Skip to content

Remove LLM response caching module - #9

Merged
briansrls merged 1 commit into
mainfrom
claude/review-llm-integration-R3zIY
Jan 31, 2026
Merged

briansrls merged 1 commit into
mainfrom
claude/review-llm-integration-R3zIY

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Summary

Removes the cache module from llm-ops, including the CacheKey, LlmCache, and CacheRegistry types along with all associated tests and documentation.

Changes

  • Deleted lib/llm-ops/src/cache.rs (380 lines)

    • Removed content-addressable response caching implementation
    • Removed per-provider cache namespacing logic
    • Removed LRU-style eviction based on hit counts
    • Removed comprehensive test suite for cache functionality
  • Updated lib/llm-ops/src/lib.rs

    • Removed pub mod cache; declaration
    • Removed caching documentation from module-level docs

Rationale

The caching layer is being removed from the core llm-ops library. This functionality may be:

  • Moved to a separate crate for better separation of concerns
  • Implemented at a different architectural layer
  • Replaced with an alternative caching strategy

The removal is clean with no remaining references to the cache module in the public API.

https://claude.ai/code/session_01YWr5RgyznYNtJy3UWfQ3Nu

The cache module was an in-memory response cache keyed by
(provider, model, messages, params). This is not needed — the
intended caching strategy is to structure messages so callers get
maximum cache hits from the provider's own caching (Anthropic
prompt caching via CacheControl hints, OpenAI automatic prefix
caching). The CacheControl/ContentBlock API in chat.rs already
handles this correctly.

https://claude.ai/code/session_01YWr5RgyznYNtJy3UWfQ3Nu
@briansrls
briansrls merged commit 1dc141c into main Jan 31, 2026
1 check passed
briansrls pushed a commit that referenced this pull request Feb 5, 2026
Correctness fixes:
1. HashBuilder now includes path + delimiter + length to prevent
   boundary collisions (e.g., A="ab",B="c" vs A="a",B="bc")
2. Glob errors propagated instead of silently dropped
3. CI "Fresh" check now verifies output files exist (handles case
   where manifest restored from cache but files weren't)
4. Manifest load errors return Error, not Missing (corrupted JSON
   no longer falls back to file existence)
5. Verify mode is strict: missing manifest = fail (can't prove
   freshness without it)

Design issues documented in TODO_hacks for future cleanup:
- #6: Duplicate codegen hash logic (fix with gunbc-infra)
- #8: GUNBC_EXEC_MODE env var bridge
- #9: ResourceHandle forgeable
- #10: ManagedResource::compute_key lacks manifest param
- #11: SimpleResource silent empty hash
- #12: check_state computes keys when entry missing

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
briansrls pushed a commit that referenced this pull request Feb 13, 2026
Addresses feedback from 2026-02-12 PR review across 6 key areas:

1. Fix probe→observer recursion (#1): Intermediate observers are now
   promoted to probes unconditionally (not gated on Exact matchers).
   Tests are seeded from baseline DryRun, so concrete values aren't
   needed. This enables compositional segment testing A→B + B→C.

2. Fix extract_observers() seen/merge bug (#2): NodeExamples with only
   input-dependent matchers (Exact/Contains) no longer suppress valid
   chain-safe matchers from live_expected_outputs for the same node.
   Switched to merge-by-node approach using BTreeMap union.

3. Make gaps fail CI (#3): Coverage gaps now generate a failing
   test_observability_invariant_no_gaps test instead of just a header
   comment. Aligns behavior with the stated invariant.

4. Make lowering failures loud (#4): DAG lowering errors now generate a
   failing test_probe_observer_lowering_failed test instead of silently
   returning None and skipping all chain tests.

5. Seed policy fail-closed (#5/#8): Inverted seed_policy_for_type to
   whitelist known-safe primitive types (String, Bool, Int, etc.) and
   default unknown types to ExplicitSeedRequired. New types and aliases
   no longer silently fall into placeholder generation.

6. Additional hardening:
   - Add input_mocks as a probe source (#6) for DAGs seeded via entry
     input ports
   - Track weak observers (Any/IsRequest/IsResponse) in coverage
     reports (#5) so teams can identify low-value assertions
   - Promoted probes now appear in analysis results
   - ParamType::from(&str) panics on unknown types instead of silently
     defaulting to Str (#9)
   - Int parsing returns ParseError::InvalidInt instead of unwrap_or(0)

https://claude.ai/code/session_014cTfu4arnDzFZCELaR26P4
briansrls added a commit that referenced this pull request Mar 3, 2026
- OutputPathMetadataOp: content_upsert output-path annotation nodes (FC-7)
- ResourcePassthroughOp: std.resources lifecycle nodes (non-acquire/release)

Each type has focused doc comments explaining its role, replacing the
overloaded IdentityCallableOp that served two unrelated purposes.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 7, 2026
Each comment is documented at the relevant code location with:
- The review comment number for traceability
- Root cause explanation
- Fix direction and what it's blocked on

#8 dfs_finish_order: visited-set-bounded recursion, needs worklist (I1/I2)
#9 dfs_collect_component: same pattern, same fix
#10 CostExtern: honest boundary marker, needs stdlib cost contracts
#11 iteration_element_name: positional heuristic, needs cross-module lookup (CG-2/CG-3)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 11, 2026
Node.name dissolution Phase 2b: thread source_index into the harder
utility functions that lacked it, completing the migration of all
accessor call sites to _at variants.

- 00_core.dag: thread source_index through find_property, transport
  accessors (base_url, headers, env, etc.), service_config_* functions,
  expr_has_self_call, expr_has_non_tail_self_call
- 03_resolve.dag: add source_index to resolve_modules, resolve_import,
  get_exported_names, get_item_name, get_variant_names; add
  import_specific_names_at
- 04_infer.dag: migrate classify_let_value, classify_argument
- 05_emit_rust.dag: thread source_index through emit_imports,
  child_from_key, response handling, emit_auth_source_ctor
- 05_emit_python.dag, 05_emit_go.dag: emit_imports threading
- complexity.dag: thread si through collect_call_evidence,
  iteration_element_name, analyze_structural_bounds
- compile.dag: serialize_import_node threading

All non-_at accessor calls now receive real source_index. The non-_at
function definitions remain (task #9) pending final cleanup.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 18, 2026
Addresses ChatGPT review on R2 (SHA 04bd642, APPROVE_WITH_COMMENTS).
Non-blocking concern: D2 step 4 now makes two Transform-target
substitution arms load-bearing (Callable(id) and
FieldProject.field_child), but the Acceptance suite only locked the
Callable path.

Locks the FieldProject arm with test #11
(test_3a4_refined_generic_field_project_in_predicate_discharges):

    type Box<T> { inner: T, tag: Int }
    fn f<T>(x: Box<T> where x.tag != 0) -> Box<T> = x
    fn caller(b: Box<Int> where b.tag != 0) -> Box<Int> = f(b)

Tag-field-over-Int keeps the operator arm concrete so the test
isolates the FieldProject substitution path; pairs symmetrically
with #9 (Callable arm). Verifies D2's claim that FieldProject is
genuinely in the admitted Transform-target substitution class, not
a doc-only promise.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 18, 2026
…e) (#522)

* WIP: D

* docs: DB-16 R2 — Transform-target substitution in cloned predicate body

Addresses codex blocking review on Part 1 (SHA f879d5f): D2 as
originally written specified predicate-body cloning with only the
parameter slot re-pointed, so generic `Callable(Instantiation{...})`
targets inside predicate bodies would retain template-rooted
`TypeParam` arguments post-clone. At discharge, the callee's cloned
body would carry `Instantiation{args: [T -> S_outer]}` while the
caller's body carries `Instantiation{args: [T -> Int]}`, and
`declaration_shapes_equivalent` (infer.rs:3579-3618) bottoms out on
atom-to-atom for the argument comparison — discharge silently fails.

Extension (D2 step 4 + D4 + D6 + Impl pointer + Open Q2):
- `clone_predicate_body` gets a new `subst: &SubstStack` parameter.
  Transform-target walk routes `Callable(id)` and `FieldProject.field_child`
  through `concretize_decl_with_subst`. `Operator(_)` untouched.
- DB-11's callers pass an empty `SubstStack` (no behavior change;
  16 `test_3a3_*` tests guard the regression).
- Acceptance gains two tests: `test_3a4_refined_generic_callable_in_predicate_discharges`
  (positive: load-bearing against the codex-named regression class)
  and `test_3a4_refined_generic_callable_in_predicate_distinct_template_rejects`
  (negative: confirms D6 no-entailment preserved under substitution).
- D6 commitment unchanged: substitution is categorical (`T := Int`
  writes `Int` everywhere), not inference/implication/ordering.

ChatGPT review still in flight; any orthogonal signal lands as a
follow-up commit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: DB-16 R2.1 — fail-closed diagnostics + single-authority cache

Addresses ChatGPT review (APPROVE_WITH_COMMENTS, non-blocking) on
SHA f879d5f. Two Part-2 clarifications folded into the design:

1. Fail-closed diagnostics (D2 steps 1, 2, 4). Once D1 establishes
   that substitution is required, subsequent failures (substituted
   base doesn't resolve, malformed predicate shape, out-of-fragment
   body reaching the materialize phase) register a Diagnostic per
   C-8 rather than silently returning None. Only unbound-TypeParam
   at D1 (legitimate retry absence) keeps the silent fallthrough.

2. Single-authority cache (D3, D7). Phase-based materialization
   locked: runs in materialize_callable_signature_instantiations
   (infer.rs:2236, already &mut Dag), extends
   concretize_decl_with_subst with a refinement branch. Dedup is a
   structural scan over dag.declarations() via
   find_equivalent_substituted_refined_decl — mirrors
   find_equivalent_anonymous_instantiation. The "cache" IS the Dag;
   no parallel semantic side table. signature_type_shape stays
   &Dag — no walker widening.

Open Q1 (`&Dag` vs `&mut Dag`) marked resolved: phase-based approach
chosen, rationale recorded in D3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: DB-16 R2.2 — FieldProject acceptance lock (chatgpt R2 review)

Addresses ChatGPT review on R2 (SHA 04bd642, APPROVE_WITH_COMMENTS).
Non-blocking concern: D2 step 4 now makes two Transform-target
substitution arms load-bearing (Callable(id) and
FieldProject.field_child), but the Acceptance suite only locked the
Callable path.

Locks the FieldProject arm with test #11
(test_3a4_refined_generic_field_project_in_predicate_discharges):

    type Box<T> { inner: T, tag: Int }
    fn f<T>(x: Box<T> where x.tag != 0) -> Box<T> = x
    fn caller(b: Box<Int> where b.tag != 0) -> Box<Int> = f(b)

Tag-field-over-Int keeps the operator arm concrete so the test
isolates the FieldProject substitution path; pairs symmetrically
with #9 (Callable arm). Verifies D2's claim that FieldProject is
genuinely in the admitted Transform-target substitution class, not
a doc-only promise.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: DB-16 R3 — collapse to single construction authority

Addresses ChatGPT R2.1 review (SHA a13e383, REQUEST_CHANGES).
Blocking concern: R2.1's revised D3 moved construction to the
materialize phase (concretize_decl_with_subst branch), but D1, RA-4,
and Implementation Pointer still described signature_type_shape /
reattach_refinement_to_substituted_base as the constructor. Two
stories for one production site — avoidable "produce here, maybe
rediscover there" ambiguity Part 2 would inherit.

R3 collapses to one explicit authority:

- **Producer (D2):** concretize_decl_with_subst's new refinement
  branch, fired inside materialize_callable_signature_instantiations
  (&mut Dag). Sole construction site for substituted refined carriers.

- **Consumer (D1):** signature_type_shape gains a read-only pre-
  terminator branch. When refinement_base_requires_substitution
  fires, calls find_equivalent_substituted_refined_decl (&Dag, pure
  scan) to find the pre-materialized carrier. Lookup miss falls
  through to DB-11 identity-terminator + retry machinery.

Removed helper reattach_refinement_to_substituted_base — it was the
dual-authority artifact. D2's 7-step walk now explicitly runs inside
the concretize branch; no separate helper.

Touched sections: design preamble (new single-authority paragraph),
D1 (code sketch + narrative rewritten for lookup), D2 (opening
reframed), RA-4 (construction site = phase, not walker),
Implementation Pointer (split into Producer/Consumer sides),
Associations (construction site + lookup site distinguished).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* DB-16 Part 2: refined-generic substitution impl + tests (3a.3 closure)

Implements the design from docs/design-db16-refined-generic-substitution.md
(R3: unified construction authority).

**Producer (D2).** `concretize_decl_with_subst` (infer.rs:2706) gains
a refinement branch that fires before the connective match when
`decl.refinement.is_some()` AND `refinement_base_requires_substitution`
returns true. The branch calls `materialize_substituted_refined_decl`,
which performs the D2 7-step walk: resolve substituted base → extract
predicate slots → allocate fresh composite param port → clone
predicate body with Transform-target substitution → wrap in fresh
Bind → build fresh predicate-Arrow Declaration → allocate the fresh
substituted-refined carrier. Each failure mode registers an explicit
`Diagnostic::ResolveError` per C-8.

**Consumer (D1).** `signature_type_shape` stays `&Dag` read-only.
New pre-terminator branch: when the refinement base requires
substitution, call `find_equivalent_substituted_refined_decl` and
return the pre-materialized carrier if found. Lookup miss falls
through to the DB-11 identity-terminator + retry machinery.

**Transform-target substitution.** `clone_predicate_body` extended
with a `subst: &SubstStack` parameter. Transform-target walk routes
`Callable(id)` and `FieldProject.field_child` through
`concretize_decl_with_subst`. `Operator(_)` untouched. DB-11's
callers in `lower.rs` pass an empty `SubstStack` — regression-
guarded by all 16 `test_3a3_*` tests remaining green.

**Structural equivalence under substitution.**
`callable_decls_equal_under_subst` + `normalized_instantiation_args`
handle the template-side Instantiations that carry extra bindings
for outer TypeParams (e.g., gate's Instantiation{always_true,
[T'→T_gate, T_gate→T_gate]} vs caller's {always_true, [T'→Int]}):
normalize both to their template-own-type-param args only, then
resolve through subst and compare.

**Cross-module access.** `SubstStack` and `concretize_decl_with_subst`
promoted to `pub(crate)` in `infer.rs`. `clone_predicate_body` and
`outer_predicate_slots` promoted to `pub(crate)` in `lower.rs`.

**Acceptance.** `test_3a4_*` suite (9 new + 3 pre-existing) passes.
New DB-16 tests: discharges_across_substitution,
distinct_refinement_rejects, identity_across_instantiation_sites,
literal_arg_rejects, composite_discharges,
callable_in_predicate_discharges (Callable arm),
callable_in_predicate_distinct_template_rejects (no-entailment under
substitution), field_project_in_predicate_discharges (FieldProject
arm), substrate_integrity_behavior_still_five_variants. Tests use
`always_true<T>(x: T) -> Bool` generic-helper pattern so predicate
bodies type-check for abstract T.

**ROADMAP.** 3a.3 row flipped 🟡 Partial → ✅ Shipped. Closed-block
`Remaining (blocking for ✅ Shipped)` removed. New `Closed (DB-16,
PR #522)` entry. Added `Landing: DB-16 refined-generic substitution
(S, PR #522)` section.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* DB-16 R3.1: self-binding-only filter + harden materialize invariants

Addresses two reviews on 12fbaff:

**Codex BLOCKING (infer.rs:3244):** `normalized_instantiation_args`
previously filtered substituted callable-target instantiations down
to `template.type_params`, dropping all non-template-param bindings.
That silently collapsed two instantiations that differed only by
retained callable-argument identity — a Facts-Flow-Forward violation.

Fix: strip **only** self-bindings (`arg.parameter == arg.value`),
which are the reattachment artifacts from `resolve_callable_target`'s
unification under outer generic scopes (where outer TypeParams bind
to themselves pending inference). Non-self bindings carry semantic
identity from `retained_template_arguments_for_target` and are now
preserved across the equivalence walk. Two instantiations that differ
only by a non-self retained binding correctly compare unequal.

Why this still closes the original 1105-vs-1101 divergence: 1105 had
[T'→T_gate, T_gate→T_gate] — the second is self-binding, stripped.
Filtered form [T'→T_gate] matches 1101's [T'→Int] after subst.

**ChatGPT NON-BLOCKING (infer.rs:2873-2884, 2949-2952):** three
"defensive fallthrough" branches in `materialize_substituted_refined_decl`
silently returned `template_refined` on caller-contract violations
(missing refinement edge, non-ResolvedIdentifier connective, predicate
connective mutated post-slot-extraction). Per chatgpt's note: each
is probably unreachable today but could mask bugs if the construction
authority drifts.

Hardened to `unreachable!()` with explicit message naming the
violated caller contract. Truly-unreachable invariant violations now
panic with backtrace rather than degrading silently. Genuine
substrate-integrity failures (step-1 base resolution, step-2
predicate shape, step-4 out-of-fragment body) continue to attach
`Diagnostic::ResolveError` and return `template_refined` per C-8.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* DB-16 R3.2: close claude-review + chatgpt-review items

Three additions per reviews on 12fbaff / 3a897f4:

**Identity-across-sites as a checked invariant (chatgpt design question).**
`test_3a4_refined_generic_identity_across_instantiation_sites` now
asserts a structural invariant rather than just verifying compilation
success. After compile, count anonymous refined-Int declarations
whose connective is `Atom(ResolvedIdentifier(Int))`. Expected: 2
(one per caller's own `where` clause). Dedup failure would produce
3+ as materialize-allocated carriers accumulate. Directly checks the
substrate-hygiene claim from D7 — if dedup regresses, the test fires
before duplicate carriers pollute the DAG.

