.

Fix: strikethrough the post-R3 entry; explicitly note migration into
R3 as T-V2-Retirement lane per 2026-04-30 user directive "nothing can
be deferred past R3." Single authoritative placement; cross-link to
Lane structure §11.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* docs(r3): aggregator pattern — coercion table + precondition + exclusion rules

Addresses BLOCKING #2748 (briansrls inline at L71): live §1.8 uses 7 status
values, not 3 (PASSING, SATISFIED-BY-CONSTRUCTION, CONSUMER_LANDED, DECLARED,
R3-LOAD-BEARING, HELD-CANVAS-DEFERRED, DEFERRED). The 3-value lattice meet
was not machine-checkable as written.

- Coercion table: SATISFIED-BY-CONSTRUCTION → PASSING; INTEGRATION_RECEIPT
  partial-slice → CONSUMER_LANDED; identity for the 3 lattice values.
- Precondition rule: bare R3-LOAD-BEARING is scope-metadata, not closure
  progress; constituents with that status are not aggregator-ready until
  cell inlines closure-progress (e.g., 'R3-LOAD-BEARING — DECLARED').
- Exclusion rule: DEFERRED + HELD-CANVAS-DEFERRED MUST NOT appear in any
  aggregator's depends_on: per §1.5 honest-close arithmetic.
- Cluster F candidate reframed: NOT aggregator-ready at HEAD because rows
  #81/#82/#83/#95 carry bare R3-LOAD-BEARING; precondition fix required
  before pilot. Cluster M / K / V2-Retirement candidates similarly subject
  to precondition check at pilot time.
- Invariants P2 cleanliness note: coercion table + precondition + exclusion
  are themselves a single derivation authority; no parallel authority for
  closure progress.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): cascade ci_yml_deleted → ci_yml_hand_authority_dissolved rename

Per PM cascade (PR #2744 commit 19a1d8d absorbing briansrls BLOCKING
on line 32): file artifact presence is orthogonal to hand-authority
dissolution. YamlStatic / BinaryShim / PythonShim all require some
.github/workflows/ci.yml for GH Actions trigger discovery; P5 / Pure
Bootstrap dissolves authority, not file presence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): relocate aggregator pattern from §1.8 to §1.9 per codex P2 finding

Addresses codex REQUEST_CHANGES /api/reviews/9982 on PR #2748: putting
aggregator rows directly in §1.8 alongside their constituents violated
INVARIANTS P2 single-authority — even with "derived not hand-set" prose,
the row shape didn't structurally prevent treatment as a closure
obligation, and the side-taxonomy of "does not participate in §1.7
corpus rules" was a P2 boundary-discipline violation inside the
canonical ledger.

Restructured:
- Aggregators relocated to a NEW §1.9 section (separate table)
- Distinct ID namespace: V1, V2, ... (NOT numeric §1.8 row IDs)
- Different table columns (View ID / View Name / Cluster Lane /
  depends_on: / Derived Status / Notes) to make visual distinction
  obvious
- depends_on: references §1.8 row #s by foreign-key style
- Derived Status rendered as <DERIVED> in committed text; never stored
  as snapshot (per feedback_no_snapshot_integers_in_briefs)
- §1.8 "97 enumerated / 96 R3-load-bearing" arithmetic preserved
  unchanged; §1.9 entries do not appear in that arithmetic
- Coercion table + precondition + exclusion rules carried forward
- Cluster F precondition catch (rows #81/#82/#83/#95 carry bare
  R3-LOAD-BEARING) preserved

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): annotate R4-carve citation with supersession marker

Fixes CI failure on PR #2748: scripts/check-r4-carve-dissolution-discipline.sh
flagged the coercion-table row for R3-LOAD-BEARING which mentioned 'R4-carved'
without a supersession annotation. Reframed to cite carve-promotion-IN-R3
2026-05-09 + DISSOLVED status per Director ratification gunbc#846.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): correct #83 characterization + add filename note

Per cursor APPROVE_WITH_COMMENTS /api/reviews/10000 on PR #2748:

- Row #83 (lens_capability_register_zero_proxy_zero_stub) was incorrectly
  listed alongside #81/#82/#95 as carrying "bare R3-LOAD-BEARING". The
  authoritative ledger has #83 reading "DECLARED — full scope IN R3
  (carve-promotion-IN-R3 2026-05-09)", which inlines closure-progress
  alongside scope-metadata and already coerces to DECLARED under the
  precondition rule. Reframed #83 as a positive counter-example showing
  the inline-pattern #81/#82/#95 still need to adopt.

- Added top-of-doc filename note explaining the §1.8 vs §1.9 mismatch:
  filename retained for review-thread anchor stability; substantive
  section is §1.9.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add sunset condition for aggregator pattern pilot doc

Per cursor /api/reviews/10013 optional tighten: PILOT scaffold needs a
single checkable sunset to satisfy P5 scaffold-posture discipline.
Sunset: doc retires when docs/r3-program-plan.md contains §1.9 per the
specified table shape AND at least one §1.9 view entry is live in the
ledger.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add composite-status coercion rule (CONSUMER_LANDED + PASSING)

Addresses briansrls BLOCKING inline at L66 on PR #2748: coercion table
omitted live §1.8 composite forms like 'CONSUMER_LANDED + PASSING'
(~25 instances in the ledger, including candidate Cluster M constituent
#86 program_generator_carrier_landed).

Added:
- Explicit row for 'CONSUMER_LANDED + PASSING' → PASSING
- General composite rule '<earlier> + <later>' → coerce to <later>
  (rightmost component; conjunction-of-progression-stages semantics);
  covers future composite forms not enumerated.

This makes #86 view-ready under the precondition rule (coerces cleanly
to PASSING).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag) (#2747)

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* docs: add CI workflow emitter-dispatch canvas

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs: add T-CI-WAD slice 4 skeleton

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs: clarify T-CI-WAD projection sketch

* docs: align T-CI-WAD prep with c-refined shape

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs(r3): T-WAD substrate-shape comparison canvas — gate #56 (#2749)

* docs(r3): flip §1.8 #85 forall_exists_quantifier_substrate_landed to CONSUMER_LANDED + PASSING

PR #2647 (vivid-dove-106 / Cluster M Phase 1a) merged carriers into src/v3/std/verification.dag at HEAD; ledger row was drifted DECLARED. Per post-merge ledger-receipt sync discipline (Director-ratified at gunbc#828 c#4415884211).

Caught by Debt-Paydown PM ledger-sync check — thanks silent-ram-834.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): downgrade §1.8 #85 to DECLARED per codex BLOCKING + row #17 precedent

Prior CONSUMER_LANDED + PASSING flip overstated the gate per INVARIANTS §P2 strict reading: carriers + hand-written ratchet ≠ generated consumer proof. Mirrors row #17 (numeric_abstract_carriers_landed) shape: carrier substrate landed, hand-written ratchet noted, CONSUMER_LANDED deferred to generated consumer + SuiteClaim wrapper migration + V Mgr #87 runner consumer.

Sibling row #86 carries same overclaim risk via PR #2645 precedent — separate amendment if Director rules.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: T-WAD substrate-shape comparison canvas (gate #56)

Mgr-tier comparison canvas surfacing three substrate-shape options for
gate #56 ci_workflow_modeled_as_dag under FULL R3-close elevation:

- (a) PR #2736 provider-neutral CIWorkflowDag (semantic-only)
- (b) WI-1 PR #2746 actions.dag-concrete + EmissionTarget? (transport-only)
- (c) Hybrid — CIWorkflowDag as semantic source + Workflow.emission_target
  as transport-artifact selector + projection function project_github_actions:
  CIWorkflowDag -> Workflow as the structural fold connecting them

§0 grep-verifies PR #2736 body claim ("hand-authored GitHub Actions transport
copy was removed") against actual diff: actions.dag Workflow/Job/Step
carriers at :21/:110/:147 intact; PR adds CIWorkflowDag without removing
actions.dag carriers, leaving dual-authority unresolved at HEAD.

§5 recommends option (c) for Director ratification on:
- single-authority per concept layer (gate-dependency at gunbc.ci;
  transport at extdeps.github.actions) per MODELING.md M9
- decoupled cost-of-change axes (new provider vs new emission target)
- preserves both already-authored PRs' substrate contributions
- aligns with docs/design-emission-model.md single-emitter discipline

Authority: PM relay msg_a945b141 (deep-wolf-155) routing Director
msg_34e9a381 substrate-shape question per
feedback_substrate_shape_belongs_in_mgr_canvas.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7 addendum — INVARIANTS P1 reframes (c) to (c-refined)

BLOCKING inline review on PR #2746 (briansrls c#4427988541) flagged
that adding EmissionTarget to dsl/extdeps/github/actions.dag puts a
gunbc emission-policy fact into the GitHub Actions platform model,
violating extdeps fidelity and INVARIANTS P1.

§7 accepts the finding (structurally correct per actions.dag header
:1-12 platform-vs-CI-logic discriminator), disqualifies §1 option (b)
as-authored, partially invalidates §1 option (c) as-authored (the
two-layer concept-layering argument STILL holds; only the EmissionTarget
placement on extdeps fails P1).

§7.3 surfaces option (c-refined): EmissionTarget lives in gunbc/ci.dag
as a sum type + parameter to project_github_actions(ci_workflow_dag,
target) -> Workflow. extdeps.github.actions.Workflow is unmodified.
Pinned Workflow values for emission validation live in gunbc namespace.

§7.5 revises ratification asks: PR #2746 disposition shifts from
"framing-narrowing" to substantive substrate retraction on the field-
placement decision (sum-type shape stands; placement relocates).

§7.6 distinguishes (c-refined) from PM-proposed alternatives:
- not PM(b) [EmissionTarget on CIPipeline] — same M9 join-cost as
  PR #2746 §3 Option B
- not PM(c) [WorkflowEmission wrapper] — same sibling-decision cost
  PR #2746 §3 Option C already rejected
(c-refined) expresses emission-target choice at the projection
invocation (per docs/design-emission-model.md: emission is structural
projection, choice is property of the call not the value).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §8 retraction — derive Workflow from projection, not separate authority

codex REQUEST_CHANGES on PR #2749 (review 9970) flagged that option (c)
as authored proposed both a projection function CIWorkflowDag -> Workflow
AND a separately hand-declared Workflow value the emitter "validates
against" as a pinned target — INVARIANTS P2 / modeling-discipline.md
Practice 5 dual-authority condition.

Finding accepted. §8 retracts the pinned-Workflow-as-modeled-authority
framing; in-place edits applied to §1 (option (c) intro), §4 (S0
sequencing), §5 (ratification ask #5), §7.3 (WI-2 placement), §7.5
(revised recommendation).

Replacement framing: the only Workflow value in modeled authority is
the projection function output, structurally derived from a single
source. WI-2's gunbc_ci_yml_workflow becomes a name binding to the
derived result (data gunbc_ci_yml_workflow: Workflow =
project_github_actions(ci_workflow_dag, YamlStatic)), not an
independent declaration. Byte-level regression fixtures live in
tests/, not dsl/, and are not part of modeled authority.

Layering argument unchanged: gate-dependency at gunbc.ci.CIWorkflowDag;
platform transport at extdeps.github.actions.Workflow (unmodified);
emission policy in gunbc namespace; artifact derived from single source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: cite feedback_extdeps_header_discriminator_before_field_placement

Per PM relay msg_72e2ab50: Director memorialized actions.dag:1-12
discriminator rule as feedback_extdeps_header_discriminator_before_field_placement.
Add citation in §7's discriminator block for audit trail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: cite P2 (Boundary Discipline) not P1 for single-authority

gpt-5.5-pro APPROVE_WITH_COMMENTS review 9972 caught that the
single-authority / "every fact lives in exactly one place" principle
is INVARIANTS.md P2 Boundary Discipline, not P1. P1 is Modeling
Faithfulness.

Operator BLOCKING quote at §7 invoked "P1" verbatim; both principles
are in play:
- P2 because emission-policy authority must live in exactly one place
  (gunbc/ci.dag), not split across extdeps and gunbc
- P1 because placing gunbc-policy state on an extdeps carrier makes
  the carrier no longer faithful to its header's "platform facts
  only" claim

§7.1 prose updated to explicitly distinguish the two principles and
note that subsequent single-authority references cite P2.
§7.4 table row relabeled "INVARIANTS P2 (Boundary Discipline / single
authority)".
§7.5 ratification ask #2 cites P2 + P1.
§7 heading updated to "INVARIANTS P2/P1 BLOCKING reframes (c)".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: classify EmissionTarget coproduct per Practice 4 (§7.3.1)

BLOCKING inline review on PR #2749 at line :573 (briansrls
2026-05-12T07:04:15Z): proposed EmissionTarget 4-variant coproduct
landed without 🟢/🟡/🔴 dissolution classification, violating
modeling-discipline.md Practice 4 (coproduct dissolution).

Finding accepted. §7.3.1 added classifying EmissionTarget as
🟡 YELLOW (scaffold) with full reasoning across all four dissolution
patterns:
- Pattern 1 (fact placement): N/A — empty payloads
- Pattern 2 (variant-is-data): blocked by closed-set guardrail
- Pattern 3 (algebraic form): N/A — not std/ algebraic operations
- Pattern 4 (dimensional): live dissolution path; ~2-3 axes
  (target_language, requires_shim, runtime_executes) plausible but
  not yet forced at four variants

YELLOW not GREEN: Pattern 4 plausibly works; closing the door would
be wrong. YELLOW not RED: dissolving prematurely without consumer-
side pressure risks landing wrong axes (requires_shim partially
redundant with target_language at current variants).

Named dissolution trigger (per YELLOW requirements): (a) fifth
target landing that breaks the four-way axis, OR (b) consumer needing
single-dimension pattern-match, OR (c) Slice 4/5 implementation
surfacing an unpredicted axis. Any forces dimensional record shape.

Ledger note: classification is canvas-level; implementing PR (WI-2
re-brief per §5/§7.5 ask #4) MUST carry the same classification +
trigger as a // 🟡 YELLOW (scaffold) comment on the type declaration
citing this canvas §7.3.1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: canvas RATIFIED — §9 ratification dispositions

Director (zesty-bear-812) ratified option (c-refined) at
2026-05-12T07:04:18Z per PR #2749 comment (session msg_4f7f536d
to PM deep-wolf-155). Updates:

- Status header changed to RATIFIED with ratification authority
  citation
- §9 added with all 5 ratification asks dispositioned:
  - (c-refined) substrate-shape: RATIFIED
  - PR #2746: AMEND (4 specific changes for still-heron-763)
  - PR #2736 body: SATISFIED prior
  - PR #2745 WI-2: SCOPE EXPANSION APPROVED, PM authors re-brief
  - S1 projection function: NEW §1.8 GATE (project_github_actions_landed,
    substrate-shape family); aggregator pilot row #56+4→#56+5
- Downstream cascade documented per Director directive

Director attributed feedback_extdeps_header_discriminator_before_field_placement
discipline rule to the §7+§8 self-correction trajectory.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: inline SUPERSEDED banners on §1(c)/§2.3/§3/§4/§5

codex BLOCKING review 9986 at sha 38c28cd flagged that §2.3/§3/§5
still contain the now-overturned option-(c)-as-authored framing
(EmissionTarget on extdeps.Workflow + hand-declared pinned Workflow).
For a RATIFIED canvas, leaving those sections unmarked materially
states the wrong substrate shape — readers would have to read through
to §7/§8/§9 to discover the supersession.

Finding accepted. Inline SUPERSEDED banners added at the top of:
- §1 Option (c) sub-section: points to §7.3/§7.4/§8/§9 for current shape
- §2.3 Option (c) evaluation: flags the "emission validates declared
  Workflow against projection" sentence as the dual-authority condition
  §8 retracts
- §3 WI-1 assumption-breakage: OVERTURNED bullets explicitly listed
  (placement, "Workflow chooses target" framing, framing-narrowing
  disposition)
- §4 Slice sequencing under (c): SUPERSEDED in part — structure
  remains valid under (c-refined); placement-specific descriptions
  overturned by §7/§8; WI-2 scope larger than §5.4 implied per §9 ask #4
- §5 Recommendation: all three positions (extdeps placement,
  framing-narrowing PR #2746 disposition, pinned-Workflow validation
  target) OVERTURNED; current recommendation is (c-refined) per §7.5+§9

Earlier framings preserved as canvas-evolution record (showing
self-correction trajectory through §7+§8), but each affected section
now flags its own superseded status without requiring a full-doc read.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §6 Q#2 RESOLVED banner — overturned superseded Workflow framing

cursor APPROVE_WITH_COMMENTS review 10001 (non-blocking) noted that §6
open question #2 still partly explained the projected signature via
"PR #2746 places the field on Workflow", which contradicts §7.3
(c-refined) where extdeps.github.actions.Workflow is frozen unmodified.

Fix: add inline RESOLVED banner at §6 head pointing to §7.3 + §9; rewrite
Q#2 entry to flag the superseded framing inline — the parametric
signature was the right answer regardless of placement, but the rationale
over-attributed to a placement that no longer stands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: inline 🟡 YELLOW checkpoint at §7.3 EmissionTarget declaration

Operator BLOCKING inline review on PR #2749 at :657 (briansrls
2026-05-12T07:58:34Z): the §7.3 code block declaring type
EmissionTarget lacked the inline 🟢/🟡/🔴 classification annotation
required by modeling-discipline.md Practice 4 "any new enum with
N ≥ 2 variants must have a checkpoint comment naming its classification."

The classification reasoning exists in §7.3.1 prose section, but the
declaration site itself was missing the checkpoint comment, which is
the form Practice 4 requires.

Fix: add inline 🟡 YELLOW (scaffold) comment block above the type
declaration citing §7.3.1 for full reasoning + the three-condition
dissolution trigger + likely Pattern 4 dissolution path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7.3.2 Shape A/B clarification — EmissionTarget names realization modes

Operator BLOCKING inline review on PR #2749 at :657 (briansrls
2026-05-12T07:58:35Z): YamlStatic variant of EmissionTarget would
"make a Shape B CI YAML artifact mode an emission target despite
THESIS Shape A/B requiring YAML artifacts to be generated by .dag
user programs, not compiler emission targets."

Per THESIS:215-216, Shape A = compiler language targets (compiler
emits directly); Shape B = user-program artifacts (YAML, Terraform,
K8s, etc. — emitted by .dag programs walking typed values, NOT
compiler render targets). YAML for ci.yml is Shape B; gunbc
doesn't have a YAML emission target.

Finding accepted as naming-and-framing concern, not substrate-shape
concern. Added §7.3.2 clarifying:

- EmissionTarget names a REALIZATION MODE selector, not a parallel
  compiler emission target
- YamlStatic = Shape B (.dag program renders YAML from Workflow)
- BinaryShim = Shape A binary + Shape B YAML shim wrapper
- PythonShim = Shape A Python + Shape B YAML shim wrapper
- InlineGunbc = Shape A (gunbc runtime as host)

No substrate retraction: variants, YELLOW classification, dissolution
trigger, gunbc-namespace placement, parametric signature all stand.
Naming consideration noted (WorkflowRealizationMode would carry less
Shape-A baggage), but renaming forces re-ratification without
corresponding substrate change — keep name, document the mapping at
declaration site per §7.5 ask #4 implementation PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: fix §9 ask #5 slice/gate name — Slice 8 ci_yml_dissolved, not Slice 5 ci_yml_deleted

gpt-5.5-pro REQUEST_CHANGES on PR #2749 sha f5b57e7 (review 10037)
caught that §9 ratification ask #5 wrote the projection-function gate
as "discrete from Slice 5 (ci_yml_deleted, state-check)", but per the
canvas's own §1 (Director-ratified gate-set) and §4 Slice sequencing:
- Slice 5 = BinaryShim emitter (workflow_emission_target_toggle_proven)
- Slice 8 = ci.yml dissolution (gate name: ci_yml_dissolved)

The conflation could mislead workers updating PR #2748 to wire the new
project_github_actions_landed gate against the wrong slice/gate.

Fix: §9 ask #5 now reads "discrete from Slice 8 ci_yml_dissolved",
matching the canvas's earlier authoritative gate-set + §4 sequencing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: §5.5 inventory audit — 7→22 expression-capable fields

codex BLOCKING (review on sha 4f41aeb) + operator BLOCKING inline at
:315 (2026-05-12 ~09:12Z): site inventory was keyed to ci.yml examples
not actions.dag schema + GH Actions context-availability docs.
Under-modeling the platform expression-capable surface by ~15 sites.

Finding accepted as substantive scope correction. Added §5.5 with
full audit table against actions.dag HEAD + GH Actions docs:

Total expression-capable surface: 22 fields across Workflow / Job /
RunStep / UsesStep / ConcurrencySpec / RunnerSpec. The 7-site
enumeration was the ci.yml-keyed minimum subset; the
actions.dag-keyed audit extends to 22.

§5.5.1 sets migration rule: ALL expression-capable fields migrate
uniformly under (c). Per-field opt-in produces hidden parallel
authority (P2/P5 violation). Implementing PR audits against actions.dag
HEAD + GH Actions context-availability docs and migrates any
additional sites surfaced.

§5.5.2 surfaces typed-field expression semantics as new substantive
question (§6 Q#4) — timeout_minutes/continue_on_error/cancel_in_progress
are typed fields where GH Actions string-coerces expressions. Three
candidate shapes (wrap / TypedOrExpression sum / defer); Director-tier
choice.

§5.5.3 retains §1/§2 7-site framing as ci.yml-keyed reference;
substrate-shape ratification covers expanded 22-site scope per §5.5.1
migration rule.

§6 Q#2 sequencing updated to "22 expression-capable fields"; new Q#4
adds typed-field semantics question.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: update PR #2749 cross-link — EmissionTarget → WorkflowRuntime

Per PR #2749 commit 575eb7e (rename EmissionTarget → WorkflowRuntime
to resolve P2 name-collision with src/v3/SELF_HOSTING.md:609 Shape-A
EmissionTarget), update the single cross-reference in §7 here to match
the new name. Substantive content unchanged — orthogonal-axes argument
still holds.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §5.5.1 — split 22 sites into 13 string + 7 typed-field + 2 enum-ext

codex REQUEST_CHANGES on PR #2751 review 10083 (sha presumably 0cc2c28e
or 28d503c): §5.5.1 said "ALL 22 expression-capable fields migrate to
Expression" but §5.5.2 / §6 Q#4 left typed-field shape (Int?/Bool sites)
as an open Director-tier question. Implementer following §5.5.1 would
author the wrap-to-Expression shape immediately while §5.5.2 says hold.

Finding accepted. §5.5.1 split into three classes:

- 13 string-typed sites — uniform String→Expression migration, in scope
  for §7.5 ask #4 prereq PR
- 7 typed-field sites (timeout_minutes/continue_on_error/
  cancel_in_progress) — HOLD until §6 Q#4 ratifies wrap/sum/defer
- 2 enum-extension sites (RunnerSpec, UsesStep.uses) — new variant
  added to existing sum/struct, in scope for §7.5 ask #4 prereq PR

In-scope for substrate-prereq PR: 13 + 2 = 15 sites. Out-of-scope
(deferred): 7 typed-field sites.

§5.5.1 now non-contradictory with §5.5.2 / §6 Q#4: implementer reading
§5.5.1 migrates 15 sites; the 7 typed-field sites explicitly HOLD with
a named trigger (§6 Q#4 ratification).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §5.5 inventory expansion — add Workflow.name + Job.name (22→24 sites)

Operator BLOCKING on PR #2751 at :365 (briansrls 2026-05-12T10:12:15Z):
the string-typed migration class omitted Job.name: String?; GH Actions
context-availability table lists jobs.<job_id>.name as expression-capable.
Same applies to Workflow.name (workflow name supports expressions).

Audit gap fixed. §5.5 table adds:
- Workflow.name: String (:22) — string-typed expression-capable
- Job.name: String? (:112) — string-typed expression-capable

Counts updated:
- Total expression-capable: 22 → 24 sites
- String-typed class: 13 → 15 sites
- In-scope for prereq PR: 15 → 17 sites (15 string + 2 enum-extension)
- Out-of-scope (typed-field HOLD): 7 sites (unchanged)
- Under-modeling delta: 15 → 17 sites (ci.yml-keyed 7-site enumeration
  missed 17 sites in actions.dag schema)

§5.5.1 enumerated list of string-typed sites adds Workflow.name + Job.name.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: §5.5 — remove UsesStep.uses (literal-only per GH workflow-syntax)

Operator BLOCKING on PR #2751 at :381 (briansrls 2026-05-12T10:12:15Z):
classifying UsesStep.uses as expression-capable invents platform
capability — GH Actions workflow-syntax treats uses: as a literal
action location; the context-availability table does NOT list
jobs.<job_id>.steps.uses. Modeling it as expression-capable would
violate INVARIANTS.md P1 modeling faithfulness.

Verified against GH Actions docs (workflow-syntax + context-availability):
uses: is a literal action ref resolved before workflow expressions
evaluate.

Finding accepted. Removed UsesStep.uses from §5.5 inventory + struck out
the row + removed planned ExpressionActionRef variant from
enum-extension class.

Counts updated:
- Total: 24 → 23 sites
- Enum-extension class: 2 → 1 site (RunnerSpec only)
- In-scope for prereq PR: 17 → 16 sites (15 string + 1 enum-ext)
- Under-modeling delta: 17 → 16 sites
- Typed-field HOLD class: 7 sites (unchanged)

§5.5.1 enum-extension block now explains why UsesStep.uses was
removed for audit trail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7 ratification ask #4 — reflect §5.5 expanded scope (16 in-scope, 7 HOLD)

Operator BLOCKING on PR #2751 at :543 (briansrls 2026-05-12T10:12:15Z):
§7 ratification dispositions still referenced the 7-site enumeration from
the original ratification framing, while §5.5 expanded the audit to
23 sites. Downstream implementation reading only §7 would preserve
opaque-string authorities at the non-§7-enumerated sites — P2/P5
violation by structural drift.

Fix: §7 ratification point #4 rewritten to cite §5.5 audit set + 16
in-scope sites + 7 typed-field HOLD class with named trigger.

Site-count correction note expanded from single-event to cumulative
correction sequence documenting all 4 BLOCKING-driven expansions
(5→7→22→24→23). Audit trail preserved; the (c) substrate-shape
ratification covers all 23 expression-capable sites uniformly per
"single-authority for expression substrate" principle — implementing
PR migrates 16 immediately, 7 typed-field sequenced post §6 Q#4
ratification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 expand to MatrixStrategy carriers (23→28 sites; audit-methodology note per codex review 10128)

Cross-product of GH context-availability table × actions.dag carriers adds
MatrixStrategy.{dimensions,include,exclude,fail_fast,max_parallel}.
Updated counts: 28 total / 18 string-typed / 9 typed-field / 1 enum-ext;
19 in-scope for prereq PR, 9 HOLD for §6 Q#4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 remove Workflow.name (literal-only per GH context-availability; run-name is expression-capable key and not currently a Workflow field) — operator BLOCKING :274

28→27 total, 18→17 string-typed, 19→18 in-scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 add DispatchInput.default (operator BLOCKING :298) — workflow_call/workflow_dispatch input defaults per GH context-availability

27→28 total, 17→18 string-typed, 18→19 in-scope. MatrixStrategy already present per commit 9c1f0a1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): status-block migration scope = 19 in-scope + 9 HOLD (was '5 sites uniform') — operator BLOCKING :7

Aligns top-of-file status with §5.5 / §7 ratified scope: 28 total / 18 string-typed + 1 enum-ext = 19 in-scope for prereq PR / 9 typed-field HOLD on §6 Q#4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5.1/§7/audit-trail count reconciliation (28/18/19/9) — cursor review 10134

Sweep stale internal counts: 23→28 site totals, 15→17 string-typed in audit blockquote, 5→9 typed-field, 16+7→19+9 deferred. Added correction step 5 to audit trail covering MatrixStrategy + DispatchInput.default additions and Workflow.name removal. Aligns §5.5.1, §5.5 audit-trail blockquote, §7.5 ask #4 with §5.5 audit totals.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix 'seven sites-already-migrated' (→19) + P5/modeling-discipline citation drift — cursor review 10145

:146 + :231-233: dissolution-cost wording updated from pre-§5.5 '7 sites' to post-audit '19 sites + 9 typed-field once §6 Q#4 resolves'.
:289-291: scaffold-arm sunset-milestone citation moved from INVARIANTS P5 (which mandates checkable dissolution trigger) to modeling-discipline.md Practice 4 (home of the scaffold-comment convention).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5.1 derivation discipline + add MatrixStrategy carriers to class lists; §6 Q#5 (DispatchInput carrier-split) + Q#6 (RunnerSpec runs-on grammar) — codex BLOCKING 10150

(1) §5.5.1 lists now explicitly enumerate MatrixStrategy carriers per class: dimensions/include/exclude in string-container (18 total), fail_fast/max_parallel in typed-field HOLD (9 total). Added explicit derivation-from-§5.5-table discipline note. Cross-check 18+9+1=28 ✓.

(2) §6 Q#5: shared DispatchInput collapses workflow_call vs workflow_dispatch expression-context-availability axes; carrier-split question surfaced (Director-tier sequencing relative to Slice 4 prereq PR).

(3) §6 Q#6: RunnerSpec under-models runs-on grammar (scalar/array/object + expressions at multiple positions); §2 (c) ExpressionRunner only covers scalar case. Carrier-split question surfaced.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(r3): DispatchInput.default → carrier-split-blocked class (workflow_dispatch is literal-only per GH context table) — operator BLOCKING :369

GH context-availability marks only on.workflow_call.inputs.<id>.default as expression-capable; on.workflow_dispatch.inputs.<id>.default is literal-only. Migrating the shared DispatchInput.default to Expression would invent workflow_dispatch capability (P1 violation).

§5.5 table row updated: ✗ split capability; §5.5.1 adds new 'carrier-split-blocked sites (1)' class; counts now 17 string-container + 9 typed-field-HOLD + 1 enum-extension + 1 carrier-split-blocked = 28 ✓. In-scope for prereq PR: 19→18. §6 Q#5 sharpened from 'sequencing question' to 'BLOCKED until carrier-split lands'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 Job.runner audit row + §5.5.1 enum-extension class flag partial-coverage (array/object/label-element expressions unmodeled) — operator BLOCKING :345

§2 (c) ExpressionRunner covers only whole-runs-on scalar-expression case. Array form (mixed literal/expression elements) and object form (group/labels expressions) require §6 Q#6 RunsOn carrier-split. Scalar-only case stays in §7.5 ask #4 prereq PR; array/object defer to §6 Q#6 resolution.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
openai-pro REQUEST_CHANGES: §10 Q-PB0-ClusterM-Cold-Risk6 must not list #86
as both §1.8 PASSING and awaiting #85/#86 canvas ratification. Phase 1
column now marks #86 landed; disposition scopes pending Substrate work to

Co-authored-by: Cursor <cursoragent@cursor.com>
#85 only (#84 Verification tail unchanged).
briansrls added a commit that referenced this pull request May 12, 2026
…y worker brief (#2762)

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: canvas RATIFIED — §7 ratification dispositions

Director (zesty-bear-812) ratified option (c) at 2026-05-12T07:39:44Z
per PR #2751 comment (session msg_168005e1 to PM deep-wolf-155).

- Status header updated to RATIFIED
- §7 added with 4 ratification points + cascade implications:
  1. Expression sum-type at dsl/extdeps/github/actions.dag: RATIFIED
  2. Single OpaqueString variant + 🟡 YELLOW: RATIFIED
  3. Three-condition dissolution trigger: RATIFIED
  4. 5-site uniform migration: RATIFIED
- Cascade documented: cool-carp-720 (WI-2) Expression wrapping;
  stern-stag-854 (Slice 4-5) emit logic stays trivial; PR #2746 can
  reference ratified Expression substrate

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: site-count correction — 5→7 expression sites in actions.dag

Operator BLOCKING inline review on PR #2751 at :34 (briansrls
2026-05-12T07:45:24Z) flagged that actions.dag has Job.if_condition
+ RunStep.if_condition + UsesStep.if_condition (3 if_condition sites),
not 1. Same expansion applies to env: RunStep.env + UsesStep.env (2
sites), not 1.

Finding accepted. Actual migration scope is 7 sites total:
- Job.if_condition (:117)
- RunStep.if_condition (:154)
- UsesStep.if_condition (:163)
- RunnerSpec (new ExpressionRunner variant)
- ConcurrencySpec.group (:?)
- Step.with[k] (UsesStep:160)
- RunStep.env (:151) + UsesStep.env (:162)

Updates:
- §1 table: if_condition row shows 3 sites; env row shows 2 sites
- §1 narrative: "seven expression sites" with enumeration
- §2 (a/b/c) code samples: all 7 sites in option (c) sketch; Step
  carrier modeled with RunStep/UsesStep variants properly
- §3 reasoning point #1: explicit P2/P5 framing — leaving any
  if_condition/env site un-migrated creates hidden parallel authority
  (typed at one site, opaque at others) blocking P5 dissolution at
  un-migrated sites
- §5 / §6 / §7 site-count refs updated
- §7 site-count correction note: framing the expansion as
  site-count correction, NOT substrate-shape correction — ratification
  point #4's "single-authority for expression substrate" already covered
  ALL expression sites in actions.dag uniformly; 7-site scope is
  implementing-PR responsibility

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §4 dissolution target — template-string layer for extdeps fidelity

Operator BLOCKING #2 on PR #2751 at :214 (briansrls 2026-05-12T07:45:24Z):
the §4 dissolution target sketched a pure Expression AST, but GH Actions
expression-bearing scalars are template strings with alternating literal-
text and ${{...}} segments (e.g., concurrency.group:
${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}).
A pure-AST terminal shape under-models what the platform actually parses,
violating INVARIANTS.md P1 (modeling faithfulness).

Finding accepted. §4 dissolution target corrected to two-layer shape:

  Expression
    = OpaqueString(String)
    | Template(List<TemplateSegment>)

  TemplateSegment
    = TextSegment(String)
    | ExpressionSegment(ExpressionAst)

  ExpressionAst = Literal | Var | BinOp | Func | Index (etc.)

This is extdeps-faithful: mirrors the platform's actual parse structure
(template-string layer over expression-AST layer). Pure-literal /
pure-expression / mixed scalars all collapse cleanly into the segment
list.

Original sketch preserved as authoring-evolution record; corrected shape
supersedes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §6 Q#1 RESOLVED — sum form, not record (per BLOCKING at :258)

Operator BLOCKING #3 on PR #2751 at :258 (briansrls 2026-05-12T07:45:24Z):
§6 open question #1 incorrectly treated record form and one-arm sum as
equivalent. A record form (type Expression { value: String }) does NOT
preserve:
- Single-arm pattern-match property on consumers (record access
  projects to .value as String; no tag to match)
- Single-edit second-variant dissolution path (record → sum is a
  carrier-shape change, not a one-line declaration edit; every
  consumer must be rewritten to switch from .value access to
  pattern-match)

This breaks Practice 4 (coproduct dissolution) and P5 (Progress Is
Dissolution) — the dissolution receipt the YELLOW classification
relies on assumes the dissolution is cheap; record form makes it
expensive.

Q#1 resolved inline: Expression lands as a one-arm sum
(type Expression = OpaqueString(String)), NOT a record. This was
implied by §3 reasoning point #4 ("Pre-empts the type-alias trap")
which applies equally to record-form aliases, but the §6 framing
treated both as admissible — corrected.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: add CI workflow emitter-dispatch canvas (#2746)

* docs: add CI workflow emitter-dispatch canvas

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs: align workflow emitter canvas with substrate comparison

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs: keep InlineGunbc out of initial target enum

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs(r3): §1.8 acceptance-aggregator pattern scaffold (pilot) (#2748)

* docs(r3): expand R3 lanes to 12 + lens-framework invariant + analysis findings

User directive 2026-04-30: "nothing can be deferred past R3 - we have to
readjust R3 if something is missing." PM-driven audit + Director ratification.

R3 lane expansion (10 → 12):
- T-V2-Retirement (NEW; PB Manager continuation): src/v2/ retirement
  cascades from T-FixedPoint + T-LensProducer-Retirement; structurally
  cheap to pull in. Gates: v2_oracle_no_remaining_test_consumers +
  v2_directory_deleted.
- T-Free-Consequences-Demonstration (NEW; Verification Manager): 10-gate
  TestClaim suite operationalizing thesis "free consequences" framing.
  Auto-parallelism + auto-memoization + cross-target opt + space-bound CX.
  Loop-iteration parallelism: sequential default + opt-in via
  Lens<Iteration-Independence> (zero-heuristic; same shape as
  Lens<Bind-Independence>).

Priority corrections folded into existing lanes (no new lanes):
- C1 (T-Tier3-Dissolution sub-gate): tier3_mirror_dissolution_perf_within_budget
  with thresholds <=2x median, <=5x p99 (cargo bench fixtures per retired
  mirror).
- C2 (Substrate continuation, T-Anthropic-Wire scope expansion):
  ProviderTypedWire<P> carrier extracted IN R3 (path (a) commit; drops the
  prior 6-month elapsed-time check exactly per user directive).

design-lens-framework.md amendment:
- Lens.read MUST depend only on (Node, Behavior) pair, not external state.
- Locks memoizable shape; runtime memoization becomes auto-memoization free
  consequence instance (T-Free-Consequences-Demonstration).

ROADMAP.md additions (### Post-merge debt (2026-04-30 analyses)):
- 4 novel findings from paired exploratory + reflective analyses
  (gpt-5-5-pro 991114f / gpt-5-5-thinking ad016c5):
  * Duplicate record-literal fields silently dropped (highest-value bug)
  * ValueBody Rust<->.dag mirror drift; no isomorphism gate
  * FieldMap duplicate-free invariant lost in .dag mirror
  * Operator inference fabricates (T,T)->T for non-algebra LHS
- 8 reflective-analysis priority corrections folded into R3 trajectory
- 2 stale rows marked RESOLVED (repeat_string + lower_fn_body re-derive)

Routed to R3 Mgrs via inbox dispatches (#1130 / #1131 / #1133 / #1276 / #846).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): reframe Rust<->.dag isomorphism as producer-first

cool-crab-614 PR #1324 research reframed the proposal: missing substrate
is a reflected-Dag query/report PRODUCER (Lens<DagShapeReport>), not a
new predicate variant. RustDagIsomorphism becomes a CONSUMER (TestClaim
comparing two DagShapeReport outputs via BinaryDimensionReportEquals),
eliminating parallel-authority risk.

Reflection-aware modifiers for unified BinaryDimensionReportEquals now
cover 4 surfaces: TC1 eta-equivalence + TC2 strategy-order + TC3
evaluation-step + shape-report (reflected-Dag query).

Single substrate-introduction; multiple consumers via reflection-aware
modifiers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): fix lower_fn_body row citation per #1319 review

PR #1319 review (cursor 9d2dffb) flagged that the RESOLVED note cited
`src/v3/compiler/src/lower.rs:61670-61688` but lower.rs is only 7919
lines. Original line citations referenced the analysis snapshot's
aggregate-numbering scheme, not live file.

Verified live state: `lower_fn_body_into_existing_decl` symbol does NOT
exist in current lower.rs; equivalent path is `lower_fn_item_expr_body`
(:4410+); non-Arrow arm at :4433-4451 reports
`Diagnostic::ResolveError` with explicit invariant-violation message
("violated lowering invariant: seed_function_signatures_phase did not
produce an Arrow connective for this Fn") and returns outer_scope.
That IS the fail-closed shape the original row asked for; resolution
note now correctly cites live behavior.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): resolve v2-retirement contradiction per #1319 review

PR #1319 review (codex a9a9894) flagged contradiction: T-V2-Retirement
added as R3 lane (line 100) but Compromises table (line 165) still
listed v2 retirement as Post-R3 operational cleanup. INVARIANTS P1
"Documentation Describes Live State" violation.

Fix: strikethrough the post-R3 entry; explicitly note migration into
R3 as T-V2-Retirement lane per 2026-04-30 user directive "nothing can
be deferred past R3." Single authoritative placement; cross-link to
Lane structure §11.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* docs(r3): aggregator pattern — coercion table + precondition + exclusion rules

Addresses BLOCKING #2748 (briansrls inline at L71): live §1.8 uses 7 status
values, not 3 (PASSING, SATISFIED-BY-CONSTRUCTION, CONSUMER_LANDED, DECLARED,
R3-LOAD-BEARING, HELD-CANVAS-DEFERRED, DEFERRED). The 3-value lattice meet
was not machine-checkable as written.

- Coercion table: SATISFIED-BY-CONSTRUCTION → PASSING; INTEGRATION_RECEIPT
  partial-slice → CONSUMER_LANDED; identity for the 3 lattice values.
- Precondition rule: bare R3-LOAD-BEARING is scope-metadata, not closure
  progress; constituents with that status are not aggregator-ready until
  cell inlines closure-progress (e.g., 'R3-LOAD-BEARING — DECLARED').
- Exclusion rule: DEFERRED + HELD-CANVAS-DEFERRED MUST NOT appear in any
  aggregator's depends_on: per §1.5 honest-close arithmetic.
- Cluster F candidate reframed: NOT aggregator-ready at HEAD because rows
  #81/#82/#83/#95 carry bare R3-LOAD-BEARING; precondition fix required
  before pilot. Cluster M / K / V2-Retirement candidates similarly subject
  to precondition check at pilot time.
- Invariants P2 cleanliness note: coercion table + precondition + exclusion
  are themselves a single derivation authority; no parallel authority for
  closure progress.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): cascade ci_yml_deleted → ci_yml_hand_authority_dissolved rename

Per PM cascade (PR #2744 commit 19a1d8d absorbing briansrls BLOCKING
on line 32): file artifact presence is orthogonal to hand-authority
dissolution. YamlStatic / BinaryShim / PythonShim all require some
.github/workflows/ci.yml for GH Actions trigger discovery; P5 / Pure
Bootstrap dissolves authority, not file presence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): relocate aggregator pattern from §1.8 to §1.9 per codex P2 finding

Addresses codex REQUEST_CHANGES /api/reviews/9982 on PR #2748: putting
aggregator rows directly in §1.8 alongside their constituents violated
INVARIANTS P2 single-authority — even with "derived not hand-set" prose,
the row shape didn't structurally prevent treatment as a closure
obligation, and the side-taxonomy of "does not participate in §1.7
corpus rules" was a P2 boundary-discipline violation inside the
canonical ledger.

Restructured:
- Aggregators relocated to a NEW §1.9 section (separate table)
- Distinct ID namespace: V1, V2, ... (NOT numeric §1.8 row IDs)
- Different table columns (View ID / View Name / Cluster Lane /
  depends_on: / Derived Status / Notes) to make visual distinction
  obvious
- depends_on: references §1.8 row #s by foreign-key style
- Derived Status rendered as <DERIVED> in committed text; never stored
  as snapshot (per feedback_no_snapshot_integers_in_briefs)
- §1.8 "97 enumerated / 96 R3-load-bearing" arithmetic preserved
  unchanged; §1.9 entries do not appear in that arithmetic
- Coercion table + precondition + exclusion rules carried forward
- Cluster F precondition catch (rows #81/#82/#83/#95 carry bare
  R3-LOAD-BEARING) preserved

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): annotate R4-carve citation with supersession marker

Fixes CI failure on PR #2748: scripts/check-r4-carve-dissolution-discipline.sh
flagged the coercion-table row for R3-LOAD-BEARING which mentioned 'R4-carved'
without a supersession annotation. Reframed to cite carve-promotion-IN-R3
2026-05-09 + DISSOLVED status per Director ratification gunbc#846.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): correct #83 characterization + add filename note

Per cursor APPROVE_WITH_COMMENTS /api/reviews/10000 on PR #2748:

- Row #83 (lens_capability_register_zero_proxy_zero_stub) was incorrectly
  listed alongside #81/#82/#95 as carrying "bare R3-LOAD-BEARING". The
  authoritative ledger has #83 reading "DECLARED — full scope IN R3
  (carve-promotion-IN-R3 2026-05-09)", which inlines closure-progress
  alongside scope-metadata and already coerces to DECLARED under the
  precondition rule. Reframed #83 as a positive counter-example showing
  the inline-pattern #81/#82/#95 still need to adopt.

- Added top-of-doc filename note explaining the §1.8 vs §1.9 mismatch:
  filename retained for review-thread anchor stability; substantive
  section is §1.9.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add sunset condition for aggregator pattern pilot doc

Per cursor /api/reviews/10013 optional tighten: PILOT scaffold needs a
single checkable sunset to satisfy P5 scaffold-posture discipline.
Sunset: doc retires when docs/r3-program-plan.md contains §1.9 per the
specified table shape AND at least one §1.9 view entry is live in the
ledger.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add composite-status coercion rule (CONSUMER_LANDED + PASSING)

Addresses briansrls BLOCKING inline at L66 on PR #2748: coercion table
omitted live §1.8 composite forms like 'CONSUMER_LANDED + PASSING'
(~25 instances in the ledger, including candidate Cluster M constituent
#86 program_generator_carrier_landed).

Added:
- Explicit row for 'CONSUMER_LANDED + PASSING' → PASSING
- General composite rule '<earlier> + <later>' → coerce to <later>
  (rightmost component; conjunction-of-progression-stages semantics);
  covers future composite forms not enumerated.

This makes #86 view-ready under the precondition rule (coerces cleanly
to PASSING).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag) (#2747)

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* docs: add CI workflow emitter-dispatch canvas

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs: add T-CI-WAD slice 4 skeleton

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs: clarify T-CI-WAD projection sketch

* docs: align T-CI-WAD prep with c-refined shape

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs(r3): T-WAD substrate-shape comparison canvas — gate #56 (#2749)

* docs(r3): flip §1.8 #85 forall_exists_quantifier_substrate_landed to CONSUMER_LANDED + PASSING

PR #2647 (vivid-dove-106 / Cluster M Phase 1a) merged carriers into src/v3/std/verification.dag at HEAD; ledger row was drifted DECLARED. Per post-merge ledger-receipt sync discipline (Director-ratified at gunbc#828 c#4415884211).

Caught by Debt-Paydown PM ledger-sync check — thanks silent-ram-834.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): downgrade §1.8 #85 to DECLARED per codex BLOCKING + row #17 precedent

Prior CONSUMER_LANDED + PASSING flip overstated the gate per INVARIANTS §P2 strict reading: carriers + hand-written ratchet ≠ generated consumer proof. Mirrors row #17 (numeric_abstract_carriers_landed) shape: carrier substrate landed, hand-written ratchet noted, CONSUMER_LANDED deferred to generated consumer + SuiteClaim wrapper migration + V Mgr #87 runner consumer.

Sibling row #86 carries same overclaim risk via PR #2645 precedent — separate amendment if Director rules.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: T-WAD substrate-shape comparison canvas (gate #56)

Mgr-tier comparison canvas surfacing three substrate-shape options for
gate #56 ci_workflow_modeled_as_dag under FULL R3-close elevation:

- (a) PR #2736 provider-neutral CIWorkflowDag (semantic-only)
- (b) WI-1 PR #2746 actions.dag-concrete + EmissionTarget? (transport-only)
- (c) Hybrid — CIWorkflowDag as semantic source + Workflow.emission_target
  as transport-artifact selector + projection function project_github_actions:
  CIWorkflowDag -> Workflow as the structural fold connecting them

§0 grep-verifies PR #2736 body claim ("hand-authored GitHub Actions transport
copy was removed") against actual diff: actions.dag Workflow/Job/Step
carriers at :21/:110/:147 intact; PR adds CIWorkflowDag without removing
actions.dag carriers, leaving dual-authority unresolved at HEAD.

§5 recommends option (c) for Director ratification on:
- single-authority per concept layer (gate-dependency at gunbc.ci;
  transport at extdeps.github.actions) per MODELING.md M9
- decoupled cost-of-change axes (new provider vs new emission target)
- preserves both already-authored PRs' substrate contributions
- aligns with docs/design-emission-model.md single-emitter discipline

Authority: PM relay msg_a945b141 (deep-wolf-155) routing Director
msg_34e9a381 substrate-shape question per
feedback_substrate_shape_belongs_in_mgr_canvas.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7 addendum — INVARIANTS P1 reframes (c) to (c-refined)

BLOCKING inline review on PR #2746 (briansrls c#4427988541) flagged
that adding EmissionTarget to dsl/extdeps/github/actions.dag puts a
gunbc emission-policy fact into the GitHub Actions platform model,
violating extdeps fidelity and INVARIANTS P1.

§7 accepts the finding (structurally correct per actions.dag header
:1-12 platform-vs-CI-logic discriminator), disqualifies §1 option (b)
as-authored, partially invalidates §1 option (c) as-authored (the
two-layer concept-layering argument STILL holds; only the EmissionTarget
placement on extdeps fails P1).

§7.3 surfaces option (c-refined): EmissionTarget lives in gunbc/ci.dag
as a sum type + parameter to project_github_actions(ci_workflow_dag,
target) -> Workflow. extdeps.github.actions.Workflow is unmodified.
Pinned Workflow values for emission validation live in gunbc namespace.

§7.5 revises ratification asks: PR #2746 disposition shifts from
"framing-narrowing" to substantive substrate retraction on the field-
placement decision (sum-type shape stands; placement relocates).

§7.6 distinguishes (c-refined) from PM-proposed alternatives:
- not PM(b) [EmissionTarget on CIPipeline] — same M9 join-cost as
  PR #2746 §3 Option B
- not PM(c) [WorkflowEmission wrapper] — same sibling-decision cost
  PR #2746 §3 Option C already rejected
(c-refined) expresses emission-target choice at the projection
invocation (per docs/design-emission-model.md: emission is structural
projection, choice is property of the call not the value).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §8 retraction — derive Workflow from projection, not separate authority

codex REQUEST_CHANGES on PR #2749 (review 9970) flagged that option (c)
as authored proposed both a projection function CIWorkflowDag -> Workflow
AND a separately hand-declared Workflow value the emitter "validates
against" as a pinned target — INVARIANTS P2 / modeling-discipline.md
Practice 5 dual-authority condition.

Finding accepted. §8 retracts the pinned-Workflow-as-modeled-authority
framing; in-place edits applied to §1 (option (c) intro), §4 (S0
sequencing), §5 (ratification ask #5), §7.3 (WI-2 placement), §7.5
(revised recommendation).

Replacement framing: the only Workflow value in modeled authority is
the projection function output, structurally derived from a single
source. WI-2's gunbc_ci_yml_workflow becomes a name binding to the
derived result (data gunbc_ci_yml_workflow: Workflow =
project_github_actions(ci_workflow_dag, YamlStatic)), not an
independent declaration. Byte-level regression fixtures live in
tests/, not dsl/, and are not part of modeled authority.

Layering argument unchanged: gate-dependency at gunbc.ci.CIWorkflowDag;
platform transport at extdeps.github.actions.Workflow (unmodified);
emission policy in gunbc namespace; artifact derived from single source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: cite feedback_extdeps_header_discriminator_before_field_placement

Per PM relay msg_72e2ab50: Director memorialized actions.dag:1-12
discriminator rule as feedback_extdeps_header_discriminator_before_field_placement.
Add citation in §7's discriminator block for audit trail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: cite P2 (Boundary Discipline) not P1 for single-authority

gpt-5.5-pro APPROVE_WITH_COMMENTS review 9972 caught that the
single-authority / "every fact lives in exactly one place" principle
is INVARIANTS.md P2 Boundary Discipline, not P1. P1 is Modeling
Faithfulness.

Operator BLOCKING quote at §7 invoked "P1" verbatim; both principles
are in play:
- P2 because emission-policy authority must live in exactly one place
  (gunbc/ci.dag), not split across extdeps and gunbc
- P1 because placing gunbc-policy state on an extdeps carrier makes
  the carrier no longer faithful to its header's "platform facts
  only" claim

§7.1 prose updated to explicitly distinguish the two principles and
note that subsequent single-authority references cite P2.
§7.4 table row relabeled "INVARIANTS P2 (Boundary Discipline / single
authority)".
§7.5 ratification ask #2 cites P2 + P1.
§7 heading updated to "INVARIANTS P2/P1 BLOCKING reframes (c)".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: classify EmissionTarget coproduct per Practice 4 (§7.3.1)

BLOCKING inline review on PR #2749 at line :573 (briansrls
2026-05-12T07:04:15Z): proposed EmissionTarget 4-variant coproduct
landed without 🟢/🟡/🔴 dissolution classification, violating
modeling-discipline.md Practice 4 (coproduct dissolution).

Finding accepted. §7.3.1 added classifying EmissionTarget as
🟡 YELLOW (scaffold) with full reasoning across all four dissolution
patterns:
- Pattern 1 (fact placement): N/A — empty payloads
- Pattern 2 (variant-is-data): blocked by closed-set guardrail
- Pattern 3 (algebraic form): N/A — not std/ algebraic operations
- Pattern 4 (dimensional): live dissolution path; ~2-3 axes
  (target_language, requires_shim, runtime_executes) plausible but
  not yet forced at four variants

YELLOW not GREEN: Pattern 4 plausibly works; closing the door would
be wrong. YELLOW not RED: dissolving prematurely without consumer-
side pressure risks landing wrong axes (requires_shim partially
redundant with target_language at current variants).

Named dissolution trigger (per YELLOW requirements): (a) fifth
target landing that breaks the four-way axis, OR (b) consumer needing
single-dimension pattern-match, OR (c) Slice 4/5 implementation
surfacing an unpredicted axis. Any forces dimensional record shape.

Ledger note: classification is canvas-level; implementing PR (WI-2
re-brief per §5/§7.5 ask #4) MUST carry the same classification +
trigger as a // 🟡 YELLOW (scaffold) comment on the type declaration
citing this canvas §7.3.1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: canvas RATIFIED — §9 ratification dispositions

Director (zesty-bear-812) ratified option (c-refined) at
2026-05-12T07:04:18Z per PR #2749 comment (session msg_4f7f536d
to PM deep-wolf-155). Updates:

- Status header changed to RATIFIED with ratification authority
  citation
- §9 added with all 5 ratification asks dispositioned:
  - (c-refined) substrate-shape: RATIFIED
  - PR #2746: AMEND (4 specific changes for still-heron-763)
  - PR #2736 body: SATISFIED prior
  - PR #2745 WI-2: SCOPE EXPANSION APPROVED, PM authors re-brief
  - S1 projection function: NEW §1.8 GATE (project_github_actions_landed,
    substrate-shape family); aggregator pilot row #56+4→#56+5
- Downstream cascade documented per Director directive

Director attributed feedback_extdeps_header_discriminator_before_field_placement
discipline rule to the §7+§8 self-correction trajectory.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: inline SUPERSEDED banners on §1(c)/§2.3/§3/§4/§5

codex BLOCKING review 9986 at sha 38c28cd flagged that §2.3/§3/§5
still contain the now-overturned option-(c)-as-authored framing
(EmissionTarget on extdeps.Workflow + hand-declared pinned Workflow).
For a RATIFIED canvas, leaving those sections unmarked materially
states the wrong substrate shape — readers would have to read through
to §7/§8/§9 to discover the supersession.

Finding accepted. Inline SUPERSEDED banners added at the top of:
- §1 Option (c) sub-section: points to §7.3/§7.4/§8/§9 for current shape
- §2.3 Option (c) evaluation: flags the "emission validates declared
  Workflow against projection" sentence as the dual-authority condition
  §8 retracts
- §3 WI-1 assumption-breakage: OVERTURNED bullets explicitly listed
  (placement, "Workflow chooses target" framing, framing-narrowing
  disposition)
- §4 Slice sequencing under (c): SUPERSEDED in part — structure
  remains valid under (c-refined); placement-specific descriptions
  overturned by §7/§8; WI-2 scope larger than §5.4 implied per §9 ask #4
- §5 Recommendation: all three positions (extdeps placement,
  framing-narrowing PR #2746 disposition, pinned-Workflow validation
  target) OVERTURNED; current recommendation is (c-refined) per §7.5+§9

Earlier framings preserved as canvas-evolution record (showing
self-correction trajectory through §7+§8), but each affected section
now flags its own superseded status without requiring a full-doc read.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §6 Q#2 RESOLVED banner — overturned superseded Workflow framing

cursor APPROVE_WITH_COMMENTS review 10001 (non-blocking) noted that §6
open question #2 still partly explained the projected signature via
"PR #2746 places the field on Workflow", which contradicts §7.3
(c-refined) where extdeps.github.actions.Workflow is frozen unmodified.

Fix: add inline RESOLVED banner at §6 head pointing to §7.3 + §9; rewrite
Q#2 entry to flag the superseded framing inline — the parametric
signature was the right answer regardless of placement, but the rationale
over-attributed to a placement that no longer stands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: inline 🟡 YELLOW checkpoint at §7.3 EmissionTarget declaration

Operator BLOCKING inline review on PR #2749 at :657 (briansrls
2026-05-12T07:58:34Z): the §7.3 code block declaring type
EmissionTarget lacked the inline 🟢/🟡/🔴 classification annotation
required by modeling-discipline.md Practice 4 "any new enum with
N ≥ 2 variants must have a checkpoint comment naming its classification."

The classification reasoning exists in §7.3.1 prose section, but the
declaration site itself was missing the checkpoint comment, which is
the form Practice 4 requires.

Fix: add inline 🟡 YELLOW (scaffold) comment block above the type
declaration citing §7.3.1 for full reasoning + the three-condition
dissolution trigger + likely Pattern 4 dissolution path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7.3.2 Shape A/B clarification — EmissionTarget names realization modes

Operator BLOCKING inline review on PR #2749 at :657 (briansrls
2026-05-12T07:58:35Z): YamlStatic variant of EmissionTarget would
"make a Shape B CI YAML artifact mode an emission target despite
THESIS Shape A/B requiring YAML artifacts to be generated by .dag
user programs, not compiler emission targets."

Per THESIS:215-216, Shape A = compiler language targets (compiler
emits directly); Shape B = user-program artifacts (YAML, Terraform,
K8s, etc. — emitted by .dag programs walking typed values, NOT
compiler render targets). YAML for ci.yml is Shape B; gunbc
doesn't have a YAML emission target.

Finding accepted as naming-and-framing concern, not substrate-shape
concern. Added §7.3.2 clarifying:

- EmissionTarget names a REALIZATION MODE selector, not a parallel
  compiler emission target
- YamlStatic = Shape B (.dag program renders YAML from Workflow)
- BinaryShim = Shape A binary + Shape B YAML shim wrapper
- PythonShim = Shape A Python + Shape B YAML shim wrapper
- InlineGunbc = Shape A (gunbc runtime as host)

No substrate retraction: variants, YELLOW classification, dissolution
trigger, gunbc-namespace placement, parametric signature all stand.
Naming consideration noted (WorkflowRealizationMode would carry less
Shape-A baggage), but renaming forces re-ratification without
corresponding substrate change — keep name, document the mapping at
declaration site per §7.5 ask #4 implementation PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: fix §9 ask #5 slice/gate name — Slice 8 ci_yml_dissolved, not Slice 5 ci_yml_deleted

gpt-5.5-pro REQUEST_CHANGES on PR #2749 sha f5b57e7 (review 10037)
caught that §9 ratification ask #5 wrote the projection-function gate
as "discrete from Slice 5 (ci_yml_deleted, state-check)", but per the
canvas's own §1 (Director-ratified gate-set) and §4 Slice sequencing:
- Slice 5 = BinaryShim emitter (workflow_emission_target_toggle_proven)
- Slice 8 = ci.yml dissolution (gate name: ci_yml_dissolved)

The conflation could mislead workers updating PR #2748 to wire the new
project_github_actions_landed gate against the wrong slice/gate.

Fix: §9 ask #5 now reads "discrete from Slice 8 ci_yml_dissolved",
matching the canvas's earlier authoritative gate-set + §4 sequencing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: §5.5 inventory audit — 7→22 expression-capable fields

codex BLOCKING (review on sha 4f41aeb) + operator BLOCKING inline at
:315 (2026-05-12 ~09:12Z): site inventory was keyed to ci.yml examples
not actions.dag schema + GH Actions context-availability docs.
Under-modeling the platform expression-capable surface by ~15 sites.

Finding accepted as substantive scope correction. Added §5.5 with
full audit table against actions.dag HEAD + GH Actions docs:

Total expression-capable surface: 22 fields across Workflow / Job /
RunStep / UsesStep / ConcurrencySpec / RunnerSpec. The 7-site
enumeration was the ci.yml-keyed minimum subset; the
actions.dag-keyed audit extends to 22.

§5.5.1 sets migration rule: ALL expression-capable fields migrate
uniformly under (c). Per-field opt-in produces hidden parallel
authority (P2/P5 violation). Implementing PR audits against actions.dag
HEAD + GH Actions context-availability docs and migrates any
additional sites surfaced.

§5.5.2 surfaces typed-field expression semantics as new substantive
question (§6 Q#4) — timeout_minutes/continue_on_error/cancel_in_progress
are typed fields where GH Actions string-coerces expressions. Three
candidate shapes (wrap / TypedOrExpression sum / defer); Director-tier
choice.

§5.5.3 retains §1/§2 7-site framing as ci.yml-keyed reference;
substrate-shape ratification covers expanded 22-site scope per §5.5.1
migration rule.

§6 Q#2 sequencing updated to "22 expression-capable fields"; new Q#4
adds typed-field semantics question.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: update PR #2749 cross-link — EmissionTarget → WorkflowRuntime

Per PR #2749 commit 575eb7e (rename EmissionTarget → WorkflowRuntime
to resolve P2 name-collision with src/v3/SELF_HOSTING.md:609 Shape-A
EmissionTarget), update the single cross-reference in §7 here to match
the new name. Substantive content unchanged — orthogonal-axes argument
still holds.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §5.5.1 — split 22 sites into 13 string + 7 typed-field + 2 enum-ext

codex REQUEST_CHANGES on PR #2751 review 10083 (sha presumably 0cc2c28e
or 28d503c): §5.5.1 said "ALL 22 expression-capable fields migrate to
Expression" but §5.5.2 / §6 Q#4 left typed-field shape (Int?/Bool sites)
as an open Director-tier question. Implementer following §5.5.1 would
author the wrap-to-Expression shape immediately while §5.5.2 says hold.

Finding accepted. §5.5.1 split into three classes:

- 13 string-typed sites — uniform String→Expression migration, in scope
  for §7.5 ask #4 prereq PR
- 7 typed-field sites (timeout_minutes/continue_on_error/
  cancel_in_progress) — HOLD until §6 Q#4 ratifies wrap/sum/defer
- 2 enum-extension sites (RunnerSpec, UsesStep.uses) — new variant
  added to existing sum/struct, in scope for §7.5 ask #4 prereq PR

In-scope for substrate-prereq PR: 13 + 2 = 15 sites. Out-of-scope
(deferred): 7 typed-field sites.

§5.5.1 now non-contradictory with §5.5.2 / §6 Q#4: implementer reading
§5.5.1 migrates 15 sites; the 7 typed-field sites explicitly HOLD with
a named trigger (§6 Q#4 ratification).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §5.5 inventory expansion — add Workflow.name + Job.name (22→24 sites)

Operator BLOCKING on PR #2751 at :365 (briansrls 2026-05-12T10:12:15Z):
the string-typed migration class omitted Job.name: String?; GH Actions
context-availability table lists jobs.<job_id>.name as expression-capable.
Same applies to Workflow.name (workflow name supports expressions).

Audit gap fixed. §5.5 table adds:
- Workflow.name: String (:22) — string-typed expression-capable
- Job.name: String? (:112) — string-typed expression-capable

Counts updated:
- Total expression-capable: 22 → 24 sites
- String-typed class: 13 → 15 sites
- In-scope for prereq PR: 15 → 17 sites (15 string + 2 enum-extension)
- Out-of-scope (typed-field HOLD): 7 sites (unchanged)
- Under-modeling delta: 15 → 17 sites (ci.yml-keyed 7-site enumeration
  missed 17 sites in actions.dag schema)

§5.5.1 enumerated list of string-typed sites adds Workflow.name + Job.name.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: §5.5 — remove UsesStep.uses (literal-only per GH workflow-syntax)

Operator BLOCKING on PR #2751 at :381 (briansrls 2026-05-12T10:12:15Z):
classifying UsesStep.uses as expression-capable invents platform
capability — GH Actions workflow-syntax treats uses: as a literal
action location; the context-availability table does NOT list
jobs.<job_id>.steps.uses. Modeling it as expression-capable would
violate INVARIANTS.md P1 modeling faithfulness.

Verified against GH Actions docs (workflow-syntax + context-availability):
uses: is a literal action ref resolved before workflow expressions
evaluate.

Finding accepted. Removed UsesStep.uses from §5.5 inventory + struck out
the row + removed planned ExpressionActionRef variant from
enum-extension class.

Counts updated:
- Total: 24 → 23 sites
- Enum-extension class: 2 → 1 site (RunnerSpec only)
- In-scope for prereq PR: 17 → 16 sites (15 string + 1 enum-ext)
- Under-modeling delta: 17 → 16 sites
- Typed-field HOLD class: 7 sites (unchanged)

§5.5.1 enum-extension block now explains why UsesStep.uses was
removed for audit trail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7 ratification ask #4 — reflect §5.5 expanded scope (16 in-scope, 7 HOLD)

Operator BLOCKING on PR #2751 at :543 (briansrls 2026-05-12T10:12:15Z):
§7 ratification dispositions still referenced the 7-site enumeration from
the original ratification framing, while §5.5 expanded the audit to
23 sites. Downstream implementation reading only §7 would preserve
opaque-string authorities at the non-§7-enumerated sites — P2/P5
violation by structural drift.

Fix: §7 ratification point #4 rewritten to cite §5.5 audit set + 16
in-scope sites + 7 typed-field HOLD class with named trigger.

Site-count correction note expanded from single-event to cumulative
correction sequence documenting all 4 BLOCKING-driven expansions
(5→7→22→24→23). Audit trail preserved; the (c) substrate-shape
ratification covers all 23 expression-capable sites uniformly per
"single-authority for expression substrate" principle — implementing
PR migrates 16 immediately, 7 typed-field sequenced post §6 Q#4
ratification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 expand to MatrixStrategy carriers (23→28 sites; audit-methodology note per codex review 10128)

Cross-product of GH context-availability table × actions.dag carriers adds
MatrixStrategy.{dimensions,include,exclude,fail_fast,max_parallel}.
Updated counts: 28 total / 18 string-typed / 9 typed-field / 1 enum-ext;
19 in-scope for prereq PR, 9 HOLD for §6 Q#4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 remove Workflow.name (literal-only per GH context-availability; run-name is expression-capable key and not currently a Workflow field) — operator BLOCKING :274

28→27 total, 18→17 string-typed, 19→18 in-scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 add DispatchInput.default (operator BLOCKING :298) — workflow_call/workflow_dispatch input defaults per GH context-availability

27→28 total, 17→18 string-typed, 18→19 in-scope. MatrixStrategy already present per commit 9c1f0a1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): status-block migration scope = 19 in-scope + 9 HOLD (was '5 sites uniform') — operator BLOCKING :7

Aligns top-of-file status with §5.5 / §7 ratified scope: 28 total / 18 string-typed + 1 enum-ext = 19 in-scope for prereq PR / 9 typed-field HOLD on §6 Q#4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5.1/§7/audit-trail count reconciliation (28/18/19/9) — cursor review 10134

Sweep stale internal counts: 23→28 site totals, 15→17 string-typed in audit blockquote, 5→9 typed-field, 16+7→19+9 deferred. Added correction step 5 to audit trail covering MatrixStrategy + DispatchInput.default additions and Workflow.name removal. Aligns §5.5.1, §5.5 audit-trail blockquote, §7.5 ask #4 with §5.5 audit totals.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix 'seven sites-already-migrated' (→19) + P5/modeling-discipline citation drift — cursor review 10145

:146 + :231-233: dissolution-cost wording updated from pre-§5.5 '7 sites' to post-audit '19 sites + 9 typed-field once §6 Q#4 resolves'.
:289-291: scaffold-arm sunset-milestone citation moved from INVARIANTS P5 (which mandates checkable dissolution trigger) to modeling-discipline.md Practice 4 (home of the scaffold-comment convention).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5.1 derivation discipline + add MatrixStrategy carriers to class lists; §6 Q#5 (DispatchInput carrier-split) + Q#6 (RunnerSpec runs-on grammar) — codex BLOCKING 10150

(1) §5.5.1 lists now explicitly enumerate MatrixStrategy carriers per class: dimensions/include/exclude in string-container (18 total), fail_fast/max_parallel in typed-field HOLD (9 total). Added explicit derivation-from-§5.5-table discipline note. Cross-check 18+9+1=28 ✓.

(2) §6 Q#5: shared DispatchInput collapses workflow_call vs workflow_dispatch expression-context-availability axes; carrier-split question surfaced (Director-tier sequencing relative to Slice 4 prereq PR).

(3) §6 Q#6: RunnerSpec under-models runs-on grammar (scalar/array/object + expressions at multiple positions); §2 (c) ExpressionRunner only covers scalar case. Carrier-split question surfaced.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(r3): DispatchInput.default → carrier-split-blocked class (workflow_dispatch is literal-only per GH context table) — operator BLOCKING :369

GH context-availability marks only on.workflow_call.inputs.<id>.default as expression-capable; on.workflow_dispatch.inputs.<id>.default is literal-only. Migrating the shared DispatchInput.default to Expression would invent workflow_dispatch capability (P1 violation).

§5.5 table row updated: ✗ split capability; §5.5.1 adds new 'carrier-split-blocked sites (1)' class; counts now 17 string-container + 9 typed-field-HOLD + 1 enum-extension + 1 carrier-split-blocked = 28 ✓. In-scope for prereq PR: 19→18. §6 Q#5 sharpened from 'sequencing question' to 'BLOCKED until carrier-split lands'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 Job.runner audit row + §5.5.1 enum-extension class flag partial-coverage (array/object/label-element expressions unmodeled) — operator BLOCKING :345

§2 (c) ExpressionRunner covers only whole-runs-on scalar-expression case. Array form (mixed literal/expression elements) and object form (group/labels expressions) require §6 Q#6 RunsOn carrier-split. Scalar-only case stays in §7.5 ask #4 prereq PR; array/object defer to §6 Q#6 resolution.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): tighten Slice 4 brief P2/P3 single-authority bar + carrier-gap STOP condition — codex BLOCKING review 10208

(1) Workflow field derivation: replace 'CIWorkflowDag content + structural defaults' with strict single-authority requirement; STOP authoring if any field lacks an input-domain source. No fabricated values, no second source of truth. P2/P3 bar made explicit per INVARIANTS + modeling-discipline Practices 3 + 5.

(2) Carrier-gap encounter: STOP condition for this PR (not side-channel-while-continuing). Worker must wait for warm-wolf-698 resolution (substrate-prereq PR / out-of-scope narrowing / brief revision) before resuming. Continuing with a gap = fabricated authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): correct PythonShim ratification — 3 initial arms (YamlStatic + BinaryShim + PythonShim) per emitter-dispatch canvas; only InlineGunbc is DESIGN-ONLY — operator BLOCKING PR #2768 :33

Earlier brief commit 4d40d3b erroneously demoted PythonShim to DESIGN-ONLY. Verified against origin/main:docs/design-ci-workflow-emitter-dispatch.md:126 — ratified shape is `WorkflowRuntime = YamlStatic | BinaryShim | PythonShim` with projection calls + acceptance semantics; only InlineGunbc is design-only pending real runtime consumer (canvas §5.4). Phase B updates Phase A enum + dissolution-trigger comment + Phase B BinaryShim+PythonShim stub note + reference list.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): replace RunStep.* / UsesStep.* glob with exact 17-site enumeration — operator BLOCKING PR #2768 :70

Glob shorthand was incorrectly broader than the §5.5.1 string-container set; would pull in UsesStep.uses (literal-only) + *.timeout_minutes/*.continue_on_error (typed HOLD). Now exact enumeration: Workflow.env (1) + Job.name/if_condition/env/concurrency.group (4) + RunStep.{name,run,env,working_directory,if_condition} (5) + UsesStep.{name,with,env,if_condition} (4) + MatrixStrategy.{dimensions,include,exclude} (3) = 17 ✓. Excluded fields explicitly noted.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
Per operator directive 2026-05-12T~20:00Z: "define the remainder of R3
now, including all dependencies, so we can max parallelize all the work."

Comprehensive audit of §1.8 ledger:
- 102 R3-load-bearing gates total
- ~32 CLOSED (31%); ~40 IN-FLIGHT (39%); ~31 OPEN (30%)
- 2 lanes 100% done: T-Omni-Shape-B, T-Free-Consequences-Demonstration
- Standing gate #75 PASSING

Critical-path identified:
- Cluster M (T-Tests-As-Data-Completeness): gate #84 dissolves ~80-90 of
  101 SG-0 hand-Rust test entries in single closure. Phase 1 (#85/#86
  substrate) dispatch-ready NOW. Total 4-8w to full Cluster M closure.
- Cluster F (T-LP-Retirement): gates #81/#82/#83/#95 carve-promoted-IN-R3
  per Director 2026-05-09. F-α + F-β.1 parallel-dispatchable NOW.
  Total 3-4w to full Cluster F closure.

14 gates identified as dispatch-ready NOW (no prerequisite blocking).
Wave-1 dispatch plan covers 13-15 parallel workers across 3 R3 Mgrs.

Worker spawn capacity analysis:
- Substrate Mgr: 16 max, 1 active → +15 budget
- Debt-Paydown Mgr: 8 max, 0 active → +8 budget
- Verification Mgr: 8 max, 3 active → +5 budget
- Total +28 R3 spawn budget; currently at ~5; can scale 5-6x

Throughput levers ranked:
1. Land review-parser fix (eliminates per-PR PM bypass overhead)
2. Pre-author Wave-1 briefs in bulk
3. Spawn to Mgr capacity
4. Cluster M Phase 1 immediate dispatch (critical-path)
5. F-β.1 canvas immediate authoring
6. PB Mgr successor spawn (currently no active session)
7. Class-authorization batch merges (Director-ratified)

6 open Qs for operator decision.

Honest 6-8 week timeline to R3 close-ready with full Wave-1 dispatch
+ brief queue depth + parser fix landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…lans (#2775)

* docs: decomposition-algebra modeling project (DRAFT)

Operator-supplied premise: project decomposition as algebra where children sum to parent meaning; walk-back when integration contradicts construction.

This draft formalizes:
- §1 The contradiction trigger (algebraic imbalance | claim contradiction)
- §2 Types sketch (Node, Claim, Decomposition, Witness, WalkBackEvent) — gunbc-lens-style; eventual home in dsl/std/ as MeaningDecomposition lens analogous to Cost lens
- §3 Walk-back algorithm (procedure with StableAncestor | RootContested termination)
- §4 Worked example — PR #2745 misread retroactively traced through procedure (2026-05-12 PM execution error)
- §5 Dashboard comms application sketch — message-as-walk-back-signal mapping
- §6 Open questions (coefficient semantics, claim equivalence, root-asker, rebalance cost, implementation surface)
- §7 Next step: validate on N=3-5 real cases before .dag formalization

Iteration expected.

* docs: decomposition-algebra rewrite for ctrl/ migration scoping

Replaces procedural walk-back draft (d534fd4) with structural-integration
shape per operator directive 2026-05-12: migrate ctrl/ processes into .dag
substrate; algebra is authoritative, ctrl/ TS becomes projected emission.

Audit-grounded with grep-verified citations across dsl/std/ + ctrl PR refs
(#1192/#1193/#1195/#1197). Identifies 4 modeling gaps (EventLog<T> primitive,
Lens<A,B> type, bounded multiplicity, unified Witness) + workflow-types
dissolution scope (dsl/gunbc/workflow/types.dag overlaps with decomp-algebra;
proposed dissolution rather than coexistence). First-cut migration target
recommended: review-verdict-parser (today's parser-lag pain validates the
heuristic-pass cost per feedback_lenses_not_passes).

Phase 1 substrate-file skeleton (~50 lines) sketched. Cost-of-change
contract = 1 file for new Mode variants / Operation arms.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(decomp-algebra): inline §13 validation case study; drop git-history cross-ref

Addresses claude #10308 review finding: §13's pointer to "previous draft in
git history at d534fd4" was a quirk for a brand-new file (per reviewer:
harmless but worth fixing). Inlines the PR #2745 misread walk-back trace
self-contained so readers don't need to git-log to follow the validation.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: ctrl/ → .dag migration project plan (parallel program tree)

Companion to docs/design-decomposition-algebra.md. Authored per operator
directive 2026-05-12: parallel program tree beside zesty-bear-812, model
dependencies, migrate as much ctrl/ as possible ASAP.

Audit of ctrl/ via gh API identifies:
- 3 partial .dag files already in ctrl (workflows/review.dag etc.)
- ~17 TS subsystems with documented designs in scripts/session-dashboard/
- 4 in-flight algebra PRs #1192-#1197 (decomposition algebra series)
- Top-level constitutional docs (AGENTS/AUDIT/CODING/INVARIANTS/REVIEW_*/SCOPE_*/TESTING)

Plan structure:
- Phase 1: algebra substrate (dsl/std/process_algebra.dag)
- Phase 1.5: 5-8 parallel subsystem modeling PRs (doc-only, type-only)
  Items 1/3/4/5/6 can start NOW without Phase 1
- Phase 2: CLI projection to Rust binary
- Phase 3: HTTP/SQL/audit-event extdeps (R4 emission targets)
- Phase 4: ctrl/ cut-over per subsystem
- Phase 5: generalize

Proposes Ctrl-Migration Director parallel to gunbc R3-close Director;
3 Mgrs (Substrate/Subsystem-Modeling/Verification), Emission-Targets Mgr
spawned later. First-week concrete actions named.

6 open Qs for operator decision: file placement (gunbc vs ctrl), Director
shape, workflow-types dissolution scope, first migration target, ctrl PR
#1192-#1197 disposition, cross-Director coordination protocol.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): comprehensive ctrl/ subsystem catalog (16 subsystems)

Per operator directive 2026-05-12T~18:55Z: audit ALL session-dashboard
work + identify what can migrate today. Gh-API audit of gunb-ai/ctrl
identified ~21,800 TS LOC across 16 subsystems.

Key findings:
- Existing demo precedent at research/.../inbox_delivery_slice.dag proves
  the `service` + typed-functions shape works today (~90% done already)
- 237 .mjs files in scripts/session-dashboard/ organized into ~16 subsystems
- ~20 .mjs in chatgpt-reviewer/ (browser DOM walking; partial-doable now)
- 3 .mjs in api-reviewer/ (CLI backend selection)
- 3 partial .dag in workflows/ (review, branch_review, review_config)

Strategy shift: model SERVICE CONTRACTS (types + typed function signatures
+ pure helpers), not just types. Demo proves it works today.

Subsystems classified:
- 8 items independent NOW (no Phase 1 dependency) — parallel first wave
- 6 items consume Phase 1 algebra substrate — second wave
- 2 items partial-NOW (chatgpt-reviewer browser, server HTTP routes)
- ~16 PRs total for Phase 1.5 (bundled by subsystem)

Operator-resolved Qs:
- Q-A: gunbc-side placement (dsl/ctrl/*.dag)
- Q-D: review-verdict already in flight per operator

New Qs added:
- Q-G: service-contract authority claim (future vs co vs substrate)
- Q-H: per-subsystem PR cadence (bundle by subsystem, ~16 PRs total)

First-wave dispatch updated: 8 workers parallel Day 2-5; 6 more Day 6-10.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): replace-ASAP framing + parallel critical paths

Per operator directive 2026-05-12T~19:05Z: this is replacement, not
"future authority"; emission targets are critical-path parallel with
algebra substrate, not deferred. 4 Mgrs spawn Day 1 (not 3).

Changes:
- §1 Mission: replace dashboard ASAP; intent layer THIN, substrate
  rigor; compositional-modeling discipline (M9 DFS, lens-not-pass,
  cost-of-change = 1)
- §5 Program tree: orthogonal to zesty-bear-812 confirmed; 4 Mgrs
  (Substrate / Subsystem-Modeling / Emission-Targets / Verification)
  spawn together Day 1
- §6 Phase sequencing: Phase 1 + 1.5 + 3 in PARALLEL, all critical
  path. Per-subsystem cut-over fires as trio converges.
- §10 First-week actions: Emission-Targets Mgr spawns Day 1 not Day-N
- §11 Q-G RESOLVED: substrate becomes authority immediately when
  emission proves out per subsystem; no co-authority window

Three operator Qs resolved this session: A (gunbc-side), D (review-
verdict in flight), G (replace-immediately).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: address codex BLOCKING review #10331 (5 findings on PR #2775)

All 5 findings valid; substantive review, real gaps. Fixed in-place
rather than reply-without-fix.

Finding 1 — audit scope correction (LIVE V3 LENS SUBSTRATE):
prior audit scoped to dsl/std/ only; missed src/v3/std/lens.dag
(Director-locked 6-field Lens<C>) + src/v3/std/dimensions.dag:35
(Witness<Carrier> = Inhabits | Violates) + src/v3/std/coproduct_projection.dag
(Practice 4 dispatch substrate) + ~16 worked lens instances in
src/v3/lenses/. §3 mapping table corrected with these as ✓ EXISTS.

Finding 2 — workflow-types dissolution axis conflation:
§4 initial proposal conflated decomposition axis (Mode) with workflow
phase axis (IssueLifecycleStage). Corrected to preserve both as
structural coordinates (Mode × Phase product) per Practice 4 dimensional
dissolution. Phase open enum staged with dissolution trigger =
per-consumer enumeration. Until proof lands, workflow-types stay extant;
decomp-algebra co-located not replacing.

Finding 3 — Reopen/Regress operations added:
prior §6 claimed monotonicity (canCloseNode ≥ on composition) without
explicit reverse operations. Added Reopen { ReopenWitness } + Regress
{ RegressionWitness } operations with typed witness payloads. Replaced
monotonicity claim with closure-decision lattice: forward-stable subset
preserves; Reopen/Regress/Replan/Escalate explicitly retract closure
state with witnessed cause. No silent regression.

Finding 4 — staging discipline for catalog:
§3 catalog preamble corrected: every "doable NOW" row is STAGED with
explicit dissolution trigger, NOT authoritative-on-arrival. Trigger =
per-subsystem realization receipt + consumer parity (emission target
+ parity test + cut-over PR deletes TS). 🟡 STAGED until trigger fires.

Finding 5 — Practice 4 coverage widened:
§8 brief template gate 2 changed from "Practice 4 receipts on any open
enum" to "every enum/sum with ≥2 variants" (closed sums need
dissolution analysis too). Receipt format named (classification +
pattern + trigger). STOP criterion added: closed sum with no clear
dissolution pattern surfaces to Director.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(decomp-algebra): address codex inline BLOCKING — Lens/Witness parallel authority

Codex BLOCKING inline at docs/design-decomposition-algebra.md:154 + queued
companion: §5 Gap 2 proposed `Lens<S, A> { view, update }` and Gap 4
proposed `Witness { author, ... }` — both create parallel authority with
v3 substrate (Lens<C> at src/v3/std/lens.dag, Witness<C> at
src/v3/std/dimensions.dag:35).

Fixes per INVARIANTS P2 (single-authority) + MODELING.md M9 (DFS concept
DAG before defining):

1. Gap 2 RETRACTED — no new Lens carrier. State-projection in
   decomp-algebra reuses FreeMonoid<TimestampedEvent<Operation>> + fold
   (already in dsl/std/algebra.dag:390). If a future bidirectional-update
   use case surfaces, escalate to Substrate Mgr for shape audit.

2. Gap 4 RENAMED — decomp-algebra's "Witness" → "Attestation" to avoid
   name collision with v3 Witness<Carrier>. The carriers are
   structurally distinct (Attestation is human-intent attestation;
   v3 Witness<C> is per-Behavior inhabitance proof). Cascade applied:
   - Operation variants: attestation: Attestation
   - WitnessedOverride → AttestedOverride
   - ReopenWitness → ReopenAttestation
   - RegressionWitness → RegressionAttestation
   - Evidence enum → AttestationEvidence
   - StructuralLens → StructuralLensReceipt (refs v3 Lens<C> instance)
   - §7 dissolution receipt updated
   - §9 substrate skeleton updated
   - §13 worked example refs updated

Per feedback_self_hosting_md_authority_audit_before_substrate_naming.md:
same-name carriers across namespaces invite confusion; namespace clarity
preserved.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(decomp-algebra): preserve stage-bound pipeline facts (codex inline BLOCKING #2)

Codex BLOCKING inline at docs/design-decomposition-algebra.md:108: prior
dissolution proof would drop stage-bound pipeline coordinate facts
(StageRunKey, ClaimLease, SignalType, PipelineArtifact, ArtifactType,
MetricRecord) used downstream — violates P2 facts-flow-forward.

Grep verified at dsl/gunbc/workflow/types.dag:
- StageRunKey:159 — threads through StageOutcome / PipelineArtifact /
  MetricRecord / RetryDue / TerminalStateReached
- ClaimLease:166 — lease-execution claim
- SignalType:235 — idempotency-keyed signal payload tag
- PipelineArtifact:120,212-214 — stage-output artifact
- ArtifactType:214,226 — artifact taxonomy
- Metrics:225,318 — per-stage telemetry

Fix: only stage-VALUE collapses to (Mode, Phase); run-keyed pipeline
facts remain structurally distinct as forward-flowing coordinates.
Per feedback_projections_must_compose_facts.md + INVARIANTS P2.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(decomp-algebra): drop false monotonicity claim (codex inline BLOCKING #3)

Codex BLOCKING inline at docs/design-decomposition-algebra.md:231: prior
"forward-stable subset" framing was still false. Decompose adds children
→ retracts parent closure (COMPOSITE_HAS_OPEN_CHILDREN). Replan adds
reconcile child → same. Declare(Bucket) introduces BUCKET_NOT_DRAINED.
No Operation subset is universally monotonic in canCloseNode.

Fix: drop the monotonicity claim entirely. Replace with typed effects-
per-operation classification — each operation's effect on closure-
eligibility is type-signature-visible. Consumers MUST NOT assume
monotonicity across event-log composition.

Effects-per-operation classification added: Declare/Decompose/Drain/
Replan/Escalate/Pause/Reopen/Regress/AttestedOverride each with explicit
closure-eligibility effect (neutral / improves / retracts).

The only operational invariant retained: every closure-eligibility
transition is witnessed by an explicit Operation; no silent transitions.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): correct authority claim per P2 staging discipline (codex inline BLOCKING #4)

Codex BLOCKING inline at docs/r4-ctrl-dag-migration-project-plan.md:61:
§3 strategy paragraph claimed "contract becomes authority from PR-merge"
which contradicted line 73 staging discipline AND violated INVARIANTS P2
(declarations alone are staging, not landed authority).

Fix: §3 strategy paragraph now explicitly states .dag files are 🟡 STAGED
on merge, NOT 🟢 AUTHORITY. Authority requires generated consumer or
emission target. Trio convergence (emission + parity + cut-over PR
deletes TS file) is the named dissolution trigger.

Consistent with feedback_no_textual_enforcement_bridges.md: textual
claims of authority don't substitute for structural enforcement.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): Ctrl-Migration Director spawned + line 303 receipt scope (codex inline BLOCKING #5)

Two changes:

1. Codex BLOCKING at line 303: brief template scope bullet still said
   "Practice 4 receipts for any open enum" while acceptance gate #2 (line
   314) said "every enum/sum with ≥2 variants". Aligned scope bullet
   with gate per codex inline BLOCKING #5.

2. Operator directive 2026-05-12T~19:20Z: deep-wolf-155 operates at
   CEO/PM tier above gunbc R3-close Director zesty-bear-812. Ctrl-
   Migration Director spawned as CHILD under PM via dashboard-ops
   work-items create — node://adhoc-dc298bc7-9f7 (status=ready,
   2026-05-12T19:20:39Z). Auto-spawn fires within ~30s.

§5 tree updated to reflect:
- deep-wolf-155 (CEO/PM, root) above zesty-bear-812
- Ctrl-Migration Director as new child of deep-wolf-155
- PM owns inter-program coordination
- Each Director independent on program scope

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: C compiler + LLVM in .dag execution promotion plan

Per operator directive 2026-05-12T~19:30Z: parallel program plan to
ctrl-migration. Promotes existing research-viability artifacts at
~/ctrl/research/.../c-compiler-in-dag/ to executing production program.

Existing research is well-developed:
- PLAN.md (Brian-approved 2026-05-04 with A1-A10 locks)
- W0 shared IR primitives (5 files in extdeps/common/ir/)
- W4 LLVM IR spike (DONE — substrate + emit + types + trivial program)
- W7 XLS/Verilog spike (DONE)
- Phase-2 expression evaluator (DONE)
- 3 lens-counterfactual real-world bug case studies
- gunbc src/v3/lenses/ has 16 production lens instances ready to consume

This doc proposes the EXECUTION shape that consumes the research plan:
- Phase A (~1-2 weeks): promote research → production substrate
  (~6-9 PRs moving W0/W4/W7/phase-2-evaluator into gunbc dsl/extdeps/)
- Phase B (~6-12 months parallel): Frontend (W3a + W11) + IR (W2 + W2d)
  + Lens-Application (W8 + W10) + Pressure-Test
- Phase C (multi-month): emission targets (codegen, runtime, linker)
- Phase D (open-ended): "LLVM entirely" if pursued

Proposed program tree: NEW C-Compiler+LLVM Director under PM/CEO,
parallel to zesty-bear-812 (gunbc R3-close) + clever-ant-97 (ctrl-
migration). 5 Mgrs (Substrate, Frontend, IR, Lens-Application,
Pressure-Test).

Scope decision required (Q-A): interpretation (a) "C frontend + LLVM IR
substrate" (existing research scope; proposed) vs (b) "LLVM entirely"
(optimizer + codegen as .dag; multi-year).

6 open Qs for operator decision (§9).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): Wave-1-trio checkpoint + staged-debt throttle (claude #10327 exploratory observations)

Per claude #10327 review observations on PR #2775 (APPROVE-with-exploratory):

1. "Ambitious blast radius for a plan in DRAFT; worth a checkpoint after
   Wave 1 lands one full trio (algebra ✓ + subsystem ✓ + emission ✓)
   before fanning the rest out, otherwise you risk 16 staged .dag files
   with no dissolution receipts firing."

   → §7 now requires WAVE-1-TRIO CHECKPOINT at ~Day 7-10 before Wave 2
   dispatch. If trio doesn't converge by Day 10, pause Wave 2 + surface
   to PM for re-scope.

2. "Parallel ≠ independent: Phase 1.5 PRs that land before their
   matching Phase 3 emission target are deliberately accepting staged-
   debt, and the Verification Mgr is the throttle."

   → §6 now states parallel-with-throttle explicitly. Verification Mgr
   enforces staged-debt budget: if 3+ subsystems merged with no matching
   emission, Subsystem-Modeling Mgr PAUSES new dispatch until catch-up.

Both observations were exploratory (review verdict was APPROVE not
BLOCKING), but substantive design feedback worth incorporating
structurally rather than acknowledging.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): remaining-work dependency graph + max-parallelization plan

Per operator directive 2026-05-12T~20:00Z: "define the remainder of R3
now, including all dependencies, so we can max parallelize all the work."

Comprehensive audit of §1.8 ledger:
- 102 R3-load-bearing gates total
- ~32 CLOSED (31%); ~40 IN-FLIGHT (39%); ~31 OPEN (30%)
- 2 lanes 100% done: T-Omni-Shape-B, T-Free-Consequences-Demonstration
- Standing gate #75 PASSING

Critical-path identified:
- Cluster M (T-Tests-As-Data-Completeness): gate #84 dissolves ~80-90 of
  101 SG-0 hand-Rust test entries in single closure. Phase 1 (#85/#86
  substrate) dispatch-ready NOW. Total 4-8w to full Cluster M closure.
- Cluster F (T-LP-Retirement): gates #81/#82/#83/#95 carve-promoted-IN-R3
  per Director 2026-05-09. F-α + F-β.1 parallel-dispatchable NOW.
  Total 3-4w to full Cluster F closure.

14 gates identified as dispatch-ready NOW (no prerequisite blocking).
Wave-1 dispatch plan covers 13-15 parallel workers across 3 R3 Mgrs.

Worker spawn capacity analysis:
- Substrate Mgr: 16 max, 1 active → +15 budget
- Debt-Paydown Mgr: 8 max, 0 active → +8 budget
- Verification Mgr: 8 max, 3 active → +5 budget
- Total +28 R3 spawn budget; currently at ~5; can scale 5-6x

Throughput levers ranked:
1. Land review-parser fix (eliminates per-PR PM bypass overhead)
2. Pre-author Wave-1 briefs in bulk
3. Spawn to Mgr capacity
4. Cluster M Phase 1 immediate dispatch (critical-path)
5. F-β.1 canvas immediate authoring
6. PB Mgr successor spawn (currently no active session)
7. Class-authorization batch merges (Director-ratified)

6 open Qs for operator decision.

Honest 6-8 week timeline to R3 close-ready with full Wave-1 dispatch
+ brief queue depth + parser fix landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…wording (#2780)

* docs: decomposition-algebra modeling project (DRAFT)

Operator-supplied premise: project decomposition as algebra where children sum to parent meaning; walk-back when integration contradicts construction.

This draft formalizes:
- §1 The contradiction trigger (algebraic imbalance | claim contradiction)
- §2 Types sketch (Node, Claim, Decomposition, Witness, WalkBackEvent) — gunbc-lens-style; eventual home in dsl/std/ as MeaningDecomposition lens analogous to Cost lens
- §3 Walk-back algorithm (procedure with StableAncestor | RootContested termination)
- §4 Worked example — PR #2745 misread retroactively traced through procedure (2026-05-12 PM execution error)
- §5 Dashboard comms application sketch — message-as-walk-back-signal mapping
- §6 Open questions (coefficient semantics, claim equivalence, root-asker, rebalance cost, implementation surface)
- §7 Next step: validate on N=3-5 real cases before .dag formalization

Iteration expected.

* docs: decomposition-algebra rewrite for ctrl/ migration scoping

Replaces procedural walk-back draft (d534fd4) with structural-integration
shape per operator directive 2026-05-12: migrate ctrl/ processes into .dag
substrate; algebra is authoritative, ctrl/ TS becomes projected emission.

Audit-grounded with grep-verified citations across dsl/std/ + ctrl PR refs
(#1192/#1193/#1195/#1197). Identifies 4 modeling gaps (EventLog<T> primitive,
Lens<A,B> type, bounded multiplicity, unified Witness) + workflow-types
dissolution scope (dsl/gunbc/workflow/types.dag overlaps with decomp-algebra;
proposed dissolution rather than coexistence). First-cut migration target
recommended: review-verdict-parser (today's parser-lag pain validates the
heuristic-pass cost per feedback_lenses_not_passes).

Phase 1 substrate-file skeleton (~50 lines) sketched. Cost-of-change
contract = 1 file for new Mode variants / Operation arms.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(decomp-algebra): inline §13 validation case study; drop git-history cross-ref

Addresses claude #10308 review finding: §13's pointer to "previous draft in
git history at d534fd4" was a quirk for a brand-new file (per reviewer:
harmless but worth fixing). Inlines the PR #2745 misread walk-back trace
self-contained so readers don't need to git-log to follow the validation.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: ctrl/ → .dag migration project plan (parallel program tree)

Companion to docs/design-decomposition-algebra.md. Authored per operator
directive 2026-05-12: parallel program tree beside zesty-bear-812, model
dependencies, migrate as much ctrl/ as possible ASAP.

Audit of ctrl/ via gh API identifies:
- 3 partial .dag files already in ctrl (workflows/review.dag etc.)
- ~17 TS subsystems with documented designs in scripts/session-dashboard/
- 4 in-flight algebra PRs #1192-#1197 (decomposition algebra series)
- Top-level constitutional docs (AGENTS/AUDIT/CODING/INVARIANTS/REVIEW_*/SCOPE_*/TESTING)

Plan structure:
- Phase 1: algebra substrate (dsl/std/process_algebra.dag)
- Phase 1.5: 5-8 parallel subsystem modeling PRs (doc-only, type-only)
  Items 1/3/4/5/6 can start NOW without Phase 1
- Phase 2: CLI projection to Rust binary
- Phase 3: HTTP/SQL/audit-event extdeps (R4 emission targets)
- Phase 4: ctrl/ cut-over per subsystem
- Phase 5: generalize

Proposes Ctrl-Migration Director parallel to gunbc R3-close Director;
3 Mgrs (Substrate/Subsystem-Modeling/Verification), Emission-Targets Mgr
spawned later. First-week concrete actions named.

6 open Qs for operator decision: file placement (gunbc vs ctrl), Director
shape, workflow-types dissolution scope, first migration target, ctrl PR
#1192-#1197 disposition, cross-Director coordination protocol.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): comprehensive ctrl/ subsystem catalog (16 subsystems)

Per operator directive 2026-05-12T~18:55Z: audit ALL session-dashboard
work + identify what can migrate today. Gh-API audit of gunb-ai/ctrl
identified ~21,800 TS LOC across 16 subsystems.

Key findings:
- Existing demo precedent at research/.../inbox_delivery_slice.dag proves
  the `service` + typed-functions shape works today (~90% done already)
- 237 .mjs files in scripts/session-dashboard/ organized into ~16 subsystems
- ~20 .mjs in chatgpt-reviewer/ (browser DOM walking; partial-doable now)
- 3 .mjs in api-reviewer/ (CLI backend selection)
- 3 partial .dag in workflows/ (review, branch_review, review_config)

Strategy shift: model SERVICE CONTRACTS (types + typed function signatures
+ pure helpers), not just types. Demo proves it works today.

Subsystems classified:
- 8 items independent NOW (no Phase 1 dependency) — parallel first wave
- 6 items consume Phase 1 algebra substrate — second wave
- 2 items partial-NOW (chatgpt-reviewer browser, server HTTP routes)
- ~16 PRs total for Phase 1.5 (bundled by subsystem)

Operator-resolved Qs:
- Q-A: gunbc-side placement (dsl/ctrl/*.dag)
- Q-D: review-verdict already in flight per operator

New Qs added:
- Q-G: service-contract authority claim (future vs co vs substrate)
- Q-H: per-subsystem PR cadence (bundle by subsystem, ~16 PRs total)

First-wave dispatch updated: 8 workers parallel Day 2-5; 6 more Day 6-10.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): replace-ASAP framing + parallel critical paths

Per operator directive 2026-05-12T~19:05Z: this is replacement, not
"future authority"; emission targets are critical-path parallel with
algebra substrate, not deferred. 4 Mgrs spawn Day 1 (not 3).

Changes:
- §1 Mission: replace dashboard ASAP; intent layer THIN, substrate
  rigor; compositional-modeling discipline (M9 DFS, lens-not-pass,
  cost-of-change = 1)
- §5 Program tree: orthogonal to zesty-bear-812 confirmed; 4 Mgrs
  (Substrate / Subsystem-Modeling / Emission-Targets / Verification)
  spawn together Day 1
- §6 Phase sequencing: Phase 1 + 1.5 + 3 in PARALLEL, all critical
  path. Per-subsystem cut-over fires as trio converges.
- §10 First-week actions: Emission-Targets Mgr spawns Day 1 not Day-N
- §11 Q-G RESOLVED: substrate becomes authority immediately when
  emission proves out per subsystem; no co-authority window

Three operator Qs resolved this session: A (gunbc-side), D (review-
verdict in flight), G (replace-immediately).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: address codex BLOCKING review #10331 (5 findings on PR #2775)

All 5 findings valid; substantive review, real gaps. Fixed in-place
rather than reply-without-fix.

Finding 1 — audit scope correction (LIVE V3 LENS SUBSTRATE):
prior audit scoped to dsl/std/ only; missed src/v3/std/lens.dag
(Director-locked 6-field Lens<C>) + src/v3/std/dimensions.dag:35
(Witness<Carrier> = Inhabits | Violates) + src/v3/std/coproduct_projection.dag
(Practice 4 dispatch substrate) + ~16 worked lens instances in
src/v3/lenses/. §3 mapping table corrected with these as ✓ EXISTS.

Finding 2 — workflow-types dissolution axis conflation:
§4 initial proposal conflated decomposition axis (Mode) with workflow
phase axis (IssueLifecycleStage). Corrected to preserve both as
structural coordinates (Mode × Phase product) per Practice 4 dimensional
dissolution. Phase open enum staged with dissolution trigger =
per-consumer enumeration. Until proof lands, workflow-types stay extant;
decomp-algebra co-located not replacing.

Finding 3 — Reopen/Regress operations added:
prior §6 claimed monotonicity (canCloseNode ≥ on composition) without
explicit reverse operations. Added Reopen { ReopenWitness } + Regress
{ RegressionWitness } operations with typed witness payloads. Replaced
monotonicity claim with closure-decision lattice: forward-stable subset
preserves; Reopen/Regress/Replan/Escalate explicitly retract closure
state with witnessed cause. No silent regression.

Finding 4 — staging discipline for catalog:
§3 catalog preamble corrected: every "doable NOW" row is STAGED with
explicit dissolution trigger, NOT authoritative-on-arrival. Trigger =
per-subsystem realization receipt + consumer parity (emission target
+ parity test + cut-over PR deletes TS). 🟡 STAGED until trigger fires.

Finding 5 — Practice 4 coverage widened:
§8 brief template gate 2 changed from "Practice 4 receipts on any open
enum" to "every enum/sum with ≥2 variants" (closed sums need
dissolution analysis too). Receipt format named (classification +
pattern + trigger). STOP criterion added: closed sum with no clear
dissolution pattern surfaces to Director.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(decomp-algebra): address codex inline BLOCKING — Lens/Witness parallel authority

Codex BLOCKING inline at docs/design-decomposition-algebra.md:154 + queued
companion: §5 Gap 2 proposed `Lens<S, A> { view, update }` and Gap 4
proposed `Witness { author, ... }` — both create parallel authority with
v3 substrate (Lens<C> at src/v3/std/lens.dag, Witness<C> at
src/v3/std/dimensions.dag:35).

Fixes per INVARIANTS P2 (single-authority) + MODELING.md M9 (DFS concept
DAG before defining):

1. Gap 2 RETRACTED — no new Lens carrier. State-projection in
   decomp-algebra reuses FreeMonoid<TimestampedEvent<Operation>> + fold
   (already in dsl/std/algebra.dag:390). If a future bidirectional-update
   use case surfaces, escalate to Substrate Mgr for shape audit.

2. Gap 4 RENAMED — decomp-algebra's "Witness" → "Attestation" to avoid
   name collision with v3 Witness<Carrier>. The carriers are
   structurally distinct (Attestation is human-intent attestation;
   v3 Witness<C> is per-Behavior inhabitance proof). Cascade applied:
   - Operation variants: attestation: Attestation
   - WitnessedOverride → AttestedOverride
   - ReopenWitness → ReopenAttestation
   - RegressionWitness → RegressionAttestation
   - Evidence enum → AttestationEvidence
   - StructuralLens → StructuralLensReceipt (refs v3 Lens<C> instance)
   - §7 dissolution receipt updated
   - §9 substrate skeleton updated
   - §13 worked example refs updated

Per feedback_self_hosting_md_authority_audit_before_substrate_naming.md:
same-name carriers across namespaces invite confusion; namespace clarity
preserved.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(decomp-algebra): preserve stage-bound pipeline facts (codex inline BLOCKING #2)

Codex BLOCKING inline at docs/design-decomposition-algebra.md:108: prior
dissolution proof would drop stage-bound pipeline coordinate facts
(StageRunKey, ClaimLease, SignalType, PipelineArtifact, ArtifactType,
MetricRecord) used downstream — violates P2 facts-flow-forward.

Grep verified at dsl/gunbc/workflow/types.dag:
- StageRunKey:159 — threads through StageOutcome / PipelineArtifact /
  MetricRecord / RetryDue / TerminalStateReached
- ClaimLease:166 — lease-execution claim
- SignalType:235 — idempotency-keyed signal payload tag
- PipelineArtifact:120,212-214 — stage-output artifact
- ArtifactType:214,226 — artifact taxonomy
- Metrics:225,318 — per-stage telemetry

Fix: only stage-VALUE collapses to (Mode, Phase); run-keyed pipeline
facts remain structurally distinct as forward-flowing coordinates.
Per feedback_projections_must_compose_facts.md + INVARIANTS P2.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(decomp-algebra): drop false monotonicity claim (codex inline BLOCKING #3)

Codex BLOCKING inline at docs/design-decomposition-algebra.md:231: prior
"forward-stable subset" framing was still false. Decompose adds children
→ retracts parent closure (COMPOSITE_HAS_OPEN_CHILDREN). Replan adds
reconcile child → same. Declare(Bucket) introduces BUCKET_NOT_DRAINED.
No Operation subset is universally monotonic in canCloseNode.

Fix: drop the monotonicity claim entirely. Replace with typed effects-
per-operation classification — each operation's effect on closure-
eligibility is type-signature-visible. Consumers MUST NOT assume
monotonicity across event-log composition.

Effects-per-operation classification added: Declare/Decompose/Drain/
Replan/Escalate/Pause/Reopen/Regress/AttestedOverride each with explicit
closure-eligibility effect (neutral / improves / retracts).

The only operational invariant retained: every closure-eligibility
transition is witnessed by an explicit Operation; no silent transitions.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): correct authority claim per P2 staging discipline (codex inline BLOCKING #4)

Codex BLOCKING inline at docs/r4-ctrl-dag-migration-project-plan.md:61:
§3 strategy paragraph claimed "contract becomes authority from PR-merge"
which contradicted line 73 staging discipline AND violated INVARIANTS P2
(declarations alone are staging, not landed authority).

Fix: §3 strategy paragraph now explicitly states .dag files are 🟡 STAGED
on merge, NOT 🟢 AUTHORITY. Authority requires generated consumer or
emission target. Trio convergence (emission + parity + cut-over PR
deletes TS file) is the named dissolution trigger.

Consistent with feedback_no_textual_enforcement_bridges.md: textual
claims of authority don't substitute for structural enforcement.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): Ctrl-Migration Director spawned + line 303 receipt scope (codex inline BLOCKING #5)

Two changes:

1. Codex BLOCKING at line 303: brief template scope bullet still said
   "Practice 4 receipts for any open enum" while acceptance gate #2 (line
   314) said "every enum/sum with ≥2 variants". Aligned scope bullet
   with gate per codex inline BLOCKING #5.

2. Operator directive 2026-05-12T~19:20Z: deep-wolf-155 operates at
   CEO/PM tier above gunbc R3-close Director zesty-bear-812. Ctrl-
   Migration Director spawned as CHILD under PM via dashboard-ops
   work-items create — node://adhoc-dc298bc7-9f7 (status=ready,
   2026-05-12T19:20:39Z). Auto-spawn fires within ~30s.

§5 tree updated to reflect:
- deep-wolf-155 (CEO/PM, root) above zesty-bear-812
- Ctrl-Migration Director as new child of deep-wolf-155
- PM owns inter-program coordination
- Each Director independent on program scope

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: C compiler + LLVM in .dag execution promotion plan

Per operator directive 2026-05-12T~19:30Z: parallel program plan to
ctrl-migration. Promotes existing research-viability artifacts at
~/ctrl/research/.../c-compiler-in-dag/ to executing production program.

Existing research is well-developed:
- PLAN.md (Brian-approved 2026-05-04 with A1-A10 locks)
- W0 shared IR primitives (5 files in extdeps/common/ir/)
- W4 LLVM IR spike (DONE — substrate + emit + types + trivial program)
- W7 XLS/Verilog spike (DONE)
- Phase-2 expression evaluator (DONE)
- 3 lens-counterfactual real-world bug case studies
- gunbc src/v3/lenses/ has 16 production lens instances ready to consume

This doc proposes the EXECUTION shape that consumes the research plan:
- Phase A (~1-2 weeks): promote research → production substrate
  (~6-9 PRs moving W0/W4/W7/phase-2-evaluator into gunbc dsl/extdeps/)
- Phase B (~6-12 months parallel): Frontend (W3a + W11) + IR (W2 + W2d)
  + Lens-Application (W8 + W10) + Pressure-Test
- Phase C (multi-month): emission targets (codegen, runtime, linker)
- Phase D (open-ended): "LLVM entirely" if pursued

Proposed program tree: NEW C-Compiler+LLVM Director under PM/CEO,
parallel to zesty-bear-812 (gunbc R3-close) + clever-ant-97 (ctrl-
migration). 5 Mgrs (Substrate, Frontend, IR, Lens-Application,
Pressure-Test).

Scope decision required (Q-A): interpretation (a) "C frontend + LLVM IR
substrate" (existing research scope; proposed) vs (b) "LLVM entirely"
(optimizer + codegen as .dag; multi-year).

6 open Qs for operator decision (§9).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): Wave-1-trio checkpoint + staged-debt throttle (claude #10327 exploratory observations)

Per claude #10327 review observations on PR #2775 (APPROVE-with-exploratory):

1. "Ambitious blast radius for a plan in DRAFT; worth a checkpoint after
   Wave 1 lands one full trio (algebra ✓ + subsystem ✓ + emission ✓)
   before fanning the rest out, otherwise you risk 16 staged .dag files
   with no dissolution receipts firing."

   → §7 now requires WAVE-1-TRIO CHECKPOINT at ~Day 7-10 before Wave 2
   dispatch. If trio doesn't converge by Day 10, pause Wave 2 + surface
   to PM for re-scope.

2. "Parallel ≠ independent: Phase 1.5 PRs that land before their
   matching Phase 3 emission target are deliberately accepting staged-
   debt, and the Verification Mgr is the throttle."

   → §6 now states parallel-with-throttle explicitly. Verification Mgr
   enforces staged-debt budget: if 3+ subsystems merged with no matching
   emission, Subsystem-Modeling Mgr PAUSES new dispatch until catch-up.

Both observations were exploratory (review verdict was APPROVE not
BLOCKING), but substantive design feedback worth incorporating
structurally rather than acknowledging.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): remaining-work dependency graph + max-parallelization plan

Per operator directive 2026-05-12T~20:00Z: "define the remainder of R3
now, including all dependencies, so we can max parallelize all the work."

Comprehensive audit of §1.8 ledger:
- 102 R3-load-bearing gates total
- ~32 CLOSED (31%); ~40 IN-FLIGHT (39%); ~31 OPEN (30%)
- 2 lanes 100% done: T-Omni-Shape-B, T-Free-Consequences-Demonstration
- Standing gate #75 PASSING

Critical-path identified:
- Cluster M (T-Tests-As-Data-Completeness): gate #84 dissolves ~80-90 of
  101 SG-0 hand-Rust test entries in single closure. Phase 1 (#85/#86
  substrate) dispatch-ready NOW. Total 4-8w to full Cluster M closure.
- Cluster F (T-LP-Retirement): gates #81/#82/#83/#95 carve-promoted-IN-R3
  per Director 2026-05-09. F-α + F-β.1 parallel-dispatchable NOW.
  Total 3-4w to full Cluster F closure.

14 gates identified as dispatch-ready NOW (no prerequisite blocking).
Wave-1 dispatch plan covers 13-15 parallel workers across 3 R3 Mgrs.

Worker spawn capacity analysis:
- Substrate Mgr: 16 max, 1 active → +15 budget
- Debt-Paydown Mgr: 8 max, 0 active → +8 budget
- Verification Mgr: 8 max, 3 active → +5 budget
- Total +28 R3 spawn budget; currently at ~5; can scale 5-6x

Throughput levers ranked:
1. Land review-parser fix (eliminates per-PR PM bypass overhead)
2. Pre-author Wave-1 briefs in bulk
3. Spawn to Mgr capacity
4. Cluster M Phase 1 immediate dispatch (critical-path)
5. F-β.1 canvas immediate authoring
6. PB Mgr successor spawn (currently no active session)
7. Class-authorization batch merges (Director-ratified)

6 open Qs for operator decision.

Honest 6-8 week timeline to R3 close-ready with full Wave-1 dispatch
+ brief queue depth + parser fix landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: fix cursor #10356 findings — correct INVARIANTS labels + Phase A scope wording

Both BLOCKING findings on already-merged PR #2775 (cursor/composer-2 review #10356):

1. docs/design-decomposition-algebra.md:492 — INVARIANTS labels were wrong:
   - P1 is "Modeling Faithfulness" (single-authority is a consequence)
   - P2 is "Boundary Discipline" (illegal-states-unrepresentable is
     docs/modeling-discipline.md Practice 2, downstream of P2)
   - P5 is "Progress Is Dissolution" (Pure Bootstrap is the separate
     docs/design-pure-bootstrap-zero.md thesis)

2. docs/r4-c-compiler-and-llvm-in-dag-program-plan.md:246 — §8 said
   Phase A is "doc-shape promotion only" but §3 describes ~6-9 PRs
   promoting .dag substrate into dsl/extdeps/. Reconciled: "no compiler
   runtime code in Phase A" — typed .dag substrate promotion IS the work
   (real tree additions); Rust runtime / parser-emitter execution /
   codegen invocation are Phase B / Phase C scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…ion-owned) — codex BLOCKING review 10431 on PR #2782

(1) S2 brief deleted: per docs/r3-program-plan.md:311-312 — #85 carriers already landed via PR #2647, remaining work is consumer-side (Verification lane / V Mgr #87 cascade); #86 already CONSUMER_LANDED + PASSING. Substrate lane has no work on these gates.

(2) S4 brief deleted: per docs/r3-structure.md:214 + docs/r3-program-plan.md:391 (Director-locked 2026-04-28 distribute-work-centralize-ledger) — #36 bridge_retirement_ledger_zero is Verification-owned. The 5 distributed bridges are separate gates (2 Substrate, 3 PB); none is #36.

(3) Authored r3-wave1-substrate-lane-retractions.md as audit-trail receipt + updated queue (5 items down from 7).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
…rogramGenerator) per operator adversarial probe 2026-05-13

Operator follow-up probe 2026-05-13: "for complexity - do we have testcases representing random combinations of functions, validating that the correct complexity result is generated? please add that"

HEAD audit:
- `ProgramGenerator` substrate carrier LANDED (gate #86; `src/v3/std/verification.dag`) but only used in `m1_5_verification_test.rs::program_generator_authoring_surface_compiles_cleanly` (compile-surface verification, NOT actual random-program generation)
- `ForAll` quantifier in `verification.dag` is wired only for `ForAllTargets` (cross-target per Gap 2), NOT for `ForAll(random_program)` quantification
- Complexity cementing test at `src/v3/compiler/tests/integration/cementing/complexity_lens_behavioral_completion.rs`: only 2 hand-authored cases (`literal_bind_cements_constant_complexity_summary` + `recursive_countdown_cements_linear_work_and_span`)
- Zero `proptest` / `quickcheck` / random-composition tests against the complexity lens

Result: gate #79 `lens_capability_register_zero_proxy_zero_stub` lens-completion can claim "behaviorally complete" while never having validated against arbitrary nested compositions — the substrate's SymbolicCost composition class is enormous vs the 2 cementing cases.

Fix: Gap 12 added — Property-based complexity-lens validation via ProgramGenerator. Owner: Verification Mgr (still-moth-538). Substrate Mgr (warm-wolf-698) co-owns the ProgramGenerator-instance + oracle authoring.

Sub-program: (1) ProgramGenerator complexity-instance producing structurally-bounded random function compositions; (2) complexity oracle (`.dag`-authored function from generated-program → expected ComplexitySummary; NO bridge-Rust oracle per feedback_no_textual_enforcement_bridges); (3) `ForAll<ProgramGenerator>` quantifier extension (currently only ForAllTargets); (4) property-based TestClaim asserting complexity_of(g) == oracle(g) for N≥100 samples per CI run; (5) CI integration with seed-pinning + reproducibility discipline.

Close criterion: (a) ProgramGenerator complexity-instance landed; (b) `.dag`-authored oracle landed; (c) ForAll<ProgramGenerator> TestClaim landed + passing with N≥100; (d) zero oracle-vs-lens divergence; (e) CI seed-pinning ratcheted.

Effort estimate: 2-3 weeks, parallelizable with Gap 11 substrate-shape canvas authoring. Gap 12 generator depends on Gap 11 substrate decision so generator can produce the full composition class.

§2 sequencing updated: Gap 12 in Phase C (Verification Mgr lane); §6 checklist tracks Gap 12 as post-§4-ratification adversarial finding. Document order in §1 corrected to Gap 11 → Gap 12 (matching gap-number sequence).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
…prereq)

Mgr canvas surfaced to Director per Track 1 of dispatch msg_970d691d
+ Verification Mgr scope read msg_04b125e2.

Existing GeneratedFromDag (verification.dag:437; PR #2645 #86 PASSING)
carries one-direction set-membership only; PR #3013 Gap 5 close
criterion requires positive-authority predicate failing closed on
(a) missing source, (b) orphan output, (c) byte drift. This is P1
substrate-fact introduction routed to Director.

Two candidate shapes:
- §2.A refinement of GeneratedFromDag with manifest_entries list
  (Mgr-rec preliminary per feedback_practice2_vs_practice4_disambiguation
  cross-variant Practice-2 favor)
- §2.B sibling GeneratorManifest carrier (isolates new fact; Q3
  representation-duality risk)

5 surfaced design Qs: refinement vs sibling, dag_source typing
(DeclarationRef recommended), source_hash vs SnapshotRef precedent
alignment, orphan-detection directory-walk admissibility, per-class
same-shape preservation per Verification Mgr scope read.

Out-of-scope: 99-test bulk-port TestClaim authoring (bright-bee-903
lane); negative-authority predicate (already authored).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
…tor-ratified §2.A)

Director ratified canvas option (a) §2.A refinement at msg_05837745:
Q1 §2.A refinement + Q2 DeclarationRef + Q3 SnapshotRef + Q4
directory-walk-in-existing-evaluator + Q5 per-class same-shape
preserved. Worker dispatch authorized under standing Substrate Mgr
program authority.

Brief covers: GeneratedManifestEntry type authoring, GeneratedFromDag
refinement (manifest_entries replacing generated_paths), 3-way
SnapshotRef byte-equality assertion in eval_generated_from_dag_shape,
directory-walk orphan-output detection at tests/ scan-root,
distinct structured diagnostics for missing-source/orphan-output/
byte-drift drift modes, same-PR atomic migration of all 4 test_runner
call-sites + bootstrap regeneration, #86 PASSING-evidence in-place
transition.

Q4 scan-root future-refinement flag carried as STOP-AND-PING trigger
(NOT in scope for THIS PR per ratification).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
Director re-ratification msg_606e0e50 after worker warm-wren-479
STOP-AND-PING (msg_1284363e) surfaced three canvas-level shape
concerns at pre-implementation grep.

Amendments:
- Q3-amend (b): source_hash: ContentHash (was SnapshotRef). Worker
  grep verified SnapshotRef is sentinel-string registry-key at
  test_runner.rs:4742, NOT a byte-equality hash. ContentHash
  (core/infra::hash, CLAUDE.md hash-unification) is the canonical hash
  type that names the actual fact.
- Q-RegenCapability (β) SPLIT: this PR is substrate-shape-only;
  runtime regen-from-DeclarationRef + 3-way byte-equality assertion
  + directory-walk orphan-detection split to follow-up
  Evaluator-Mgr-owned PR (blocked on Evaluator Mgr lane re-spawn).
- Q-FixtureMapping deferred: per-file DeclarationRef + ContentHash
  enumeration moves to follow-up Verification-Mgr-owned integration
  slice per still-moth-538 msg_6c50e646 framing.

Brief §0 split disposition explicit. §1.1 ContentHash. §2.1 lockstep
field-rename only (no new runtime capability). §4 minimal-shape
manifest_entries for #86 PASSING in-place transition. §5 revised
STOP triggers. §7 follow-up workstream sequencing.

Gap 5 close-criterion narration in PR #3013 unchanged: actual close
fires when runtime PR lands, not this PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
Director Q-StubValuePosture (b) ratification msg_3b99a90f resolves the
codex BLOCKING review on PR #3040: prior struct-with-stubs framing for
`GeneratedManifestEntry { output_path, dag_source, source_hash }`
required fixtures to fabricate `dag_source` / `source_hash` values
(C-9: "missing fields / values may not fabricate empty nodes or
strings" under INVARIANTS P3). Substrate Mgr msg_c2ae1158 proposed +
Director ratified the typed-state-explicit sum-variant shape:

  type GeneratedManifestEntry
    = PendingFact { output_path: Path }
    | ResolvedFact {
        output_path: Path
        dag_source: DeclarationRef
        source_hash: NonEmptyStr
      }

`PendingFact` IS the typed "unknown" carrier — no fabricated facts.
`ResolvedFact` materialization defers to the follow-up Evaluator-Mgr-
owned runtime PR where hash-derivation produces real values at the
construction boundary. Gate #86 PASSING preserved on shape; the
3-way byte-equality assertion only fires on `ResolvedFact` arms.

Evaluator side reads `output_path` from whichever variant arm; the
runner handles both the single-field PendingFact shorthand (payload
flattened to a bare String literal) and the multi-field ResolvedFact
record-payload shape via dual destructure.

Fixture sites migrated to PendingFact-only:
- tests/dag/t_r1c_d_pb_census_gates.dag (3 entries)
- tests/integration/test_runner_test.rs (inline DSL, 1 entry)

Bootstrap regenerated via regen_bootstrap --features bootstrap-regen-fresh.
Key integration tests green:
- test_runner_dispatches_pb_census_predicate_shapes ✓
- r1c_d_pb_census_gates_suite_evaluates_through_runner ✓

Other m1_5_verification_test / m1_5_testgen_test failures are
pre-existing on main (verified via stash diff) and unrelated to this
substrate refinement.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
…ymmetry (#3037)

* docs(r3): fix interrogation-doc JS/TS scope drift + add Gap 11 (LogCost asymmetry / complexity composition completeness)

Operator adversarial probe 2026-05-13 surfaced two issues:

1. docs/r3-close-interrogation.md §285 + §291 cited "Rust + JavaScript + Python (3 R3 Shape-A targets per §3.1)" — drift relative to §518 of same doc which correctly enumerates "R3 = 3 Shape-A targets: Rust / Python / Go". The JavaScript framing was operator-illustrative example pre-dating R3 scope finalization that authored into normative scope text.

Fix: §285 scope claim corrected to "Rust + Python + Go"; JavaScript references in bug-shape examples preserved as illustrative-not-scope with explicit clarifying note pointing to §518 authority. §291 cross-target-test-claim bullet expanded to include "Go via go test" alongside the illustrative JavaScript/jest reference.

2. Operator probe: "regarding complexity - what about more complex combinations of complexity - i.e. n log (n^k) i.e. nested algorithms - do we handle all permutations of those?" + "regarding logcost - my concern is that this seems orthogonal to logcost - shouldn't it work for any arbitrary combination of cost?"

HEAD audit: SymbolicCost in src/v3/std/algebra.dag has structural asymmetry — ProductCost + SumCost are recursive over arbitrary SymbolicCost; LogCost + PolynomialCost take only SizeVariable (terminal). Cannot construct Log(complex) directly. normalize() body handles sum/product identities + LinearCost-squared → PolynomialCost, but NO log-power rule (log(n^k) → k log(n)), NO log-product rule, NO nested-log handling. AsymptoticClass enumerated lattice ceilings on polynomial×log composition (loses log factor on classification).

Fix: Gap 11 added to close plan §1 — Complexity composition completeness / LogCost asymmetry. Sub-promise of gate #79 complexity behavioral close that the 2026-05-13 adversarial sweep missed. Owner: Substrate Mgr (warm-wolf-698). Substrate-shape canvas decision required: (A) LogCost recursive over SymbolicCost (symmetric with Product/Sum) OR (B) dag-authored canonicalization rule that runs before LogCost construction with named log-algebra coverage. Close criterion: shape ratified + normalize/canonicalization landed + lattice tier review + cementing corpus extended with nested compositions (n log n^k, n² log n, n log² n, log log n).

Plan §2 sequencing updated to include Gap 11 in Phase B (Substrate Mgr lane). §6 checklist updated with the post-§4-ratification adversarial finding status.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add Gap 12 (property-based complexity-lens validation via ProgramGenerator) per operator adversarial probe 2026-05-13

Operator follow-up probe 2026-05-13: "for complexity - do we have testcases representing random combinations of functions, validating that the correct complexity result is generated? please add that"

HEAD audit:
- `ProgramGenerator` substrate carrier LANDED (gate #86; `src/v3/std/verification.dag`) but only used in `m1_5_verification_test.rs::program_generator_authoring_surface_compiles_cleanly` (compile-surface verification, NOT actual random-program generation)
- `ForAll` quantifier in `verification.dag` is wired only for `ForAllTargets` (cross-target per Gap 2), NOT for `ForAll(random_program)` quantification
- Complexity cementing test at `src/v3/compiler/tests/integration/cementing/complexity_lens_behavioral_completion.rs`: only 2 hand-authored cases (`literal_bind_cements_constant_complexity_summary` + `recursive_countdown_cements_linear_work_and_span`)
- Zero `proptest` / `quickcheck` / random-composition tests against the complexity lens

Result: gate #79 `lens_capability_register_zero_proxy_zero_stub` lens-completion can claim "behaviorally complete" while never having validated against arbitrary nested compositions — the substrate's SymbolicCost composition class is enormous vs the 2 cementing cases.

Fix: Gap 12 added — Property-based complexity-lens validation via ProgramGenerator. Owner: Verification Mgr (still-moth-538). Substrate Mgr (warm-wolf-698) co-owns the ProgramGenerator-instance + oracle authoring.

Sub-program: (1) ProgramGenerator complexity-instance producing structurally-bounded random function compositions; (2) complexity oracle (`.dag`-authored function from generated-program → expected ComplexitySummary; NO bridge-Rust oracle per feedback_no_textual_enforcement_bridges); (3) `ForAll<ProgramGenerator>` quantifier extension (currently only ForAllTargets); (4) property-based TestClaim asserting complexity_of(g) == oracle(g) for N≥100 samples per CI run; (5) CI integration with seed-pinning + reproducibility discipline.

Close criterion: (a) ProgramGenerator complexity-instance landed; (b) `.dag`-authored oracle landed; (c) ForAll<ProgramGenerator> TestClaim landed + passing with N≥100; (d) zero oracle-vs-lens divergence; (e) CI seed-pinning ratcheted.

Effort estimate: 2-3 weeks, parallelizable with Gap 11 substrate-shape canvas authoring. Gap 12 generator depends on Gap 11 substrate decision so generator can produce the full composition class.

§2 sequencing updated: Gap 12 in Phase C (Verification Mgr lane); §6 checklist tracks Gap 12 as post-§4-ratification adversarial finding. Document order in §1 corrected to Gap 11 → Gap 12 (matching gap-number sequence).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): address briansrls BLOCKING on PR #3037 — recalibrate Gap 11 HEAD evidence + rewrite §285 probes to R3 targets

Two BLOCKING findings from operator briansrls comment-4445313478 at 2026-05-13T21:04:54Z:

B1 (docs/r3-actual-close-plan.md Gap 11): operator-probe notes were promoted to HEAD evidence without verifying actual classifier behavior in src/v3/std/algebra.dag + src/v3/compiler/src/dag_cost_generated.rs.

Verified HEAD evidence (revised):
- `classify_symbolic_cost` at dag_cost_generated.rs:289-312 maps ALL composite costs (ProductCost / SumCost) to `ClassUnknown` — no composition handling. Prior framing "lattice ceilings to ClassPolynomial" / "collapses to ClassLinearithmic" was wrong; actual behavior is collapse to ClassUnknown for any composition.
- `ClassLinearithmic` + `ClassExponential` are unreachable outputs from the classifier — only constructible via string-to-AsymptoticClass deserialization at enforced_lens_application.rs:960-962 for user-declared enforcement budgets. 2 of 8 lattice tiers are write-only.
- SymbolicCost substrate has no `ExponentialCost` variant; `2^n` cannot be represented in source cost. ClassExponential is the lattice analog but unreachable from any SymbolicCost expression.
- normalize() at algebra.dag:537-548 handles only sum/product identity rules + LinearCost-squared → PolynomialCost(degree=2). No log-rule simplification, no Product/Sum→named-tier normalization.

Recalibrated Gap 11 "What's missing" — 6 items (was 4): (1) classify_symbolic_cost composition arms (root issue — even n log n classifies to Unknown), (2) LogCost recursive shape OR canonicalization rule, (3) ExponentialCost variant decision, (4) ClassLinearithmic/Exponential reachability gap, (5) normalize log-rule extensions, (6) cost-lens fold audit.

Recalibrated close criterion — 7 items (was 5), adding (a) classifier produces all reachable tiers including ClassLinearithmic for n log n, (c) ExponentialCost ratified-or-excluded, (e) AsymptoticClass reachability review complete with formal annotation of input-only tiers.

Effort estimate revised up from 2-4 weeks to 3-5 weeks per recalibrated sub-program scope.

B2 (docs/r3-close-interrogation.md §285+§291+§295+§297+§312): the prior fix added a "JavaScript references are illustrative-not-scope" disclaimer but left the gating probes themselves using JavaScript examples. Per operator: "convert the concrete R3 probes to Rust/Python/Go".

Rewrote 5 gating probes + introduction + 2 falsification probes + 1 R3-close-audit-for-class line to use Rust/Go/Python concretely:
- Cross-target serialization round-trip: Rust → Go (not JS)
- Cross-target numeric width: Rust u32 vs Go uint32 vs Python arbitrary-precision int (not JS 53-bit)
- Cross-target effect divergence: Rust tokio vs Go goroutines+channels vs Python asyncio (not JS Promise)
- Cross-target boundary trust: Rust ↔ Go gRPC/HTTP/FFI (not Rust ↔ JS FFI/WASM)
- Cross-target test-claim transferability: cargo test / pytest / go test (removed JS jest)
- Modeling-level cross-target gap: Go's nil-interface-vs-nil-concrete-type (not JS prototype-pollution)
- R3 close audit demo: Rust server + Go client (not JS client)
- Introduction text: "Rust ↔ Go ↔ Python via shared .dag substrate" (was Rust ↔ JavaScript ↔ Python)

Disclaimer language removed — probes are now R3-scope-correct without needing a disclaimer.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): fix Gap 11 PolynomialCost field-type + line-cite per cursor APPROVE_WITH_COMMENTS PR #3037

Cursor BLOCKING (sha 412a8cb, 2026-05-13T21:16Z) — 2 substantive findings on Gap 11 HEAD evidence:

F1 (line 383, INVARIANTS P1 modeling-faithfulness): PolynomialCost field cited as `degree: Nat` but actual substrate at `src/v3/std/algebra.dag:193` is `degree: DegreeAtLeastTwo` (refinement type, NOT raw Nat). The refinement encodes substrate-level guarantee that polynomial degree ≥ 2 (degree 1 redundant with LinearCost; degree 0 redundant with ConstantCost). Load-bearing for ClassPolynomial classifier arm at `dag_cost_generated.rs:297-306` and string-arm decoding in `enforced_lens_application.rs`.

F2 (line 380, minor lens): cite "lines 190-196 (7 variants)" misaligns with substrate — line 190 is the `type SymbolicCost inhabits Semiring<SymbolicCost>` declaration; variant arms span lines 191-197 (7 arms). Corrected cite.

Fix: updated PolynomialCost row to `degree: DegreeAtLeastTwo` with named rationale + load-bearing-citation; corrected line-cite to "lines 191-197, 7 variant arms; inhabits Semiring<SymbolicCost> declaration at line 190".

Cursor exploratory note acknowledged: confirms Gap 11 evidence is otherwise correct (`ProductCost / SumCost → ClassUnknown` at dag_cost_generated.rs:308-310; `ClassLinearithmic` / `ClassExponential` string arms at enforced_lens_application.rs:960-962) — the PolynomialCost field-type was the only substantive slip.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): address codex BLOCKING on PR #3037 sha 797a6d9 — Gap 11 reduce_sum drop_dominated already-landed + Gap 12 retarget to existing QuantifiedTestClaim authority

Codex BLOCKING (2 findings) on PR #3037 sha 797a6d9:

B1 (Gap 11): "Gap 11 audited the top-level normalize match/classifier arms without following reduce_sum helpers → revise the evidence and plan to distinguish already-landed SumCost dominance normalization from the remaining raw/surviving composite classification gap."

Verified at HEAD: reduce_sum in src/v3/std/algebra.dag calls drop_dominated on multi-term Sum lists, stripping asymptotically-dominated terms (e.g. Sum([Linear(n), Constant(5)]) → Linear(n) at normalize-time, then unwrapping single-survivor via wrap_sum). My prior framing said "Sum: drop ConstantCost(0) (additive identity)" only — missed the dominance reduction step.

Fix at Gap 11 HEAD evidence:
- normalize body section now distinguishes Sum-side dominance reduction (already-landed via reduce_sum → drop_dominated → wrap_sum cascade) from Product-side (which only has single-term unwrap + LinearCost² fold)
- "What the compiler reports for nested algorithms" adds 2 Sum-side cases: Sum([Linear(n), Constant(5)]) → ClassLinear ✓ (dominance flow handles); Sum([Linear(n), Linear(m)]) → ClassUnknown ✗ (multi-var multi-term survivors, classifier-tier gap)
- "What's missing" item 1 (classifier composition handling) restructured to distinguish Sum-side single-dominator flow (already-correct via terminal arms post-dominance-reduction) from Product-side composition arms + multi-var Sum survivors (remaining classifier-tier gap)

B2 (Gap 12): "Gap 12 checked the target-specific predicate path but not the QuantifiedTestClaim path in verification.dag/test_runner.rs → rewrite HEAD evidence to say property-based quantifier evaluation is NYI while the shape and NYI runner boundary are already landed."

Same finding as briansrls inline BLOCKING on PR #3038 line 463 (which I fixed at PR #3038 sha 38fd26a). Porting the Gap 12 retargeting to PR #3037 since this PR is the source of Gap 12 framing.

Verified at HEAD: src/v3/std/verification.dag has type Quantifier = ForAll | Exists at claim-layer (separate from ForAllTargets cross-target predicate); type QuantifiedTestClaim { name, generator: ProgramGenerator, quantifier: Quantifier, predicate: TestPredicate, requires } at :542; full Suite + TestNode integration (:574 + :594) + obligation_for_quantified_claim at :627. Runner is NotYetImplemented at test_runner.rs:2511 with named gate #85 dissolution trigger via Cluster M Phase 2/3.

Fix at Gap 12 HEAD evidence:
- Replaces "ForAll wired only via ForAllTargets" framing with explicit citation of existing Quantifier + QuantifiedTestClaim + Suite/TestNode/obligation integration
- Result: gate #79 honest close requires (a) wiring the EXISTING QuantifiedTestClaim runner per gate #85 dissolution trigger, (b) authoring complexity-generator + oracle, (c) authoring property-based QuantifiedTestClaim data declarations against existing substrate (NOT extending ForAllTargets)
- "What's missing" recalibrated 5→6 items: NEW item 1 is runner wiring at test_runner.rs:2511; removed step "Extend ForAll quantifier surface from ForAllTargets" (was wrong authority)
- Plan to cash sub-program restructured: NEW step 1 audit QuantifiedTestClaim shape sufficiency; NEW step 5 wire runner at test_runner.rs:2511
- Close criterion adds (d): runner wired at test_runner.rs:2511 with N≥100 sample evaluation

This synchronizes PR #3037 Gap 12 framing with the corrective already landed on PR #3038 sha 38fd26a. When PR #3037 merges first (natural cadence), PR #3038's Gap 12 changes will be no-op overlap on rebase.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
…coercion-engine architectural separation (#3038)

* docs(r3): fix interrogation-doc JS/TS scope drift + add Gap 11 (LogCost asymmetry / complexity composition completeness)

Operator adversarial probe 2026-05-13 surfaced two issues:

1. docs/r3-close-interrogation.md §285 + §291 cited "Rust + JavaScript + Python (3 R3 Shape-A targets per §3.1)" — drift relative to §518 of same doc which correctly enumerates "R3 = 3 Shape-A targets: Rust / Python / Go". The JavaScript framing was operator-illustrative example pre-dating R3 scope finalization that authored into normative scope text.

Fix: §285 scope claim corrected to "Rust + Python + Go"; JavaScript references in bug-shape examples preserved as illustrative-not-scope with explicit clarifying note pointing to §518 authority. §291 cross-target-test-claim bullet expanded to include "Go via go test" alongside the illustrative JavaScript/jest reference.

2. Operator probe: "regarding complexity - what about more complex combinations of complexity - i.e. n log (n^k) i.e. nested algorithms - do we handle all permutations of those?" + "regarding logcost - my concern is that this seems orthogonal to logcost - shouldn't it work for any arbitrary combination of cost?"

HEAD audit: SymbolicCost in src/v3/std/algebra.dag has structural asymmetry — ProductCost + SumCost are recursive over arbitrary SymbolicCost; LogCost + PolynomialCost take only SizeVariable (terminal). Cannot construct Log(complex) directly. normalize() body handles sum/product identities + LinearCost-squared → PolynomialCost, but NO log-power rule (log(n^k) → k log(n)), NO log-product rule, NO nested-log handling. AsymptoticClass enumerated lattice ceilings on polynomial×log composition (loses log factor on classification).

Fix: Gap 11 added to close plan §1 — Complexity composition completeness / LogCost asymmetry. Sub-promise of gate #79 complexity behavioral close that the 2026-05-13 adversarial sweep missed. Owner: Substrate Mgr (warm-wolf-698). Substrate-shape canvas decision required: (A) LogCost recursive over SymbolicCost (symmetric with Product/Sum) OR (B) dag-authored canonicalization rule that runs before LogCost construction with named log-algebra coverage. Close criterion: shape ratified + normalize/canonicalization landed + lattice tier review + cementing corpus extended with nested compositions (n log n^k, n² log n, n log² n, log log n).

Plan §2 sequencing updated to include Gap 11 in Phase B (Substrate Mgr lane). §6 checklist updated with the post-§4-ratification adversarial finding status.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add Gap 12 (property-based complexity-lens validation via ProgramGenerator) per operator adversarial probe 2026-05-13

Operator follow-up probe 2026-05-13: "for complexity - do we have testcases representing random combinations of functions, validating that the correct complexity result is generated? please add that"

HEAD audit:
- `ProgramGenerator` substrate carrier LANDED (gate #86; `src/v3/std/verification.dag`) but only used in `m1_5_verification_test.rs::program_generator_authoring_surface_compiles_cleanly` (compile-surface verification, NOT actual random-program generation)
- `ForAll` quantifier in `verification.dag` is wired only for `ForAllTargets` (cross-target per Gap 2), NOT for `ForAll(random_program)` quantification
- Complexity cementing test at `src/v3/compiler/tests/integration/cementing/complexity_lens_behavioral_completion.rs`: only 2 hand-authored cases (`literal_bind_cements_constant_complexity_summary` + `recursive_countdown_cements_linear_work_and_span`)
- Zero `proptest` / `quickcheck` / random-composition tests against the complexity lens

Result: gate #79 `lens_capability_register_zero_proxy_zero_stub` lens-completion can claim "behaviorally complete" while never having validated against arbitrary nested compositions — the substrate's SymbolicCost composition class is enormous vs the 2 cementing cases.

Fix: Gap 12 added — Property-based complexity-lens validation via ProgramGenerator. Owner: Verification Mgr (still-moth-538). Substrate Mgr (warm-wolf-698) co-owns the ProgramGenerator-instance + oracle authoring.

Sub-program: (1) ProgramGenerator complexity-instance producing structurally-bounded random function compositions; (2) complexity oracle (`.dag`-authored function from generated-program → expected ComplexitySummary; NO bridge-Rust oracle per feedback_no_textual_enforcement_bridges); (3) `ForAll<ProgramGenerator>` quantifier extension (currently only ForAllTargets); (4) property-based TestClaim asserting complexity_of(g) == oracle(g) for N≥100 samples per CI run; (5) CI integration with seed-pinning + reproducibility discipline.

Close criterion: (a) ProgramGenerator complexity-instance landed; (b) `.dag`-authored oracle landed; (c) ForAll<ProgramGenerator> TestClaim landed + passing with N≥100; (d) zero oracle-vs-lens divergence; (e) CI seed-pinning ratcheted.

Effort estimate: 2-3 weeks, parallelizable with Gap 11 substrate-shape canvas authoring. Gap 12 generator depends on Gap 11 substrate decision so generator can produce the full composition class.

§2 sequencing updated: Gap 12 in Phase C (Verification Mgr lane); §6 checklist tracks Gap 12 as post-§4-ratification adversarial finding. Document order in §1 corrected to Gap 11 → Gap 12 (matching gap-number sequence).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): address briansrls BLOCKING on PR #3037 — recalibrate Gap 11 HEAD evidence + rewrite §285 probes to R3 targets

Two BLOCKING findings from operator briansrls comment-4445313478 at 2026-05-13T21:04:54Z:

B1 (docs/r3-actual-close-plan.md Gap 11): operator-probe notes were promoted to HEAD evidence without verifying actual classifier behavior in src/v3/std/algebra.dag + src/v3/compiler/src/dag_cost_generated.rs.

Verified HEAD evidence (revised):
- `classify_symbolic_cost` at dag_cost_generated.rs:289-312 maps ALL composite costs (ProductCost / SumCost) to `ClassUnknown` — no composition handling. Prior framing "lattice ceilings to ClassPolynomial" / "collapses to ClassLinearithmic" was wrong; actual behavior is collapse to ClassUnknown for any composition.
- `ClassLinearithmic` + `ClassExponential` are unreachable outputs from the classifier — only constructible via string-to-AsymptoticClass deserialization at enforced_lens_application.rs:960-962 for user-declared enforcement budgets. 2 of 8 lattice tiers are write-only.
- SymbolicCost substrate has no `ExponentialCost` variant; `2^n` cannot be represented in source cost. ClassExponential is the lattice analog but unreachable from any SymbolicCost expression.
- normalize() at algebra.dag:537-548 handles only sum/product identity rules + LinearCost-squared → PolynomialCost(degree=2). No log-rule simplification, no Product/Sum→named-tier normalization.

Recalibrated Gap 11 "What's missing" — 6 items (was 4): (1) classify_symbolic_cost composition arms (root issue — even n log n classifies to Unknown), (2) LogCost recursive shape OR canonicalization rule, (3) ExponentialCost variant decision, (4) ClassLinearithmic/Exponential reachability gap, (5) normalize log-rule extensions, (6) cost-lens fold audit.

Recalibrated close criterion — 7 items (was 5), adding (a) classifier produces all reachable tiers including ClassLinearithmic for n log n, (c) ExponentialCost ratified-or-excluded, (e) AsymptoticClass reachability review complete with formal annotation of input-only tiers.

Effort estimate revised up from 2-4 weeks to 3-5 weeks per recalibrated sub-program scope.

B2 (docs/r3-close-interrogation.md §285+§291+§295+§297+§312): the prior fix added a "JavaScript references are illustrative-not-scope" disclaimer but left the gating probes themselves using JavaScript examples. Per operator: "convert the concrete R3 probes to Rust/Python/Go".

Rewrote 5 gating probes + introduction + 2 falsification probes + 1 R3-close-audit-for-class line to use Rust/Go/Python concretely:
- Cross-target serialization round-trip: Rust → Go (not JS)
- Cross-target numeric width: Rust u32 vs Go uint32 vs Python arbitrary-precision int (not JS 53-bit)
- Cross-target effect divergence: Rust tokio vs Go goroutines+channels vs Python asyncio (not JS Promise)
- Cross-target boundary trust: Rust ↔ Go gRPC/HTTP/FFI (not Rust ↔ JS FFI/WASM)
- Cross-target test-claim transferability: cargo test / pytest / go test (removed JS jest)
- Modeling-level cross-target gap: Go's nil-interface-vs-nil-concrete-type (not JS prototype-pollution)
- R3 close audit demo: Rust server + Go client (not JS client)
- Introduction text: "Rust ↔ Go ↔ Python via shared .dag substrate" (was Rust ↔ JavaScript ↔ Python)

Disclaimer language removed — probes are now R3-scope-correct without needing a disclaimer.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): fix Gap 11 PolynomialCost field-type + line-cite per cursor APPROVE_WITH_COMMENTS PR #3037

Cursor BLOCKING (sha 412a8cb, 2026-05-13T21:16Z) — 2 substantive findings on Gap 11 HEAD evidence:

F1 (line 383, INVARIANTS P1 modeling-faithfulness): PolynomialCost field cited as `degree: Nat` but actual substrate at `src/v3/std/algebra.dag:193` is `degree: DegreeAtLeastTwo` (refinement type, NOT raw Nat). The refinement encodes substrate-level guarantee that polynomial degree ≥ 2 (degree 1 redundant with LinearCost; degree 0 redundant with ConstantCost). Load-bearing for ClassPolynomial classifier arm at `dag_cost_generated.rs:297-306` and string-arm decoding in `enforced_lens_application.rs`.

F2 (line 380, minor lens): cite "lines 190-196 (7 variants)" misaligns with substrate — line 190 is the `type SymbolicCost inhabits Semiring<SymbolicCost>` declaration; variant arms span lines 191-197 (7 arms). Corrected cite.

Fix: updated PolynomialCost row to `degree: DegreeAtLeastTwo` with named rationale + load-bearing-citation; corrected line-cite to "lines 191-197, 7 variant arms; inhabits Semiring<SymbolicCost> declaration at line 190".

Cursor exploratory note acknowledged: confirms Gap 11 evidence is otherwise correct (`ProductCost / SumCost → ClassUnknown` at dag_cost_generated.rs:308-310; `ClassLinearithmic` / `ClassExponential` string arms at enforced_lens_application.rs:960-962) — the PolynomialCost field-type was the only substantive slip.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add Gap 13 (R2-Grounding T-Ground sub-lane residuals / no-coercion-engine architectural separation) per operator adversarial probe 2026-05-13

Operator follow-on probe 2026-05-13: "I thought we were supposed to be separating emission into coercion and proper dag modeling? is it not even close to that?"

HEAD audit:
- docs/design-emission-model.md title: "Design — Emission Model (no separate coercion engine)" — explicit ratification of structural-projection coercion + DAG-modeled substrate separation
- 5 R2-T-Ground sub-lanes implement the separation: T-Ground-Coercion-Fold + T-Ground-LanguageSpec + T-Ground-Lifetime-Analyzer + T-Ground-Diagnostic + T-Ground-CrossTarget-Meta
- src/v3/compiler/src/emit.rs (3992 lines, hand-Rust) is the legacy v2 coercion engine the design retracts; still active at HEAD; on EXPECTED_HAND_AUTHORED_NON_TEST:279 (PB-0 ratchet)
- src/v3/std/emit_model.dag exists but marked 🟡 SCAFFOLD (Coercion-Fold dissolution — Slice B rows, Slice C consumer); per-target TypeRealization carrier partially-stubbed
- dsl/std/coercion.dag has new coercion vocabulary but still names v2/05_emit.dag as consumer in header comment (transitional form; legacy engine not retired)
- R2-Grounding closed-with-residuals 2026-04-29 (analogous to R2-Evaluator per Director audit msg_82b9c4bb); 5 T-Ground sub-lanes are R2-residual work carried into R3 as r3-continuation
- Close plan §1 at HEAD does NOT track these residuals as an explicit Gap — missed-during-original-sweep gap analogous to R2-Evaluator residuals that Gap 3 absorbed

Result: emit.rs retirement is structurally gated on 5 T-Ground sub-lanes + R2-Evaluator + PB-0 retirement campaign. PB-0 ratchet (177 entries) tracks emit.rs entry-counting but NOT architectural-shape verification. design-emission-model.md no-engine discipline is operator-named but close plan doesn't have a "no-engine discipline cashed at HEAD" check.

Fix: Gap 13 added — R2-Grounding T-Ground sub-lane residuals. Owner: Director-tier coordination (analogous to Gap 3 cross-Mgr audit); R3 Substrate Mgr (warm-wolf-698) owns sub-lane execution; Director ratifies audit verdict + any new §1.8 row.

Sub-program: (1) Director R2-Grounding audit analogous to msg_82b9c4bb R2-Evaluator audit; (2) per-sub-lane dispatch post-audit; (3) emit_model.dag SCAFFOLD dissolution (Coercion-Fold Slice B + Slice C); (4) coercion.dag v2/05_emit.dag consumer reference retirement; (5) §1.8 row decision (author "no-engine discipline cashed" row OR formally declare existing gate covers); (6) emit.rs entry retirement downstream of sub-lane completions.

Close criterion: (a) Director audit complete; (b) 5 R2-T-Ground sub-lanes status=green in docs/r2-closure-ledger.md refreshed against HEAD; (c) emit_model.dag SCAFFOLD marker removed; (d) coercion.dag v2/05_emit.dag reference removed; (e) emit.rs entry removed from EXPECTED_HAND_AUTHORED_NON_TEST; (f) §1.8 row landed or declared-covered.

Connection to Gap 1 + Gap 3: Gap 13 is architectural-shape sibling to Gap 1 (Gap 1 says "list empty"; Gap 13 says "the architectural separation that justifies the list-empty outcome is structurally complete"). Gap 13 is analogous R2-residual to Gap 3 (R2-Evaluator); both surfaced post-§4 — R2-Evaluator via Director audit, R2-Grounding via operator adversarial probe.

Effort estimate: 6-12 weeks (analogous to Gap 3 R2-Evaluator joint precondition; substrate-canvas-tier work dominant cost; per-sub-lane execution parallel-able under Substrate Mgr).

§2 sequencing updated: Gap 13 in Phase E (Director-tier coordination, parallel with Gap 3). §6 checklist tracks Gap 13 as post-§4-ratification adversarial finding requiring Director audit.

Stacks on PR #3037 (Gap 11 + Gap 12 + interrogation-doc drift fix); merges cleanly after PR #3037 lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): absorb Director R2-Grounding audit msg_8ae92369 — Gap 13 recalibration (5→11 sub-lanes) + §4 sub-item 6 + sequencing discipline

Director R2-Grounding audit (msg_8ae92369 2026-05-13) absorbed. Critical first-order finding: PM originally cited 5 T-Ground sub-lanes in Gap 13 framing; actual ledger count is **11 sub-lanes** per docs/r2-closure-ledger.md:108 ("11 lanes per engine-reframe") + docs/briefs/r2-grounding-manager.md:168 ("now 11 lanes; engine-reframe locked 2026-04-28"). PM-side under-counted the residual surface by ~half.

11-sub-lane recalibration:
- GREEN (1 of 11): T-Ground-Pilot (PR #765 merged 2026-04-25)
- IN-FLIGHT (7 of 11): T-Ground-Rust / Python / Go / LanguageSpec / Coercion-Fold / Lifetime-Analyzer / CrossTarget-Meta — each cites era-#1168-#1241 PRs + R3-tier slice landings; HEAD-state likely partial-cashed
- NOT-STARTED (3 of 11): T-Ground-Diagnostic / T-Ground-Tests / T-Ground-Dissolve (brief-only at R2-close)

Director estimation: 3-5 of 11 effectively GREEN at HEAD; 4-6 in-flight; 3 not-started. Full per-sub-lane HEAD audit needed (analogous to neat-heron-793 R2-Evaluator ledger refresh).

Director audit (b)/(c)/(d) findings:
- (b) NO R3 Grounding Mgr session in current subtree; authority partially dispersed under warm-wolf-698 Substrate Mgr organically (PR #1980 Coercion-Fold retirement + PR #2103 L6 + PR #2272 u128 + PR #2279 SelectedTargetInhabitance + PR #2229 cost_target_realization). Same anti-pattern as merry-gull-128 absence.
- (c) Brief coverage COMPREHENSIVE — even stronger than R2-Evaluator (8 dedicated T-Ground briefs + 9+ R3-tier slice briefs).
- (d) Director recommends OPTION (α) re-spawn R3 Grounding Mgr as 5th R3 Mgr lane (post-Evaluator re-spawn making 4), with critical scope-discrimination caveat: Mgr-tier brief authoring must discriminate Grounding-owned scope vs Substrate-Mgr-already-absorbed scope (warm-wolf-698 organic absorption).

Director sequencing discipline (Note 2 + Note 3 carried forward from msg_f0a54769):
- Close criterion = substrate-debt-only (11 sub-lanes status=green per r2-closure-ledger refresh + emit_model.dag SCAFFOLD dissolution + coercion.dag schema dissolution + emit.rs retirement + §1.8 row)
- Dispatch staffing prereq SEPARATE from close criterion (sub-item 6 ratification ≠ substrate-debt satisfaction)
- Sequencing: re-spawn AFTER operator §4 sub-item 6 ratification, NOT before

§4 sub-item 6 added: R3 Grounding Mgr dispatch shape — (α) re-spawn 5th R3 Mgr lane (PM + Director recommended with scope-discrimination canvas as first deliverable) / (β) fold into warm-wolf-698 Substrate Mgr (named scope-bloat risk: substantial dual-program lane shape; warm-wolf-698 already carries 9-worker Phase B batch + Cluster M Phase 3 coordination + canvas authoring) / (γ) Director-direct ad-hoc (PM does NOT recommend per r2-structure.md:73 anti-pattern).

Bundling: per Director recommendation, §4 sub-item 5 (Evaluator) + sub-item 6 (Grounding) need same dashboard-tier intervention (composite-shape support per operator escalation msg_acf78d37 in flight). Recommend bundling both into one operator-ratification batch — dashboard-tier intervention unblocks both lanes simultaneously.

Effort estimate revised: 6-12 weeks → 8-16 weeks (11 sub-lanes vs originally 5; scope-discrimination canvas added).

§6 checklist updated: Gap 13 entry refreshed with 11-sub-lane scope + audit completion; §4 sub-item 6 added as new checkbox bundled with sub-item 5.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): record operator ratification of §4 sub-item 6 + bundled-5-asks (R3 Grounding Mgr re-spawn + --shape flag + parser fix + PR #3036/#3025 merge-bypass) PR #3038

Operator briansrls ratified all 5 bundled asks 2026-05-13 via PM AskUserQuestion (per Director recommendation msg_eaaca237 + msg_922eac5b bundling; PM-routing per msg_7ce4dcc0):

1. Ask 1 — Dashboard-tier intervention: (b) durable `--shape` flag in dashboard-ops work-items create authorized (unblocks both Evaluator + Grounding Mgr re-spawn + all future Mgr-tier spawns)
2. Ask 2 — §4 sub-item 5 (R3 Evaluator Mgr): (α) re-spawn as 4th R3 Mgr lane RATIFIED
3. Ask 3 — §4 sub-item 6 (R3 Grounding Mgr): (α) re-spawn as 5th R3 Mgr lane RATIFIED with scope-discrimination canvas as Mgr-tier first-deliverable per Gap 13 sub-program step 3
4. Ask 4 — Cursor-composer-2 parser fix: (a) fix-dispatch authorized (class-level unblock for PR #3014/#3025/#3036/#3037)
5. Ask 5 — PR #3036 + PR #3025 merge-bypass: Director squash-merge both authorized (precondition (2) of feedback_operator_tier_merge_bypass_precedent cashed)

§6 checklist updates: §4 sub-item 6 marked [x] RATIFIED with execution shape; Gap 13 marked [x] with ratification context; previous Gap 13 entry recalibrated 5→11 sub-lanes per Director audit msg_8ae92369 preserved as audit trail.

§4 header: ratification outcomes split into two batches — "Initial ratification batch (PR #3013 merge)" covering items 1-5 + Phase A authorization; "Bundled-5-asks ratification batch (PR #3038 routing)" covering item 6 + dashboard-tier intervention + parser fix + bypass-merge directive.

§4 sub-item 6 preamble updated: now reads "RATIFIED (α) re-spawn by operator briansrls 2026-05-13 via bundled-5-asks PM-routing — see Ratification outcomes above". Pattern parallels sub-item 5 ratification framing.

§5 process discipline note updated: removed "meta-blocked" framing for Gap 3 + Gap 13 close-criteria (both sub-items 5 + 6 ratified; meta-block resolved); substrate-debt execution proceeds per ratified Mgr-lane dispatch shape (Director executes re-spawn post `--shape` flag landing per Ask 1).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): fix Phase E Gap 13 dispatch bullet — 5→11 sub-lanes + R3 Grounding Mgr execution per operator REQUEST_CHANGES on PR #3038

openai-pro REQUEST_CHANGES (briansrls comment-... 2026-05-13T21:52:16Z) — stale Phase E dispatch bullet at docs/r3-actual-close-plan.md:617 carried 2 errors against the recalibrated Gap 13 body:

1. "5 R2-T-Ground sub-lane status verification" — STALE; Director audit msg_8ae92369 recalibrated count to 11 sub-lanes (1 GREEN + 7 in-flight + 3 not-started); body at lines 505 + 564 already reflects 11
2. "Substrate Mgr executes sub-lane closures" — STALE; pre-assigned execution to Substrate Mgr before operator §4 sub-item 6 ratification. Operator ratified (α) re-spawn R3 Grounding Mgr (5th R3 Mgr lane) at 2026-05-13 via bundled-5-asks PM-routing; Grounding Mgr executes, NOT Substrate Mgr

openai-pro finding: "the stale Gap 13 Phase E line is load-bearing planning text" — a worker following Phase E could audit 5 lanes and stop while the close criterion requires 11, AND would route execution to Substrate Mgr instead of the ratified R3 Grounding Mgr lane.

Fix at line 617:
- "5 R2-T-Ground sub-lane status verification" → "11 R2-T-Ground sub-lanes" with explicit recalibration note + feedback_full_predicate_over_categorized_grep_in_scope_statements citation
- "Substrate Mgr executes sub-lane closures" → "R3 Grounding Mgr (5th R3 Mgr lane, re-spawn (α) RATIFIED by operator 2026-05-13 per §4 sub-item 6) executes the 11 sub-lane closures + scope-discrimination canvas as Mgr-tier first-deliverable"
- Added: execution gated on --shape flag landing per §4 sub-item 1 ratification

Now consistent with Gap 13 body (lines 505 + 564 + 736) + §4 sub-item 6 ratification state + Director audit findings (b)/(d).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): retarget Gap 12 to existing QuantifiedTestClaim authority + runner wiring per briansrls BLOCKING on PR #3038 line 463

briansrls BLOCKING comment-... 2026-05-13T22:42:32Z on docs/r3-actual-close-plan.md:463 (INVARIANTS P2 single authority / documentation describes live state) — Gap 12 framing pointed workers at wrong authority.

PRIOR (WRONG) FRAMING: "ForAll quantifier in verification.dag is wired only for ForAllTargets ... NOT for ForAll(random_program) quantification". Plan said workers should "extend ForAll quantifier surface from ForAllTargets to ForAll<ProgramGenerator>".

VERIFIED HEAD EVIDENCE (correcting the framing):
- `type Quantifier = ForAll | Exists` at src/v3/std/verification.dag — claim-layer quantifier for property-based testing; SEPARATE from ForAllTargets (which is the cross-target quantifier on different axis per Gap 2)
- `type QuantifiedTestClaim { name, generator: ProgramGenerator, quantifier: Quantifier, predicate: TestPredicate, requires: List<ResourceReference> }` at src/v3/std/verification.dag:542 — the EXISTING single-authority for ForAll<ProgramGenerator> property-based claims
- Suite integration LANDED: `type SuiteClaim = Enumerated(TestClaim) | Quantified(QuantifiedTestClaim)` at :594
- TestNode integration LANDED: `type TestNodeRef = EnumeratedTestNode(TestClaim) | QuantifiedTestNode(QuantifiedTestClaim)` at :574
- Obligation projection LANDED: `obligation_for_quantified_claim` at :627
- Test fixture LANDED: `data smoke_quantified_claim: QuantifiedTestClaim = { ... }` at test_runner_test.rs:1247
- Runner is `NotYetImplemented` at test_runner.rs:2511 with named gate #85 dissolution trigger via Cluster M Phase 2/3

Per the existing substrate, INVARIANTS P2 single-authority is structurally complete at the substrate level. The gap is the RUNNER, not the substrate.

CORRECTED FRAMING: Gap 12 now targets (1) wiring the existing QuantifiedTestClaim runner per gate #85 dissolution trigger, (2) authoring complexity-specific ProgramGenerator instance + oracle, (3) authoring property-based QuantifiedTestClaim data declarations against existing substrate. NOT extending ForAllTargets.

Sub-program restructured:
- Step 1 (NEW): audit QuantifiedTestClaim shape sufficiency per feedback_construction_over_ratchets (model first; extend only if needed)
- Step 5 (NEW): wire the runner at test_runner.rs:2511 (replace NotYetImplemented per gate #85 dissolution trigger — Cluster M Phase 2/3 lane scope per inline cite)
- Removed step "extend ForAll quantifier surface from ForAllTargets" (was wrong authority)

Close criterion adds (d): runner wired at test_runner.rs:2511 with N≥100 sample evaluation; removes prior "ForAll<ProgramGenerator> extension" framing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): fix stale Gap 13 dispatch-prereq blocker state — operator already ratified per briansrls openai-pro BLOCKING PR #3038

briansrls openai-pro REQUEST_CHANGES (manual-trigger sha 38fd26a 22:57Z) — line 591 stale relative to ratification state:

Finding (INVARIANTS P2 single-authority / top-down PM intent review): line 591 said "PM-recommendation Option (α) is on-record but execution waits on operator" — CONTRADICTS line 671 (§4 sub-item 6 RATIFIED) + line 722 (§5 process-discipline note: both sub-items ratified + execution proceeds after --shape lands). Worker following Gap 13 section could stall the lane incorrectly.

Root cause: I authored the Dispatch staffing prereq paragraph BEFORE operator §4 sub-item 6 ratification landed (commit 962ce5d). When I recorded ratification at commit 198a752, I updated §4 + §6 checklist but didn't update this prereq paragraph. Stale pre-ratification framing survived.

Fix: rewrote Dispatch staffing prereq paragraph to reflect post-ratification state:
- "RATIFIED 2026-05-13 per §4 sub-item 6: (α) re-spawn as 5th R3 Mgr lane confirmed"
- Sequencing now says "re-spawn occurs AFTER --shape flag landing per §4 Ask 1 ratification" (NOT "AFTER operator §4 sub-item 6 confirmation")
- Cites Director dispatched --shape flag worker adhoc-745d73fa-6c4 per msg_14c3ad9d
- Explicit: "execution is now gated on dashboard-tier --shape flag availability, NOT on operator confirmation (which is already in place)"

PR #3038 was ready=True (2 distinct approvals codex + cursor on 38fd26a; 0 active reviews; mergeable=MERGEABLE; checks=passing) when briansrls manual-triggered openai-pro found this stale line. Fix is small + restores ready=True path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 14, 2026
… 5 close prereq) (#3040)

* WIP: R3 Cluster M generator-manifest substrate refinement (Gap 5 close prereq

* WIP: substrate-shape consumer migration + bootstrap regen

Cluster M generator-manifest substrate refinement — substrate-shape-only
scope per amended brief msg_606e0e50 (Q3-amend ContentHash + runtime
split). Applies the consumer-side migration on top of the prior
verification.dag refinement:

- test_runner.rs eval_generated_from_dag_shape: 4-site lockstep
  field-rename from generated_paths to manifest_entries. Reads
  entry.output_path for the existing one-direction set-membership +
  outside-paths hand-count semantics; dag_source + source_hash are
  carried forward unused for the follow-up Evaluator-Mgr-owned runtime
  PR (3-way byte-equality assertion + directory-walk).
- tests/dag/t_r1c_d_pb_census_gates.dag fixture migrated to
  manifest_entries with bare-record literals; dag_source +
  source_hash stubs per Director Q-FixtureMapping deferral.
- tests/integration/test_runner_test.rs inline DSL fixture migrated
  identically.
- tests/integration/m1_5_verification_test.rs reflection expectation
  updated for the renamed payload field.
- Bootstrap regenerated via `cargo run -p v3-compiler --bin
  regen_bootstrap --features bootstrap-regen-fresh`.

BLOCKED on STOP-AND-PING msg_ceb979d1: ContentHash branded literals
fail where-refinement narrowing at the literal boundary in fixture
contexts (lower.rs:6094). Holding for parent ratification on α
(substrate-side narrowing-branch extension) vs β (drop the brand;
use NonEmptyStr matching SnapshotRef precedent) before the fixture
sites compile.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Flip source_hash: ContentHash → NonEmptyStr (Director Q3-RE-AMEND β)

Per Director ratification msg_8423d468 + parent re-amended brief
(commit 39787ca): drop the `ContentHash` brand on
`GeneratedManifestEntry.source_hash`; use bare `NonEmptyStr` matching
the `SnapshotRef = NonEmptyStr` carrier-shape precedent at
`verification.dag:31` + `FixedPointConverges.expected` at line 431.

The branded `where brand("ContentHash")` refinement fails literal-
narrowing discharge in fixture contexts (`lower.rs:6094`); no
construction precedent for branded NonEmptyStr literals exists on
main today. Substrate-side narrowing-branch extension (path α)
preserved as future canvas; this PR remains substrate-shape-only
per the Q-RegenCapability β split. Branded `ContentHash` re-
introduction is deferred to the follow-up Evaluator-Mgr-owned
runtime PR at its hash-derivation construction boundary, where
lowerer constraints do not apply.

Bootstrap regenerated via `cargo run -p v3-compiler --bin
regen_bootstrap --features bootstrap-regen-fresh`.

Key integration tests now green:
- test_runner_dispatches_pb_census_predicate_shapes
- r1c_d_pb_census_gates_suite_evaluates_through_runner

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Regenerate bootstrap after main merge (β source_hash + main drift)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Align brief with landed shape — Q3-RE-AMEND β NonEmptyStr (addresses cursor/composer-2 finding)

cursor/composer-2 review on sha 3b5bef8 flagged brief vs verification.dag
authority drift per INVARIANTS P1 "documentation describes live state":
brief §0/§1.1 still showed source_hash: ContentHash after the Q3-RE-AMEND β
flip to NonEmptyStr landed in verification.dag (msg_8423d468).

Updated brief sections to reflect the two-cycle Q3 ratification history:
header (RE-AMENDED status), §0 (NonEmptyStr field type), §1.1 (type-sketch
+ Why-section now narrates both cycles), §5 trigger (iii) (RESOLVED via
β re-amend), §7.2 (follow-up runtime PR may re-introduce branded
ContentHash at its construction boundary), §8 references (msg_8423d468
added + ContentHash carrier as deferred re-introduction).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Migrate GeneratedManifestEntry to PendingFact | ResolvedFact sum-variant

Director Q-StubValuePosture (b) ratification msg_3b99a90f resolves the
codex BLOCKING review on PR #3040: prior struct-with-stubs framing for
`GeneratedManifestEntry { output_path, dag_source, source_hash }`
required fixtures to fabricate `dag_source` / `source_hash` values
(C-9: "missing fields / values may not fabricate empty nodes or
strings" under INVARIANTS P3). Substrate Mgr msg_c2ae1158 proposed +
Director ratified the typed-state-explicit sum-variant shape:

  type GeneratedManifestEntry
    = PendingFact { output_path: Path }
    | ResolvedFact {
        output_path: Path
        dag_source: DeclarationRef
        source_hash: NonEmptyStr
      }

`PendingFact` IS the typed "unknown" carrier — no fabricated facts.
`ResolvedFact` materialization defers to the follow-up Evaluator-Mgr-
owned runtime PR where hash-derivation produces real values at the
construction boundary. Gate #86 PASSING preserved on shape; the
3-way byte-equality assertion only fires on `ResolvedFact` arms.

Evaluator side reads `output_path` from whichever variant arm; the
runner handles both the single-field PendingFact shorthand (payload
flattened to a bare String literal) and the multi-field ResolvedFact
record-payload shape via dual destructure.

Fixture sites migrated to PendingFact-only:
- tests/dag/t_r1c_d_pb_census_gates.dag (3 entries)
- tests/integration/test_runner_test.rs (inline DSL, 1 entry)

Bootstrap regenerated via regen_bootstrap --features bootstrap-regen-fresh.
Key integration tests green:
- test_runner_dispatches_pb_census_predicate_shapes ✓
- r1c_d_pb_census_gates_suite_evaluates_through_runner ✓

Other m1_5_verification_test / m1_5_testgen_test failures are
pre-existing on main (verified via stash diff) and unrelated to this
substrate refinement.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Sync amended brief from warm-wolf-698 (sum-variant PendingFact|ResolvedFact)

Brings docs/briefs/r3-cluster-m-generator-manifest-substrate-refinement-worker.md
into alignment with the substrate-shape now landed in this PR. Parent
authored commit 9fe0962 on session/warm-wolf-698-gate-63-canvas;
syncing here so this PR carries the authoritative brief alongside the
substrate edits it ratifies.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Regenerate bootstrap after main merge (sum-variant + main drift)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore: apply cargo fmt (sum-variant migration formatting)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Regenerate bootstrap after main merge (T-WAD Slice 6 drift)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Brief §0: align scope bullets with sum-variant PendingFact shape (openai-pro non-blocking finding)

openai-pro/gpt-5-5-pro APPROVE_WITH_COMMENTS on sha 29786cb flagged
brief §0 line 20 still referenced "trivial dag_source + trivial
source_hash" stubs from the pre-sum-variant framing. Per P3 / C-9 +
Director Q-StubValuePosture (b) ratification msg_3b99a90f, the
implemented contract is that pending entries carry no fabricated
provenance — fixture sites use PendingFact { output_path } only.

Updated §0 IN-SCOPE bullets so a follow-up worker reads the
authoritative landed shape (sum-variant + NonEmptyStr) and the
PendingFact-only fixture posture, not the retracted stub framing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Fix ResolvedFact decode for multi-field positional payload (codex BLOCKING)

codex/codex-default BLOCKING at test_runner.rs:5052 sha 1fbda4d:
ResolvedFact accepted by label but routed through single_payload, while
.dag variant constructors lower multi-field payloads positionally — any
resolved manifest entry would fail-closed BEFORE the promised follow-up
hash check could consume it (P2 facts-flow-forward / fail-closed
contract). Verified empirically: ResolvedFact { output_path, dag_source,
source_hash } lowers as payload=[<output_path>, <dag_source>,
<source_hash>] (3 positional slots), not [Record { ... }].

Replace the single_payload-based decode with a head-slot reader that
accepts all three observed lowering shapes:
- single-field record variants (PendingFact) → payload=[<bare literal>]
- multi-field record variants (ResolvedFact) → payload=[<output_path>,
  <other_slots>...]
- record-wrapped (some construction paths) → payload=[Record { ... }]

Both arms of GeneratedManifestEntry place output_path at field index 0,
so reading payload[0] (with optional record-fields fallback) extracts
the path correctly in every supported lowering shape.

Inline test fixture now exercises both PendingFact AND ResolvedFact
arms in the same GeneratedFromDag predicate, ratcheting the dual-decode
path so the follow-up Evaluator-Mgr-owned runtime PR can land hash-
check semantics on a structurally-consumable carrier.

Key integration tests green:
- test_runner_dispatches_pb_census_predicate_shapes ✓
- r1c_d_pb_census_gates_suite_evaluates_through_runner ✓

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 14, 2026
…rsor finding)

cursor/composer-2 APPROVE_WITH_COMMENTS flagged a naming slip:
ledger row #86 named the receipt as
`t_r1c_d_pb_census_gates_suite_evaluates_through_runner` but the
wired integration test is
`t_pb_b_1_dag_runner_test::r1c_d_pb_census_gates_suite_evaluates_through_runner`
(no `t_` prefix on the test fn; the `t_` lives on the module name).
The .dag harness header at tests/dag/t_r1c_d_pb_census_gates.dag is
the source of truth.

INVARIANTS 'documentation describes live state' — grep-accurate symbol
restored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 14, 2026
* §1.8 ledger-receipt sync — rows #84 #86 post-PR-#3040 landing

Per feedback_post_merge_ledger_receipt_sync: atomic post-merge ledger
sync following PR #3040 squash-merge (SHA 7c29361 "R3 Cluster M
generator-manifest substrate refinement (shape-only; Gap 5 close
prereq)").

Row #84 `every_rust_test_ports_to_dag_or_generated`:
- Adds explicit substrate-shape-readiness landing citation against
  PR #3040 / 7c29361 (GeneratedFromDag.manifest_entries + sum-variant
  GeneratedManifestEntry = PendingFact | ResolvedFact per Director
  msg_3b99a90f).
- Documents that Gap 5 actual close remains gated on the follow-up
  Evaluator-Mgr-owned runtime PR per Director Q-RegenCapability β
  SPLIT disposition (msg_606e0e50) + brief §7.1: 3-way byte-equality
  assertion + directory-walk orphan-output detection at the well-known
  tests/ scan-root.
- References the Verification-Mgr-owned per-file FixtureMapping
  enumeration follow-up (brief §7.2) that materialises ResolvedFact
  instances once the runtime PR lands.

Row #86 `program_generator_carrier_landed`:
- Preserves CONSUMER_LANDED + PASSING status.
- Adds "refined shape PASSING preserved in-place" citation against
  PR #3040 / 7c29361 — the carrier moved from
  generated_paths: List<Path> to manifest_entries:
  List<GeneratedManifestEntry> (sum-variant) without PASSING regression;
  r1c_d_pb_census_gates_suite_evaluates_through_runner continues
  green under the refined shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Fix row #86 test symbol — module-qualified, no spurious t_ prefix (cursor finding)

cursor/composer-2 APPROVE_WITH_COMMENTS flagged a naming slip:
ledger row #86 named the receipt as
`t_r1c_d_pb_census_gates_suite_evaluates_through_runner` but the
wired integration test is
`t_pb_b_1_dag_runner_test::r1c_d_pb_census_gates_suite_evaluates_through_runner`
(no `t_` prefix on the test fn; the `t_` lives on the module name).
The .dag harness header at tests/dag/t_r1c_d_pb_census_gates.dag is
the source of truth.

INVARIANTS 'documentation describes live state' — grep-accurate symbol
restored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls
briansrls deleted the claude/blue-team-bt1 branch June 1, 2026 18:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant