From f5b02e8cab61346fce7e2a356f599fcd86db06fc Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Thu, 20 Aug 2026 03:57:56 +0000 Subject: [PATCH 01/12] stage0 mirror debt: the 15 drifted mirrors as declared debt with derived membership MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Nothing on main writes the stage0 Rust mirrors — RegenVerifyGate and SelfHostStalenessGate were deleted at the root in the regen cut and no workflow computes the fixed point — so drift accumulates unobserved. required-regen is red on main tip with 15 files. Operator ruling (relayed via deep-ant-102): disposition the population as declared debt now, re-gate next. Regenerating main is refused while no writer exists and while the emitter produces the E0583 defect. Membership is NOT authored: it is whatever the comparator reports. Only the per-row disposition is authored, and an undispositioned drift refuses, so forgetting a judgement breaks loudly rather than silently shrinking the reported population. No digest columns. A stored desired digest is a fact about the generator binary, not about this repository, and would go silently wrong the next time the emitter changes; a stored committed digest would make the gate forgeable by hand-editing a mirror and retyping its row. Population corroborated by two independent runs on two commits (102bd153315 and main tip 23dd9f6abba) returning the same 15 names. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FwPMTY6Myy3scaMNn33cg5 --- dag/gunbc/stage0_mirror_debt.dag | 107 +++++++++++++++++++++++++++++++ 1 file changed, 107 insertions(+) create mode 100644 dag/gunbc/stage0_mirror_debt.dag diff --git a/dag/gunbc/stage0_mirror_debt.dag b/dag/gunbc/stage0_mirror_debt.dag new file mode 100644 index 00000000000..581ee897aa6 --- /dev/null +++ b/dag/gunbc/stage0_mirror_debt.dag @@ -0,0 +1,107 @@ +module gunbc.stage0_mirror_debt + +// The committed stage0 Rust mirrors that differ from what their authority emits today. +// +// MEMBERSHIP IS NOT AUTHORED HERE. The population is whatever the required-regen comparator +// reports as drifted on the run. What is authored is the per-row DISPOSITION: why a drifted +// path is carried rather than repaired. A drifted path with no authored disposition refuses. +// That is the honest failure direction — forgetting a judgement breaks loudly, whereas +// forgetting a row would be invisible and the reported count would still read as stable. +// +// WHY THE DEBT EXISTS AT ALL: nothing on main writes these mirrors. RegenVerifyGate and +// SelfHostStalenessGate were deleted at the root in the regen cut, and no workflow computes +// the fixed point, so drift accumulates unobserved. Operator ruling 2026-08-20 (relayed via +// deep-ant-102): disposition the population as declared debt now, re-gate next; regenerating +// main is REFUSED while no writer exists and while the emitter produces the defect below. + +type MirrorAuthority + = SourceModule { name: String } + | CrateRootAggregate + +// CrateRootAggregate is NULLARY on purpose. lib.rs is assembled by the emitter from the set it +// actually emitted; it carries no `// Source module:` line and there is no module to name. +// It must NOT cite gunbc.stage0_emit_plan_generated even though that roster lists lib.rs among +// its paths: that projection's generator gunbc.stage0_emit_plan is DELETED, so the citation +// would point at a dead producer and be wrong in a way nothing would catch. A payload here +// would say something false; nullary says the true thing. + +type MirrorGenerator + = Stage0Emit + | WetActuator + +// Stage0Emit is the required-regen population. WetActuator is the separately actuated kind. +// READ THE NEXT TWO NAMES CAREFULLY, THEY DIFFER BY ONE LEADING WORD AND ARE OPPOSITE KINDS: +// gunbc_stage0_crate_layout_generated.rs Stage0Emit — IS in this population +// bootstrap_stage0_crate_layout_generated.rs WetActuator — is NOT, and is the only stage0 +// path named in gunbc.generated_artifact + +type MirrorDebtDisposition + = CarriedNoWriter + | CarriedEmissionDefective { defect: String } + | CarriedReasonNotEstablished + +// CarriedReasonNotEstablished is a DEFERRED question about a real thing, not an invented one: +// each row below measurably drifts, so a cause exists for every one of them; which cause is +// simply not established yet. Defaulting these into CarriedNoWriter would assert a cause +// nobody measured, and authoring bespoke reasons that cannot be defended would be fabricated +// plausible output. The arm is deliberately cheap to write: forcing an author to produce a +// reason at the moment of refusal manufactures exactly the plausible-sounding cause this +// column exists to keep out. +// +// SO THE CLAIM THIS CARRIER SUPPORTS IS NARROW, AND IS STATED HERE RATHER THAN LEFT TO BE +// DISCOVERED AS A WEAKNESS: every drifted path is ACCOUNTED FOR. Not every drifted path is +// UNDERSTOOD. The count of rows on this arm is reported and ranked every run, and it is +// NEVER gated — membership is derived, so ordinary authority work grows the population +// through no fault of any author, and a monotone cap would make legitimate work unlandable +// behind a red the contributor cannot close. + +type MirrorDebtRow { + path: String + authority: MirrorAuthority + generator: MirrorGenerator + disposition: MirrorDebtDisposition +} + +// THE POPULATION AS MEASURED. Two independent runs on two different commits returned this +// same 15-name list: snappy-eagle-615's run at 102bd1533150d04e9fc8bcf423a24c43e09a3713 (SHA +// baked as a literal and asserted in-script, EXPECT == ACTUAL) and a second run at main tip +// 23dd9f6abbaa18720ba6272f40851003c0747c76. Two commits, two runs, identical membership. +// That corroborates the POPULATION only — both runs used the same comparator, so it is not +// independent evidence about the comparator itself. +// +// These rows are transcribed from that measurement and are NOT the gate's oracle. The gate +// recomputes both sides per run and takes its baseline from git. Nothing here is a digest, +// deliberately: a stored desired digest is not a fact about this repository at all, it is a +// fact about the generator binary that produced it, and it would go silently wrong the next +// time the emitter changes. +// +// CarriedNoWriter is currently UNINHABITED and that is deliberate rather than an oversight. +// The absent writer is why NO row gets repaired — it is a global fact about main, not a +// discriminating per-row cause — so claiming it for a specific path would assert more than +// was measured. The arm stays declared because the gate switches on it and because a row +// will earn it as soon as one file's drift is shown to be ordinary staleness. + +data stage0_mirror_debt_rows: List = [ + MirrorDebtRow { + path: "src/v1/stage0/src/gunbc_stage0_crate_layout_generated.rs", + authority: SourceModule { name: "gunbc.stage0_crate_layout_generated" }, + generator: Stage0Emit, + disposition: CarriedEmissionDefective { + defect: "Regenerating this path emits a bare `pub mod` name inside a Rust string literal, so the emitted crate fails rustc E0583 (unresolved module). The bare names sit in a string constant of the committed mirror, which is why no emitter change reaches them and why the repair is a regeneration rather than a code edit. Blocked while regenerating main is refused." + } + }, + MirrorDebtRow { path: "src/v1/stage0/src/lib.rs", authority: CrateRootAggregate, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/std_algebra.rs", authority: SourceModule { name: "std.algebra" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/std_measure.rs", authority: SourceModule { name: "std.measure" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/std_occurrence_binding_candidates.rs", authority: SourceModule { name: "std.occurrence_binding_candidates" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/std_pareto.rs", authority: SourceModule { name: "std.pareto" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/std_witness_admission.rs", authority: SourceModule { name: "std.witness_admission" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_complexity.rs", authority: SourceModule { name: "v1.compiler.complexity" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_emit.rs", authority: SourceModule { name: "v1.compiler.emit" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_emit_rust.rs", authority: SourceModule { name: "v1.compiler.emit_rust" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_infer.rs", authority: SourceModule { name: "v1.compiler.infer" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_infer_lookup.rs", authority: SourceModule { name: "v1.compiler.infer_lookup" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_infer_resolve.rs", authority: SourceModule { name: "v1.compiler.infer_resolve" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_parse.rs", authority: SourceModule { name: "v1.compiler.parse" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/v1_std_core.rs", authority: SourceModule { name: "v1.std.core" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished } +] From 314621fa9652ab0760eca78fa251cbd096e63deb Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Thu, 20 Aug 2026 04:03:06 +0000 Subject: [PATCH 02/12] stage0 mirror debt: five rows upgraded off the unestablished arm by measurement; the defect arm withdrawn Captured the literal emitted-vs-committed diff for five of the fifteen and found two distinct mechanisms, neither of which was guessable from the line counts: MODULE-SET DRIFT lib.rs is short exactly one `pub mod` line, and the crate-layout mirror's three string-literal module lists are behind, including a rename (expected_red_roster_join -> v1_compiler_expected_red_roster_join). MATCH-GUARD EMISSION the emitter now emits `if matches!(..)` guards on match arms the committed mirror carries unguarded. Seen in std_occurrence_binding_candidates.rs, v1_compiler_infer_resolve.rs, v1_compiler_emit.rs. Both are ordinary staleness, so those five become CarriedAuthorityAdvanced. The other ten were not individually diffed and stay CarriedReasonNotEstablished: drift spans three orders of magnitude, so a shared mechanism is a hypothesis, not a measurement. CarriedEmissionDefective is WITHDRAWN entirely. The one row nominated for it was the crate-layout mirror, on the strength of a report that the regenerated crate fails rustc E0583. The emitted candidate measured here carries the CORRECTED module name, so this file's own evidence does not support the defect claim, and the report was another session's measurement not reproduced here. Filing an unverified defect would be exactly the fabricated cause this column exists to keep out. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FwPMTY6Myy3scaMNn33cg5 --- dag/gunbc/stage0_mirror_debt.dag | 52 +++++++++++++++++++++----------- 1 file changed, 35 insertions(+), 17 deletions(-) diff --git a/dag/gunbc/stage0_mirror_debt.dag b/dag/gunbc/stage0_mirror_debt.dag index 581ee897aa6..3946cbfe3e3 100644 --- a/dag/gunbc/stage0_mirror_debt.dag +++ b/dag/gunbc/stage0_mirror_debt.dag @@ -36,24 +36,44 @@ type MirrorGenerator // path named in gunbc.generated_artifact type MirrorDebtDisposition - = CarriedNoWriter - | CarriedEmissionDefective { defect: String } + = CarriedAuthorityAdvanced | CarriedReasonNotEstablished +// CarriedAuthorityAdvanced: MEASURED as ordinary staleness — the authority moved and the +// committed mirror did not follow, so a regeneration would close it and nothing more is wrong. +// Two mechanisms were observed directly in the emitted-versus-committed diff: +// MODULE-SET DRIFT the emitted crate names modules the committed mirror does not, and +// renames one (`expected_red_roster_join` becomes +// `v1_compiler_expected_red_roster_join`). Seen in lib.rs, which is +// short exactly one `pub mod` line, and in the crate-layout mirror, +// whose three string-literal module lists are each behind. +// MATCH-GUARD EMISSION the emitter now emits `if matches!(..)` guards on match arms that the +// committed mirror carries unguarded. Seen in +// std_occurrence_binding_candidates.rs, v1_compiler_infer_resolve.rs and +// v1_compiler_emit.rs. +// // CarriedReasonNotEstablished is a DEFERRED question about a real thing, not an invented one: -// each row below measurably drifts, so a cause exists for every one of them; which cause is -// simply not established yet. Defaulting these into CarriedNoWriter would assert a cause -// nobody measured, and authoring bespoke reasons that cannot be defended would be fabricated -// plausible output. The arm is deliberately cheap to write: forcing an author to produce a -// reason at the moment of refusal manufactures exactly the plausible-sounding cause this -// column exists to keep out. +// every row below measurably drifts, so a cause exists for each; which cause is simply not +// established yet. These ten were not individually diffed. Defaulting them into +// CarriedAuthorityAdvanced would generalise from five files to fifteen — the drift ranges over +// three orders of magnitude (1 to 492 changed lines), so a shared mechanism is a hypothesis and +// not a measurement. The arm is deliberately cheap to write: forcing an author to produce a +// reason at the moment of refusal manufactures exactly the plausible-sounding cause this column +// exists to keep out. // // SO THE CLAIM THIS CARRIER SUPPORTS IS NARROW, AND IS STATED HERE RATHER THAN LEFT TO BE // DISCOVERED AS A WEAKNESS: every drifted path is ACCOUNTED FOR. Not every drifted path is -// UNDERSTOOD. The count of rows on this arm is reported and ranked every run, and it is -// NEVER gated — membership is derived, so ordinary authority work grows the population +// UNDERSTOOD. The count of rows on the unestablished arm is reported and ranked every run, and +// it is NEVER gated — membership is derived, so ordinary authority work grows the population // through no fault of any author, and a monotone cap would make legitimate work unlandable // behind a red the contributor cannot close. +// +// NO ARM CLAIMS A DEFECTIVE EMISSION. An earlier revision of this file dispositioned the +// crate-layout mirror as emission-defective, citing a report that the regenerated crate fails +// rustc E0583. That disposition was withdrawn: the emitted candidate measured here carries the +// CORRECTED module name, so this file's own evidence does not support the defect claim, and the +// E0583 report belongs to another session's measurement that was not reproduced here. Filing an +// unverified defect would have been the fabricated-cause failure this column exists to prevent. type MirrorDebtRow { path: String @@ -86,22 +106,20 @@ data stage0_mirror_debt_rows: List = [ path: "src/v1/stage0/src/gunbc_stage0_crate_layout_generated.rs", authority: SourceModule { name: "gunbc.stage0_crate_layout_generated" }, generator: Stage0Emit, - disposition: CarriedEmissionDefective { - defect: "Regenerating this path emits a bare `pub mod` name inside a Rust string literal, so the emitted crate fails rustc E0583 (unresolved module). The bare names sit in a string constant of the committed mirror, which is why no emitter change reaches them and why the repair is a regeneration rather than a code edit. Blocked while regenerating main is refused." - } + disposition: CarriedAuthorityAdvanced }, - MirrorDebtRow { path: "src/v1/stage0/src/lib.rs", authority: CrateRootAggregate, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/lib.rs", authority: CrateRootAggregate, generator: Stage0Emit, disposition: CarriedAuthorityAdvanced }, MirrorDebtRow { path: "src/v1/stage0/src/std_algebra.rs", authority: SourceModule { name: "std.algebra" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, MirrorDebtRow { path: "src/v1/stage0/src/std_measure.rs", authority: SourceModule { name: "std.measure" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, - MirrorDebtRow { path: "src/v1/stage0/src/std_occurrence_binding_candidates.rs", authority: SourceModule { name: "std.occurrence_binding_candidates" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/std_occurrence_binding_candidates.rs", authority: SourceModule { name: "std.occurrence_binding_candidates" }, generator: Stage0Emit, disposition: CarriedAuthorityAdvanced }, MirrorDebtRow { path: "src/v1/stage0/src/std_pareto.rs", authority: SourceModule { name: "std.pareto" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, MirrorDebtRow { path: "src/v1/stage0/src/std_witness_admission.rs", authority: SourceModule { name: "std.witness_admission" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_complexity.rs", authority: SourceModule { name: "v1.compiler.complexity" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, - MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_emit.rs", authority: SourceModule { name: "v1.compiler.emit" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_emit.rs", authority: SourceModule { name: "v1.compiler.emit" }, generator: Stage0Emit, disposition: CarriedAuthorityAdvanced }, MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_emit_rust.rs", authority: SourceModule { name: "v1.compiler.emit_rust" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_infer.rs", authority: SourceModule { name: "v1.compiler.infer" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_infer_lookup.rs", authority: SourceModule { name: "v1.compiler.infer_lookup" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, - MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_infer_resolve.rs", authority: SourceModule { name: "v1.compiler.infer_resolve" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, + MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_infer_resolve.rs", authority: SourceModule { name: "v1.compiler.infer_resolve" }, generator: Stage0Emit, disposition: CarriedAuthorityAdvanced }, MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_parse.rs", authority: SourceModule { name: "v1.compiler.parse" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, MirrorDebtRow { path: "src/v1/stage0/src/v1_std_core.rs", authority: SourceModule { name: "v1.std.core" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished } ] From 177e2bbc69636f2c228a245d9450a27d604663a9 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Thu, 20 Aug 2026 04:07:08 +0000 Subject: [PATCH 03/12] stage0 mirror debt: withdraw the cross-commit stability claim from the carrier The population comment asserted that two runs at two different commits returned the same 15 names, and offered that as the baseline's strongest evidence. Both runs measured the SAME tree: ctrl-build applies the dispatcher's local diff as patches after checkout, and patches do not move HEAD, so the run reporting a main-tip SHA had been patched back to 102bd15331. What survives is reproducibility by two operators at one commit. Stability of the population across commits is NOT established, and the carrier now says so rather than implying otherwise. The retraction is recorded in place rather than deleted: the withdrawn claim was broadcast fleet-wide and acted on, so a carrier that quietly drops the premise would leave consumers still holding it. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FwPMTY6Myy3scaMNn33cg5 --- dag/gunbc/stage0_mirror_debt.dag | 20 ++++++++++++++------ 1 file changed, 14 insertions(+), 6 deletions(-) diff --git a/dag/gunbc/stage0_mirror_debt.dag b/dag/gunbc/stage0_mirror_debt.dag index 3946cbfe3e3..41d71dce11e 100644 --- a/dag/gunbc/stage0_mirror_debt.dag +++ b/dag/gunbc/stage0_mirror_debt.dag @@ -82,12 +82,20 @@ type MirrorDebtRow { disposition: MirrorDebtDisposition } -// THE POPULATION AS MEASURED. Two independent runs on two different commits returned this -// same 15-name list: snappy-eagle-615's run at 102bd1533150d04e9fc8bcf423a24c43e09a3713 (SHA -// baked as a literal and asserted in-script, EXPECT == ACTUAL) and a second run at main tip -// 23dd9f6abbaa18720ba6272f40851003c0747c76. Two commits, two runs, identical membership. -// That corroborates the POPULATION only — both runs used the same comparator, so it is not -// independent evidence about the comparator itself. +// THE POPULATION AS MEASURED, AT ONE COMMIT: 102bd1533150d04e9fc8bcf423a24c43e09a3713. +// Two operators dispatched independently and both returned this same 15-name list. That +// establishes the measurement REPRODUCES. It does NOT establish that the population is stable +// across commits, and nothing here should be dispositioned on that premise. +// +// An earlier revision of this comment claimed the two runs were at two different commits and +// offered that as the strongest evidence for the baseline. It is WITHDRAWN. Both runs measured +// the same tree: ctrl-build fetches a base, checks it out, then applies the dispatcher's local +// diff as patches, and patches do not move HEAD — so the second run reported a main-tip SHA +// while its content had been patched back to this commit. The retraction is recorded here +// rather than silently deleted, because the withdrawn claim was broadcast and acted on, and a +// carrier that quietly drops a premise leaves every consumer still holding it. +// +// Neither run is independent evidence about the COMPARATOR: both used it. // // These rows are transcribed from that measurement and are NOT the gate's oracle. The gate // recomputes both sides per run and takes its baseline from git. Nothing here is a digest, From 082bb13709f41bcace650660d1f745c78985c1c9 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Thu, 20 Aug 2026 04:16:23 +0000 Subject: [PATCH 04/12] stage0 mirror debt: delete a comment naming an arm the type does not have; state the join key MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The trailing block asserted that CarriedNoWriter "is currently UNINHABITED" and that "the gate switches on it". No such constructor exists — MirrorDebtDisposition is CarriedAuthorityAdvanced | CarriedReasonNotEstablished. The paragraph survived the revision that renamed the arm. This is the DESIGN 4c class in a file about that class: a // block asserting a machine fact its own declaration contradicts, unreadable by any Accepted program, so nothing catches it. It also named its consumer by name, so a gate wired from the prose rather than the type would have matched a constructor that does not exist and surfaced the error in the reader's lane. Deleted rather than re-added: no row inhabits it, and a variant nothing carries is speculative modeling. Also states the join key. Membership arrives from the comparator as BASENAMES; the path field is the display form. Sound because the generated surface is one flat directory, but it is a second key space over one population and has already cost a dispatch — a regen refusing "emit missing generated file compiler_tests.rs" because the emit map keys on emit path while the roster keys on basename. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FwPMTY6Myy3scaMNn33cg5 --- dag/gunbc/stage0_mirror_debt.dag | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/dag/gunbc/stage0_mirror_debt.dag b/dag/gunbc/stage0_mirror_debt.dag index 41d71dce11e..37a68a5e496 100644 --- a/dag/gunbc/stage0_mirror_debt.dag +++ b/dag/gunbc/stage0_mirror_debt.dag @@ -103,11 +103,13 @@ type MirrorDebtRow { // fact about the generator binary that produced it, and it would go silently wrong the next // time the emitter changes. // -// CarriedNoWriter is currently UNINHABITED and that is deliberate rather than an oversight. -// The absent writer is why NO row gets repaired — it is a global fact about main, not a -// discriminating per-row cause — so claiming it for a specific path would assert more than -// was measured. The arm stays declared because the gate switches on it and because a row -// will earn it as soon as one file's drift is shown to be ordinary staleness. +// MEMBERSHIP JOINS ON BASENAME, NOT ON THE PATH COLUMN. The comparator that supplies the +// population reports basenames ("std_algebra.rs"); the path field below is the DISPLAY form +// and is not the key. The join is sound because the generated surface is one flat directory, +// so basenames are unique — but it is a second key space over one population, and this has +// already cost a dispatch: a regen run refused with "emit missing generated file +// compiler_tests.rs" purely because the emit map keys on emit path while the committed roster +// keys on basename. Stated here so the next reader does not rediscover it. data stage0_mirror_debt_rows: List = [ MirrorDebtRow { From d6e2c8eebf98459e32889015022a90015887d3ff Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Thu, 20 Aug 2026 04:25:18 +0000 Subject: [PATCH 05/12] stage0 mirror debt: say plainly that nothing reads these rows yet MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Review on #8631 flagged that the carrier lands with no consumer — the specification-without-execution shape. Fair, and the file was worse than the finding said: it described the gate in the PRESENT TENSE ("The gate recomputes both sides per run and takes its baseline from git") while no gate exists, so a reader could reasonably conclude enforcement was live. Now stated first and plainly: these rows enforce nothing, no code reads them, the file cannot refuse or fail a build or notice a sixteenth mirror drifting, and every statement about gate behaviour describes the intended consumer rather than anything that runs. The deferred consumer is the ruled sequence (disposition now, re-gate next), not an oversight — but the sequence being ruled does not make the rows enforcing, and only the prose could have said so. Same class as the arm-name defect fixed one commit earlier: prose asserting a mechanism the tree does not contain, which no Accepted program can catch. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FwPMTY6Myy3scaMNn33cg5 --- dag/gunbc/stage0_mirror_debt.dag | 19 ++++++++++++++----- 1 file changed, 14 insertions(+), 5 deletions(-) diff --git a/dag/gunbc/stage0_mirror_debt.dag b/dag/gunbc/stage0_mirror_debt.dag index 37a68a5e496..fa17fc8dc4f 100644 --- a/dag/gunbc/stage0_mirror_debt.dag +++ b/dag/gunbc/stage0_mirror_debt.dag @@ -97,11 +97,20 @@ type MirrorDebtRow { // // Neither run is independent evidence about the COMPARATOR: both used it. // -// These rows are transcribed from that measurement and are NOT the gate's oracle. The gate -// recomputes both sides per run and takes its baseline from git. Nothing here is a digest, -// deliberately: a stored desired digest is not a fact about this repository at all, it is a -// fact about the generator binary that produced it, and it would go silently wrong the next -// time the emitter changes. +// THESE ROWS ENFORCE NOTHING TODAY. NO CODE READS THEM. The gate that will consume them is +// unlanded, so this file is a declared debt record and not a control: it cannot refuse, cannot +// fail a build, and cannot detect a sixteenth mirror drifting. That is the ruled sequence — +// disposition now, re-gate next — and not an oversight, but the honest present-tense fact is +// that the population is REPORTED here by hand and CHECKED by nothing. Read any statement +// below about what the gate does as a description of the intended consumer, not of behaviour +// that exists. Until a comparator actually joins on these rows, treating them as enforcement +// would be the specification-without-execution shape DESIGN section 5 names. +// +// The rows are transcribed from the measurement above and are deliberately NOT intended as the +// gate's oracle: the consumer recomputes both sides per run and takes its baseline from git. +// Nothing here is a digest, for the same reason — a stored desired digest is not a fact about +// this repository at all, it is a fact about the generator binary that produced it, and it +// would go silently wrong the next time the emitter changes. // // MEMBERSHIP JOINS ON BASENAME, NOT ON THE PATH COLUMN. The comparator that supplies the // population reports basenames ("std_algebra.rs"); the path field below is the DISPLAY form From 9772a3151f87536008f6f291bdfaa2ceed7283a4 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Thu, 20 Aug 2026 04:40:06 +0000 Subject: [PATCH 06/12] =?UTF-8?q?stage0=20mirror=20debt:=20a=20row=20can?= =?UTF-8?q?=20go=20stale=20with=20nobody=20touching=20anything=20=E2=80=94?= =?UTF-8?q?=20and=20the=20precondition=20that=20makes=20that=20readable?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit smart-newt-495's gate executed against these rows and reported v1_compiler_parse.rs as a stale disposition — a path carrying a row that no longer drifts. Checked before deleting: their merge base is fifteen commits behind mine and #8607 lands inside that window, touching both the parse authority and its mirror. At their base both carry zero make_file_span call sites and genuinely agree; at main the authority carries two and the mirror one. The row is correct; the tree under test was not the tree the rows are about. Records both halves. The first is theirs and is right: a disposition can stop applying with no author, no edit and no diff, because ordinary authority work on main closes the drift. That is the mirror of the loud-failure property this file already claims, so a consumer must refuse in both directions or the carrier becomes a one-way ledger. The second is the precondition that episode produced: a stale verdict is only readable when the tree under test is the tree the rows describe, because the arm fails toward deleting real rows. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FwPMTY6Myy3scaMNn33cg5 --- dag/gunbc/stage0_mirror_debt.dag | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/dag/gunbc/stage0_mirror_debt.dag b/dag/gunbc/stage0_mirror_debt.dag index fa17fc8dc4f..4383de84911 100644 --- a/dag/gunbc/stage0_mirror_debt.dag +++ b/dag/gunbc/stage0_mirror_debt.dag @@ -112,6 +112,24 @@ type MirrorDebtRow { // this repository at all, it is a fact about the generator binary that produced it, and it // would go silently wrong the next time the emitter changes. // +// A ROW CAN GO STALE WITHOUT ANYONE TOUCHING THE FILE OR THIS CARRIER. Ordinary authority +// work on main closes a path's drift, and the judgement recorded here quietly stops applying — +// no author, no edit, no diff. That is the mirror of the loud-failure property above: an +// undispositioned drift breaks noisily, a disposition that has ceased to be true does not. +// A consumer must therefore refuse in BOTH directions, and a stale row is as much a defect as +// a missing one — otherwise this becomes a one-way ledger where rows only ever enter and every +// reader sees more debt than exists. +// +// WITH ONE PRECONDITION, learned by nearly deleting a correct row. A stale verdict is only +// readable when THE TREE UNDER TEST IS THE TREE THESE ROWS ARE ABOUT. A run whose base predates +// the commit that CREATED a drift will observe that path in agreement and report the debt +// closed. That happened: a gate run from a branch fifteen commits behind main reported +// v1_compiler_parse.rs as a stale row, because its base predated #8607 — at that base the +// authority and the mirror both carry zero make_file_span call sites and genuinely agree, +// while at main the authority carries two and the mirror one. "Does not drift" and "drifts, +// but not yet on this tree" are the same observation unless the subject is pinned. The arm +// fails toward DELETING REAL ROWS, so the precondition is part of the arm, not advice beside it. + // MEMBERSHIP JOINS ON BASENAME, NOT ON THE PATH COLUMN. The comparator that supplies the // population reports basenames ("std_algebra.rs"); the path field below is the DISPLAY form // and is not the key. The join is sound because the generated surface is one flat directory, From 4384b333ccef4929f8d2092e250fdde0e441956e Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Thu, 20 Aug 2026 04:47:36 +0000 Subject: [PATCH 07/12] =?UTF-8?q?stage0=20mirror=20debt:=20two=20rows=20we?= =?UTF-8?q?re=20dispositioned=20false=20by=20my=20own=20definition=20?= =?UTF-8?q?=E2=80=94=20regeneration=20does=20not=20close=20them?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit CarriedAuthorityAdvanced is defined in this file as measured ordinary staleness: "a regeneration would close it and nothing more is wrong". That is false at this baseline for lib.rs and gunbc_stage0_crate_layout_generated.rs. Verified on this tree, not taken on report: src/v1/expected_red_roster_join.dag exists, so the module is compiler-emitted; and v2.compiler.self_host.stage0_crate_layout still carries SeedRetainedIntrinsicRegistration { basename: "v1_compiler_expected_red_roster_join", has_pub_mod: true } for the same module. Both splice a pub mod line, so the regenerated crate declares the basename twice and fails rustc E0428 at generation 2 (measured by stern-tern-636 at lib.rs:160 against lib.rs:106). Generation 1 builds clean, which is why the emitted candidate looked correct here and why the earlier E0583 reading was withdrawn — the defect is real, and it is neither E0583 nor in the emitter. Adds CarriedRegenerationBlocked { blocker } and moves both rows onto it. The defect arm was withdrawn earlier for having no row that could carry it; two rows can now carry this one, with the blocker measured rather than reported. Also corrects the MODULE-SET DRIFT note: the apparent rename is duplicated authority, not lag. The stale literal ADDS rather than REPLACES, which is what two producers do — reading that symptom as staleness is exactly what put the false disposition on those rows. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FwPMTY6Myy3scaMNn33cg5 --- dag/gunbc/stage0_mirror_debt.dag | 32 +++++++++++++++++++++++++------- 1 file changed, 25 insertions(+), 7 deletions(-) diff --git a/dag/gunbc/stage0_mirror_debt.dag b/dag/gunbc/stage0_mirror_debt.dag index 4383de84911..accb42eb515 100644 --- a/dag/gunbc/stage0_mirror_debt.dag +++ b/dag/gunbc/stage0_mirror_debt.dag @@ -37,16 +37,25 @@ type MirrorGenerator type MirrorDebtDisposition = CarriedAuthorityAdvanced + | CarriedRegenerationBlocked { blocker: String } | CarriedReasonNotEstablished // CarriedAuthorityAdvanced: MEASURED as ordinary staleness — the authority moved and the // committed mirror did not follow, so a regeneration would close it and nothing more is wrong. // Two mechanisms were observed directly in the emitted-versus-committed diff: -// MODULE-SET DRIFT the emitted crate names modules the committed mirror does not, and -// renames one (`expected_red_roster_join` becomes -// `v1_compiler_expected_red_roster_join`). Seen in lib.rs, which is -// short exactly one `pub mod` line, and in the crate-layout mirror, -// whose three string-literal module lists are each behind. +// MODULE-SET DRIFT the emitted crate names modules the committed mirror does not. Seen +// in lib.rs, short exactly one `pub mod` line, and in the crate-layout +// mirror, whose three string-literal module lists are each behind. +// CAUTION, corrected after this note was first written: the apparent +// RENAME of `expected_red_roster_join` to +// `v1_compiler_expected_red_roster_join` is NOT lag. It is two +// producers declaring one module — the .dag authority makes it +// compiler-emitted while a SeedRetainedIntrinsicRegistration row still +// claims it as seed-retained — so the stale literal ADDS rather than +// REPLACES, which is what duplicated authority does and lag does not. +// Those two paths are therefore CarriedRegenerationBlocked, not +// CarriedAuthorityAdvanced; reading the symptom as staleness is what +// put a false disposition on them. // MATCH-GUARD EMISSION the emitter now emits `if matches!(..)` guards on match arms that the // committed mirror carries unguarded. Seen in // std_occurrence_binding_candidates.rs, v1_compiler_infer_resolve.rs and @@ -143,9 +152,18 @@ data stage0_mirror_debt_rows: List = [ path: "src/v1/stage0/src/gunbc_stage0_crate_layout_generated.rs", authority: SourceModule { name: "gunbc.stage0_crate_layout_generated" }, generator: Stage0Emit, - disposition: CarriedAuthorityAdvanced + disposition: CarriedRegenerationBlocked { + blocker: "Same duplicated authority as lib.rs: this mirror splices the generated_pub_mod_block that carries the second declaration of v1_compiler_expected_red_roster_join. Regenerating yields E0428 at generation 2." + } + }, + MirrorDebtRow { + path: "src/v1/stage0/src/lib.rs", + authority: CrateRootAggregate, + generator: Stage0Emit, + disposition: CarriedRegenerationBlocked { + blocker: "v1_compiler_expected_red_roster_join is declared by TWO producers: src/v1/expected_red_roster_join.dag makes it compiler-emitted (file-derived), while v2.compiler.self_host.stage0_crate_layout still carries SeedRetainedIntrinsicRegistration { basename: \"v1_compiler_expected_red_roster_join\", has_pub_mod: true } for it. Both splice a pub mod line, so the regenerated crate declares the basename twice and fails rustc E0428 at generation 2. Generation 1 builds clean because the duplicate only becomes an error once the candidate replaces the mirror." + } }, - MirrorDebtRow { path: "src/v1/stage0/src/lib.rs", authority: CrateRootAggregate, generator: Stage0Emit, disposition: CarriedAuthorityAdvanced }, MirrorDebtRow { path: "src/v1/stage0/src/std_algebra.rs", authority: SourceModule { name: "std.algebra" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, MirrorDebtRow { path: "src/v1/stage0/src/std_measure.rs", authority: SourceModule { name: "std.measure" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, MirrorDebtRow { path: "src/v1/stage0/src/std_occurrence_binding_candidates.rs", authority: SourceModule { name: "std.occurrence_binding_candidates" }, generator: Stage0Emit, disposition: CarriedAuthorityAdvanced }, From db0b9c5bc19863fc8410cc6e5190dfbf75048533 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Thu, 20 Aug 2026 04:49:42 +0000 Subject: [PATCH 08/12] stage0 mirror debt: withdraw "generation 1 builds clean" from the blocker MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The blocker string claimed the regenerated crate compiles at generation 1 and only collides at generation 2. Withdrawn by its own author: the clean generation-1 builds came from a loop script that deleted the bare pub mod line between install and build, so every one of them measured the tree minus the defect — an unmarked workaround that zeroed the defect's frequency in the runs that produced the claim. Regeneration does not compile at either generation, and it is one blocker in two spellings: E0583 before the projection is regenerated (the emitted lib.rs declares a module with no file) and E0428 after (two producers collide). The E0428 measurement is unaffected — it was taken with no sed in the script — and the two-producer fact was verified independently on this tree. This also corrects something the previous revision implied and I repeated: that the emitted bytes are correct in isolation and only fail once installed. True of the E0428 arm, false of the E0583 arm. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FwPMTY6Myy3scaMNn33cg5 --- dag/gunbc/stage0_mirror_debt.dag | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/dag/gunbc/stage0_mirror_debt.dag b/dag/gunbc/stage0_mirror_debt.dag index accb42eb515..3080179b448 100644 --- a/dag/gunbc/stage0_mirror_debt.dag +++ b/dag/gunbc/stage0_mirror_debt.dag @@ -161,7 +161,7 @@ data stage0_mirror_debt_rows: List = [ authority: CrateRootAggregate, generator: Stage0Emit, disposition: CarriedRegenerationBlocked { - blocker: "v1_compiler_expected_red_roster_join is declared by TWO producers: src/v1/expected_red_roster_join.dag makes it compiler-emitted (file-derived), while v2.compiler.self_host.stage0_crate_layout still carries SeedRetainedIntrinsicRegistration { basename: \"v1_compiler_expected_red_roster_join\", has_pub_mod: true } for it. Both splice a pub mod line, so the regenerated crate declares the basename twice and fails rustc E0428 at generation 2. Generation 1 builds clean because the duplicate only becomes an error once the candidate replaces the mirror." + blocker: "v1_compiler_expected_red_roster_join is declared by TWO producers: src/v1/expected_red_roster_join.dag makes it compiler-emitted (file-derived), while v2.compiler.self_host.stage0_crate_layout still carries SeedRetainedIntrinsicRegistration { basename: \"v1_compiler_expected_red_roster_join\", has_pub_mod: true } for it. Both splice a pub mod line, so the regenerated crate declares the basename twice and fails rustc E0428 at generation 2 (measured, lib.rs:160 against lib.rs:106). Regeneration does not compile at EITHER generation and it is one blocker wearing two spellings: before the projection is regenerated the emitted lib.rs declares a module with no file and fails E0583; after, the two producers collide and it fails E0428. An earlier revision of this blocker said generation 1 builds clean. That is WITHDRAWN — the reported clean generation-1 builds came from a loop script that deleted the bare pub mod line between install and build, so they measured the tree minus the defect." } }, MirrorDebtRow { path: "src/v1/stage0/src/std_algebra.rs", authority: SourceModule { name: "std.algebra" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, From b00c468432bc977aa20fb60ee5fbdf2055693542 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Thu, 20 Aug 2026 05:20:00 +0000 Subject: [PATCH 09/12] stage0 mirror debt: membership is authored today, and the transcription has now been checked at identity grain MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Four header corrections batched into one commit, because committing on a session branch publishes and the witness workflow cancels its in-flight run on every pull_request event — nine runs, eight cancelled, before one completed. MEMBERSHIP IS AUTHORED TODAY. Two reviews read the earlier wording in opposite directions: one as "membership derived not authored", the other as "authored-not-derived until a comparator lands". That is how a sentence reveals it was ambiguous, and the second reading was right about the present — the fifteen paths are hand-transcribed. Derived is the design, not today's state. Third instance in this file of prose written in the present tense about a mechanism that does not exist yet, and the only one an approving review caught. THE TRANSCRIPTION IS NOW CHECKED AT IDENTITY GRAIN. A gate reading these rows against a comparator-derived population on a main-based subject reported compared=128 drifted=15 sideways=0 undispositioned=0 stale_rows=0 accounted=15. A wrong row surfaces as stale, a missed path as undispositioned; both zero. Four planted controls each moved one counter family and named the planted subject, so the zeros are measured rather than blind. WHAT IT STILL DOES NOT ESTABLISH: all three reproductions use the SAME comparator. Stable under changes of subject, runner, day and binary; not independent of the instrument. A systematic bias would reproduce across all three and look identical. Also records that the consumer's malformed-path arm refuses at read time, before the ~180s emit — a cost property, not a correctness one. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FwPMTY6Myy3scaMNn33cg5 --- dag/gunbc/stage0_mirror_debt.dag | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/dag/gunbc/stage0_mirror_debt.dag b/dag/gunbc/stage0_mirror_debt.dag index 3080179b448..c3001626471 100644 --- a/dag/gunbc/stage0_mirror_debt.dag +++ b/dag/gunbc/stage0_mirror_debt.dag @@ -96,6 +96,28 @@ type MirrorDebtRow { // establishes the measurement REPRODUCES. It does NOT establish that the population is stable // across commits, and nothing here should be dispositioned on that premise. // +// MEMBERSHIP IS AUTHORED TODAY, DERIVED LATER, AND THE DISTINCTION IS NOT PEDANTRY. The fifteen +// paths below were TRANSCRIBED BY HAND from a measurement. Derived membership is the design and +// the obligation, not the present state, because nothing today derives anything. Two reviews of +// this file read the earlier wording in OPPOSITE directions — one as "membership derived not +// authored", one as "authored-not-derived until a comparator lands" — which is how a sentence +// reveals it was ambiguous. The second reading was right about today. +// +// THE TRANSCRIPTION HAS SINCE BEEN CHECKED AT IDENTITY GRAIN, which is the check this file asks +// for and is not the same as a count agreeing with a count. A gate reading these rows against a +// comparator-derived population on a main-based subject reported: +// compared=128 drifted=15 sideways=0 undispositioned=0 stale_rows=0 accounted=15 +// A row naming a path that does not drift would have surfaced as stale; a drifted path with no +// row would have surfaced as undispositioned. Both are zero. Four planted controls each moved +// exactly one counter family and named the planted subject, so those zeros are measured rather +// than the output of a gate that cannot see. +// +// WHAT THAT STILL DOES NOT ESTABLISH: all three reproductions derive membership from the SAME +// required-regen comparator. The population is stable under changes of subject, runner, day and +// binary — it is not independent of the instrument. A systematic bias in the comparator would +// reproduce across all three and look exactly like this. Closing that needs a differential +// oracle or a hand-verified specimen, not further runs of the same one. +// // An earlier revision of this comment claimed the two runs were at two different commits and // offered that as the strongest evidence for the baseline. It is WITHDRAWN. Both runs measured // the same tree: ctrl-build fetches a base, checks it out, then applies the dispatcher's local @@ -121,6 +143,11 @@ type MirrorDebtRow { // this repository at all, it is a fact about the generator binary that produced it, and it // would go silently wrong the next time the emitter changes. // +// EDITING THIS FILE BY HAND IS CHEAP TO GET WRONG AND CHEAP TO CHECK: the consumer's +// malformed-path arm refuses at READ time, before the roughly 180-second emit, so a path shape +// error reports in about a second rather than after a full regeneration. Not a correctness +// property — a cost one, and the kind a future editor otherwise learns the slow way. +// // A ROW CAN GO STALE WITHOUT ANYONE TOUCHING THE FILE OR THIS CARRIER. Ordinary authority // work on main closes a path's drift, and the judgement recorded here quietly stops applying — // no author, no edit, no diff. That is the mirror of the loud-failure property above: an From 5be454f55911353f82a07bf5fcf7ad65b5196e58 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Thu, 20 Aug 2026 05:53:54 +0000 Subject: [PATCH 10/12] =?UTF-8?q?commit=5Fworkflow:=20stop=20claiming=20Re?= =?UTF-8?q?genVerifyGate=20covers=20.dag=20compile=20drift=20=E2=80=94=20i?= =?UTF-8?q?t=20was=20retired=20at=20the=20root?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit One carrier held two contradictory claims about whether a gate exists. commit_gate_rust_suite_removed_disposition asserted "DagCompileCleanGate and RegenVerifyGate still catch .dag compile drift", while enrollment_surface_asymmetry_retired_note in the SAME module records RegenVerifyGate retired by the regen root cut. The false half was load-bearing, which is why this is not tidying: it is the sentence explaining why a hole is considered covered, so it made an unguarded class read as guarded. Verified rather than inferred — no Rust implements RegenVerifyGate, and .github/workflows/ contains only witnesses.yml and fleet-converge.yml, neither invoking --required-regen. Nothing computes the regen fixed point today. Corrected in place with a pointer to the retirement note and to the debt population that the unguarded class produced (gunbc.stage0_mirror_debt), rather than deleting the clause and leaving a reader to wonder what used to cover it. Requested by deep-ant-102 in the same ruling that ordered the debt disposition, explicitly to land in this PR rather than a lane of its own. I dropped it while building the carrier and four approvals did not catch it — reviews find defects in what is present, not omissions against the request. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FwPMTY6Myy3scaMNn33cg5 --- dag/gunbc/commit_workflow.dag | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/dag/gunbc/commit_workflow.dag b/dag/gunbc/commit_workflow.dag index 0b85957d0dc..eee36f4cf18 100644 --- a/dag/gunbc/commit_workflow.dag +++ b/dag/gunbc/commit_workflow.dag @@ -1103,7 +1103,7 @@ data githooks_pre_push_slimmed_to_fmt_disposition: Disposition = Terminal { } data commit_gate_rust_suite_removed_disposition: Disposition = Terminal { - reason: "The v1 Rust test suite (cargo fmt --all --check plus cargo nextest run -p v1-compiler-tests) was REMOVED from CI 2026-07-11 (operator ruling) — its RustMonolithGate enrollment, the rust_tests job, and rust_gates_ci.dag's CI consumers are all gone. This records the removal as intentional, not silent (the review-flagged concern). Rationale: rust_tests was NON-required (only the ci job is protection-required on the gunbc main ruleset; rust_tests and ci_regen were not) AND red on main (it exercises the v1 seed, which is being deleted under the §7 burn-down), so it delivered a permanent non-required red — the §5 tolerated-red anti-pattern — at ~37 GiB, the fleet's single largest CI memory job. AMENDED 2026-07-15 (operator ruling, the falsifier lane): the fmt HALF of this removal is REVERSED — cargo fmt --all --check is re-enrolled as a standalone build-job step (gunbc.ci_spec ci_fmt_gate_note / ci_fmt_gate_line). Every rationale above is a fact about NEXTEST (37 GiB, red, seed-runtime); fmt is 4.3s measured, parse-only, needs no build, and is green — it was collateral damage of a §3 fusion, since tools.rust_gates_ci.run_gates welds both into one ProcessExit, so killing the bundle killed the cheap green half. This amendment does NOT re-enroll RustMonolithGate (still REJECTED below) and does not return nextest to CI. AMENDED 2026-07-31 (operator ruling, PR #7490 repair): the COMPILE half for the separate v1-compiler-tests workspace crate is RE-ENROLLED as cargo check -p v1-compiler-tests --tests (gunbc.ci_spec ci_v1_compiler_tests_compile_gate_note / ci_v1_compiler_tests_compile_gate_line) — compile-only, no test execution, ~41s measured cold; NOT nextest and NOT RustMonolithGate. #7490 updated typecheck_module and fixed stage0 call sites but left four direct integration-test callers stale because neither DagCompileCleanGate nor the release build compiles that crate. The former claim 'cargo fmt stays enforced by the pre-push hook (CommitCargoFmtCheck on GitPrePushHook)' is RETRACTED as the enforcement authority: a hook is an escape hatch (§5) — opt-in per clone via a manual core.hooksPath config, bypassable with --no-verify, and absent in container worktrees — and it is PROVEN ineffective, not merely theoretically weak: #6658 landed an unformatted .rs on main 2026-07-15 and no gate caught it. The hook remains as fast local feedback, never as the wall. Coverage now: cargo fmt = the required CI path (ci needs:[build], so a red fmt step blocks the required job by construction); cargo check -p v1-compiler-tests --tests = the required CI compile path for direct Rust integration-test call sites; cargo nextest run -p v1-compiler-tests still runs LOCALLY, not in CI. Return trigger for NEXTEST — NONE by design: that suite does not re-enroll. It is retired WITH the v1 seed and deleted at §7 terminal collapse. Re-enrolling RustMonolithGate onto the required ci floor is explicitly REJECTED — it would move the ~37 GiB red job into the required merge gate. DagCompileCleanGate and RegenVerifyGate still catch .dag compile drift; this gate closes the v1-compiler-tests direct-caller hole they cannot see." + reason: "The v1 Rust test suite (cargo fmt --all --check plus cargo nextest run -p v1-compiler-tests) was REMOVED from CI 2026-07-11 (operator ruling) — its RustMonolithGate enrollment, the rust_tests job, and rust_gates_ci.dag's CI consumers are all gone. This records the removal as intentional, not silent (the review-flagged concern). Rationale: rust_tests was NON-required (only the ci job is protection-required on the gunbc main ruleset; rust_tests and ci_regen were not) AND red on main (it exercises the v1 seed, which is being deleted under the §7 burn-down), so it delivered a permanent non-required red — the §5 tolerated-red anti-pattern — at ~37 GiB, the fleet's single largest CI memory job. AMENDED 2026-07-15 (operator ruling, the falsifier lane): the fmt HALF of this removal is REVERSED — cargo fmt --all --check is re-enrolled as a standalone build-job step (gunbc.ci_spec ci_fmt_gate_note / ci_fmt_gate_line). Every rationale above is a fact about NEXTEST (37 GiB, red, seed-runtime); fmt is 4.3s measured, parse-only, needs no build, and is green — it was collateral damage of a §3 fusion, since tools.rust_gates_ci.run_gates welds both into one ProcessExit, so killing the bundle killed the cheap green half. This amendment does NOT re-enroll RustMonolithGate (still REJECTED below) and does not return nextest to CI. AMENDED 2026-07-31 (operator ruling, PR #7490 repair): the COMPILE half for the separate v1-compiler-tests workspace crate is RE-ENROLLED as cargo check -p v1-compiler-tests --tests (gunbc.ci_spec ci_v1_compiler_tests_compile_gate_note / ci_v1_compiler_tests_compile_gate_line) — compile-only, no test execution, ~41s measured cold; NOT nextest and NOT RustMonolithGate. #7490 updated typecheck_module and fixed stage0 call sites but left four direct integration-test callers stale because neither DagCompileCleanGate nor the release build compiles that crate. The former claim 'cargo fmt stays enforced by the pre-push hook (CommitCargoFmtCheck on GitPrePushHook)' is RETRACTED as the enforcement authority: a hook is an escape hatch (§5) — opt-in per clone via a manual core.hooksPath config, bypassable with --no-verify, and absent in container worktrees — and it is PROVEN ineffective, not merely theoretically weak: #6658 landed an unformatted .rs on main 2026-07-15 and no gate caught it. The hook remains as fast local feedback, never as the wall. Coverage now: cargo fmt = the required CI path (ci needs:[build], so a red fmt step blocks the required job by construction); cargo check -p v1-compiler-tests --tests = the required CI compile path for direct Rust integration-test call sites; cargo nextest run -p v1-compiler-tests still runs LOCALLY, not in CI. Return trigger for NEXTEST — NONE by design: that suite does not re-enroll. It is retired WITH the v1 seed and deleted at §7 terminal collapse. Re-enrolling RustMonolithGate onto the required ci floor is explicitly REJECTED — it would move the ~37 GiB red job into the required merge gate. DagCompileCleanGate still catches .dag compile drift; this gate closes the v1-compiler-tests direct-caller hole it cannot see. CORRECTED 2026-08-20: this sentence also named RegenVerifyGate as live cover. It is not. RegenVerifyGate was RETIRED AT THE ROOT by the regen cut — see enrollment_surface_asymmetry_retired_note in this same module, which records that retirement — and no workflow computes the regen fixed point today (.github/workflows/ contains only witnesses.yml and fleet-converge.yml; neither invokes --required-regen). The false half was load-bearing precisely because this is the sentence explaining why a hole is considered covered, so it made an unguarded class read as guarded: mirror drift accumulates on main unobserved, which is the population now recorded as declared debt in gunbc.stage0_mirror_debt." } data commit_gate_roster: List = [ From c6babacaea708a74e2e23ab61861a9c0702e3ead Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Thu, 20 Aug 2026 06:23:13 +0000 Subject: [PATCH 11/12] stage0 mirror debt: row 16, the moved baseline, the comparator defect, and the dissolution policy MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Four amendments to the debt carrier, batched into one commit because every push cancels the in-flight floor run. ROW 16 — v1_compiler_infer_types.rs, CarriedAuthorityAdvanced. The fifteen rows were discovered at 102bd15331; a guarded run on main 5a10ca7e018 reports sixteen drifted basenames. The original fifteen are a strict SUBSET, so this file has been under-reporting rather than over-reporting — the safe direction, but not a stable one, since nothing here recomputes membership and no signal fires when main moves. THE E0583 CONTRADICTION IS RESOLVED BY SEPARATING THE FACT FROM THE CLASSIFICATION. The header said the E0583 report "was not reproduced here" while the blocker string cited E0583 as measured. Both were true when written. The observation is now reproduced directly (one bare `pub mod expected_red_roster_join;` in the candidate lib.rs, no such file emitted); what stays withdrawn is the claim of a DEFECTIVE EMITTER. The bare declaration is spliced from a compiled-in string constant inside the stale mirror, so the emitter faithfully reproduces an out-of-date input and regeneration is blocked by its own previous output. That is CarriedRegenerationBlocked, not a defect row. THE COMPARATOR DEFECT IS RECORDED SEPARATELY FROM EVERY ROW, because it is a fact about the instrument and folding it into a blocker string would attribute an instrument fault to a mirror that may be fine. rustfmt is not idempotent on v1_compiler_infer.rs (stern-tern-636); compare_generated_surfaces normalizes both sides while write_emitted_tree writes normalize(emitted), so after an install the comparison is normalize(normalize(x)) against normalize(x) and reports drift for a byte-identical candidate. Two consequences: it is a FALSE POSITIVE, failing toward debt that does not exist — the opposite bias from the monoculture caveat this file already carried, and worse, because an over-report gets acted on; and THE CHECK HAD NO REACHABLE GREEN at generation 2 or later, so the only silencing action was the hand edit the gate exists to forbid. A check whose sole satisfying action is the forbidden one trains its operators to defeat it. The gen-1 symmetry argument that keeps this out of the rows below is labelled as mine and unconfirmed. DISSOLUTION POLICY — withdraw the file if the gate lane stalls. Standing authorization from deep-ant-102, recorded in the carrier rather than left in a message thread, because an authorization that lives only in a transcript cannot be acted on by whoever reads this file next. These rows enforce nothing today and the consuming gate is unlanded; that is admissible only as one leg of a sequence, and the ruling authorises the sequence, not an indefinite inert artifact. Floor green on the parent head 5be454f5591: planned=9782 executed=9782 terminal=9782 passed=9475 known_red_held=307 failed=0. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FwPMTY6Myy3scaMNn33cg5 --- dag/gunbc/stage0_mirror_debt.dag | 74 +++++++++++++++++++++++++++++--- 1 file changed, 68 insertions(+), 6 deletions(-) diff --git a/dag/gunbc/stage0_mirror_debt.dag b/dag/gunbc/stage0_mirror_debt.dag index c3001626471..3b0b084a47c 100644 --- a/dag/gunbc/stage0_mirror_debt.dag +++ b/dag/gunbc/stage0_mirror_debt.dag @@ -77,12 +77,22 @@ type MirrorDebtDisposition // through no fault of any author, and a monotone cap would make legitimate work unlandable // behind a red the contributor cannot close. // -// NO ARM CLAIMS A DEFECTIVE EMISSION. An earlier revision of this file dispositioned the -// crate-layout mirror as emission-defective, citing a report that the regenerated crate fails -// rustc E0583. That disposition was withdrawn: the emitted candidate measured here carries the -// CORRECTED module name, so this file's own evidence does not support the defect claim, and the -// E0583 report belongs to another session's measurement that was not reproduced here. Filing an -// unverified defect would have been the fabricated-cause failure this column exists to prevent. +// NO ARM CLAIMS A DEFECTIVE EMISSION, AND THE E0583 ARM HAS SINCE BEEN REPRODUCED HERE — the +// two statements are compatible and the distinction is the point. An earlier revision of this +// file dispositioned the crate-layout mirror as EMISSION-DEFECTIVE, citing a second-hand report +// of rustc E0583. That disposition was withdrawn, correctly: at the time this file's own evidence +// did not support it, and filing an unverified cause would have been the fabricated-cause failure +// this column exists to prevent. +// +// The arm has now been measured directly, on main 5a10ca7e018: the candidate lib.rs carries one +// bare `pub mod expected_red_roster_join;` while no such file is emitted, which is E0583. So the +// FACT is reproduced. What stays withdrawn is the CLASSIFICATION — this is not a defective +// emitter. The bare declaration is spliced from a compiled-in string constant inside the stale +// stage0 mirror itself, so the emitter is faithfully reproducing an input that is out of date. +// A regeneration is blocked by its own previous output, which is why the disposition is +// CarriedRegenerationBlocked and not a defect row. Recorded this way because withdrawing a claim +// and later confirming its underlying observation is the case where a carrier most easily ends up +// holding two accounts of one fact. type MirrorDebtRow { path: String @@ -174,6 +184,57 @@ type MirrorDebtRow { // compiler_tests.rs" purely because the emit map keys on emit path while the committed roster // keys on basename. Stated here so the next reader does not rediscover it. +// THE ROWS WERE MEASURED AT 102bd15331; THE POPULATION AT MAIN TIP IS 16, NOT 15. The fifteen +// paths below were discovered on that baseline. A later run on main 5a10ca7e018 — guards +// satisfied: checkout marker present, zero applied-patch lines, lib.rs hash matching local, +// duplicate-row scan empty, planned=129 executed=129, exit 1 — reported SIXTEEN drifted +// basenames. The addition is v1_compiler_infer_types.rs, now carried as a row. +// +// So the original fifteen are a strict SUBSET of the live population, and the direction matters: +// this file has been under-reporting, never over-reporting. That is the safe direction for a +// debt record but it is not a stable one, because nothing here recomputes membership — the +// population is a fact about main and this is a file, so the two diverge whenever main moves +// and no signal is emitted. Do not read the row count as a census; read it as the census taken +// at the two commits named in this block. + +// A COMPARATOR DEFECT IS RECORDED SEPARATELY FROM THE ROWS, BECAUSE IT IS A FACT ABOUT THE +// INSTRUMENT AND NOT ABOUT ANY PATH. Folding it into a blocker string would have attributed an +// instrument fault to a mirror that may be perfectly fine. +// +// Measured by stern-tern-636: rustfmt is NOT IDEMPOTENT on v1_compiler_infer.rs. In +// required_regen_host, compare_generated_surfaces normalizes BOTH sides, while write_emitted_tree +// writes normalize(emitted). After an install the comparison is therefore normalize(normalize(x)) +// against normalize(x), which differ — so the check reports DRIFT for a candidate that is +// byte-identical to what it just wrote. +// +// TWO CONSEQUENCES, and the second is the serious one. First, it is a FALSE POSITIVE: it fails +// toward reporting debt that does not exist, which is the opposite bias from the one this +// carrier's comparator-monoculture caveat warned about, and worse — an over-report is acted on. +// Second, THE CHECK HAD NO REACHABLE GREEN. At generation 2 and beyond no correct regeneration +// could satisfy it, so the only way to silence it was to hand-edit the mirror — which is exactly +// the laundering the gate exists to prevent. A check whose sole satisfying action is the +// forbidden one is not a strict check; it is a check that trains its operators to defeat it. +// +// WHY THIS DOES NOT PUT A PHANTOM IN THE ROWS BELOW, and the claim is bounded: at generation 1 +// both sides are normalized exactly once, so the comparison is symmetric and this mechanism +// cannot fire. The rows were discovered at generation 1. That reasoning is MINE, from reading the +// mechanism, and it has not been confirmed by an independent run — so it is a stated argument, +// not a measurement, and a reader re-deriving this population should re-establish it rather than +// inherit it. The repair belongs in compare_generated_surfaces (compare the committed bytes RAW +// against the bytes actually written), not here. + +// DISSOLUTION: THIS FILE IS WITHDRAWN IF THE GATE LANE STALLS. Standing authorization from +// deep-ant-102, recorded here rather than held in a message thread, because an authorization that +// lives only in a transcript cannot be acted on by whoever reads this file next. +// +// These rows enforce nothing. The gate that will consume them is unlanded. That is admissible +// only as one leg of a sequence — disposition now, re-gate next — and the ruling authorises the +// SEQUENCE, not an indefinite inert artifact. If the gate lane stalls, the correct action is to +// DELETE THIS FILE, not to keep it as a record; a debt ledger nothing reads decays into exactly +// the parallel-representation debt it was meant to retire, and it decays silently, because a row +// can go stale with no author and no edit (see the staleness block above). No further approval is +// needed to withdraw it and no one should wait for one. + data stage0_mirror_debt_rows: List = [ MirrorDebtRow { path: "src/v1/stage0/src/gunbc_stage0_crate_layout_generated.rs", @@ -202,6 +263,7 @@ data stage0_mirror_debt_rows: List = [ MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_infer.rs", authority: SourceModule { name: "v1.compiler.infer" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_infer_lookup.rs", authority: SourceModule { name: "v1.compiler.infer_lookup" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_infer_resolve.rs", authority: SourceModule { name: "v1.compiler.infer_resolve" }, generator: Stage0Emit, disposition: CarriedAuthorityAdvanced }, + MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_infer_types.rs", authority: SourceModule { name: "v1.compiler.infer_types" }, generator: Stage0Emit, disposition: CarriedAuthorityAdvanced }, MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_parse.rs", authority: SourceModule { name: "v1.compiler.parse" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, MirrorDebtRow { path: "src/v1/stage0/src/v1_std_core.rs", authority: SourceModule { name: "v1.std.core" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished } ] From bc00d058a93d31cb1c33c6ec02ef235d6860f406 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Thu, 20 Aug 2026 07:15:20 +0000 Subject: [PATCH 12/12] Withdraw the stage0 mirror debt carrier: its population no longer exists MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit #8618 regenerated all sixteen drifted mirrors and merged as bd239370923. Every row in gunbc.stage0_mirror_debt now describes a path that does not drift, so the file is a stale ledger rather than a debt record, and the standing authorisation from deep-ant-102 covers withdrawing it whole. DELETED RATHER THAN EMPTIED. Editing sixteen rows toward zero would leave a carrier asserting that no debt exists, which is not a fact anyone needs stored and which reintroduces the one-way ledger the consuming gate's stale-row refusal exists to prevent. smart-newt-495 confirmed the withdrawal costs their lane nothing: an absent carrier now reads as an empty disposition list while a malformed one still refuses, and drift-present-with-no-carrier still refuses on every path, so absence never became permission. WHAT THE CARRIER ESTABLISHED, PRESERVED HERE BECAUSE IT OUTLIVES THE FILE. The sixteen paths carried REAL content divergence, not an artifact of the rustfmt non-idempotence defect in the comparator: comparing the committed bytes at 5a10ca7e018 against the converged bytes with all whitespace stripped gives 0 formatting-only and 16 real content. That oracle is a `git show` plus `tr` and shares no code with required_regen_host, so it is the one part of this episode that does not rest on the instrument that measured everything else. It was worth having only because of its controls — a first version collapsed whitespace instead of deleting it, failed its positive control, and still printed these same numbers, which every file would have produced regardless of content. STILL NOT ESTABLISHED, and unchanged by convergence: whether the converged bytes are what the .dag authorities imply. Both oracles compare committed states; the comparator remains the only thing asserting candidate-matches-authority. THE COMMIT_WORKFLOW CLAUSE IS RE-CORRECTED IN THE SAME COMMIT, because this carrier's withdrawal falsified half of it. That clause was itself a correction landed hours earlier, and it asserted that no workflow computes the regen fixed point and that witnesses.yml does not invoke --required-regen. #8618 falsified both: main now enrols --required-regen and --required-regen-fixed-point as required steps. The clause now records both dated corrections rather than rewriting the sentence, since the second instance is the more instructive one — a correction that asserts a live enrollment fact acquires an expiry the moment enrollment changes, so what a carrier may safely assert about CI is which authority owns a fact, not which jobs happen to be running today. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FwPMTY6Myy3scaMNn33cg5 --- dag/gunbc/commit_workflow.dag | 2 +- dag/gunbc/stage0_mirror_debt.dag | 269 ------------------------------- 2 files changed, 1 insertion(+), 270 deletions(-) delete mode 100644 dag/gunbc/stage0_mirror_debt.dag diff --git a/dag/gunbc/commit_workflow.dag b/dag/gunbc/commit_workflow.dag index eee36f4cf18..3e409bf6c7c 100644 --- a/dag/gunbc/commit_workflow.dag +++ b/dag/gunbc/commit_workflow.dag @@ -1103,7 +1103,7 @@ data githooks_pre_push_slimmed_to_fmt_disposition: Disposition = Terminal { } data commit_gate_rust_suite_removed_disposition: Disposition = Terminal { - reason: "The v1 Rust test suite (cargo fmt --all --check plus cargo nextest run -p v1-compiler-tests) was REMOVED from CI 2026-07-11 (operator ruling) — its RustMonolithGate enrollment, the rust_tests job, and rust_gates_ci.dag's CI consumers are all gone. This records the removal as intentional, not silent (the review-flagged concern). Rationale: rust_tests was NON-required (only the ci job is protection-required on the gunbc main ruleset; rust_tests and ci_regen were not) AND red on main (it exercises the v1 seed, which is being deleted under the §7 burn-down), so it delivered a permanent non-required red — the §5 tolerated-red anti-pattern — at ~37 GiB, the fleet's single largest CI memory job. AMENDED 2026-07-15 (operator ruling, the falsifier lane): the fmt HALF of this removal is REVERSED — cargo fmt --all --check is re-enrolled as a standalone build-job step (gunbc.ci_spec ci_fmt_gate_note / ci_fmt_gate_line). Every rationale above is a fact about NEXTEST (37 GiB, red, seed-runtime); fmt is 4.3s measured, parse-only, needs no build, and is green — it was collateral damage of a §3 fusion, since tools.rust_gates_ci.run_gates welds both into one ProcessExit, so killing the bundle killed the cheap green half. This amendment does NOT re-enroll RustMonolithGate (still REJECTED below) and does not return nextest to CI. AMENDED 2026-07-31 (operator ruling, PR #7490 repair): the COMPILE half for the separate v1-compiler-tests workspace crate is RE-ENROLLED as cargo check -p v1-compiler-tests --tests (gunbc.ci_spec ci_v1_compiler_tests_compile_gate_note / ci_v1_compiler_tests_compile_gate_line) — compile-only, no test execution, ~41s measured cold; NOT nextest and NOT RustMonolithGate. #7490 updated typecheck_module and fixed stage0 call sites but left four direct integration-test callers stale because neither DagCompileCleanGate nor the release build compiles that crate. The former claim 'cargo fmt stays enforced by the pre-push hook (CommitCargoFmtCheck on GitPrePushHook)' is RETRACTED as the enforcement authority: a hook is an escape hatch (§5) — opt-in per clone via a manual core.hooksPath config, bypassable with --no-verify, and absent in container worktrees — and it is PROVEN ineffective, not merely theoretically weak: #6658 landed an unformatted .rs on main 2026-07-15 and no gate caught it. The hook remains as fast local feedback, never as the wall. Coverage now: cargo fmt = the required CI path (ci needs:[build], so a red fmt step blocks the required job by construction); cargo check -p v1-compiler-tests --tests = the required CI compile path for direct Rust integration-test call sites; cargo nextest run -p v1-compiler-tests still runs LOCALLY, not in CI. Return trigger for NEXTEST — NONE by design: that suite does not re-enroll. It is retired WITH the v1 seed and deleted at §7 terminal collapse. Re-enrolling RustMonolithGate onto the required ci floor is explicitly REJECTED — it would move the ~37 GiB red job into the required merge gate. DagCompileCleanGate still catches .dag compile drift; this gate closes the v1-compiler-tests direct-caller hole it cannot see. CORRECTED 2026-08-20: this sentence also named RegenVerifyGate as live cover. It is not. RegenVerifyGate was RETIRED AT THE ROOT by the regen cut — see enrollment_surface_asymmetry_retired_note in this same module, which records that retirement — and no workflow computes the regen fixed point today (.github/workflows/ contains only witnesses.yml and fleet-converge.yml; neither invokes --required-regen). The false half was load-bearing precisely because this is the sentence explaining why a hole is considered covered, so it made an unguarded class read as guarded: mirror drift accumulates on main unobserved, which is the population now recorded as declared debt in gunbc.stage0_mirror_debt." + reason: "The v1 Rust test suite (cargo fmt --all --check plus cargo nextest run -p v1-compiler-tests) was REMOVED from CI 2026-07-11 (operator ruling) — its RustMonolithGate enrollment, the rust_tests job, and rust_gates_ci.dag's CI consumers are all gone. This records the removal as intentional, not silent (the review-flagged concern). Rationale: rust_tests was NON-required (only the ci job is protection-required on the gunbc main ruleset; rust_tests and ci_regen were not) AND red on main (it exercises the v1 seed, which is being deleted under the §7 burn-down), so it delivered a permanent non-required red — the §5 tolerated-red anti-pattern — at ~37 GiB, the fleet's single largest CI memory job. AMENDED 2026-07-15 (operator ruling, the falsifier lane): the fmt HALF of this removal is REVERSED — cargo fmt --all --check is re-enrolled as a standalone build-job step (gunbc.ci_spec ci_fmt_gate_note / ci_fmt_gate_line). Every rationale above is a fact about NEXTEST (37 GiB, red, seed-runtime); fmt is 4.3s measured, parse-only, needs no build, and is green — it was collateral damage of a §3 fusion, since tools.rust_gates_ci.run_gates welds both into one ProcessExit, so killing the bundle killed the cheap green half. This amendment does NOT re-enroll RustMonolithGate (still REJECTED below) and does not return nextest to CI. AMENDED 2026-07-31 (operator ruling, PR #7490 repair): the COMPILE half for the separate v1-compiler-tests workspace crate is RE-ENROLLED as cargo check -p v1-compiler-tests --tests (gunbc.ci_spec ci_v1_compiler_tests_compile_gate_note / ci_v1_compiler_tests_compile_gate_line) — compile-only, no test execution, ~41s measured cold; NOT nextest and NOT RustMonolithGate. #7490 updated typecheck_module and fixed stage0 call sites but left four direct integration-test callers stale because neither DagCompileCleanGate nor the release build compiles that crate. The former claim 'cargo fmt stays enforced by the pre-push hook (CommitCargoFmtCheck on GitPrePushHook)' is RETRACTED as the enforcement authority: a hook is an escape hatch (§5) — opt-in per clone via a manual core.hooksPath config, bypassable with --no-verify, and absent in container worktrees — and it is PROVEN ineffective, not merely theoretically weak: #6658 landed an unformatted .rs on main 2026-07-15 and no gate caught it. The hook remains as fast local feedback, never as the wall. Coverage now: cargo fmt = the required CI path (ci needs:[build], so a red fmt step blocks the required job by construction); cargo check -p v1-compiler-tests --tests = the required CI compile path for direct Rust integration-test call sites; cargo nextest run -p v1-compiler-tests still runs LOCALLY, not in CI. Return trigger for NEXTEST — NONE by design: that suite does not re-enroll. It is retired WITH the v1 seed and deleted at §7 terminal collapse. Re-enrolling RustMonolithGate onto the required ci floor is explicitly REJECTED — it would move the ~37 GiB red job into the required merge gate. DagCompileCleanGate still catches .dag compile drift; this gate closes the v1-compiler-tests direct-caller hole it cannot see. CORRECTED 2026-08-20: this sentence also named RegenVerifyGate as live cover. It is not — RegenVerifyGate was RETIRED AT THE ROOT by the regen cut, recorded in enrollment_surface_asymmetry_retired_note in this same module. The false half was load-bearing precisely because this is the sentence explaining why a hole is considered covered, so it made an unguarded class read as guarded, and mirror drift did accumulate on main unobserved: sixteen generated stage0 mirrors had diverged from their .dag authorities by 2026-08-20, verified as real content divergence rather than a formatter artifact by a whitespace-stripped differential that shares no code with the regen comparator. RE-CORRECTED THE SAME DAY, hours later, because the first correction's own factual half died before the ink dried: it stated that no workflow computes the regen fixed point and that witnesses.yml does not invoke --required-regen. #8618 falsified both. witnesses.yml on main now enrols TWO required steps between the parse step and the floor fold — --required-regen (first generation matches the committed candidate) and --required-regen-fixed-point (G0 emit reproduces itself on a second pass) — each gated on its predecessor's outcome, and the same PR regenerated all sixteen mirrors, so the drift population is closed rather than merely observed. The hole this sentence describes is therefore GUARDED again, by a different mechanism than the retired gate it once wrongly credited. Recorded as two dated corrections rather than one rewritten sentence because the failure mode is identical in both directions and the second instance is the more instructive: a correction that asserts a live enrollment fact acquires an expiry the moment enrollment changes, so what a carrier may safely assert about CI is which authority owns a fact, not which jobs happen to be running today." } data commit_gate_roster: List = [ diff --git a/dag/gunbc/stage0_mirror_debt.dag b/dag/gunbc/stage0_mirror_debt.dag deleted file mode 100644 index 3b0b084a47c..00000000000 --- a/dag/gunbc/stage0_mirror_debt.dag +++ /dev/null @@ -1,269 +0,0 @@ -module gunbc.stage0_mirror_debt - -// The committed stage0 Rust mirrors that differ from what their authority emits today. -// -// MEMBERSHIP IS NOT AUTHORED HERE. The population is whatever the required-regen comparator -// reports as drifted on the run. What is authored is the per-row DISPOSITION: why a drifted -// path is carried rather than repaired. A drifted path with no authored disposition refuses. -// That is the honest failure direction — forgetting a judgement breaks loudly, whereas -// forgetting a row would be invisible and the reported count would still read as stable. -// -// WHY THE DEBT EXISTS AT ALL: nothing on main writes these mirrors. RegenVerifyGate and -// SelfHostStalenessGate were deleted at the root in the regen cut, and no workflow computes -// the fixed point, so drift accumulates unobserved. Operator ruling 2026-08-20 (relayed via -// deep-ant-102): disposition the population as declared debt now, re-gate next; regenerating -// main is REFUSED while no writer exists and while the emitter produces the defect below. - -type MirrorAuthority - = SourceModule { name: String } - | CrateRootAggregate - -// CrateRootAggregate is NULLARY on purpose. lib.rs is assembled by the emitter from the set it -// actually emitted; it carries no `// Source module:` line and there is no module to name. -// It must NOT cite gunbc.stage0_emit_plan_generated even though that roster lists lib.rs among -// its paths: that projection's generator gunbc.stage0_emit_plan is DELETED, so the citation -// would point at a dead producer and be wrong in a way nothing would catch. A payload here -// would say something false; nullary says the true thing. - -type MirrorGenerator - = Stage0Emit - | WetActuator - -// Stage0Emit is the required-regen population. WetActuator is the separately actuated kind. -// READ THE NEXT TWO NAMES CAREFULLY, THEY DIFFER BY ONE LEADING WORD AND ARE OPPOSITE KINDS: -// gunbc_stage0_crate_layout_generated.rs Stage0Emit — IS in this population -// bootstrap_stage0_crate_layout_generated.rs WetActuator — is NOT, and is the only stage0 -// path named in gunbc.generated_artifact - -type MirrorDebtDisposition - = CarriedAuthorityAdvanced - | CarriedRegenerationBlocked { blocker: String } - | CarriedReasonNotEstablished - -// CarriedAuthorityAdvanced: MEASURED as ordinary staleness — the authority moved and the -// committed mirror did not follow, so a regeneration would close it and nothing more is wrong. -// Two mechanisms were observed directly in the emitted-versus-committed diff: -// MODULE-SET DRIFT the emitted crate names modules the committed mirror does not. Seen -// in lib.rs, short exactly one `pub mod` line, and in the crate-layout -// mirror, whose three string-literal module lists are each behind. -// CAUTION, corrected after this note was first written: the apparent -// RENAME of `expected_red_roster_join` to -// `v1_compiler_expected_red_roster_join` is NOT lag. It is two -// producers declaring one module — the .dag authority makes it -// compiler-emitted while a SeedRetainedIntrinsicRegistration row still -// claims it as seed-retained — so the stale literal ADDS rather than -// REPLACES, which is what duplicated authority does and lag does not. -// Those two paths are therefore CarriedRegenerationBlocked, not -// CarriedAuthorityAdvanced; reading the symptom as staleness is what -// put a false disposition on them. -// MATCH-GUARD EMISSION the emitter now emits `if matches!(..)` guards on match arms that the -// committed mirror carries unguarded. Seen in -// std_occurrence_binding_candidates.rs, v1_compiler_infer_resolve.rs and -// v1_compiler_emit.rs. -// -// CarriedReasonNotEstablished is a DEFERRED question about a real thing, not an invented one: -// every row below measurably drifts, so a cause exists for each; which cause is simply not -// established yet. These ten were not individually diffed. Defaulting them into -// CarriedAuthorityAdvanced would generalise from five files to fifteen — the drift ranges over -// three orders of magnitude (1 to 492 changed lines), so a shared mechanism is a hypothesis and -// not a measurement. The arm is deliberately cheap to write: forcing an author to produce a -// reason at the moment of refusal manufactures exactly the plausible-sounding cause this column -// exists to keep out. -// -// SO THE CLAIM THIS CARRIER SUPPORTS IS NARROW, AND IS STATED HERE RATHER THAN LEFT TO BE -// DISCOVERED AS A WEAKNESS: every drifted path is ACCOUNTED FOR. Not every drifted path is -// UNDERSTOOD. The count of rows on the unestablished arm is reported and ranked every run, and -// it is NEVER gated — membership is derived, so ordinary authority work grows the population -// through no fault of any author, and a monotone cap would make legitimate work unlandable -// behind a red the contributor cannot close. -// -// NO ARM CLAIMS A DEFECTIVE EMISSION, AND THE E0583 ARM HAS SINCE BEEN REPRODUCED HERE — the -// two statements are compatible and the distinction is the point. An earlier revision of this -// file dispositioned the crate-layout mirror as EMISSION-DEFECTIVE, citing a second-hand report -// of rustc E0583. That disposition was withdrawn, correctly: at the time this file's own evidence -// did not support it, and filing an unverified cause would have been the fabricated-cause failure -// this column exists to prevent. -// -// The arm has now been measured directly, on main 5a10ca7e018: the candidate lib.rs carries one -// bare `pub mod expected_red_roster_join;` while no such file is emitted, which is E0583. So the -// FACT is reproduced. What stays withdrawn is the CLASSIFICATION — this is not a defective -// emitter. The bare declaration is spliced from a compiled-in string constant inside the stale -// stage0 mirror itself, so the emitter is faithfully reproducing an input that is out of date. -// A regeneration is blocked by its own previous output, which is why the disposition is -// CarriedRegenerationBlocked and not a defect row. Recorded this way because withdrawing a claim -// and later confirming its underlying observation is the case where a carrier most easily ends up -// holding two accounts of one fact. - -type MirrorDebtRow { - path: String - authority: MirrorAuthority - generator: MirrorGenerator - disposition: MirrorDebtDisposition -} - -// THE POPULATION AS MEASURED, AT ONE COMMIT: 102bd1533150d04e9fc8bcf423a24c43e09a3713. -// Two operators dispatched independently and both returned this same 15-name list. That -// establishes the measurement REPRODUCES. It does NOT establish that the population is stable -// across commits, and nothing here should be dispositioned on that premise. -// -// MEMBERSHIP IS AUTHORED TODAY, DERIVED LATER, AND THE DISTINCTION IS NOT PEDANTRY. The fifteen -// paths below were TRANSCRIBED BY HAND from a measurement. Derived membership is the design and -// the obligation, not the present state, because nothing today derives anything. Two reviews of -// this file read the earlier wording in OPPOSITE directions — one as "membership derived not -// authored", one as "authored-not-derived until a comparator lands" — which is how a sentence -// reveals it was ambiguous. The second reading was right about today. -// -// THE TRANSCRIPTION HAS SINCE BEEN CHECKED AT IDENTITY GRAIN, which is the check this file asks -// for and is not the same as a count agreeing with a count. A gate reading these rows against a -// comparator-derived population on a main-based subject reported: -// compared=128 drifted=15 sideways=0 undispositioned=0 stale_rows=0 accounted=15 -// A row naming a path that does not drift would have surfaced as stale; a drifted path with no -// row would have surfaced as undispositioned. Both are zero. Four planted controls each moved -// exactly one counter family and named the planted subject, so those zeros are measured rather -// than the output of a gate that cannot see. -// -// WHAT THAT STILL DOES NOT ESTABLISH: all three reproductions derive membership from the SAME -// required-regen comparator. The population is stable under changes of subject, runner, day and -// binary — it is not independent of the instrument. A systematic bias in the comparator would -// reproduce across all three and look exactly like this. Closing that needs a differential -// oracle or a hand-verified specimen, not further runs of the same one. -// -// An earlier revision of this comment claimed the two runs were at two different commits and -// offered that as the strongest evidence for the baseline. It is WITHDRAWN. Both runs measured -// the same tree: ctrl-build fetches a base, checks it out, then applies the dispatcher's local -// diff as patches, and patches do not move HEAD — so the second run reported a main-tip SHA -// while its content had been patched back to this commit. The retraction is recorded here -// rather than silently deleted, because the withdrawn claim was broadcast and acted on, and a -// carrier that quietly drops a premise leaves every consumer still holding it. -// -// Neither run is independent evidence about the COMPARATOR: both used it. -// -// THESE ROWS ENFORCE NOTHING TODAY. NO CODE READS THEM. The gate that will consume them is -// unlanded, so this file is a declared debt record and not a control: it cannot refuse, cannot -// fail a build, and cannot detect a sixteenth mirror drifting. That is the ruled sequence — -// disposition now, re-gate next — and not an oversight, but the honest present-tense fact is -// that the population is REPORTED here by hand and CHECKED by nothing. Read any statement -// below about what the gate does as a description of the intended consumer, not of behaviour -// that exists. Until a comparator actually joins on these rows, treating them as enforcement -// would be the specification-without-execution shape DESIGN section 5 names. -// -// The rows are transcribed from the measurement above and are deliberately NOT intended as the -// gate's oracle: the consumer recomputes both sides per run and takes its baseline from git. -// Nothing here is a digest, for the same reason — a stored desired digest is not a fact about -// this repository at all, it is a fact about the generator binary that produced it, and it -// would go silently wrong the next time the emitter changes. -// -// EDITING THIS FILE BY HAND IS CHEAP TO GET WRONG AND CHEAP TO CHECK: the consumer's -// malformed-path arm refuses at READ time, before the roughly 180-second emit, so a path shape -// error reports in about a second rather than after a full regeneration. Not a correctness -// property — a cost one, and the kind a future editor otherwise learns the slow way. -// -// A ROW CAN GO STALE WITHOUT ANYONE TOUCHING THE FILE OR THIS CARRIER. Ordinary authority -// work on main closes a path's drift, and the judgement recorded here quietly stops applying — -// no author, no edit, no diff. That is the mirror of the loud-failure property above: an -// undispositioned drift breaks noisily, a disposition that has ceased to be true does not. -// A consumer must therefore refuse in BOTH directions, and a stale row is as much a defect as -// a missing one — otherwise this becomes a one-way ledger where rows only ever enter and every -// reader sees more debt than exists. -// -// WITH ONE PRECONDITION, learned by nearly deleting a correct row. A stale verdict is only -// readable when THE TREE UNDER TEST IS THE TREE THESE ROWS ARE ABOUT. A run whose base predates -// the commit that CREATED a drift will observe that path in agreement and report the debt -// closed. That happened: a gate run from a branch fifteen commits behind main reported -// v1_compiler_parse.rs as a stale row, because its base predated #8607 — at that base the -// authority and the mirror both carry zero make_file_span call sites and genuinely agree, -// while at main the authority carries two and the mirror one. "Does not drift" and "drifts, -// but not yet on this tree" are the same observation unless the subject is pinned. The arm -// fails toward DELETING REAL ROWS, so the precondition is part of the arm, not advice beside it. - -// MEMBERSHIP JOINS ON BASENAME, NOT ON THE PATH COLUMN. The comparator that supplies the -// population reports basenames ("std_algebra.rs"); the path field below is the DISPLAY form -// and is not the key. The join is sound because the generated surface is one flat directory, -// so basenames are unique — but it is a second key space over one population, and this has -// already cost a dispatch: a regen run refused with "emit missing generated file -// compiler_tests.rs" purely because the emit map keys on emit path while the committed roster -// keys on basename. Stated here so the next reader does not rediscover it. - -// THE ROWS WERE MEASURED AT 102bd15331; THE POPULATION AT MAIN TIP IS 16, NOT 15. The fifteen -// paths below were discovered on that baseline. A later run on main 5a10ca7e018 — guards -// satisfied: checkout marker present, zero applied-patch lines, lib.rs hash matching local, -// duplicate-row scan empty, planned=129 executed=129, exit 1 — reported SIXTEEN drifted -// basenames. The addition is v1_compiler_infer_types.rs, now carried as a row. -// -// So the original fifteen are a strict SUBSET of the live population, and the direction matters: -// this file has been under-reporting, never over-reporting. That is the safe direction for a -// debt record but it is not a stable one, because nothing here recomputes membership — the -// population is a fact about main and this is a file, so the two diverge whenever main moves -// and no signal is emitted. Do not read the row count as a census; read it as the census taken -// at the two commits named in this block. - -// A COMPARATOR DEFECT IS RECORDED SEPARATELY FROM THE ROWS, BECAUSE IT IS A FACT ABOUT THE -// INSTRUMENT AND NOT ABOUT ANY PATH. Folding it into a blocker string would have attributed an -// instrument fault to a mirror that may be perfectly fine. -// -// Measured by stern-tern-636: rustfmt is NOT IDEMPOTENT on v1_compiler_infer.rs. In -// required_regen_host, compare_generated_surfaces normalizes BOTH sides, while write_emitted_tree -// writes normalize(emitted). After an install the comparison is therefore normalize(normalize(x)) -// against normalize(x), which differ — so the check reports DRIFT for a candidate that is -// byte-identical to what it just wrote. -// -// TWO CONSEQUENCES, and the second is the serious one. First, it is a FALSE POSITIVE: it fails -// toward reporting debt that does not exist, which is the opposite bias from the one this -// carrier's comparator-monoculture caveat warned about, and worse — an over-report is acted on. -// Second, THE CHECK HAD NO REACHABLE GREEN. At generation 2 and beyond no correct regeneration -// could satisfy it, so the only way to silence it was to hand-edit the mirror — which is exactly -// the laundering the gate exists to prevent. A check whose sole satisfying action is the -// forbidden one is not a strict check; it is a check that trains its operators to defeat it. -// -// WHY THIS DOES NOT PUT A PHANTOM IN THE ROWS BELOW, and the claim is bounded: at generation 1 -// both sides are normalized exactly once, so the comparison is symmetric and this mechanism -// cannot fire. The rows were discovered at generation 1. That reasoning is MINE, from reading the -// mechanism, and it has not been confirmed by an independent run — so it is a stated argument, -// not a measurement, and a reader re-deriving this population should re-establish it rather than -// inherit it. The repair belongs in compare_generated_surfaces (compare the committed bytes RAW -// against the bytes actually written), not here. - -// DISSOLUTION: THIS FILE IS WITHDRAWN IF THE GATE LANE STALLS. Standing authorization from -// deep-ant-102, recorded here rather than held in a message thread, because an authorization that -// lives only in a transcript cannot be acted on by whoever reads this file next. -// -// These rows enforce nothing. The gate that will consume them is unlanded. That is admissible -// only as one leg of a sequence — disposition now, re-gate next — and the ruling authorises the -// SEQUENCE, not an indefinite inert artifact. If the gate lane stalls, the correct action is to -// DELETE THIS FILE, not to keep it as a record; a debt ledger nothing reads decays into exactly -// the parallel-representation debt it was meant to retire, and it decays silently, because a row -// can go stale with no author and no edit (see the staleness block above). No further approval is -// needed to withdraw it and no one should wait for one. - -data stage0_mirror_debt_rows: List = [ - MirrorDebtRow { - path: "src/v1/stage0/src/gunbc_stage0_crate_layout_generated.rs", - authority: SourceModule { name: "gunbc.stage0_crate_layout_generated" }, - generator: Stage0Emit, - disposition: CarriedRegenerationBlocked { - blocker: "Same duplicated authority as lib.rs: this mirror splices the generated_pub_mod_block that carries the second declaration of v1_compiler_expected_red_roster_join. Regenerating yields E0428 at generation 2." - } - }, - MirrorDebtRow { - path: "src/v1/stage0/src/lib.rs", - authority: CrateRootAggregate, - generator: Stage0Emit, - disposition: CarriedRegenerationBlocked { - blocker: "v1_compiler_expected_red_roster_join is declared by TWO producers: src/v1/expected_red_roster_join.dag makes it compiler-emitted (file-derived), while v2.compiler.self_host.stage0_crate_layout still carries SeedRetainedIntrinsicRegistration { basename: \"v1_compiler_expected_red_roster_join\", has_pub_mod: true } for it. Both splice a pub mod line, so the regenerated crate declares the basename twice and fails rustc E0428 at generation 2 (measured, lib.rs:160 against lib.rs:106). Regeneration does not compile at EITHER generation and it is one blocker wearing two spellings: before the projection is regenerated the emitted lib.rs declares a module with no file and fails E0583; after, the two producers collide and it fails E0428. An earlier revision of this blocker said generation 1 builds clean. That is WITHDRAWN — the reported clean generation-1 builds came from a loop script that deleted the bare pub mod line between install and build, so they measured the tree minus the defect." - } - }, - MirrorDebtRow { path: "src/v1/stage0/src/std_algebra.rs", authority: SourceModule { name: "std.algebra" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, - MirrorDebtRow { path: "src/v1/stage0/src/std_measure.rs", authority: SourceModule { name: "std.measure" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, - MirrorDebtRow { path: "src/v1/stage0/src/std_occurrence_binding_candidates.rs", authority: SourceModule { name: "std.occurrence_binding_candidates" }, generator: Stage0Emit, disposition: CarriedAuthorityAdvanced }, - MirrorDebtRow { path: "src/v1/stage0/src/std_pareto.rs", authority: SourceModule { name: "std.pareto" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, - MirrorDebtRow { path: "src/v1/stage0/src/std_witness_admission.rs", authority: SourceModule { name: "std.witness_admission" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, - MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_complexity.rs", authority: SourceModule { name: "v1.compiler.complexity" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, - MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_emit.rs", authority: SourceModule { name: "v1.compiler.emit" }, generator: Stage0Emit, disposition: CarriedAuthorityAdvanced }, - MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_emit_rust.rs", authority: SourceModule { name: "v1.compiler.emit_rust" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, - MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_infer.rs", authority: SourceModule { name: "v1.compiler.infer" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, - MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_infer_lookup.rs", authority: SourceModule { name: "v1.compiler.infer_lookup" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, - MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_infer_resolve.rs", authority: SourceModule { name: "v1.compiler.infer_resolve" }, generator: Stage0Emit, disposition: CarriedAuthorityAdvanced }, - MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_infer_types.rs", authority: SourceModule { name: "v1.compiler.infer_types" }, generator: Stage0Emit, disposition: CarriedAuthorityAdvanced }, - MirrorDebtRow { path: "src/v1/stage0/src/v1_compiler_parse.rs", authority: SourceModule { name: "v1.compiler.parse" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished }, - MirrorDebtRow { path: "src/v1/stage0/src/v1_std_core.rs", authority: SourceModule { name: "v1.std.core" }, generator: Stage0Emit, disposition: CarriedReasonNotEstablished } -]