**Test #7 (narrowing × substitution composition, claude-review).**
`test_3a4_refined_generic_narrowing_composite_discharges` locks the
cross-product of DB-11 arm-local narrowing and DB-16 substitution.
Caller narrows concrete `pred_a(n)` via `if pred_b(n, n) then ...`;
DB-11 produces composite `pred_a(n) && pred_b(n, n)` on the caller's
refined port; DB-16 materializes the callee's substituted-refined
carrier with the same composite; flatten-and-subset discharge (DB-11)
runs unchanged over the shared substrate.

Note on narrowing shape: DB-11's `narrowable_var_name` (`lower.rs:845`)
requires a 2-argument cond with exactly one scope-bound free
variable, so `pred_b` takes two args of T with both call sites
passing `n` for both. First attempt used a 1-arg `pred_b(n)` cond
— rejected by narrowing eligibility; predicate never narrowed;
discharge failed. Fixed by mirroring DB-11's 2-arg narrowing
convention.

**Test #5 (retry-on-unbound) deferred to ROADMAP follow-up.**
`test_3a4_refined_generic_retry_on_unbound_type_param` would
exercise the `is_retryable_generic_decl` retry path when a
TypeParam is unbound at iteration N and bound at N+1, locking the
retry-then-succeed outcome. Currently implicit-covered by the
multi-site and callable-in-predicate bonus tests (both depend on
fixpoint convergence through retry iterations); explicit construction
of the scenario requires synthesized fixpoint-iteration timing.
Tracked as Lane 3 Stage 3a.3 follow-up with a 1-month yellow-flag
threshold after merge. Audit anchor: Q5 construction-authority
invariant preserved under retry.

36/36 test_3a_* tests pass (16 DB-11 + 13 DB-16 + 7 other). Full
v3-compiler test suite green; clippy + fmt gates clean.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: DB-16 R3.3 — align D3 wording with implementation helpers

Addresses ChatGPT review on 0d072a2 (lingering prose: D3 named
both `refinement_ports_equal` and `predicate_discharges` as the
dedup equivalence relation; the latter is composite-subset matching,
which would over-match in dedup). Also brings the doc in line with
the helpers R3.1 actually shipped.

Three prose tightenings:

1. **Strict structural equivalence, not discharge.** D3 now names
   `predicate_bodies_equal_under_subst` as the dedup relation — a
   strict lockstep walker modeled on DB-11's `refinement_ports_equal`.
   Removes `predicate_discharges` from the equivalence-relation
   wording (that helper is for conjunct-subset discharge, not
   dedup).

2. **Name the actual implementation helpers.** `callable_decls_equal_under_subst`
   and `normalized_instantiation_args` now appear in the doc with
   their actual semantics, matching `infer.rs`.

3. **Self-binding-only filter (R3.1).** D3 explicitly documents
   that `normalized_instantiation_args` strips **only** self-bindings
   (`arg.parameter == arg.value`) — the reattachment artifacts from
   `resolve_callable_target` unification under outer generic scopes.
   Non-self retained callable arguments are preserved so the
   Facts-Flow-Forward guarantee the codex R3.1 review locked in is
   documented, not just implemented.

4. **Dedup inclusive of user-authored carriers.** New paragraph
   explicit about the stronger guarantee the implementation provides:
   when a caller's `where` clause produces a structurally-equivalent
   carrier, the dedup scan returns the caller's carrier rather than
   allocating a fresh one. That is what
   `test_3a4_refined_generic_identity_across_instantiation_sites`
   checks (2 anon refined-Int carriers total, not 4).

Per the meta-review's KEEP_ITERATING prescription on Part 2: this
aligns the contract the remaining reviews will read against the
actual implementation object, rather than leaving them to reconcile
stale prose.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: D

* DB-16 R3.4 (revert WIP 484ca50) + authority-consolidation follow-up

Addresses ChatGPT R3.1 review (REQUEST_CHANGES): DB-16 maintains a
parallel equality authority (`predicate_bodies_equal_under_subst` +
`transform_targets_equal_under_subst` + `callable_decls_equal_under_subst` +
`normalized_instantiation_args`) shadowing DB-11's
`refinement_ports_equal` / `refinement_targets_equal` /
`declaration_shapes_equivalent`. Reviewer asked to either collapse
the dual authority or revert the ROADMAP ✅ Shipped flip.

**Attempt:** `484ca5034` (WIP: D auto-commit) tried the collapse —
extended `refinement_ports_equal` with `subst`, folded self-binding
normalization into `declaration_shapes_equivalent`'s Instantiation
arm, deleted the parallel stack.

**Regression:** the collapsed `refinement_targets_equal` resolved
the template side's Callable id through `resolve_decl_with_subst`
and then called `declaration_shapes_equivalent`. But
`declaration_shapes_equivalent` compares Instantiation argument
VALUES strictly, without threading subst. The pre-collapse
`callable_decls_equal_under_subst` had handled this via a
substitution-aware arg-value comparison. Without it, dedup scans
miss existing carriers; materialize reallocates per fixpoint
iteration; fixpoint never converges; tests hang.

**Correct consolidation path** requires threading `&SubstStack`
through `declaration_shapes_equivalent` itself, which has a
~20-call-site surface. Too wide for this PR round.

**Revert:** `src/v3/compiler/src/infer.rs` checked out from
`3dc043d7e` (R3.3 working state). 36/36 `test_3a_*` tests pass
(16 DB-11 + 13 DB-16 + 7 others). Clippy + fmt clean.

**Consolidation tracked as ROADMAP follow-up** under Landing: DB-16.
Yellow-flag threshold: 1 month after Part 2 merge. Design anchor:
`feedback_substrate_principle_audit` (single-authority invariant).

Honest posture: the parallel stack is correctness-preserving (dedup
emits strictly stronger matches than DB-11's discharge would, never
producing false dedups), but represents maintenance surface that
future drift would re-expose. The retained-argument bug Codex
caught in R3.1 was ONE class instance; the follow-up closes the
class structurally rather than locally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: DB-16 R3.5 — mark test #5 deferred in Acceptance section

Addresses codex review on cec4cb0 (non-blocking, fix-in-PR-if-easy):
the design doc's Acceptance section listed
`test_3a4_refined_generic_retry_on_unbound_type_param` as shipped
baseline even though R3.2 deferred it to a ROADMAP follow-up
(`Landing: DB-16` → `Follow-up — fixpoint-retry explicit test`).

Test #5 now annotated as "Deferred to ROADMAP follow-up" with the
rationale: implicit-covered by multi-site + callable-in-predicate
bonus tests; explicit construction requires synthesized fixpoint-
iteration timing; 1-month yellow-flag threshold.

Design record no longer overstates 3a.3 closure coverage.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: DB-16 R3.6 — align D2 failure-path prose with shipped diagnostics

Addresses codex review on c016161 (non-blocking, fix-in-PR-if-easy):
D2's failure-path prose named `Diagnostic::Internal` (a variant that
doesn't exist in v3's Diagnostic enum) and "return None" semantics,
but the landed implementation uses `Diagnostic::ResolveError` and
returns `template_refined` (the template carrier, allowing
downstream retry machinery to take over via signature_type_shape's
lookup-miss path).

The `Diagnostic::Internal` name was a drafting artifact from R2.1's
fail-closed hardening pass — I discovered at implementation time
that the v3 Diagnostic enum has ResolveError / TypeMismatch /
ArityMismatch / ParseError / TokenizerError (no Internal variant),
used `attach_diagnostic(Diagnostic::ResolveError {...})` + return
template_refined via the `unreachable!()`-in-invariant-contract-
violation vs diagnostic-in-detectable-violation split that R3.1
hardened. The doc never caught up.

Three D2 steps (1, 2, 4) updated to reflect shipped semantics.
Substantive invariant unchanged: detectable substrate-integrity
violations attach a diagnostic (C-8 fail-closed); truly-unreachable
caller-contract violations panic via `unreachable!()` (R3.1).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 27, 2026
* docs(std.unicode): cite UCD 15.x / UAX-11 authority

Closes the #920 post-merge citation gap. Header now states the file
is sourced from UCD 15.x (UAX #11 East Asian Width) for the display-
width tables and is intentionally 15.x compatible rather than pinned
to a specific minor. UAX #9 is explicitly not consulted (no bidi).
No behavior changes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: tighten P5 per-PR dissolution gate (b) for ROADMAP-cited deferrals

Require exactly one checkable receipt: delete path, SG-0 census
before/after counts, or lane plus concrete ROADMAP row/link. Call out
vague deferrals as insufficient. Align INVARIANTS §P5 (b) with the
template without duplicating the checklist.

Made-with: Cursor

* docs(audit): W-C1 follow-up harvest table

Single control surface for cleanup-lane harvest of #900/#901/#920/#897/#824/#825
per dispatch from tidy-dove-734 (#941). No ctrl#263 in repo; this docs/audit
artifact is the agreed fallback. Rows: source PR, gap, file/invariant, owner
lane, dissolution trigger, acceptance check, tracking authority, disposition.

* docs(audit): mark #920 citation follow-up closed

* docs(audit): close #897 #824 #825 harvest rows

* docs(audit): cite closure evidence for harvest rows

* WIP: Cleanup

* docs(std.unicode): clarify UAX 11 coverage

* docs: link cleanup harvest from roadmap

* docs(std.unicode): refresh bootstrap spans

* docs(std.unicode): refresh full bootstrap spans

* docs(std.unicode): refresh no-parse bootstrap spans

* docs(audit): stabilize harvest code references

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 28, 2026
… reattribution; 2+5+6+7 inline)

Director signoff on 6 items per dialogue 2026-04-28:

==================================================
Item 3: T-CostLens-Composition → Substrate (post-R2 continuation)
==================================================

Substrate authors; Verification asserts. T-CostLens-Composition is
substrate-authoring of cost facts (per-op algebra cost + per-primitive
realization cost) + Lens<SymbolicCost> instance demonstration —
substrate-shape, not verification-shape. Director-locked.

Cascade:
- r3-structure.md lane #10 row: Manager column "Verification Manager
  (or new Cost Manager)" → "Substrate Manager (post-R2 continuation)"
- §"Manager continuation across R2-R3" point 1: Substrate continues
  with T-Int128 + T-Anthropic-Wire + T-CostLens-Composition (3 lanes)
- thesis-mapping.md row :78 (Coercion cost = complexity): added
  "owned by Substrate Manager (post-R2 continuation)" annotation
- thesis-mapping.md row :127 (Target-level cost composes): cross-
  reference to row :78 ownership

==================================================
Item 4: T-Bridge-Retirement distribute work, centralize ledger
==================================================

Bridges live in PB/Substrate territory; ledger lives in Verification.
Per the 5 named bridges, Director's distribution map:

  Bridge                                   | Owner
  -----------------------------------------|------
  SourceSpan.file participation checks     | Substrate
  mark_bootstrap_secret_nominal_opacity()  | Substrate
  canonical lens-name dispatch             | PB Manager
  include_str! side channels               | PB Manager
  patch_lower_helpers_* residual           | PB Manager

  Verification owns: bridge_retirement_ledger_zero audit gate +
                     coordination/reporting cadence

Net: 3 Substrate-owned + 3 PB-owned + 1 Verification-owned ledger.
No parallel manager spawned; each natural-owner program absorbs
into existing scope.

Cascade:
- r3-structure.md lane #9 row: Manager column "Verification Manager
  (or T-LensProducer-Retirement umbrella)" → "Verification (ledger
  only); retirement work distributed per bridge map" with full
  distribution map inline
- §"Manager continuation" point 1: PB Manager continues with
  T-LensProducer-Retirement + T-FixedPoint + T-Tier3-Dissolution
  + 3 distributed bridge retirements (canonical lens-name dispatch /
  include_str! / patch_lower_helpers_* residual)
- §"Manager continuation" point 2 (Verification Manager): updated
  to "owns 2 lanes + 1 ledger gate" with explicit T-CostLens-
  Composition exclusion note

==================================================
Item 8: T-LensProducer-Retirement keep XL with internal sub-gates
==================================================

XL framing kept (critical-path is dependency-determined, not file-
count-determined). Internal sub-gate visibility added for closure-
ledger reporting:

  (i)   lens_apply.rs retired (gated on PB-Runtime interpreter-as-data)
  (ii)  lens_testgen.rs retired (same gate as lens_apply.rs)
  (iii) regen_lens.rs retired (gated on PB-1 bin-shim emit pattern —
        distinct gate)

Cascade:
- r3-structure.md lane #2 row Covers column: added "Internal sub-gates"
  section with the three sub-gates + closure-ledger-reporting note

==================================================
Items 2 + 5 + 6 + 7 (inline; no Director-specific cascade beyond what's
in the cascade above)
==================================================

Item 2: Manager count 6→7 justification — added one-line statement in
r2-structure.md §"Goal 6 (R2 closure demo) is not a lane" section: "R2
carries 7 standing managers — original 6-manager structure (locked
2026-04-26) plus Evaluator added 2026-04-28 as Goal 7. Original
structure preserved + 1 added, not restructured. Manager count rises
to 7 to reflect Evaluator's distinct program scope; does NOT split or
fold any existing manager."

Item 5: Structural-acceptance-per-lane-close discipline — codified in
r2-structure.md §"Goal 6" as discipline statement: "the demo IS the
structural acceptance gate" — each lane's closure PR proves the lane
closed correctly via a structural acceptance gate (omni_layers_share_
one_node_tree, etc.). Demo = gate's evidence, not separate artifact.
R2/R3 Release Managers coordinate visibility; the lane's manager owns
authoring. Avoids "process gate" framing.

Items 6 + 7: Post-R2 emergent work disposition — codified in
r3-structure.md §"Manager continuation" point 1: "if `ctrl/` pressure-
test or other post-R2 work surfaces new impossible-bug classes,
modeling refinements, or substrate gaps, those are absorbed by Substrate
Manager continuation as substrate-completion work — they're evidence of
substrate gaps (per closed-system principle: enumerated bug classes are
exhaustive over substrate; new classes = enumeration was wrong =
substrate gap to fill), not new lanes spawning new managers."

==================================================
Net structural changes
==================================================

R3 structure post-cascade:
  - Substrate continuation: 2 lanes → 3 lanes (T-Int128 +
    T-Anthropic-Wire + T-CostLens-Composition)
  - Verification: 4 lanes → 2 lanes + 1 ledger gate (T-V-L4-L7-Direct
    + T-V-L5-Corpus + bridge_retirement_ledger_zero audit gate)
  - PB: unchanged at 3 lanes (T-LensProducer-Retirement +
    T-FixedPoint + T-Tier3-Dissolution) + absorbs 3 distributed
    bridge retirements
  - R3 Release: unchanged at 1 lane (T-Omni-Shape-B)
  - Total lanes: still 10
  - Active managers: still 4 (Substrate / PB / Verification / R3 Release)

The split now reflects scope-shape match: Substrate authors substrate
work; PB authors bootstrap work; Verification asserts gates by
construction; Release coordinates visibility.

Verification:
  scripts/check-release-doc-authority.sh    → PASS
  scripts/test-check-release-doc-authority.sh → PASS

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 29, 2026
* docs(r2): land R2 closure ledger + signal-receiver protocol

Adds docs/r2-closure-ledger.md as the standing artifact satisfying
r2_closure_ledger_landed acceptance gate from the R2 Release Manager
brief. Carries:
- Per-manager rows (Substrate / Modeling / Grounding / Impossible-Bugs /
  Pure Bootstrap / Evaluator) at lane / sub-lane / item / class
  granularity matching each manager's brief.
- T-LensProducer-Retirement as one row with 3 internal sub-gates
  (Director cascade Item 8 — sub-progress, not three lanes).
- Reserved "R1 Residual (absorbed)" surface so R1C-B strict-receipt
  rows (sleek-pike #1164 / bold-wolf #1163) and R1 residual sweep rows
  merge in without table reshape.
- Signal-receiver protocol: cross-manager queue channel; receipt =
  ledger row update + queue ack; cadence touchpoints with
  velocity-tripwire ≥3:1 surfacing to Director per INVARIANTS §P5(c).
  Release Manager remains single ledger owner; lane-level structural
  gates stay with lane-owning managers.

Wires the brief: r2-release-manager.md owned deliverable #9 and the
r2_closure_ledger_landed acceptance gate now point to the new doc.
Minimal blast radius — no edits to docs/r2-structure.md per dispatch
guidance.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r2): address RM review on closure ledger

Non-blocking follow-ups from PR #1166 review:
- Gate-string convention note: descriptive placeholders until ROADMAP
  alignment pass; lane-owning manager is canonical-name authority.
- in-flight vs not-started convention: requires active worker PR or
  cited substrate landings; "worker brief authored" alone stays
  not-started. Flips Impossible-Bugs nested-optional + unhandled-
  diagnostic-paths rows back to not-started.
- T-Ground-Pilot row: gate corrected to pilot_inhabitance_routing_
  stability_landed; last signal cites #765 (per r2-grounding-manager).
- B4 narrative: split #1069 onto Phase 2 row; Phase 1 row keeps only
  B4.2 first-consumer wiring as last signal.
- R2-close clause: explicit that R3-continuation rows do NOT gate
  r2_close_signal_to_director_authored.
- Replace line-136 anchor in r2-structure.md citation with section
  + quoted phrase (rot-resistant per code-reviewer exploratory note).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r2): align v2-retirement timing with r2-structure authority

Two surface mentions in r2-release-manager.md said v2 retirement
operates post-R2; r2-structure.md §"R2 Release Manager" is single
authority and locks it as post-R3 (moved with the R3 structured-
program reframe). Inline review on PR #1166 flagged the dual-
authority risk. Aligns both spots; no edits to r2-structure.md.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 6, 2026
… Copy

openai-pro reviewer (PR #1783, on commit 9729c35, REQUEST_CHANGES)
correct: ClosurePrimitive is_copy rule put UniqueImmutableBorrow in
the "true" branch, but per Rust Reference §"Closure types" → "Call
traits and coercions" a closure is Copy/Clone iff it does NOT capture
by unique-immutable-borrow OR by mutable reference. This was a
substrate-correctness defect — would mark &uniq-capturing closures
Copy contrary to Rust's own closure trait rules.

Two fixes in one commit:

1. ClosurePrimitive is_copy rule (line 154): "mode = SharedBorrow" only;
   both MutableBorrow AND UniqueImmutableBorrow now block Copy. Authority
   pinned: https://doc.rust-lang.org/1.86.0/reference/types/closure.html.

2. Acceptance test #9 added: behavior-driven coverage of derived
   is_copy + closure-trait correctness with six closure cases (no
   captures, SharedBorrow, MutableBorrow, UniqueImmutableBorrow
   negative, ByValue Copy, ByValue non-Copy) + one function-item case
   (unsafe/extern qualifier blocks Fn-tower). Catches drift in the
   per-variant derivation rules before walker rows land.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 6, 2026
…R-F (#1783)

* WIP: proud-lark-674

* fix(brief): use BoundedInterval shape per HEAD substrate

* fix(brief): replace machine-local path with host-neutral phrasing

* WIP: proud-lark-674

* fix(brief): restrict Never algebra inhabitance to operation-only algebras (no value witnesses)

* fix(brief): drop encoding axis — algebra choice (FreeMonoid<Char> vs FreeMonoid<Byte>) carries encoding per design lock

* WIP: proud-lark-674

* fix(brief): correct manager label to R2 Grounding Manager per live authority docs

* WIP: proud-lark-674

* fix(brief): replace host-local git plumbing language with durable repo/git-prerequisites phrasing

* WIP: proud-lark-674

* fix(brief): fold safety into representation axis; exclude Encoding from §H Step 3 leaves

* WIP: proud-lark-674

* fix(brief): route HashSet/BTreeSet to existing Set<T> = BooleanAlgebra<T> authority per M9

* WIP: proud-lark-674

* WIP: proud-lark-674

* fix(brief): gate Cardinal substrate, split function-item/pointer/closure, escalate Option/Result substrate parent

* WIP: proud-lark-674

* WIP: proud-lark-674

* fix(brief): hash/Ord admissibility axes; route Result via dsl/std/error_primitives; closure FnTrait derived from captures; FnQualifiers as record coords

* WIP: proud-lark-674

* fix(brief): route floats via ApproximateField; expand ReferenceModel rows to full four-axis records; clean stale Option/Result gate cross-ref

* WIP: proud-lark-674

* fix(brief): remove RealizationCost authoring from T-Ground-Rust scope (owned by T-Ground-LanguageSpec)

* WIP: proud-lark-674

* fix(brief): correct closure call-trait derivation per Rust Reference (cumulative tower; move is capture mode not trait selector)

* WIP: proud-lark-674

* fix(brief): align preamble gate list with §F (PR-F sole primary; PR-I/HigherOrder conditional)

* WIP: proud-lark-674

* fix(brief): split impl Trait into argument-position (universal) and return-position (existential) rows per Rust Reference

* WIP: proud-lark-674

* fix(brief): expand FunctionItemIdentity, CaptureSet capture-paths, and ImplTraitReturn opaque_captures per Rust Reference

* WIP: proud-lark-674

* fix(brief): add UniqueImmutableBorrow as fourth CaptureMode per Rust Reference closure types

* WIP: proud-lark-674

* fix(brief): gate float rows on Real/base-carrier STOP; add edition_capture_policy + use<> legality to ImplTraitReturn

* WIP: proud-lark-674

* fix(brief): derive default_capture from edition (illegal-states discipline) — store edition only

* WIP: proud-lark-674

* fix(brief): correct M9 receipt — Float inhabits ApproximateField is comment-only; live float.dag declares Field<Word*>; add Float migration gate

* WIP: proud-lark-674

* fix(brief): float row STOP-gated; ApproximateField is post-gate candidate parent, not dispatchable HEAD consumer

* WIP: proud-lark-674

* fix(brief): remove floats from Phase 1 slice; convert test 6 to STOP assertion; add Float migration gate to STOP #7

* WIP: proud-lark-674

* fix(brief): surface full std-carrier generic signatures (hasher S, allocator A) per extdeps fidelity

* fix(brief): add STOP #11 for non-default hasher/allocator instantiation (Phase 1 default-only scope)

* fix(brief): retarget §F RealizationCost escalation cross-ref (was pointing to STOP #7 = float gate)

* WIP: proud-lark-674

* fix(brief): expand FunctionItemIdentity generic_args (type/const/lifetime); add async_kind axis to ClosurePrimitive (sync vs async tower)

* WIP: proud-lark-674

* fix(brief): closure lends_to_future is derived from captures (not stored); rename is_async to async_kind per manager terminology

* fix(brief): std-carrier trait bounds (?Sized, Allocator, Allocator+Clone); invert closure lending suppression to sync tower; correct impl-Trait edition-affects-lifetimes-only + use<> trait-method legality

* fix(brief): enumerate all five derivation inputs for impl-Trait capture defaults + use<> legality (edition, item_kind, bounds, param kind, required trait generics)

* fix(brief): correct lending semantics — by-value capture by future IS lending; encode deref-projection exception

* fix(brief): use<> precise-capture cannot narrow type/const params (must include all in-scope per Rust Reference)

* fix(brief): structure TraitObjectPrimitive (base_trait/auto_traits/object_lifetime/dyn-compat); expand impl-Trait legality to seven inputs; replace stale grounding-manager:265 line ref

* fix(brief): expand impl-Trait use<> legality to full five-constraint matrix (bound-mentioned lifetimes; anonymous-arg-position forbids use<>)

* fix(brief): bound-mentioned-lifetime constraint covers other return bounds (multi-return signature case)

* fix(brief): pin Rust Reference + std authorities to 1.86 versioned URLs (extdeps fidelity)

* fix(brief): structure authority pin (toolchain + reference + std + edition); add STOP #12 for toolchain/edition delta from pin

* fix(brief): pin §A and §B authority URLs to 1.86.0 versioned bases (clean up two remaining floating URLs)

* fix(brief): drop allocator axis from §B std-carrier rows (allocator_api unstable on 1.86); update STOP #11 to forbid allocator-bearing instantiation under stable pin

* docs(brief): unescape inline-code backticks in T-Ground-Rust brief

Addresses PR #1783 reviewer note: two `\`RealizationCost\`` instances on
line 3 used escaped backticks that render literally in some markdown
viewers. Replaced with plain inline-code spans.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(brief): trait-object base_trait Optional (zero non-auto traits valid)

Reviewer (PR #1783 inline at line 68) correct: Rust Reference §Trait
object types says "not more than one" non-auto trait — zero is valid
(e.g., `dyn Send`, `dyn Send + Sync`). Requiring exactly one base_trait
dropped auto-traits-only trait-object facts under P1/extdeps fidelity.

- §A line 68: base_trait: TraitRef -> Option<TraitRef>; "exactly one"
  -> "at most one (zero valid for auto-traits-only objects)".
- §A line 71: dyn-compatibility check applies only when Some(_); None
  case vacuously satisfied (auto traits are always dyn-compatible).
- §C line 122: TraitObjectPrimitive mirrors the Optional shape +
  vacuous-satisfaction note.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(brief): FunctionItemPrimitive derived trait-inhabitance receipt

Reviewer (PR #1783 inline at line 112 + summary on 44cff1a) correct:
FunctionItemPrimitive carried identity + signature only and dropped
Rust Reference §Function-item-types trait facts (Copy/Clone/Send/Sync
unconditional; Fn/FnMut/FnOnce conditional on unsafe/target_feature/
non-Rust ABI). Downstream grounding lost callable/admissibility facts
under P1/P2.

Added derivation receipt sub-bullet on the FunctionItemPrimitive row:
- Unconditional Copy/Clone/Send/Sync (zero-sized, no captures).
- Conditional Fn/FnMut/FnOnce derived from item_decl qualifiers:
  inhabits all three iff unsafe = false AND abi = Rust AND
  target_feature = None; otherwise blocked.
- Trait-inhabitance is DERIVED not stored (P2; mirrors ClosurePrimitive
  derived-not-stored rule for the same trait family).

Authority pinned: https://doc.rust-lang.org/1.86.0/reference/types/function-item.html

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(brief): per-variant is_copy derivation receipt for C-axis expansion

Reviewer (PR #1783 inline at line 108) correct: pilot's
IntegerPrimitive/NonIntegerPrimitive carry Copy/is_copy facts that live
Rust emission consumers read; only FunctionItemPrimitive had explicit
trait derivation among the new variants. Other new variants
(FloatPrimitive, TextualPrimitive, NeverPrimitive, CompoundPrimitive,
FunctionPointerPrimitive, ClosurePrimitive, ReferencePrimitive,
TraitObjectPrimitive, ImplTraitArgPrimitive, ImplTraitReturnPrimitive)
dropped the fact under P2 facts-flow.

Added "Per-variant is_copy derivation receipt" section after the variant
list with structural derivation for every new variant, citing Rust
Reference §"Copy" + §"Special types and traits" + §"Auto traits"
(pinned to 1.86.0). is_copy is DERIVED not stored on every variant,
mirroring the lends_to_future/fn_traits discipline in ClosurePrimitive
and the FunctionItemPrimitive precedent. Companion is_clone/is_send/
is_sync facts follow the same per-variant rule.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(brief): FunctionPointerPrimitive — FnSignature shape + variadic + HRTB axes

Reviewer (PR #1783 inline at line 120) correct: FunctionPointerPrimitive
delegated to an undefined FnSignature and only named unsafe/abi,
leaving variadic extern signatures (e.g., unsafe extern "C" fn(*const u8,
...) -> i32) and higher-ranked binders (e.g., for<'a> fn(&'a T) -> &'a T)
without a substrate home under P1/P2.

Extended the row with three additions:

1. FnSignature shape pinned: { params: List<Param>, return: ReturnType }
   per Rust Reference §"Function pointer types"; ReturnType distinguishes
   Never from () (the -> ! divergent return is structurally distinct).
   Same type shared by FunctionItem/Closure signatures (not undefined).

2. variadic: Bool axis with cross-axis constraint (variadic = true ⇒
   abi ≠ Rust per Rust Reference §"Variadic functions"; emit-time error
   otherwise). Required to round-trip extern variadic signatures.

3. hrtb: List<LifetimeParam> axis carrying the for<'a, ...> binder list.
   HRTB lifetimes introduce a fresh binder, structurally distinct from
   outer-scope lifetimes — for<'a> fn(&'a T) and fn(&'static T) are
   distinct types and the row MUST distinguish them or P1 fidelity is
   lost.

Authority: https://doc.rust-lang.org/1.86.0/reference/types/function-pointer.html
+ Rust Reference §"Variadic functions" + §"Higher-ranked trait bounds".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(brief): resolve R2/R3 manager + allocator-axis self-contradictions

openai-pro reviewer (PR #1783, on commit 0d1bac6) flagged two
self-contradictions in dispatch authority:

1. **Manager routing R2 vs R3**: line 7 said "R2 Grounding Manager"
   but line 252 + cross-program signal use "R3 Grounding Manager
   (#1745)". Future workers would have conflicting STOP-escalation
   targets. Resolved: line 7 now reads "R3 Grounding Manager (#1745)"
   with explicit absorption note for the R2→R3 rename. All routing
   now targets #1745 consistently.

2. **Allocator-axis single-authority conflict**: line 85 said
   "every collection carrier carries hidden generic parameters
   (allocator A, hasher S) that the brief MUST surface" but line 89
   + STOP #11 say allocator is unstable on 1.86 stable / out of
   scope for Phase 1. Resolved: line 85 reframed as "stable
   parameters at the pinned 1.86.0 toolchain" — hasher is in scope
   (stable), allocator is held under STOP #11/#12 (unstable).
   Authoring an allocator-axis under the stable pin is itself a
   P1 violation (unstable spec fact under stable pin).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(brief): closure is_copy derivation — UniqueImmutableBorrow blocks Copy

openai-pro reviewer (PR #1783, on commit 9729c35, REQUEST_CHANGES)
correct: ClosurePrimitive is_copy rule put UniqueImmutableBorrow in
the "true" branch, but per Rust Reference §"Closure types" → "Call
traits and coercions" a closure is Copy/Clone iff it does NOT capture
by unique-immutable-borrow OR by mutable reference. This was a
substrate-correctness defect — would mark &uniq-capturing closures
Copy contrary to Rust's own closure trait rules.

Two fixes in one commit:

1. ClosurePrimitive is_copy rule (line 154): "mode = SharedBorrow" only;
   both MutableBorrow AND UniqueImmutableBorrow now block Copy. Authority
   pinned: https://doc.rust-lang.org/1.86.0/reference/types/closure.html.

2. Acceptance test #9 added: behavior-driven coverage of derived
   is_copy + closure-trait correctness with six closure cases (no
   captures, SharedBorrow, MutableBorrow, UniqueImmutableBorrow
   negative, ByValue Copy, ByValue non-Copy) + one function-item case
   (unsafe/extern qualifier blocks Fn-tower). Catches drift in the
   per-variant derivation rules before walker rows land.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: proud-lark-674

* fix(brief): RPIT capture matrix — item_kind-scoped + per-abstract-type

openai-pro reviewer (PR #1783, on commit 251cabb, REQUEST_CHANGES)
correct on two RPIT capture-rule defects per Rust Reference §"Impl
Trait" → "Capturing":

1. **Default capture: edition rule scoped to item_kind** (line 136).
   Old text said "Rust 2015/2018/2021 captures lifetimes only if named
   in trait_bounds" (edition-only rule). The pre-2024 lifetime
   exception applies ONLY to free fns + inherent associated fns/methods.
   Trait methods + trait-impl methods capture ALL in-scope generics
   (type, const, AND lifetime) regardless of edition. Following the
   old rule would under-capture lifetimes on trait-method RPIT rows
   (P1 violation). Default-capture is now derived from
   (edition, item_kind, trait_bounds) jointly, with explicit
   item_kind-by-item_kind enumeration.

2. **use<> legality: per-abstract-type, NOT cross-sibling** (line 139).
   Old text said use<> must include lifetimes from "other return
   bounds in the same function signature" (cross-sibling). Rust
   Reference rule is per abstract return type: each return's use<>
   only needs lifetimes from its OWN bounds. Cross-sibling
   enforcement authors parallel/fictional authority and rejects
   legal Rust signatures (P1/P2). Removed other_return_bounds from
   the input list (was 7 inputs, now 6); rule reframed as
   "lifetimes appearing in THIS abstract type's own trait_bounds".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(brief): §A RPIT capture summary defers to §C item_kind matrix

openai-pro reviewer (PR #1783, on commit 7f32aec, REQUEST_CHANGES)
correct: when fixing §C in commit 7f32aec, I left §A line 74 with
the old edition-only lifetime-capture rule. §A and §C now disagreed
on the same RPIT lifetime-capture fact — duplicate authority for a
substrate fact (P1/P2 violation).

Resolved at §A line 74:
- "Edition only governs lifetime default-capture" → "Default capture
  is item_kind-dependent, NOT edition-only".
- Pre-2024 lifetime exception explicitly scoped to free fns + inherent
  associated fns/methods only; trait methods + trait-impl methods
  capture ALL in-scope generics regardless of edition.
- §A explicitly defers to §C for the authoritative item_kind-by-
  item_kind matrix.
- use<> constraint #2 also synced to §C: per-abstract-type lifetime
  rule, NOT cross-sibling.

Single authority restored: §C is the source of truth, §A is a
summary that points at it.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(brief): R2/R3 file gap + ReturnType single-authority + AbiKind sum

codex reviewer (PR #1783, on commit 7f32aec, 3 BLOCKING) all valid:

1. **Manager-authority migration gap** (line 4): brief routes to R3
   Grounding Mgr (#1745) but live authority file is named
   r2-grounding-manager.md. Resolved by adding an explicit
   "Authority-file rename pending" note: file rename is
   Director-routed scope (out of this lane); citations to
   r2-grounding-manager.md:NN reference the live HEAD path verbatim
   and remain valid until rename lands; STOP routing already targets
   #1745. Treats the two as a single coordinated authority, not a
   contradiction.

2. **ReturnType = Type | Never duplicated NeverPrimitive** (line 94):
   FnSignature gave `!` a second representation alongside the
   existing NeverPrimitive row (P2 single-authority violation).
   Resolved: ReturnType reduced to `Type`. The `-> !` divergent
   return is a Type whose row is NeverPrimitive. `-> ()` is a Type
   whose row is CompoundPrimitive { kind: Tuple, elements: [] }.

3. **variadic + abi cross-axis precondition violated illegal-states
   discipline** (line 95): variadic: Bool + abi: AbiTag let
   variadic=true ∧ abi=Rust be representable, then relied on
   validation. Resolved: variadic moved INSIDE the AbiKind sum's
   Extern arm. AbiKind = Rust | Extern { abi: ExternAbi, variadic:
   Bool }. The illegal state is now un-representable at the type
   level (P2 / API-level enforcement, not runtime validation).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(brief): Vec<T> M9 parent + lending reads (mode, body_use) jointly

codex reviewer (PR #1783, on commit 007a47c, 2 BLOCKING) both valid:

1. **Vec<T> M9 parent naming** (line 93): Vec<T> row stated only the
   refinement axes (ownership/growability/cardinality) without naming
   its M9 substrate parent first. Per MODELING.md M9 (DFS the concept
   DAG), each row should attach to the existing concept it refines.
   Fixed: Vec<T> now opens with "Inhabits List<T> = FreeMonoid<T>"
   per the M9 substrate parent (consistent with String inhabiting
   FreeMonoid<Char>). Refinement axes follow as narrowing facts.

2. **Lending derivation reads (mode, body_use) jointly** (line 127):
   prior rule classified all UniqueImmutableBorrow captures as
   non-lending. But a &uniq T capture is itself a borrow of an
   &mut T referent — if the future MUTATES through the referent
   (body_use ∈ {mutate, consume}), the underlying mutable place is
   aliased across calls, which is lending. Fixed: lending rule now
   reads BOTH mode and body_use per capture. Three lending triggers:
   - mode = MutableBorrow (any body_use)
   - mode = ByValue (consumed by future)
   - mode = UniqueImmutableBorrow AND body_use ∈ {mutate, consume}
   Non-lending: SharedBorrow (any body_use) or UniqueImmutableBorrow
   with body_use = read only, OR deref-projection exception.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(brief): line-13 manager citation + Phase-1 Q2 overclaim narrowed

openai-pro reviewer (PR #1783, on commit a7c8531, APPROVE_WITH_COMMENTS)
correct on two non-blocking findings:

1. **Line 13 stale manager citation**: cited grounding-manager.md
   (historical, classified as such later in the brief) for the
   two-authority discipline; live authority is r2-grounding-manager.md.
   Fixed: line 13 now cites r2-grounding-manager.md:60-74.

2. **Phase-1 Q2 overclaim**: line 283 said the u128/isize/usize slice
   "Validates PR-F's Q1 + Q2 locks end-to-end" — but Q2 is the
   ReferenceModel<T> pointer/reference axis set, and an integer-only
   slice doesn't exercise any pointer-family row. Fixed: claim
   narrowed to "Validates PR-F's Q1 lock only"; Q2 explicitly noted
   as NOT exercised by this slice (separate slice required).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 9, 2026
…cation table (codex BLOCKING)

codex top-level BLOCKING on PR #2358 sha 7a34af5: 2 valid findings.

**Finding 1 — §2 trigger partition assumed-shape vs mechanical**:
§2 partition was cluster-level estimation, not per-entry mechanical audit. Codex correct that "option-(c) dominance" claim needed grounding.

Fix: §2 now explicitly scopes the partition as cluster-level methodology (NOT per-entry attribution) — derived from (a) inspection of header comments where present + (b) inferred classification of commentless entries by filename pattern. Per-entry verification deferred to Task 13 (UNACCOUNTED entries grep). The cluster-level partition supports §3 velocity-math finding without per-entry attribution; both §1 + §3 conclusions reproducible at cluster-level.

**Finding 2 — §8 Director-audit bullets transcribed without per-instance verification**:
§8 listed 9 drift instances by short reference; each bullet's grounding was implicit (verified in corresponding fix commits but not surfaced inline).

Fix: §8 converted to verification table with explicit "Verification (landed authority)" column per instance. Each of the 9 drift instances now cites:
- The grep-verified landed authority (e.g., `docs/r3-program-plan.md` §1.8 row #11 + Director disposition `473b99fb...`)
- The fix commit / PR where addressed (e.g., PR #2361 sha 6efde88)
- Dispositions where applicable (e.g., #7 dissolved by Task 12 PR #2364; #9 resolved by Director (a) ratification + Task 12)

Each drift instance now self-grounds the §8 meta-finding without requiring readers to re-derive evidence per-bullet.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 9, 2026
…2358)

* docs(audit): R3 PB-0 velocity walk + SG-0 census trajectory finding

Director-greenlit follow-up to PR #2300 cluster analysis. Honest census walk + velocity-to-zero math against gates #8 (sg0_non_test_zero) + #84 (every_rust_test_ports_to_dag_or_generated) — the Pure-Bootstrap-Zero closure gates per THESIS.md:298 + ROADMAP.md:53/88.

LOAD-BEARING FINDING: SG-0 census is GROWING, not shrinking. 9-day delta 2026-04-30 → 2026-05-09: +30 entries (119 → 149), at +3.3/day average. R3 close requires gates #8 + #84 reach 0; at current trajectory the gates never close.

Per-class partition shows ~80-90 of 101 test entries dissolve via single bulk event when Cluster M (T-Tests-As-Data-Completeness) lands; remaining classes dissolve via PB-Runtime + T-V2-Retirement + T-Tier3-Dissolution + LP-Retirement.

Reclassifies Cluster M as critical-path-load-bearing for PB-0 closure thesis (PR #2300 had it as parallel). Without Cluster M COMPLETE, gate #84 cannot close inside 8-12 week R3 window.

Surfaces 2 NEW honest-close risks (Risk 5 trajectory + Risk 6 Cluster M dispatch status) for Director cycle absorption + Brian-tier framing question on whether "PB-0 by R3 close" is still load-bearing or has drifted.

Cites THESIS.md, ROADMAP.md, r3-program-plan.md §1.8 + §10, prior cluster analysis as parents; does not restate gate Pass-conditions.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(audit): §4 dependency picture — separate substrate-flow vs PB-0-closure edges (codex BLOCKING)

Codex review on PR #2358 line 92: §4 dependency diagram had A → B → M (substrate flow) but §5 Risk 4 + PR #2300 §4 Risk 2 reference M → B → E (PB-0-closure sequencing). Inconsistent edge directions violated INVARIANTS P2/P5 single-authority-metadata for sequencing.

Resolution: §4 now explicitly carries two edge-classes:
- View 1 substrate-flow: A → {B, M} (parallel-post-A)
- View 2 PB-0-closure: M → (B-PB-0-honest cementing-in-dag) → E

Both views are simultaneously true under different relations (substrate-availability vs closure-readiness). The "M → B → E" sequencing in §5 Risk 4 corresponds to View 2 — closure-honesty sequencing, not substrate flow.

PR #2300 §2 had M classified as "parallel" which is correct under View 1 substrate-flow but missed View 2 PB-0-closure-readiness; this audit's reclassification of M as "critical-path" is correct under View 2 closure-flow.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(audit): §0 + §3.2 — durable authority cite + dissolution-rate evidence partition (openai-pro APPROVE_WITH_COMMENTS)

openai-pro review on PR #2358 sha 93f187e → 9c61c4f: 2 valid findings.

§0 authority cite: replaced local filesystem path (`/Users/briansrls/.worktrees/gunbc/zesty-bear-812 thread`) with durable GitHub-comment refs:
- gunbc#846 #issuecomment-4411924843 (Director's initial relay)
- gunbc#846 #issuecomment-4412008376 (subsequent ratification + partner-work delegation)

§3.2 evidence partition: prior framing labeled the recent-PR list as "materially reduced entries" but included enabling-only landings (#2281 +1, #2271 net 0, #2200 added entries). Re-partitioned into:
- "Census-reducing landings" (only PR #2279)
- "Enabling-only landings" (#2281, #2271, #2200) — substrate/scaffold work that does NOT reduce census in-PR
- Recomputed rate using only census-reducing landings: ~0.25/day or ~0.5-1/cycle (upper bound)
- Added explicit "Why this matters for §3.3" sentence clarifying enabling-only events are prerequisites, not reductions

Boundary discipline + Modeling Faithfulness re-grounded; rate calculation now cleanly traceable to evidence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): §8 meta-finding — closure-claims-vs-HEAD drift pattern (Director scope expansion)

Director scope expansion at gunbc#846 #issuecomment-4412017502: 6 additional drift findings from parallel Director-tier audit sweep all share root cause "program-plan claims running ahead of HEAD reality." Director recommended folding pattern observation into this audit.

§8 captures 9 specific drift instances across PM + 2 Director audits:
1. §1.8 status drift (this audit §1)
2. SG-0 trajectory drift (this audit §0)
3. TC1 #11 plan-language drift (Director ask 6)
4. 10 demonstration gates runtime-path drift (Director ask 7)
5. Substrate-gap-class #61 enumeration drift (Director ask 8)
6. Gate-count canonicalization drift (Director ask 9)
7. Gate #95 carve-doc cross-ref drift (Director ask 10)
8. §10.3 ratification ledger publication drift (Director ask 11)
9. R4-carve hand-Rust drift (PM ask 2026-05-09 at #828 #issuecomment-4412052024)

Pattern shape: every instance is "document text asserts a closure-state that HEAD does not satisfy" via 4 sub-shapes (post-R3 substrate dep / trajectory divergence / one-sided conjunctive close / cross-ref drift).

Standing recommendation: status-vs-HEAD grep cadence in standing PM/Director cycle (per-Mgr lane self-check + PM weekly §1.8/§10.3 grep). Meta-finding is structural-not-personnel: drift class closes when reconciliation cadence is added explicitly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(audit): §0 audit-time snapshot disclaimer (codex BLOCKING — staleness vs HEAD)

codex BLOCKING inline @ docs/audit/r3-pb0-velocity-walk-2026-05-09.md:23: "HEAD census row is stale against sg0_census_test.rs."

Verified: at PR branch sha 5ea313c the census is 49 + 102 + 2 = 153; on origin/main cf1d523 it's 50 + 103 + 2 = 155. Audit cited 48 + 101 + 1 = 149/150. Audit numbers ARE stale relative to HEAD — main has moved 1 commit past the PR branch since audit authored.

Fix: add explicit "audit-time snapshot" disclaimer scoping the count cells to the audit window. Live source-of-truth for SG-0 trajectory is `docs/audit/r3-sg0-trajectory-tracker.md` (daily/per-cycle refresh). The trajectory finding (growth ≥ +3.3/day; gates cannot reach zero at observed velocity) is structural and remains valid regardless of point-in-time count drift; specific cells should be read "as of audit window" not "as of HEAD now."

Per `r3-sg0-trajectory-tracker.md` §7 + audit §7: methodology durable; specific numbers ephemeral. The codex finding was correct that the audit numbers were presented as if HEAD-current; disclaimer now scopes them properly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(audit): tracker-file forward-reference (codex BLOCKING — tracker on sibling PR #2361)

codex BLOCKING inline @ docs/audit/r3-pb0-velocity-walk-2026-05-09.md:17: cited `docs/audit/r3-sg0-trajectory-tracker.md` is not in PR #2358's tree — it's on sibling PR #2361. If PR #2358 merges first, the reference points to a non-existent file (P1/P2 violation).

Verified: tracker file IS on PR #2361 branch (blob `85e072cf`); IS NOT on PR #2358 branch or main.

Fix: refactored references to:
- Cite `src/v3/compiler/tests/integration/sg0_census_test.rs` directly as the live SG-0 census source-of-truth (file IS on main)
- Note tracker artifact lands via sibling PR #2361; cite-once-merged
- §8 standing-recommendation updated similarly

Snapshot scope disclaimer now self-contained — audit can land independently of PR #2361 merge ordering. No forward-references to non-merged sibling content remain.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(audit): §4 gate #8 partial Cluster M overlap (openai-pro REQUEST_CHANGES)

openai-pro review on PR #2358 sha cf89a69: §2.2 row "infer/lower/test_runner" listed Cluster M as part of test_runner's dissolution dependency, but §4 summary claimed gate #8 is "orthogonal to M/B closure flow" — internal contradiction.

Fix: amended §4 to acknowledge partial Cluster M overlap for test_runner.rs specifically (test runner retires when Cluster M's TestClaim system can drive testing end-to-end as .dag data — i.e., when #87 cementing-test discipline + bulk-port discipline land).

Gate #8 is now correctly characterized: mostly orthogonal to M/B closure flow, but not fully — test_runner.rs is the specific overlap entry per §2.2. Single canonical PB-0 closure dependency picture restored across §2.2 + §4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(audit): §1 — overclaim "every test entry has dissolution-trigger comment" corrected (codex BLOCKING)

codex inline BLOCKING @ docs/audit/r3-pb0-velocity-walk-2026-05-09.md:40: prior framing claimed "every test entry has a header-comment naming a 'dissolution trigger'." Verified at HEAD: only ~32 of 103 test entries have inline header comments. The remaining ~71 are potentially untracked hand-Rust debt under INVARIANTS P1/P5 — option-(c) discipline assumes per-entry dissolution-trigger documentation but these lack it.

Fix: §1 corrected to "About 32 of 103 test entries... the remaining ~71 entries lack inline dissolution-trigger comments." Added explicit audit finding: commentless entries are "potentially untracked hand-Rust debt" — they may have implicit dissolution paths (m1/m2 boundary tests via T-V2-Retirement + Tests-As-Data; sg* tests via Tests-As-Data; common/ helpers when downstream consumers retire) but lack the per-entry header comment.

PM follow-up (Task 13): per-entry audit of ~71 commentless entries to classify under existing clusters OR flag as untracked debt requiring fresh substrate authoring or comment-attribution PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(audit): §2 cluster-level partition scope + §8 per-instance verification table (codex BLOCKING)

codex top-level BLOCKING on PR #2358 sha 7a34af5: 2 valid findings.

**Finding 1 — §2 trigger partition assumed-shape vs mechanical**:
§2 partition was cluster-level estimation, not per-entry mechanical audit. Codex correct that "option-(c) dominance" claim needed grounding.

Fix: §2 now explicitly scopes the partition as cluster-level methodology (NOT per-entry attribution) — derived from (a) inspection of header comments where present + (b) inferred classification of commentless entries by filename pattern. Per-entry verification deferred to Task 13 (UNACCOUNTED entries grep). The cluster-level partition supports §3 velocity-math finding without per-entry attribution; both §1 + §3 conclusions reproducible at cluster-level.

**Finding 2 — §8 Director-audit bullets transcribed without per-instance verification**:
§8 listed 9 drift instances by short reference; each bullet's grounding was implicit (verified in corresponding fix commits but not surfaced inline).

Fix: §8 converted to verification table with explicit "Verification (landed authority)" column per instance. Each of the 9 drift instances now cites:
- The grep-verified landed authority (e.g., `docs/r3-program-plan.md` §1.8 row #11 + Director disposition `473b99fb...`)
- The fix commit / PR where addressed (e.g., PR #2361 sha 6efde88)
- Dispositions where applicable (e.g., #7 dissolved by Task 12 PR #2364; #9 resolved by Director (a) ratification + Task 12)

Each drift instance now self-grounds the §8 meta-finding without requiring readers to re-derive evidence per-bullet.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(audit): §1 trigger-coverage math reconcile to 101 (codex BLOCKING)

codex inline BLOCKING @ docs/audit/r3-pb0-velocity-walk-2026-05-09.md:40:
"trigger-coverage math says 32 of 103 test entries while the same audit
snapshot and §2 say 101 test entries, so the remaining-debt count is
internally inconsistent under INVARIANTS P1/P2."

Verified: §1 used "32 of 103" + "remaining ~71" while §0 audit-time
snapshot table line 25 + §2.1 line 56 + §2.1 line 69 + §3 line 134
all use 101. The 103 was introduced in commit ebfebae (BLOCKING fix
for "every entry" overclaim) — I picked 103 instead of matching the
existing 101 framing. Real internal inconsistency.

Fix: §1 trigger-coverage reconciled to 101 (matches §0 audit-time
snapshot table at sha c25b2d8df + §2.1 + §3 references):
- "32 of 103" → "32 of 101" (with explicit cite to §0 snapshot)
- "remaining ~71" → "remaining ~69" (101 − 32 = 69, partition-consistent)
- §2 methodology cite "(~32 of 103 test entries per §1)" → "(~32 of 101)"

Single audit-time-snapshot count (101) used consistently across §0/§1/§2/§3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(audit): §8 row 1 source pointer — cluster-analysis (openai-pro REQUEST_CHANGES)

openai-pro REQUEST_CHANGES on PR #2358 sha 2ba3719: §8 drift instance #1
sourced "9 gates likely promotable to CONSUMER_LANDED" to "this audit §1"
but §1 is the SG-0 option-(c) discussion, NOT a 9-gate status audit.
The source pointer didn't actually ground the row.

Verified: the 9-gate inventory is in docs/audit/r3-cluster-analysis-2026-05-09.md
§1 (PR #2300, on main), which says verbatim: "9 gates likely-promotable
from DECLARED → CONSUMER_LANDED. 88 → ~79 still-DECLARED if Mgrs
refresh ledger."

Fix: row 1 source pointer corrected to cluster-analysis doc citation
with verbatim quote + retain the existing grep-verification chain
(§1.8 + 8 merged PRs).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(audit): THESIS/ROADMAP citations to section anchors (codex non-blocking)

codex review on PR #2358 sha c27502c: non-blocking — "THESIS citation
says line 298 for the Pure Bootstrap quote, but the quote is at
THESIS.md:282 in the current repo; fix the line pointer when touching
the authority block."

Verified: THESIS:298 IS the Pure Bootstrap quote on origin/main (codex
may be reading a stale snapshot). But per
`feedback_section_anchors_over_line_numbers`, line numbers drift —
should switch to section/symbol anchors regardless.

Fix: parent-doc citations switched from line-numbers to structural
references:
- THESIS.md "Pure Bootstrap to Zero" framing + verbatim quote
  (section anchor; line-anchor-immune)
- ROADMAP.md T-PB-A lane row (`pb_hand_rust_at_shim_floor` predicate
  named explicitly) + T-PB-B lane row
  (`pb_rust_tests_outside_residual_zero` predicate named explicitly)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 18, 2026
* docs: design — the bootstrap as a complete fact model (T-32 Phase 1)

Operator-directed (briansrls, 2026-05-17): work out the bootstrap as a
fully modeled pipeline — every layer (compiler, seed, target, runtime,
machine) a declared fact model, every artifact a projection, zero
ambient hand-maintained code. Captures the design worked out in the
T-32 design conversation: the layer stack, the seed as
emit(snapshot, target, runtime), the comprehension boundary modeled as
a frozen sub-model + footprint fold + subset-Witness, the bootstrap
circularity modeled as a fixed point with a path-independent
self-validating witness, and the two honest floors (the permanent
physical axiom; the origin axiom that dissolves under path-
independence). This is the Phase-1 design content for TASKS.md T-32.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: fix path anchors + de-overclaim bootstrap.dag state (#3236 review)

cursor APPROVE_WITH_COMMENTS on #3236 — two P1 (modeling-faithfulness)
notes: (1) the layer-table paths were repo-root-unresolvable (bare
`extdeps/...`, wrong `compiler/workflow/` segment) — all .dag paths now
src/v4/-prefixed and correct (bootstrap.dag is src/v4/workflow/); (2) §5
said bootstrap.dag "already carries this as data" — on main it is a
T-20 scaffold naming the chain in its header; the staged-stage records
+ FixptStage1Stage2 + bit_identical_check as actual workflow data are
the in-flight T-20 expansion (#3213). Reworded to distinguish "this
Phase-1 model specifies the shape" from "carried as .dag data on main".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* TASKS.md T-32: wire the plan to the bootstrap-fact-model design doc

#3236 added docs/design-bootstrap-fact-model.md as "T-32's Phase-1
design content" — but T-32's TASKS.md entry (merged via #3233 before
the doc existed) did not reference it back, leaving the doc a one-way
link / effectively stray (nothing in the plan pointed to it). Add the
back-reference: T-32 Phase 1 names docs/design-bootstrap-fact-model.md
as its design content, states the Phase-1 deliverable is the operator-
ratified layer model in that doc, and that a Phase-1 worker reads it as
the brief. The doc is now consumed by the plan, not stray.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* design-bootstrap-fact-model: fix the trusting-trust + LanguageModel-authority claims (#3236 review)

codex BLOCKING ×2, both valid:

1. The fixed-point witness was doing double duty — reproduction AND
   trust-erasure. Corrected §5/§6: the bit-identical witness proves
   the fixed point is REACHED (reproduction), NOT that the seed was
   honest — a compromised seed (Thompson trusting-trust) reaches a
   compromised, self-consistent fixed point that passes the witness.
   Path-independence covers only benign entry paths. The "origin axiom
   dissolves" claim was wrong: it is a real second floor — the seed-
   honesty axiom — discharged by diverse double-compilation (Wheeler),
   not dissolved. End state = TWO floors, not one.

2. The doc treated the `LanguageModel` carrier as an existing authority;
   it is not declared (Theme-A #9). §2/§4 now mark it as open substrate
   T-32 Phase 1 must land (declare the carrier, or fix "a model IS a
   Node"), not an authority to point at.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 TASKS: align the T-32 summary with the design doc's §5/§6 (codex/cursor #3236)

The T-32 blurb pointing to docs/design-bootstrap-fact-model.md still carried
the pre-trusting-trust-fix framing — "a path-independent witness" and "the one
permanent physical axiom" — which is a stronger claim than the corrected design
doc makes. §5 qualifies path-independence to benign entry paths and scopes the
bit-identical witness to reproduction (not honesty); §6 names two floors. A
reader stopping at TASKS.md got the skewed summary. Tightened to match.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Sat May 16

* design-bootstrap-fact-model: honest compiler-pipeline status + footprint over full projection closure

Two BLOCKING review findings (#3236):

- §2 layer table overstated the v4 compiler pipeline as flatly
  "modeled". Only the front-end (01_tokenize / 02_parse) is modeled
  (CP-1a #3214); 00_compile / 03_normalize / 03_resolve / 04_infer /
  05_emit / 05_eval are T-8/T-9/T-10/T-22 scaffolds. Status now states
  this honestly under P1.

- §4 defined footprint as a fold over the snapshot alone, but §3
  defines the seed as emit(snapshot, target_model, runtime_model). The
  gate's seed_capability == footprint then undercounts the
  lowering/runtime constructs the seed must consume. footprint now folds
  over the full projection-input closure {snapshot, target_model,
  runtime_model}, matching seed_capability's "lowering the seed
  performs" component.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* design-bootstrap-fact-model: honest layer-model status — only rust.dag is modeled

BLOCKING review finding (#3236, docs/design-bootstrap-fact-model.md:31):
"the layer models needed already exist individually" overstated live
authority under INVARIANTS P1 (Documentation Describes Live State).
Verified on origin/main: rust.dag is modeled (2097 lines, T-4 rust-slice);
machine_code.dag (T-4.13), process.dag and file_system.dag (T-4.5) are
module-declaration-only scaffolds.

Fix: §2 status cells for target-language and runtime now distinguish the
modeled rust.dag from the three scaffolds; the "already exist" sentence
now states only rust.dag is modeled and names the per-file modeling as a
T-32 precondition.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* design-bootstrap-fact-model: cross-reference Practice 10 (now on main)

PR #3241 merged Practice 10 ("Don't hand-roll a derived operation") into
modeling-discipline.md. §1's principle — the seed is a projection, never
hand-code — is exactly Practice 10 at bootstrap scale: the seed is
produced by translation + emission (derived-operations registry rows 3
and 6), so a hand-written seed is the bootstrap-scale dissolution
finding. Added a one-paragraph cross-reference so the design doc leans on
the landed keystone Practice rather than restating the principle in
isolation.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Sat May 16

* design-bootstrap-fact-model: §7 Phase-1 deliverable names both honest floors

BLOCKING review finding (#3236:238): §6 establishes seed-honesty as a
real second floor discharged by diverse double-compilation, but §7's
Phase-1 deliverable enumeration named only "the named physical axiom" —
so the trust-discharge witness could fall out of T-32 (INVARIANTS P1/P2).

Fix: §7 now lists "both honest floors of §6 — the physical axiom and the
seed-honesty axiom with its diverse-double-compilation discharge
witness" as load-bearing T-32 Phase-1 deliverables, consistent with §6.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 26, 2026
briansrls added a commit that referenced this pull request May 26, 2026
briansrls added a commit that referenced this pull request May 28, 2026
* WIP: Analyses Finding #9 — implement formatter ConfigPatch monoid (T-4.16 fol

* T-4.16 follow-on: dissolve formatter-config-patch gate — add FieldPatch<T> monoid and *ConfigPatch types for all formatters

Implements ConfigPatch monoid for all 9 formatter files, dissolving the
feature:formatter-config-patch gate. Adds v4.std.patch { FieldPatch<T>,
apply_field_patch } (two-element Override/Inherit lattice per field) and
introduces *ConfigPatch record types + updated *_layer signatures for:
black, clang_format, google_java_format, ktfmt, lean4_format, prettier,
rustfmt, swift_format (gofmt trivially empty — no fields).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* prettier.dag: replace bespoke Prettier*Patch coproducts with FieldPatch<T>

Delete the 12 formatter-local patch coproducts (PrettierIntPatch,
PrettierBoolPatch, and the ten enum-specific variants) and migrate
PrettierOverrideOptions to FieldPatch<T> — eliminating the parallel
authority that violated INVARIANTS.md P2/P5.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* patch.dag: add compose_field_patch + field_patch_monoid<T> witness (M9/P1)

Grounds the declared monoid substrate against std/algebra: adds
compose_field_patch<T> (right-biased semigroup op, later layer wins)
and field_patch_monoid<T> -> Monoid<FieldPatch<T>> that assembles the
Magma/Semigroup/Monoid chain. Identity is Inherit.

Resolves the blocking inline review comment on PR #3705.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* prettier.dag: expand PrettierConfigPatch to per-field FieldPatch<T>

Replace coarse FieldPatch<PrettierFormattingOptions> with 23 per-field
patches mirroring PrettierFormattingOptions, so a layer can express a
single option override without full-record replacement. Update
prettier_layer to thread apply_field_patch per field via base.options.*
projection. Matches the per-field granularity of every other formatter
ConfigPatch.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* WIP: Analyses Finding #9 — implement formatter ConfigPatch monoid (T-4.16 fol

* patch.dag: correct grounding — right-biased optional-value monoid, not two-element lattice

FieldPatch<T> is 1 + T: for non-singleton T, distinct Override values
are distinct patches, so there is no single lattice top. Reframe the
external authority comment as the right-biased optional-value patch
monoid (Inherit = identity, Override = payload) — matching what the
compose/monoid witness actually implements.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* WIP: Analyses Finding #9 — implement formatter ConfigPatch monoid (T-4.16 fol

* field_patch_monoid.dag: remove hand-rolled field_patch_bool_eq (Practice 10)

Replace the local field_patch_bool_eq match-over-storage-shape with
law witnesses expressed purely through apply_field_patch (canonical
eliminator) and Bool == Bool equality — no new derived operation over
the FieldPatch coproduct. Each monoid law is now proven by applying the
composed patch to a concrete base and checking the Bool result.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* field_patch_monoid.dag: fix parse error — data initializer must start on same line as =

Move multi-line data initializers onto one line; extract associativity
witness into compose_assoc_lhs/rhs helper functions to keep line length
reasonable. Parser requires expression to begin on the same line as the
= token in a data declaration.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* test: wire monoid witness consumer claims in field_patch_monoid.dag

Add fp_monoid_op/fp_monoid_identity helpers that extract from
field_patch_monoid<Bool>() and three new TestClaims that route through
the Monoid witness surface rather than the raw helpers directly — so a
bad wiring of .identity or .semigroup.magma.op inside the Monoid record
would be detected.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: remove explicit <Bool> type args from field_patch_monoid calls

DAG parser treats `f<Bool>()` as a comparison expression, not a generic
type application — `Bool` is undefined as a variable. Drop the explicit
type arguments; inference resolves T=Bool from the declared return types
of fp_monoid_op and fp_monoid_identity.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* WIP: PR #3705: add right-bias TestClaim to field_patch_monoid — openai-pro RC

* WIP: PR #3705: add right-bias TestClaim to field_patch_monoid — openai-pro RC

* WIP: PR #3705: add right-bias TestClaim to field_patch_monoid — openai-pro RC

* WIP: PR #3705: add right-bias TestClaim to field_patch_monoid — openai-pro RC

* WIP: PR #3705: add right-bias TestClaim to field_patch_monoid — openai-pro RC

* fix: gate ConfigPatch record mirrors under config-patch-record-projection

Codex BLOCKING on PR #3761: scalar FieldPatch<T> is sound but per-formatter
*ConfigPatch types are hand-maintained mirrors of *Config. Add the owning
feature gate in v4.std.patch (T-4.16 follow-on dissolve-on) and consumer
tags on every formatter ConfigPatch until record-field projection lands.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix: clarify patch anchor and config-patch-record-projection owner

Claude REQUEST_CHANGES on #3761: drop misleading NixOS/Home Manager
anchor (implementation is right-biased optional-value monoid, not
commutative mkForce/mkDefault). Tighten feature gate wording and add
T-4.16 TASKS.md owner row for interim *ConfigPatch hand mirrors.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: PR #3705: add right-bias TestClaim to field_patch_monoid — openai-pro RC

* fix(T-4.16): align TASKS.md layering contract with ConfigPatch model

Codex REQUEST_CHANGES on #3705: TASKS.md still described superseded
*_layer(base, outer) full-config replacement while formatter files now
use *_layer(base, patch: *ConfigPatch) with v4.std.patch FieldPatch.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(prettier): align PrettierConfigPatch with PrettierConfig shape

Codex REQUEST_CHANGES #3761: stop flattening PrettierFormattingOptions
fields into PrettierConfigPatch. Introduce PrettierFormattingOptionsPatch
nested under options; overrides stays FieldPatch<List<...>> — matches
PrettierConfig { options, overrides } for P2 / projection contract.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: PR #3761 cursor RC fix: T-4.16 formatter ConfigPatch monoid + right-bias

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 28, 2026
* WIP: Analyses Finding #9 — implement formatter ConfigPatch monoid (T-4.16 fol

* T-4.16 follow-on: dissolve formatter-config-patch gate — add FieldPatch<T> monoid and *ConfigPatch types for all formatters

Implements ConfigPatch monoid for all 9 formatter files, dissolving the
feature:formatter-config-patch gate. Adds v4.std.patch { FieldPatch<T>,
apply_field_patch } (two-element Override/Inherit lattice per field) and
introduces *ConfigPatch record types + updated *_layer signatures for:
black, clang_format, google_java_format, ktfmt, lean4_format, prettier,
rustfmt, swift_format (gofmt trivially empty — no fields).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* prettier.dag: replace bespoke Prettier*Patch coproducts with FieldPatch<T>

Delete the 12 formatter-local patch coproducts (PrettierIntPatch,
PrettierBoolPatch, and the ten enum-specific variants) and migrate
PrettierOverrideOptions to FieldPatch<T> — eliminating the parallel
authority that violated INVARIANTS.md P2/P5.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* patch.dag: add compose_field_patch + field_patch_monoid<T> witness (M9/P1)

Grounds the declared monoid substrate against std/algebra: adds
compose_field_patch<T> (right-biased semigroup op, later layer wins)
and field_patch_monoid<T> -> Monoid<FieldPatch<T>> that assembles the
Magma/Semigroup/Monoid chain. Identity is Inherit.

Resolves the blocking inline review comment on PR #3705.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* prettier.dag: expand PrettierConfigPatch to per-field FieldPatch<T>

Replace coarse FieldPatch<PrettierFormattingOptions> with 23 per-field
patches mirroring PrettierFormattingOptions, so a layer can express a
single option override without full-record replacement. Update
prettier_layer to thread apply_field_patch per field via base.options.*
projection. Matches the per-field granularity of every other formatter
ConfigPatch.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* WIP: Analyses Finding #9 — implement formatter ConfigPatch monoid (T-4.16 fol

* patch.dag: correct grounding — right-biased optional-value monoid, not two-element lattice

FieldPatch<T> is 1 + T: for non-singleton T, distinct Override values
are distinct patches, so there is no single lattice top. Reframe the
external authority comment as the right-biased optional-value patch
monoid (Inherit = identity, Override = payload) — matching what the
compose/monoid witness actually implements.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* WIP: Analyses Finding #9 — implement formatter ConfigPatch monoid (T-4.16 fol

* field_patch_monoid.dag: remove hand-rolled field_patch_bool_eq (Practice 10)

Replace the local field_patch_bool_eq match-over-storage-shape with
law witnesses expressed purely through apply_field_patch (canonical
eliminator) and Bool == Bool equality — no new derived operation over
the FieldPatch coproduct. Each monoid law is now proven by applying the
composed patch to a concrete base and checking the Bool result.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* field_patch_monoid.dag: fix parse error — data initializer must start on same line as =

Move multi-line data initializers onto one line; extract associativity
witness into compose_assoc_lhs/rhs helper functions to keep line length
reasonable. Parser requires expression to begin on the same line as the
= token in a data declaration.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* test: wire monoid witness consumer claims in field_patch_monoid.dag

Add fp_monoid_op/fp_monoid_identity helpers that extract from
field_patch_monoid<Bool>() and three new TestClaims that route through
the Monoid witness surface rather than the raw helpers directly — so a
bad wiring of .identity or .semigroup.magma.op inside the Monoid record
would be detected.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: remove explicit <Bool> type args from field_patch_monoid calls

DAG parser treats `f<Bool>()` as a comparison expression, not a generic
type application — `Bool` is undefined as a variable. Drop the explicit
type arguments; inference resolves T=Bool from the declared return types
of fp_monoid_op and fp_monoid_identity.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* WIP: PR #3705: add right-bias TestClaim to field_patch_monoid — openai-pro RC

* WIP: PR #3705: add right-bias TestClaim to field_patch_monoid — openai-pro RC

* WIP: PR #3705: add right-bias TestClaim to field_patch_monoid — openai-pro RC

* fix: gate ConfigPatch record mirrors under config-patch-record-projection

Codex BLOCKING on PR #3761: scalar FieldPatch<T> is sound but per-formatter
*ConfigPatch types are hand-maintained mirrors of *Config. Add the owning
feature gate in v4.std.patch (T-4.16 follow-on dissolve-on) and consumer
tags on every formatter ConfigPatch until record-field projection lands.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix: clarify patch anchor and config-patch-record-projection owner

Claude REQUEST_CHANGES on #3761: drop misleading NixOS/Home Manager
anchor (implementation is right-biased optional-value monoid, not
commutative mkForce/mkDefault). Tighten feature gate wording and add
T-4.16 TASKS.md owner row for interim *ConfigPatch hand mirrors.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(T-4.16): align TASKS.md layering contract with ConfigPatch model

Codex REQUEST_CHANGES on #3705: TASKS.md still described superseded
*_layer(base, outer) full-config replacement while formatter files now
use *_layer(base, patch: *ConfigPatch) with v4.std.patch FieldPatch.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(T-4.16): update TASKS.md pattern line for ConfigPatch layering

Complete codex 18630 authority alignment: §T-4.16 pattern line still
described *_layer-only scaffold; now documents *ConfigPatch + per-field
apply_field_patch to match landed formatter files.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(prettier): align PrettierConfigPatch with PrettierConfig shape

Codex REQUEST_CHANGES #3761: stop flattening PrettierFormattingOptions
fields into PrettierConfigPatch. Introduce PrettierFormattingOptionsPatch
nested under options; overrides stays FieldPatch<List<...>> — matches
PrettierConfig { options, overrides } for P2 / projection contract.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix: remove formatter conflict markers

* WIP: Resolve merge conflict on PR #3705 (session/vivid-wren-215): merge origi

* chore: no-op refresh to reset review cycle

* chore: no-op refresh (2) to reset review cycle

* chore: add trailing newline to black.dag to refresh review cycle

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 28, 2026
… parity)

Peer-aligned with KotlinLanguageModel/SwiftLanguageModel; compiler authority
remains LanguageModel = Node until ingest projection lands.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 29, 2026
…ava excluded) (#3798)

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* fix(python): address review blockers for decimal int lex and claim header

Model decimal integers as 0|[1-9][0-9]* with a bounded T-6/T-7 gated scaffold
for full Python 3.14 integer-literals (bases, underscores). python_wave2a.dag
already uses Scope/Owns/Consumes without Discovery prose.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(python): add T-22 outcome-to-bool claim-bridge disposition marks

Match kotlin_mvp1_grammar_claim.dag Practice-10 predicate dissolution
comments on Outcome→Bool projection helpers.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(python): T-22 disposition mark on wave2a parse_accepted helper

Match python_mvp1_grammar_claim / kotlin_mvp1 predicate-dissolution pattern.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(P5): receipt for python wave-2a smoke ratchet expansion on PR #3798

INVARIANTS §SG-0 row + harness module comment + sg0 census note: +0-path
extension of v4_python_language_model_declares_t11_translation_rules; T-PB-B deferral.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(P5): sg0 census comment for PR #3798 python smoke expansion

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(python): disposition marks for catalog/nonzero-digit; clarify T-6 layout gate

Suite one-or-more already modeled via Sequence+Repeat(stmt) at python_grammar_suite_expr.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(python): gate PythonLanguageModel as lex/grammar bundle (Theme-A #9 parity)

Peer-aligned with KotlinLanguageModel/SwiftLanguageModel; compiler authority
remains LanguageModel = Node until ingest projection lands.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* WIP: T-4.17 Wave 2a: python lex/grammar data fill (deps T-6/T-7/T-4; cpp/java

* fix(p5): restore INVARIANTS SG-0 row break + smoke test doc comment newline

Claude RC: v4_compiler_emit_translate_smoke_test.rs row was joined onto
v4_compiler_compile_public_terminal_smoke_test.rs via dropped newline; restore
distinct markdown table rows. Restore blank //! separator before Dissolution block.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(python): move wave-2a parse fixture into TestClaim module

python_wave2a_non_mvp_source belongs in python_wave2a.dag with peer
rust/kotlin/swift wave-2a claims, not extdeps/languages/python.dag.
Keeps the language-spec module scoped to reference/model facts (P1/P2).

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 30, 2026
§10 worked-example walkthrough (per operator's DFS-discipline directive
2026-05-30):
  - §10.1 SG-1 generalized: RustAtomRealization → TargetAtomRealization
    (language-parametric per operator caution); added §10.1.1 worksheet form
  - §10.2 SG-2 generic carrier arity: grounded DFS finds Instantiation
    declared in std/node.dag:19 + PositionalEdges per :113, but NO
    TargetTypeExpressionProjection in extdeps/languages/rust.dag and NO
    Instantiation grep hit in src/v4/compiler/. Systemic fix: author
    TargetTypeExpressionProjection consumed per-connective by 05_emit.
  - §10.3 SG-5/SG-6 Set/BoundedLattice: grounded DFS finds Set<T> at
    std/collection.dag:52 with NO Ord constraint, BoundedLattice<T> at
    std/algebra.dag:66 with meet/join required, but NO Set realization
    in extdeps/languages/rust.dag. Systemic fixes: TargetCollectionRealization
    + BoundedLattice instance completeness gate in 04_infer.
  - §10.4 summary: total dispatch reduces from "fix 7951 errors" to 4 bounded
    modeling work items, each with brief-required worksheet preventing
    spot-fix trap.

Blocking-review fixes:
  - briansrls/codex BLOCKING: rung 2 "chosen targets" dilutes L6 standard #9.
    Reworded to "every project-committed target" + added explicit note
    distinguishing rung-2-smoke from L6-full-coverage.
  - briansrls/codex BLOCKING: D7 outside §8 (sign-off can omit it). Moved D7
    into §8 with full retrospective-ratification framing; §9.5 now references
    §8.D7 rather than duplicating.
  - cursor BLOCKING (prior round): D4 omitted TASKS.md:802 predicate 1
    ("every other scheduled task"). D4 now lists all 6 v4-done predicates
    with ladder mapping; acknowledges rung 7+8 framing was incomplete.
  - cursor BLOCKING (prior round): D1 claimed 9 rungs cover all 17 standards
    but #6 (Tier 2 runtime safety) skipped. D1 now acknowledges 16/17 and
    surfaces 3 options for #6 (rung 10, extend rung 9, or scope it out).

briansrls inline at :269 (std/node.dag:84-85 cite "not present") will be
addressed via PR reply — the cite IS present at lines 84-85 of current
src/v4/std/node.dag and was verified via grep during the SG-1 DFS.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 30, 2026
… sign-off) (#3938)

* docs(planning): v4 correctness ladder + current-state audit (2026-05-30)

Planning artifact for operator sign-off. Maps the 17 correctness standards
THESIS.md already articulates to a live gating audit: of 17 named standards,
exactly 1 fires per-slice on PRs today (Tier 1 Rust type check); 13 have
substrate but no activation; the diagnosis lane's "0 rustc errors" target
addresses standard #1 only.

Proposes a 9-rung correctness ladder collapsing the 17 standards into binary
PR gates (rung 0 parses → rung 9 lenses gate PRs). Sequencing: fixture-first
(nat_semiring), driving emit through every rung on one fixture before widening,
inverting the current "broad single-rung gate" shape that produced the 7951
error count.

Surfaces 6 operator decisions (§8) for sign-off:
  D1 ladder ontology correctness
  D2 fixture-first vs broad-fix-first strategy
  D3 rung 5 cross-target equivalence as release gate
  D4 rung 4 emit-matches-eval as release-minimum (vs rung 7 fixpoint)
  D5 anti-shelfware policy for substrate-without-activation
  D6 accept §7 Phase 1 dispatch

Doc invents no new standards; the 17 are pre-existing in THESIS.md.
Contribution is the audit, ladder, and sequencing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(planning): §9 integrate v4 ship interrogation questionnaire

Cross-maps the existing 346-probe adversarial questionnaire
(docs/v4-close-interrogation.md, prior 2026-05-13 validation:
0/152 answered) onto the 9-rung ladder:
  - rung 0-2 ↔ §3.1 omni-emission
  - rung 3   ↔ §3.7d round-trip
  - rung 4-6 ↔ §3.6/§3.7 L7 + integration
  - rung 5   ↔ §3.5 L6 cross-target
  - rung 7   ↔ §4.2 self-host fixpoint
  - rung 8   ↔ §3.3 tests-as-data
  - rung 9   ↔ §1 dimensions + §4.1 lens self-application + §2.5 impossible bugs

Adopts the questionnaire's §0 disposition vocabulary (PROVEN / WEAK-EVIDENCE
/ GAP / OPERATOR-DECISION-REQUIRED / NOT-IN-V4 / NOT-PROMISED) across both
artifacts.

Sample-evaluates 8 probes across §1.6/§3.3/§4.2/§3.1/§3.6/§4.1/§2.5 — pattern
confirms: probes mapping to rungs 4-9 predominantly disposition as GAP, same
finding as §3's substrate-rich/activation-poor diagnosis viewed through the
questionnaire's lens.

Adds:
  - D7 (new operator decision): dispatch Phase 0 systematic 346-probe
    validation in parallel with Phase 1 (estimate 6-10h worker time)
  - D1 modification: ladder confirmed as complement, not replacement,
    of the questionnaire

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(planning): §3.1 answer the "honest task completion" question

During PR review the operator asked: "what doc tracks what tasks have
actually been completed/closed?" Honest answer: no single doc does today.

Adds §3.1 documenting:
  - TASKS.md status vocabulary (7 markers, including ambiguous [DONE])
  - Two worked examples of [DONE] meaning substrate-only:
      * T-19 lens/testgen.dag [DONE] — not activated against PRs
      * T-17 lens/synthesis.dag [DONE #3768] — partial per §3 audit
  - The five partial reality-side audits that exist today
  - Phase 0 (silent-raven-384, work item adhoc-7020540d-622) is producing
    the missing consolidated receipt-honesty doc:
    docs/audit/v4-close-interrogation-validation-2026-05-30.md
  - The operative reading trio for PR #3938 review:
      1. src/v4/TASKS.md (claim side, with vocabulary caveats)
      2. This doc §3 (gating reality for 17 thesis standards)
      3. Phase 0 output (receipt reality, incremental)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: PM May 29

* docs(planning): §10 worked-example root-cause analysis (SG-1 Symbol/Atom)

Operator concern (2026-05-30): past pattern of error-count-driven dispatch
led to spot-fixes that calcified poor modeling decisions. Before dispatching
any SG-class lane, walk the modeling DFS together.

Adds §10 with the structure (symptom / identification / spot-fix-to-avoid
/ root cause by layer / systemic fix / dispatch shape) and SG-1 fully
worked through:

  Layer 1: emit template bug (Symbol used as constructor on a type alias)
  Layer 2: substrate single-authority gap — no `RustAtomRealization` fact
           declares how kernel-ambient atoms project to Rust; type-emit
           and value-emit derive independently and disagree
  Layer 3: tracked modeling debt at std/node.dag:84 — Symbol-as-edge-tag
           pattern is gated for dissolution into structural Loop-bound
           coordinates; spot-fixing the emitter would create new Symbol-tag
           consumers in generated Rust, directly contradicting the gated
           "forbidden" clause and blocking the dissolution

Recommendation: layer 2 first (one bounded substrate addition + two emit
consumers; non-blocking to layer 3). Layer 3 separately when T-12 ready.
Layer 1 not dispatched at all (would calcify layers 2-3).

Dispatch shape protects against spot-fix trap: brief requires authoring
the modeling fact, FORBIDS template special-casing, requires escalation
of any Atom that doesn't fit the schema.

Awaits operator ratification of structure before doing SG-2 / SG-5 / SG-6
the same way.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(planning): cursor follow-up findings — D4 authority, §9.2 scope

cursor finding 1: D4 proposed rung 4 as release-minimum citing "THESIS does
not require it for v4 ship," but TASKS.md:801-815 explicitly defines v4-done
as bit-identical self-emit (rung 7) + TestClaim suite passes (rung 8), and
TASKS.md:1239 says "The release is when v4-done."

Retracted the earlier framing. D4 now states the authority check, surfaces
the contradiction with the prior draft, and reframes the operator decision:
either confirm rung 7+8 as the release gate (Option A — implies §7 needs
phases 5+) or amend TASKS.md:805-808 with named rationale (Option B —
substantive change to operational authority).

PM-recommendation: Option A. Lowering the v4-done bar via this doc would
tacitly narrow the close gate below the thesis's strongest correctness
commitment without going through the proper amendment surface.

cursor finding 2: §9.2 claimed "~90% of probes close via §7 sequencing"
but §7 explicitly stops at rung 6. Replaced with honest scope statement:
§7 closes the bulk of emit/eval probes; rungs 7-9 are the largest
unaddressed block (~96 probes by silent-raven-384's section counts) and
require either §7 Phase 5+ or a separate program. Closure coupled to D4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(planning): §9.4 Phase 0 redo completion note

silent-raven-384 completed the per-probe redo on PR #3941 commit
68b9bd7 at ~01:27Z. Final distribution: 0 PROVEN / 267 WEAK-EVIDENCE
/ 42 GAP / 37 NOT-CHECKED — matches the predicted realistic distribution
and confirms substrate-rich/activation-poor diagnosis at probe granularity.

PR #3941 mergeable=clean per dashboard. Operator merges manually per
current temporary policy.

Historical "uniform-GAP first pass" caveat preserved as worker-management
context (categorical error caught, redo brief sent, redo landed within
10 minutes).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: PM May 29

* docs(planning): SG-2 + SG-3 worksheets + blocking-review fixes

§10 worked-example walkthrough (per operator's DFS-discipline directive
2026-05-30):
  - §10.1 SG-1 generalized: RustAtomRealization → TargetAtomRealization
    (language-parametric per operator caution); added §10.1.1 worksheet form
  - §10.2 SG-2 generic carrier arity: grounded DFS finds Instantiation
    declared in std/node.dag:19 + PositionalEdges per :113, but NO
    TargetTypeExpressionProjection in extdeps/languages/rust.dag and NO
    Instantiation grep hit in src/v4/compiler/. Systemic fix: author
    TargetTypeExpressionProjection consumed per-connective by 05_emit.
  - §10.3 SG-5/SG-6 Set/BoundedLattice: grounded DFS finds Set<T> at
    std/collection.dag:52 with NO Ord constraint, BoundedLattice<T> at
    std/algebra.dag:66 with meet/join required, but NO Set realization
    in extdeps/languages/rust.dag. Systemic fixes: TargetCollectionRealization
    + BoundedLattice instance completeness gate in 04_infer.
  - §10.4 summary: total dispatch reduces from "fix 7951 errors" to 4 bounded
    modeling work items, each with brief-required worksheet preventing
    spot-fix trap.

Blocking-review fixes:
  - briansrls/codex BLOCKING: rung 2 "chosen targets" dilutes L6 standard #9.
    Reworded to "every project-committed target" + added explicit note
    distinguishing rung-2-smoke from L6-full-coverage.
  - briansrls/codex BLOCKING: D7 outside §8 (sign-off can omit it). Moved D7
    into §8 with full retrospective-ratification framing; §9.5 now references
    §8.D7 rather than duplicating.
  - cursor BLOCKING (prior round): D4 omitted TASKS.md:802 predicate 1
    ("every other scheduled task"). D4 now lists all 6 v4-done predicates
    with ladder mapping; acknowledges rung 7+8 framing was incomplete.
  - cursor BLOCKING (prior round): D1 claimed 9 rungs cover all 17 standards
    but #6 (Tier 2 runtime safety) skipped. D1 now acknowledges 16/17 and
    surfaces 3 options for #6 (rung 10, extend rung 9, or scope it out).

briansrls inline at :269 (std/node.dag:84-85 cite "not present") will be
addressed via PR reply — the cite IS present at lines 84-85 of current
src/v4/std/node.dag and was verified via grep during the SG-1 DFS.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(planning): D1 — acknowledge standard #6 gap (cursor finding)

D1 prior text claimed 9 rungs cover all 17 standards. Standard #6 (Tier 2
runtime safety) is not assigned to any rung — see ladder table at §6.
D1 now acknowledges 16/17 coverage and surfaces 3 options for #6:
add rung 10, extend rung 9, or ratify gap as separately-tracked.

(Second commit because the first batch failed to match this specific
old_string; reapplied on current state.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: PM May 29

* WIP: PM May 29

* docs(planning): SG-1 + sugar pre-dispatch tightening (operator review 2026-05-30)

Operator pre-dispatch tightening feedback addressed:

§10.1 SG-1 substrate sketch + worker brief tightened:
  - Canonical carrier home: TargetAtomRealization type definition lives ONCE
    in the target-realization substrate (sibling to SG-2's
    TargetTypeExpressionProjection); rows per-language in extdeps/.
  - Authority key: source_carrier: Node (canonical carrier identity),
    NOT source_atom: Symbol (raw spelling). Added display_name field for
    diagnostics-only — never authority. Prevents accidental name-keyed
    realization table.
  - Parametric value_form: TargetValueTemplate consuming source atom value
    identity (fn(SourceAtomValue) -> TargetValueExpression OR structural
    template with declared slot). Hardcoded values per-row rejected.
  - Cross-reference to SG-2: TargetAtomRealization.type_form MUST be an
    instance of TargetTypeExpressionProjection (SG-2 substrate). SG-1 must
    NOT coin a second target-type-expression vocabulary. Hard cross-section
    invariant.
  - Bidirectional readability per §10.6: forms must work for both emission
    and ingestion. One-direction-only forms rejected.
  - Worker brief rewritten using operator's tightened structure (named
    sections: Canonical carrier home / Rows / Consumers / Authority key /
    Parametric value_form / Bidirectional / Falsification / Non-goals).

§10.5 SG-CANDIDATE-1 sugar tightened with three implementation constraints:
  - Declared normalization in .dag language model (emit ∘ ingest
    canonicalization must be declared, not surprising — T-36 round-trip
    discipline).
  - No new substrate Node shape (no SymbolsBlock); downstream sees only
    three `data X: Symbol = X` rows.
  - Per-symbol diagnostic loci (locus must survive desugaring per "show
    the correct code" discipline).

§10.5 SG-1 separation hard rule:
  - SG-CANDIDATE-1 cannot be a prerequisite for SG-1.
  - SG-1 cannot be partially "solved" by adopting sugar in source files
    while leaving type/value emit disagreement untouched.
  - The two work items are independent and must not be bundled.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(planning): cursor 21360 fixes — vocab reconcile, worksheet match, 30-day clarify

cursor REQUEST_CHANGES 21360 (on HEAD 83fe804) — three real findings addressed:

(1) §9/D1 single-axis vs §10.0/§11.4 two-axis vocabulary conflict:
    D1 now explicitly says questionnaire §0 single-axis vocabulary is
    SUPERSEDED by the §10.0 two-axis form for close-related artifacts.
    Ratifying §10.0 retroactively updates questionnaire §0. PR #3941 already
    adopts two-axis. Operator decision adjusted to include "ratify two-axis
    supersedes single-axis."

(2) §617-618 SG-1 worksheet "Deepest unsound boundary" placed
    TargetAtomRealization in extdeps/languages/<lang>.dag, contradicting
    the tightened analysis + worker brief which places carrier type in
    canonical home with only ROWS in extdeps. Worksheet text now matches
    the tightened sketch: carrier ONCE in canonical home, rows per-language.
    Also added cross-reference to SG-2 TargetTypeExpressionProjection so
    worksheet doesn't coin parallel type-expression vocabulary.

(3) §11.4 "remove residual 30-day framing" conflicted with D5's
    substantive ≤30-day anti-shelfware deadline policy. Clarified §11.4:
    target is plan-duration "30-day" framing in §7 ONLY; D5's deadline
    policy is a separate substantive parameter (keep, or revise as
    parametric per-lens-family).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 30, 2026
…irmations

Project maintainer review 2026-05-30 applied:

- Add working framing at top: small public release with two advertised
  target surfaces (Rust + TypeScript), plus the "release sentence" the
  tag must make true.
- Split D-REL-3 into D-REL-3a (source-language subset) and D-REL-3b
  (target/artifact matrix = Rust + TypeScript only).
- Confirm all five D-REL decisions (1, 2, 3a, 3b, 4, 5) as DECIDED
  2026-05-30, with reviewer recommendations as the agreed answers.
- Soften package-manager non-goal: "allowed only if verified before tag;
  otherwise omitted from public docs and tracked for v0.1.1+". Same
  language applied to Gate C, Item D, §5, and the "Distribution ruling"
  block in already-decided rulings.
- Add Rust/TypeScript explicit checks to Gate A (rustc/cargo, tsc
  --noEmit; absence noted in SUPPORTED.md when applicable; negative
  fail-closed tests).
- Add Rust/TypeScript scope constraint to Gate E (release notes claim
  only Rust + TS; other languages either labeled not-supported or
  omitted).
- Item H: release notes derive *from SUPPORTED.md*, not from internal
  release goals.
- Item D: SUPPORTED.md framing now declares Rust/TS per-surface support
  level (full-compile vs artifact-interface) explicitly; "supports" is
  never used without saying what supports means.
- Public website ruling: must obey SUPPORTED.md matrix; no broad
  compiler-support claims.
- Dissolution comments tension resolved with explicit split rule: load-
  bearing in source files (.dag/.rs), stripped/neutralized in user-
  facing docs. Gate D's grep already enforces this.
- Add non-goal #9: source/target/artifact surfaces beyond Rust + TS.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 30, 2026
…to v4

Maintainer ruling 2026-05-30 post-audit: v0.1.0 advertised target surfaces
are the three v2 emit paths that already exist — Rust
(05_emit_rust.dag), Go (05_emit_go.dag), Python (05_emit_python.dag).
TypeScript becomes v4 early-support, not v0.1.0. This resolves
verification gap V1 (no v2 emit_typescript.dag exists).

Updates across the doc:
- Framing block: three surfaces, with the release-sentence updated.
- Goal #2: Rust + Go + Python with per-surface check tool named.
- Non-goal #9: TypeScript explicitly v4 early-support; C++/LLVM still out.
- D-REL-3b: CONFIRMED + RECONCILED; per-surface check tool spelled out
  (rustc/cargo, go build/go vet, python -m py_compile).
- V1 row: RESOLVED.
- Gate A: separate Rust / Go / Python bullets with check commands;
  per-example absence pattern preserved ("if not supposed to support X,
  noted in SUPPORTED.md").
- Gate E: release notes claim only Rust + Go + Python; TS labeled
  "v4 early-support".
- Item D (SUPPORTED.md description): three surfaces, full-compile vs
  runnable-example levels, TS listed in out-of-scope.
- Website ruling: states the three v0.1.0 surfaces + TS as v4-future.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 30, 2026
* docs(release): v0.1.0 consolidated state snapshot for review

Add docs/RELEASE_v0.1.0.md — section-by-section status against
RELEASE_TODO.md so a reviewer can decide tag readiness without
re-deriving state from git log. Names the four remaining gates
before `git tag v0.1.0` and the deferred-to-post items.

Location chosen so the file survives publish-snapshot.sh §2
strip-list (only docs/{briefs,history,debt,review-findings,admin,
db-history,postmortems,audit,r3,proposals,perf,decisions} are
stripped — top-level docs/*.md are kept).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(release): state decided private/public sync model in §2

Per operator decision relayed by Release Jun 1 manager: public
gunb-ai/daglang is source of truth post-launch; private gunb-ai/gunbc
is a development scratchpad to keep internal session traffic off the
public repo. Sync direction inverts at the v0.1.0 tag: one-shot
force-push seed + private→public visibility flip, then v0.2.0+ work
PRs against daglang directly and private pulls from public.

Adds three open implementation questions for v0.2.0+ (inverted-flow
tooling, promotion trigger, community surface) marked as not blocking
v0.1.0. Adds the visibility flip as gating item 5.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(release): add goals/non-goals/acceptance criteria; note plan downgrade done

Top-of-doc checklist so reviewers can see scope and the testable conditions
for `git tag v0.1.0` in one place. §1 and gating item #1 updated to
reflect the Enterprise → org (Teams) downgrade executed by operator
2026-05-30.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(release): note gunb-ai/frontend is a separate repo, not part of v0.1.0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(release): adopt reviewer-driven scope revision; gate A-E; add to strip-list

Substantial revision of docs/RELEASE_v0.1.0.md to anchor the reviewer's
"small, verified, fail-closed product surface" posture:

- Add scope-revision section with the reviewer posture verbatim.
- Restate the five D-REL decisions as DECIDED vs PENDING, with reviewer
  recommendations as the working default for pending items.
- Apply already-decided rulings: Enterprise->Teams DONE; Homebrew/.deb/APT
  IN scope (reversed defer); gunb.ai Pages site from gunb-ai/daglang;
  inverted post-launch sync; dissolution comments stay; no PM jargon.
- Add SUPPORTED.md section (D-REL-3 deliverable; the heart of v0.1.0).
- Replace prior acceptance criteria with reviewer's Gates A-E.
- Add rollback plan and user-facing release-notes pointer
  (docs/release/v0.1.0-release-notes.md, separate in-flight PR).

Also adds docs/RELEASE_v0.1.0.md, RELEASE_TODO.md, and WISHLIST.md to
scripts/publish-snapshot.sh STRIP_PATHS so these maintainer-facing planning
docs do not ship publicly. Collision risk with adhoc-12a071f5-04a (separate
cleanup PR adding RELEASE_TODO.md + WISHLIST.md) noted in the doc.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Release Jun1 consolidated state doc (operator-requested, blocks v0.1.0 r

* docs(release): decouple binary target matrix from package-manager channels

Per parent clarification:

- Binary target matrix (the six musl/darwin/windows-msvc targets in
  release.dag): per-target dry-run gating under D-REL-2 — drop any target
  that fails the dry-run from the v0.1.0 matrix.
- Install/distribution channels: Homebrew, .deb, APT do NOT ship at
  v0.1.0. They are modeled with 🟡 markers in install.dag as v0.2.0+
  emission intent; the actual Formula / deb-control / apt-repo content
  is not yet emitted. v0.1.0 install paths are curl install.sh
  (pending PR #3992) and build-from-source.

§5 rewritten into two explicit subsections so the two axes can't be
conflated. Non-goals expanded with an explicit channels-deferred entry.
Already-decided rulings entry rewritten to state "modeled ≠ shipped".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(release): scope Gate D grep to user-facing docs (resolves cursor REQUEST_CHANGES)

Cursor flagged that Gate D's repo-wide grep for adhoc-/session-slug terms
contradicted the "dissolution comments stay" ruling (load-bearing model
marks in .dag files ship as-is). Gate D now explicitly scopes the grep to
user-facing docs and excludes .dag source + any path carrying load-bearing
marks, so the two policies no longer collide.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(release): apply maintainer review — Rust+TS surfaces, D-REL confirmations

Project maintainer review 2026-05-30 applied:

- Add working framing at top: small public release with two advertised
  target surfaces (Rust + TypeScript), plus the "release sentence" the
  tag must make true.
- Split D-REL-3 into D-REL-3a (source-language subset) and D-REL-3b
  (target/artifact matrix = Rust + TypeScript only).
- Confirm all five D-REL decisions (1, 2, 3a, 3b, 4, 5) as DECIDED
  2026-05-30, with reviewer recommendations as the agreed answers.
- Soften package-manager non-goal: "allowed only if verified before tag;
  otherwise omitted from public docs and tracked for v0.1.1+". Same
  language applied to Gate C, Item D, §5, and the "Distribution ruling"
  block in already-decided rulings.
- Add Rust/TypeScript explicit checks to Gate A (rustc/cargo, tsc
  --noEmit; absence noted in SUPPORTED.md when applicable; negative
  fail-closed tests).
- Add Rust/TypeScript scope constraint to Gate E (release notes claim
  only Rust + TS; other languages either labeled not-supported or
  omitted).
- Item H: release notes derive *from SUPPORTED.md*, not from internal
  release goals.
- Item D: SUPPORTED.md framing now declares Rust/TS per-surface support
  level (full-compile vs artifact-interface) explicitly; "supports" is
  never used without saying what supports means.
- Public website ruling: must obey SUPPORTED.md matrix; no broad
  compiler-support claims.
- Dissolution comments tension resolved with explicit split rule: load-
  bearing in source files (.dag/.rs), stripped/neutralized in user-
  facing docs. Gate D's grep already enforces this.
- Add non-goal #9: source/target/artifact surfaces beyond Rust + TS.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Release Jun1 consolidated state doc (operator-requested, blocks v0.1.0 r

* docs(release): reconcile D-REL-1 with publish-snapshot; strip src/v4

Cursor REQUEST_CHANGES findings:

1. D-REL-1 was CONFIRMED (strip src/v4) but scripts/publish-snapshot.sh
   only stripped four v4 markdown files — "v4 code itself stays" comment
   contradicted the confirmed scope. Fixed: STRIP_PATHS now strips
   src/v4 wholesale. The four individual v4 markdown entries are
   subsumed and removed. Comment notes the supersession of the older
   RELEASE_TODO.md §6 "Keep" list.

2. Gate B's "src/v4 stripped OR — if it ships —" branch contradicted
   D-REL-1's hard strip. Removed the "if it ships" escape; Gate B now
   states the strip as the only acceptable state.

3. D-REL-1 table row updated to call out the supersession of
   RELEASE_TODO.md's §6 "Keep" list (that doc is itself stripped from
   the public export, so the contradiction is invisible publicly but
   should not exist in the maintainer doc either).

Also incorporates the nimble-crane-490 non-blocking suggestion:
non-goal #10 makes the v4-done predicate burn-down explicitly out of
scope for v0.1.0, with the predicate-state cross-check noted (0/6
PROVEN, 5 YELLOW, 1 GRAY).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(release): D-REL-4 status: DECIDED but enforcement PENDING

Cursor REQUEST_CHANGES: D-REL-4 was marked CONFIRMED ("strip all other
docs") but scripts/publish-snapshot.sh STRIP_PATHS does not yet strip the
root THESIS/INVARIANTS/MODELING/CODING/TESTING files or the large
docs/thesis/, docs/invariants/, docs/planning/, docs/design-* trees. A
dry-run today would export them, contradicting the confirmed scope.

Honest fix: D-REL-4 is DECIDED in principle but ENFORCEMENT PENDING. The
user-facing docs (GETTING_STARTED, LANGUAGE, CLI, EXAMPLES, SUPPORTED,
CONTRIBUTING) don't exist yet — wiring full STRIP_PATHS enforcement
before they land would leave the public export with nothing useful.
Follow-up pass before tag must (a) author the user docs and (b) extend
STRIP_PATHS to remove everything outside the keep list. Gate B and
Gate D catch the gap if this slips.

§3 note also softened from "are stripped" to "intended to be stripped;
enforcement queued as pre-tag follow-up".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(release): surface five pre-tag verification gaps (PM audit 2026-05-30)

Release-readiness audit from nimble-dove-733 (routed via PM still-fox-289)
flagged five evidence gaps that the gates aspire to close but that no
evidence backs:

V1. TypeScript surface unsubstantiated — no v2 emit_typescript.dag
    exists; TS appears only in language catalog + v4 test claims.
    D-REL-3b row updated with "⚠ NEEDS RECONCILIATION (substrate)"
    flag: either land an emit_typescript lens with tsc round-trip
    before tag, or amend D-REL-3b to Rust-only.
V2. docs/SUPPORTED.md does not exist; no owner, no ETA. Likely lane
    surfaced (nimble-crane-490).
V3. install.sh PR #3992 STALLED (0 reviews, 0 CI). Distribution
    ruling updated to flag the stall and the resolution options
    (route shepherd vs drop curl-install).
V4. Weather demo end-to-end UNVERIFIED against --target rust.
V5. No verification log on Gates A-E; reviewer cannot distinguish
    pre-checked from untested. Evidence convention added to gates
    intro (✓ commit-sha date / ⏳ owner / ✗).

All five surfaced as a single "Pre-tag verification gaps (open)"
section between the D-REL table and the already-decided rulings, with
gap → gate mapping and explicit owner/ETA columns (PENDING where no
owner exists). These are hard blocks on tag until resolved.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(release): v0.1.0 targets = Rust + Go + Python; TypeScript moves to v4

Maintainer ruling 2026-05-30 post-audit: v0.1.0 advertised target surfaces
are the three v2 emit paths that already exist — Rust
(05_emit_rust.dag), Go (05_emit_go.dag), Python (05_emit_python.dag).
TypeScript becomes v4 early-support, not v0.1.0. This resolves
verification gap V1 (no v2 emit_typescript.dag exists).

Updates across the doc:
- Framing block: three surfaces, with the release-sentence updated.
- Goal #2: Rust + Go + Python with per-surface check tool named.
- Non-goal #9: TypeScript explicitly v4 early-support; C++/LLVM still out.
- D-REL-3b: CONFIRMED + RECONCILED; per-surface check tool spelled out
  (rustc/cargo, go build/go vet, python -m py_compile).
- V1 row: RESOLVED.
- Gate A: separate Rust / Go / Python bullets with check commands;
  per-example absence pattern preserved ("if not supposed to support X,
  noted in SUPPORTED.md").
- Gate E: release notes claim only Rust + Go + Python; TS labeled
  "v4 early-support".
- Item D (SUPPORTED.md description): three surfaces, full-compile vs
  runnable-example levels, TS listed in out-of-scope.
- Website ruling: states the three v0.1.0 surfaces + TS as v4-future.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(release): fix v4-done tracker filename (cursor non-blocking note)

s/burn-down/tracker/ — actual file in tree is
docs/planning/v4-done-predicate-tracker-2026-05-30.md.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Release Jun1 consolidated state doc (operator-requested, blocks v0.1.0 r

* docs(release): D-REL-1 (iv) flip — v3/v4 ship public labeled alpha/WIP

Operator flipped D-REL-1 posture 2026-05-30 to flavor (iv): v3 + v4
substrate ships public in v0.1.0 labeled alpha / WIP — no Wave-2
predicate-closure gating, honest error count documented (~7,951 v4
rustc errors), bar is "compilable bootstrap". Fail-closed: if v4
doesn't compile at tag time, README + SUPPORTED.md flip the alpha
label to pre-alpha/experimental — no scope strip, no tag delay.

Plus PM clarification: TypeScript surface authoritatively resolved.
v0.1.0 supported emit targets = Rust + Python + Go (the three v2
emits). TypeScript = v4-alpha-only, lives in SUPPORTED.md's v4-alpha
section, not part of the v2 supported contract.

Changes across the doc:

- D-REL-1 row REWRITTEN: ship public labeled alpha/WIP; no gating;
  fail-closed = label flip, not strip.
- D-REL-3b: Rust + Python + Go (authoritative ruling); TS = v4-alpha.
- D-REL-4 status: removes "v3/v4 are stripped" claim.
- D-REL-5 status: rationale updated — releases under (iv) because
  v0.1.0's supported contract doesn't depend on v4 predicate-closure.
- Scope-revision section: explicit reconciliation paragraph — "stripped"
  vs "explicitly unsupported" is now case-by-case (process docs vs
  in-progress substrate).
- Non-goal #1: REVISED to reflect (iv) — no longer strips v4.
- Non-goal #5 (src/v3): REVISED to reflect (iv).
- Non-goal #10 (v4-done predicates): drops Wave-2 gating; predicates
  documented honestly in SUPPORTED.md, not used as strip trigger.
- Already-decided rulings: Long-term distribution scope note clarifies
  the (iv) flip is about substrate posture only, not distribution
  channels (Homebrew/.deb/APT stay v0.2.0+).
- Gate B: v3/v4 substrate is alpha — not on supported contract;
  SUPPORTED.md per-surface labels what is/isn't claimed.
- Item D (SUPPORTED.md description): adds alpha/WIP section for v3/v4
  substrate and TypeScript (v4-alpha); per-surface alpha/PROVEN/GAP
  detail pulled from sharp-otter-407's ship-disposition supplement.
- Item F (Rollback): split into leak-rollback and v4-compile-rollback;
  the latter encodes flavor (iv) semantics (label flip only).
- §6 housecleaning: src/v3 no longer stripped.
- Cross-refs: add sharp-otter-407 supplement and #4005 release-notes
  truth table pointers (both in flight, separate PRs).
- Verification gaps V2/V3/V4: owner/ETA columns updated with the
  worker-dispatch references from snappy-bee-513 (post-D-REL-3b
  confirmation): SUPPORTED.md author, #3992 shepherd check, fresh
  weather-demo e2e verification worker.
- publish-snapshot.sh: src/v3 and src/v4 REMOVED from STRIP_PATHS
  per the (iv) flip; comment block updated to reference the supersession
  of the older RELEASE_TODO.md §6 housecleaning legacy.

PER-PR HOLD remains in effect — not self-merging; awaiting operator
review.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(publish-snapshot): re-add v4 process docs to STRIP_PATHS

Claude REQUEST_CHANGES: by the doc's own (iv) reconciliation rule
("process docs / agent traffic = stripped; substrate in-progress =
alpha-labeled"), the four v4 process markdown files (TASKS.md,
BRIEF_TEMPLATE.md, CULTURE.md, DECISIONS.md) are agent-process traffic
and should remain stripped. The (iv) flip applies to v4 *substrate*
(code under src/v4/{std,extdeps,compiler,lens,workflow,install,test,...}),
not to these process docs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(release): tighten Public website ruling with marketing-surface guards

Adds explicit constraints derived from the operator's homepage-strategy
discussion (2026-05-30):

- No raw maintainer-internal figures (~7,951 rustc errors etc.) on the
  marketing surface; those live in SUPPORTED.md / docs/v4-status.md.
- No install/build command on the homepage unless verified under Gate C
  on every advertised target (make install / brew install / apt install
  absent until distribution ruling lets them ship).
- Hero claims scoped to v0.1.0 supported contract (Rust + Python + Go,
  documented subset). Omni-emission / lens-as-CI / impossible-bug
  material allowed in clearly-labeled "Vision" sections, never hero or
  support-claim register.
- "Impossible bug" framing scoped to bug classes PROVEN on the v0.1.0
  surface; otherwise forward-looking phrasing only.

Broader homepage content strategy (hero copy candidates, demo
prioritization, three-post launch blog plan, naming stack) lives in
session memory as project-homepage-framing; that's daglang PR #1
territory, not this doc.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(release): ZERO OVERCLAIM posture — honest per-target Python/Go scope

Operator follow-on to flavor (iv): 'i do NOT want ANY overclaim'. Three
adjustments to enforce that across the doc:

1. Scope-revision section: add ZERO OVERCLAIM block making the
   reviewer's "silently emits plausible output" anti-pattern the hard
   release bar — no claim ships without evidence. Cross-reference to
   silent-bee-431 + sharp-otter-407 parallel disclaimer work.

2. D-REL-3b: honest per-surface scope. Rust = full example-scale today.
   Python + Go = small-smoke verified only (minimal hand-curated
   fixtures). Weather and v4-substrate Python emit currently produces
   invalid Python; Go emit currently fails go build. Python and Go are
   therefore NOT on the v0.1.0 support contract for non-trivial inputs
   — only the small-smoke surface is claimed.

3. Gate A: split per-target verification accordingly. Rust = the only
   surface verified at example-scale today. Python and Go = small-smoke
   only; SUPPORTED.md must enumerate the qualifying fixtures and
   declare non-trivial emit as outside the support contract.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(release): refine Python/Go disclaimer with specific failure classes

Per smart-stag-871 via PM: failure class is NOT pure TCO — most TCO is
single-authority. Replace generic "invalid Python / fails go build"
wording with the actual surface bugs and v0.1.1 fix ETAs:

- Python: match-as-expression + TCO temp-decl surface bugs; fix ETA
  ~2-3 working days.
- Go: package/module layout + := scope issues; fix ETA ~1-2 working
  days.

Disclaimer is COMMITTED for the v0.1.0 tag tomorrow; relaxation lifts to
the v0.1.1 narrative as the named fixes land. Applied in both D-REL-3b
row and Gate A per-target bullets so the doc is internally consistent.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls
briansrls deleted the claude/review-llm-integration-R3zIY branch June 1, 2026 18:41
briansrls pushed a commit that referenced this pull request Jun 9, 2026
…se, lane adhoc-ce8d7ae6)

Records the measured T3 root-cause (substrate-consistency defect, not the
positional-vs-labeled model question — the witness never compiled) and
registers conditional #9 (Optional-representation unification, sibling of
#5 Map). Branch criterion: surface flavor => bounded arm-normalization
sweep; deep flavor => #9, co-landing with the Map map_get/match_pattern
bridge. Grounds the defect class at collection.dag:28/112 (canonical
Present|Absent vs Some/None arms over a Witness-typed value). Flavor
unmeasured; the lane reports it.

https://claude.ai/code/session_018QC433THjRyqiHuP8czPi4
briansrls added a commit that referenced this pull request Jun 10, 2026
…e, bidirectional coercion, self-host, Map, PROV, carrier-axis) (#4605)

* docs: design — termination checker (fuel-elimination lane C1)

Checker-not-discoverer design for replacing remaining/fuel threading in
06_translate with validated descent proofs: carrier upgrades in
v4.std.cardinality (lexicographic TerminationProof + ProofEdge port),
SCC checker ported from dsl/std/{termination,graph}.dag onto
v4.std.dependency, serialize_type_expr_* cluster as the minimal slice,
fuel-triad dissolution ratchet (40 remaining-params / 20 guards -> 0).

https://claude.ai/code/session_018QC433THjRyqiHuP8czPi4

* docs: design — general value-set lattice (non-integer containment)

Closed description family (Empty/Universal/IntegerInterval/Enumeration/
Product/TaggedUnion) with anchor-gated structural containment, semantic
strictness replacing R1's syntactic !=, integer_value_set fold-in per its
own dissolve-on-arrival marker, R1/R2 as the executing consumers, and the
decidability carve stated honestly (predicate refinements stay refusal).

https://claude.ai/code/session_018QC433THjRyqiHuP8czPi4

* docs: design — bidirectional emit/ingest as one declared coercion relation

One FormalGrammar production-row set per target, both directions derived
as interpreters over the same rows; production selection = find_witness
over a closed candidate set; four static bidirectionality obligations
(slot bijection, forward/backward determinism, declared quotient);
inverse-aware constraints on emit ladder T3-T6; home-language add-subset
slice with round-trip claim as the inverse proof. Notes dangling CP-1b
anchors (TASKS.md, design-v4-compiler-homomorphism.md).

https://claude.ai/code/session_018QC433THjRyqiHuP8czPi4

* docs: design — self-host fixed point (v4 bootstrap ratchet)

Precise oracle (stage1==stage2 bit-identical over a declared artifact
set, DB-8 prerequisite, located divergence diffs), hand_maintained_src
as declared data + census sweep with per-entry dissolution triggers,
four-stage plan honoring the emit-ladder gate (stage A buildable now:
zip-fold equality wiring + census; B per-module convergence ladder;
C whole-compiler promotion, operator-gated pins; D diverse double-
compilation). Notes SELF_HOSTING.md path drift (lives in src/v3/).

https://claude.ai/code/session_018QC433THjRyqiHuP8czPi4

* docs: design — Map representation unification (extensional data, one equality authority)

Map<K,V> re-shaped from stored-closure partial function to finite
extensional entry data (the P1 nickname fix); map_get signature
preserved, body honest; PartialFunction<K,V> carrier for the intensional
concept with derivable one-way map->function projection; v2
raw_map_lookup dual-dispatch chokepoint + match_pattern bridge delete;
closes B-MAP-LOOKUP-OPTION-C-1, B-LOOKUP-1, finite-set-uniqueness
markers in one landing. #4564 runtime semantics are the regression
floor; iteration-order (DB-8) escalated as Q-M1.

https://claude.ai/code/session_018QC433THjRyqiHuP8czPi4

* docs: designs — provenance occurrence-id anchoring (PROV/T-8) + carrier-core-axis decision memo

PROV: opaque occurrence id stamped on Node (brand-channel playbook),
span data off-tree in a per-compile SpanIndex keyed by id, reusing
Locus/Extent ByteRange as the span carrier; one equality-exclusion rule
at the single equality authority; carried/derived transport receipts;
fail-closed Unanchored/NoEnclosingOccurrence outcomes. Written as input
to the HELD operator scoping decision.

Carrier axis: decision criterion (functional dependency => coincidence
obligation, not a sixth axis; independent pair => ModelCoreFactAxisCarrier)
with a measure-first census as the front door; folding into Encoding
rejected on both branches.

https://claude.ai/code/session_018QC433THjRyqiHuP8czPi4

* docs: tracking memo — Optional match-surface consistency (T3 root-cause, lane adhoc-ce8d7ae6)

Records the measured T3 root-cause (substrate-consistency defect, not the
positional-vs-labeled model question — the witness never compiled) and
registers conditional #9 (Optional-representation unification, sibling of
#5 Map). Branch criterion: surface flavor => bounded arm-normalization
sweep; deep flavor => #9, co-landing with the Map map_get/match_pattern
bridge. Grounds the defect class at collection.dag:28/112 (canonical
Present|Absent vs Some/None arms over a Witness-typed value). Flavor
unmeasured; the lane reports it.

https://claude.ai/code/session_018QC433THjRyqiHuP8czPi4

* docs: apply operator rulings to design open questions (2026-06-09)

Q-B1: commitment reframed as the four obligations, not a formalism —
grammar formalisms are modeled data; PEG may exist as parse-only;
bidirectional verdict = passing obligations 1-4.
Q-M1: canonical key order IS the Map representation (one order, plain
structural equality, DB-8 by construction; no insertion-order concept).
Q-V2: no new CoercionMismatchKind variant (fewer variants for now).
Q-T2: gate-in-infer confirmed; checker made relocation-cheap by
construction (pure substrate function; infer holds only the gating wire).
Q-S2: wave-1 artifact set = emitted .rs; committed-.rs-era transition
noted as its own lane re-declaring the compare set.
Q-S3: pin rotation operator-GO only, confirmed.

https://claude.ai/code/session_018QC433THjRyqiHuP8czPi4

* docs(termination): FunctionRef/call-graph audit — producer does not exist; T-9 rides #4581

Audited 2026-06-09 against the live tree: call-graph extraction is not
readable as substrate facts today, three layers deep — (1) zero
production writers of dependency_binds_to_edge (4 lens fixtures only;
dependency.dag's own T-9 marker confirmed unbuilt); (2) resolve_atom
materializes canonicalized spelling, not reference (spelling re-join
would rebuild the channel BRAND is dissolving); (3) no stage produces
ComputationNode trees and no FunctionRef carrier is landed — call sites
have no v4 representation. Fix: T-9 BindsTo materialization lands as a
rider on #4581's binding_id stamping (same write, same seam), serving
the dependency classifier, structural_resolution lens, and this checker
with one producer. Slice step 2 now gated on that producer.

https://claude.ai/code/session_018QC433THjRyqiHuP8czPi4

* docs: sizing — COMPREP (function bodies in the v4 pipeline)

Measured: the THESIS computation substrate is consumable shapes with
zero producers — no stage builds ComputationNode trees, no FunctionRef
carrier landed, eval's Transform arm is a call_primitive slot, and the
mvp1 'emitted add fn' is a TypeNode Arrow signature (the T0/RTADD/T1
receipts are type-expr-tier). Sized as a first-class node: wave 0
carriers ride #4581 binding_id + the T-9 rider (no new FunctionRef
carrier, fewer variants; body = Arrow.body per E-9); wave 1 keystone =
source-ingested add body through parse/resolve/infer/eval by execution
(~PROV-sized); waves 2-4 behaviors/translate/breadth. Gates SELFHOST
facets 1-2 (co-equal with SPINE), termination-checker layer 3, emit
ladder T4+, STAGE-ADOPTION. Recommends honest relabeling of T0/RTADD/T1
as signature-tier in the dep graph. Cross-linked from the termination
design's prerequisite section.

https://claude.ai/code/session_018QC433THjRyqiHuP8czPi4

* docs: portfolio-review fixes — Node identity-channel authority + four seam closures

New: design-node-identity-channels.md — single P2 authority for Node-
carried fields and equality participation (binding_id IN / occurrence id
OUT / BindsTo rides the binding_id channel); #4581 is the linchpin seam;
landing order fixed; allocator-determinism obligation flagged to #4581
(DB-8/fixed-point back door). PROV Q-P2 resolved against it; COMPREP
wave 0 lands through it.

Seam closures: Map Q-M1 reconciled to canonical-order-is-representation
(insertion-order draft withdrawn; canonical total order on keys named as
the introduced requirement); map_get/match_pattern bridge deletion
ownership assigned to the Map landing with the Optional sweep explicitly
excluding the site (deep flavor => one co-landed PR); value-set
de-gated from the termination checker (structurally terminating;
checker validates it later, nothing waits).

https://claude.ai/code/session_018QC433THjRyqiHuP8czPi4

* docs: fix doc_refs CI (regen doc-chain) + resolve T3 dual-authority seam

- docs/thesis/doc-authority.md: regenerate embedded doc-chain via
  check_doc_refs.py --write-graph (new design docs joined the graph;
  the stale chain was the doc_refs CI failure).
- design-bidirectional-coercion.md §6: precedence note — rows-not-
  closures remains the direction authority; the T3 fold-carrier binding
  decision (incl. positional/labeled discipline) lands only after the
  one bounded run, with design-optional-surface.md §4 as the single
  authority for sequencing (review thread r3384485736).

https://claude.ai/code/session_018QC433THjRyqiHuP8czPi4

---------

Co-authored-by: Claude <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 14, 2026
…, compile-clean non-exhaustive match — and locate the compile-clean refusal (#6604)

* Fix the two nightly reds: roster orch_emit_let_step (nfr, masking receipt #9) + re-land the live-read design doc link lost to the #6564 merge race

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix the third nightly red (compile-clean) + locate the refusal: converge_cli_applied_knob_count one-special-variant dispatch (#6598 x #6586 stale-base interaction made main compile-red); floor compile-clean refusal now prints located hard diagnostics (it previously printed ok=false with zero located errors — this patch is what found the non-exhaustive match); nfr lens-precision note (field-scrutinee matches are lens-invisible, no roster row)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Roster the two #6582 structural-eq sites (live_read_carrier_eq, path_pattern_eq — coordination: silent-eagle-662's resolved audit, supersedes #6614) + dedupe the replace-all's second roster insertion

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Jul 23, 2026
…agent history sweep, receipts throughout)

docs/plans/resolve-regression-journey.md answers the operator's 2026-07-23
question ('what fundamentally keeps regressing? we have fixed resolve
several times and it comes back worse') from a 65-event dated fix ledger
over origin/main since 2026-06-25 plus the in-tree receipt docs, with an
adversarial verification pass:

- The measured trajectory: ~8m floor (pre-flip) -> discovery flip x12
  demand (#6438, 2026-07-09) -> timeout bounce 30..270 raised to fit ->
  #6848 (+18m time AND the 1GB/process parse baseline, RSS 6.5->20GB,
  2026-07-20) -> mechanism-correct follow-ups recovering less than priced
  (M1 ~0% on capped hosts) -> the 4h memory.high crawl -> #7120/#7122/#9.
  Three mechanisms wear one trend line: added demand, retention to the
  cap, cap lost.
- The five grains of one duplication (per-thread/-entry/-run/-process/-PR),
  discovered serially, fixed independently, no shared already-computed
  authority — instance-patching as validation where construction
  (ComputationIdentity) is the fix.
- Verified: NO floor-time regression gate exists (the 5s law is enforced
  but scoped to eval; the regression mass lives in the exempted infra
  carve-out); 5+ merges since 07-01 added corpus-denominated work with
  zero merge-time cost pricing.
- What ends it, in order: the cost wall (budget refusal + regression
  gate), the identity authority, the retention lane, cost pricing at
  merge.

Registered in doc_graph_roots (reachability suite 7/7 PASS by execution).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants