Repository navigation
T-Substrate NominalOpacity carrier (carrier-only staging) - #900
Conversation
|
Manager review for #869 dispatch: Good direction on the carrier: this follows the manager decision by adding a Before flipping ready, please close these blockers:
Keep the scope bounded: carrier + minimal fail-closed consumer proof only. Full |
|
Manager review addressed — itemized: 1. Missing Shape B consumer proof. The walker function and its consumer test are both on this branch (head
The brief §Slice (Shape B) defines the consumer as a "minimal lens / structural-walk consumer that reads the carrier and fails closed" — 2. Rust/.dag parity for accessors. Documented in the PR body. 3. Constructor audit. All hand-written 4. PR body. Now filled in: brief path, audit receipt, carrier rationale, walk discipline, Shape B choice, consumer-proof receipt, STOP checklist, test disposition, Modeling readiness status. Modeling #858 readiness signal explicitly not posted yet — will only fire after DB-8 + clippy + workspace tests confirm clean on the reviewer host. Disposition: Holding draft. The implementation session was time-boxed mid-flight; gates listed in PR body §"Test / lint disposition" need a reviewer-host re-run (I do not have cargo available in this environment to verify DB-8 myself). Please flag any gate failure as a STOP — I will not bump the DB-8 ratchet and will surface to issue #869 if it drifts. |
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
42d4ef41· Trigger:schedule - Thinking:
213s wall
BLOCKING (1)
Root Cause
src/v3/compiler/src/dag.rstest fixture seeds the opaque carrier and then immediately adds a second field initializer → remove the trailing nominal_opacity: None so the Some(NominalOpacity { ... }) case is actually compiled and tested.
| nominal_opacity: Some(NominalOpacity { | ||
| permitted_accessors: vec![accessor_a_id], | ||
| }), | ||
| nominal_opacity: None, |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
There was a problem hiding this comment.
Stale at HEAD bcd479357. The duplicate-initializer compile error this finding called out has been fixed since the original commit 42d4ef4. Local build is clean and the v3 test suite passes (542/0). The earlier dashboard "v3 failing" alerts referred to (a) the duplicate-initializer fix landing on prior heads, then (b) a regen-bootstrap miss after the origin/main merge that has now been corrected by re-running regen_bootstrap --features bootstrap-regen-fresh to pick up DeclarationHasRefinement.
… test
The mechanical pass that added `nominal_opacity: None,` to every
`Declaration { ... }` constructor matched on the test constructor too,
which already initialized the field to `Some(NominalOpacity { ... })`.
Result was a Rust E0062 (duplicate field) compile error that blocked
the consumer-proof test from running. Removing the spurious second
initializer.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
Manager disposition for the queued API review blocker: Verified against current head No code change is needed for that specific review item. Keep #900 draft for the remaining declared gates in the PR body: DB-8 fixed-point, workspace tests, clippy, and the final Modeling readiness signal after those pass. |
|
Queued-feedback disposition against current head Re-verified the No additional code change is needed for that feedback item. Keep #900 draft until the remaining gates listed in the PR body are actually verified: DB-8 fixed-point, workspace tests, clippy, and the final Modeling readiness signal. |
|
Manager review against current head The previously queued duplicate-initializer blocker is resolved. Current
The latest diff also adds Remaining action is gate state, not this old review item: current head's workflow is skipped because #900 is still draft. If your local/worker host has verified DB-8 fixed-point, workspace tests, clippy, and fmt, say so and flip ready. If not, either run those gates on the worker branch or explicitly request ready-for-review so CI can provide the host receipts. Do not post Modeling #858 readiness until those gates are green. |
|
Manager draft audit disposition: marked ready for review. This PR is not abandoned. The prior blocking review item was fixed on current head, the Shape B carrier + fail-closed boundary consumer/test are present, and the remaining uncertainty is gate verification. Keeping the PR draft prevents CI from producing those receipts. Known before merge: DB-8 fixed-point, workspace tests, clippy, fmt, and final Modeling readiness signal must be green/posted. If CI shows DB-8 drift or non-trivial generated-snapshot movement, treat it as the STOP condition documented in the PR body. |
|
Already fixed in db6b2fa (pushed). Reviewer was looking at sha 42d4ef4 (pre-fix). The mechanical pass that added Lib test now passes: A second blocker surfaced from the new Workspace tests + clippy + DB-8 ratchet running on host now. Will not flip ready until those report clean. If DB-8 drifts, that's a STOP per dispatch — surfacing to #869, not bumping the ratchet. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9c962b7055
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| accessor: Option<DeclarationId>, | ||
| ) -> Option<crate::diagnostics::Diagnostic> { | ||
| let decl = dag.declaration(decl_id); | ||
| let opacity = decl.nominal_opacity.as_ref()?; |
There was a problem hiding this comment.
Traverse instantiation templates when checking nominal opacity
check_nominal_opacity_descent only reads decl.nominal_opacity on the current declaration and exits early when that field is None. For generic instantiations (TypeConnective::Instantiation), walkers typically hold the instantiated DeclarationId, while opacity is naturally attached to the template declaration; in that case this check returns None and allows structural descent through an effectively opaque type. This creates a fail-open path for nominally opaque generics (for example future Secret<T> instantiations) unless every instantiation is redundantly annotated, so the check should resolve through the instantiation template (or equivalent normalization) before authorizing descent.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Verified against current head 5cd4cf0fc905c0a991c6b35df0cba7acadc7f401. This finding is valid. check_nominal_opacity_descent reads only the current declaration's nominal_opacity and does not normalize TypeConnective::Instantiation to the template declaration before deciding. For Shape B to be fail-closed for future Secret<T>, the worker needs to resolve instantiation/template opacity or explicitly carry opacity onto all materialized instantiations, with a test proving an opaque generic instantiation fails closed.
|
CI disposition for current head This is a real remaining blocker. Failing tests:
This matches the carrier landing scope, not a DB-8 drift yet. Please push a worker-owned fix commit for the reflection binding/test/manifest updates, then rerun CI. Keep Modeling #858 readiness blocked until these are green and DB-8/regen gates also complete. |
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
9c962b70· Trigger:schedule - Thinking:
413s wall
BLOCKING (2)
Root Cause
src/v3/compiler/src/dag.rsDeclaration gained a substrate field but derived-declaration construction still relies on per-call-site defaults → add a shared carry-forward policy that copies or explicitly resolves nominal_opacity, including dedup/equivalence keys.
| @@ -3182,6 +3187,7 @@ pub(crate) fn concretize_decl_with_subst( | |||
| inhabits: None, | |||
There was a problem hiding this comment.
BLOCKING: concretize_decl_with_subst materializes derived Declaration records with nominal_opacity: None, so inference specialization can silently strip the new substrate fact instead of carrying it forward.
There was a problem hiding this comment.
Verified against current head 5cd4cf0fc905c0a991c6b35df0cba7acadc7f401. This finding is valid. concretize_decl_with_subst still writes nominal_opacity: None when materializing substituted declarations, which can erase the new substrate fact. The worker should add a deliberate carry-forward/normalization policy here rather than defaulting to None, plus a regression test for opacity surviving inference specialization.
There was a problem hiding this comment.
Verified — at HEAD bcd479357, concretize_decl_with_subst (infer.rs:3190) does set nominal_opacity: None on the derived Instantiation Declaration. This is intentional under the carrier-only re-scope.
Per the updated PR body and the re-scope decision at #869, "specialization / lowering opacity policy" is one of the four named work items in the dissolution follow-up PR (alongside fail-closed walker/descent, diagnostic-kind .dag authority, and std Secret<T> marking). Choosing carry-forward semantics here — clone-from-source vs. clone-from-template vs. union vs. strip — is policy that belongs in the same PR that lands the consumers which depend on it.
The carrier is dormant data at this PR: nothing reads nominal_opacity yet, so the explicit : None cannot silently strip a live signal. The dissolution PR owns the carry-forward semantics together with the enforcement that motivates them.
| @@ -4763,6 +4776,7 @@ fn specialize_decl_for_lowering( | |||
| inhabits: None, | |||
There was a problem hiding this comment.
BLOCKING: specialize_decl_for_lowering has the same nominal_opacity reset when creating specialized Declaration records, so lower-time specialization can erase a sealed boundary before the fail-closed consumer sees it.
There was a problem hiding this comment.
Verified against current head 5cd4cf0fc905c0a991c6b35df0cba7acadc7f401. This finding is valid. specialize_decl_for_lowering still writes nominal_opacity: None in the specialized declaration paths, so lower-time specialization can erase a sealed boundary. The worker should carry or resolve the opacity policy consistently with the inference-side fix and add a regression test covering lower-time specialization.
There was a problem hiding this comment.
Same disposition as the infer.rs::concretize_decl_with_subst finding (#900 thread on infer.rs:3187). specialize_decl_for_lowering at lower.rs:4916 sets nominal_opacity: None on the specialized Declaration; this is intentional under the carrier-only re-scope.
"Specialization / lowering opacity policy" is named explicitly as one of the four work items in the dissolution follow-up PR. Carry-forward semantics ride alongside the fail-closed walker, diagnostic-kind .dag authority, and Secret<T> marking. The carrier is dormant data at this PR — nothing reads nominal_opacity — so the explicit : None does not silently strip a live signal.
|
Current-head manager disposition for #900 ( Progress: the expected reflected
New review findings are valid and blocking:
Please push a worker-owned fix commit for the remaining reflection binding, manifest refresh, instantiation-template opacity handling, and specialization carry-forward policy. Keep Modeling #858 readiness blocked until CI is green and DB-8/regen gates complete. |
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
1e86259c· Trigger:schedule - Thinking:
313s wall
BLOCKING (1)
Root Cause
src/v3/std/substrate.dagnominal_opacity landed as a substrate fact without making structural descent go through a single enforced accessor boundary → route the existing generic walkers/lens tests through check_nominal_opacity_descent or replace direct descent APIs with a checked wrapper.
Non-blocking — Strengths
src/v3/std/substrate.dagThe carrier uses typed DeclarationRef edges for permitted accessors rather than stringly accessor names.
| /// lenses at the descent boundary. | ||
| pub fn check_nominal_opacity_descent( | ||
| dag: &Dag, | ||
| decl_id: DeclarationId, |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
There was a problem hiding this comment.
Verified against current head 1e86259c5b5ce08ef942c40b7dfaccd6c8c0fdd0. This finding is valid. The PR currently adds check_nominal_opacity_descent and a direct unit test, but no existing structural-walk/descent path is forced through that boundary; the PR body also says lenses can adopt it later. Shape B requires a fail-closed structural-walk consumer, not only an opt-in helper. Please route the relevant generic structural-walk/descent API through this check, or replace direct descent with a checked wrapper, and add a regression showing an opaque declaration cannot be structurally walked without a permitted accessor. Keep Modeling #858 readiness blocked.
There was a problem hiding this comment.
Resolved by re-scope to carrier-only staging at HEAD bcd479357. The opt-in helper this finding refers to (check_nominal_opacity_descent) and its associated Diagnostic::NominalOpacityViolation variant have been removed entirely from src/v3/compiler/src/:
$ grep -rn 'check_nominal_opacity_descent\\|NominalOpacityViolation' src/v3/compiler/src/ src/v3/compiler/tests/
(no results)
This PR now ships only the substrate carrier (NominalOpacity struct + Declaration.nominal_opacity optional field + Rust/Go TypeRealization). It is dormant data — no enforcement, no diagnostic, no walker. The fail-closed walker/descent + diagnostic-kind .dag authority + Secret<T> marking + specialization/lowering carry-forward policy are the explicit follow-up dissolution trigger named in the updated PR body.
The finding is correct about the previous head — there's no way to make an opt-in helper safe — and the carrier-only re-scope is the right answer: ship the carrier alone, then ship enforcement coherently in one PR with the consumer that motivates it.
|
Current manager disposition for #900 at head The new API review blocker is valid: Current CI state: Prior carry-forward blockers remain part of the closeout unless the current branch has resolved them with tests: opacity must survive instantiation/template lookup, |
|
Review metadata
1. Story of the diffThis PR adds a new substrate-level declaration fact for nominal opacity. The central shape is The concern is that the substrate carrier is landed as real authority, but the diff does not yet make the intended 2. Invariant categories
Finding (BLOCKING) — The diff touches substrate directly:
Because
Finding (BLOCKING) — Facts-flow-forward / fail-closed is not preserved through derived declaration paths. In
and
These paths are deriving fresh declarations from existing declaration structure; if a nominal-opaque generic declaration is specialized or concretized, the opacity fact is erased and downstream code sees a plausible transparent declaration rather than either the propagated opacity carrier or a typed failure to remap accessors. That is exactly the kind of silent fact drop the modeling discipline is meant to prevent.
Compliant — The new failure shape is a typed diagnostic carrier rather than string probing:
Finding (BLOCKING, because it covers a substrate invariant) — The added unit test proves only the helper on a synthetic declaration:
N/A — The diff does not edit a thesis/design file marked locked or explicitly diverge from a locked decision; the concerns above are live substrate/modeling issues in the changed code.
Finding (BLOCKING) — The helper is explicitly described as future-call-site machinery: 3. VerdictREQUEST_CHANGES The PR adds the right kind of substrate carrier and typed diagnostic shape, but the live std |
|
Current CI disposition for head 505e419:
Failing items:
Required next step is exactly the host-side generated refresh you identified: run the bootstrap regen path against current main+branch contents, include the updated generated files and parse_corpus_manifest.txt, then rerun fmt/ci/v3/self_host_ratchet. Keep carrier-only staging scope and keep #858 blocked. |
Absorbs main's recent substrate additions (std.unicode CharClass, ValueBody list substrate, extdeps typed-primitive structural gaps) that were dropped when the prior conflict-marker fix restored generated outputs to the f363ffb baseline. Verified locally: the three previously-failing v3 tests (dag_new_exposes_std_unicode_charclass, rust_pilot_primitives_value_body_is_structural_list, handwritten_parse_snapshot_matches_manifest) now pass. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
afbf441b· Trigger:schedule - Thinking:
65s wall
|
Review metadata
Findings (if any)
I did read the rubric from the pinned context paths ( VerdictREQUEST_CHANGES — procedural, not on PR content. The review as specified (diff-anchored, principle-backed) is blocked until a checkout that includes Exploratory (optional): The session transcript in this environment mentioned |
|
Review metadata
Verdict: APPROVE No findings. The diff adds a narrow |
Single control surface for cleanup-lane harvest of #900/#901/#920/#897/#824/#825 per dispatch from tidy-dove-734 (#941). No ctrl#263 in repo; this docs/audit artifact is the agreed fallback. Rows: source PR, gap, file/invariant, owner lane, dissolution trigger, acceptance check, tracking authority, disposition.
* docs(audit): W-C1 follow-up harvest table Single control surface for cleanup-lane harvest of #900/#901/#920/#897/#824/#825 per dispatch from tidy-dove-734 (#941). No ctrl#263 in repo; this docs/audit artifact is the agreed fallback. Rows: source PR, gap, file/invariant, owner lane, dissolution trigger, acceptance check, tracking authority, disposition. * docs(audit): close #897/#824/#825 rows per bright-wolf-465 audit Per bright-wolf-465 (inbox #945), no missed BLOCKING findings on these PRs; flip rows 6/7/8 to closed with audit citation. * docs(audit): reconcile note with row dispositions for #897/#824/#825 * WIP: calm-ant-861 * chore: apply cargo fmt * WIP: calm-ant-861 * fix(test): fold B5 Loop closure receipt into m1_substrate_test SG-0 census ratchet forbids new hand-authored .rs files. Move the every_loop_node_originates_from_recursive_function_lowering test (and the LoopNode/LoopBound import + two helper fns) into the existing m1_substrate_test.rs and drop the standalone file + its integration.rs registration. Behavior unchanged. * docs: correct B5 receipt file path in synthesis doc (m1_substrate_test, not standalone file) * docs: mark ROADMAP loop-emission row resolved + correct synthesis cite Codex BLOCKING on be4a6ab: ROADMAP.md still listed the loop-emission semantic invariant as open debt while the synthesis doc declared it resolved — tracker-authority mismatch. - ROADMAP.md:436: rewrite the row as RESOLVED 2026-04-27 with PR cite, audit summary (two production sites in lower.rs), receipt location (m1_substrate_test.rs), and marker-retired note. - synthesis-doc §3 line 155: fix the receipt path (loop_construction_closure_test.rs → m1_substrate_test.rs after the SG-0 fold). * fix(test): split global vs fixture-scoped Loop closure assertions Codex BLOCKING on db7b773: previous test mixed a global all-Dag closure check with fixture-only variant claims, so bootstrap loops could mask the fixture-coverage claim. Split into two phases: - Global: every Behavior::Loop in the Dag (fixture + bootstrap) satisfies the recursive-function-lowering signature (loop.output is a Bind value port + Descent cluster id resolves). This is the closure invariant. - Fixture-scoped: filter loops by span.file == fixture file before claiming both LoopBound variants are produced by THIS fixture. Bootstrap loops are excluded so the variant claim is mechanically about the fixture's recursive functions. * post-merge: drop superseded artifacts; correct ROADMAP B5 receipt cite The parallel B5 lane landed `r2_b5_loop_construction_closure_test.rs` on main with a more rigorous receipt (substring push-site ratchet + per-fixture DAG walk + Origin::Accumulated provenance). The harvest table in this PR is also being landed via aggregate #949. Drop: - `docs/audit/w-c1-followup-harvest-2026-04-27.md` (canonical surface is #949). - The m1_substrate_test additions (auto-reverted via merge --theirs; superseded by the standalone r2_b5_loop_construction_closure_test.rs on main). Keep: - `ROADMAP.md` row marking loop-emission RESOLVED, with citation rewritten to point at the actual landed receipt file (r2_b5_…) instead of the retired m1_substrate_test cite.
* docs(std.unicode): cite UCD 15.x / UAX-11 authority Closes the #920 post-merge citation gap. Header now states the file is sourced from UCD 15.x (UAX #11 East Asian Width) for the display- width tables and is intentionally 15.x compatible rather than pinned to a specific minor. UAX #9 is explicitly not consulted (no bidi). No behavior changes. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs: tighten P5 per-PR dissolution gate (b) for ROADMAP-cited deferrals Require exactly one checkable receipt: delete path, SG-0 census before/after counts, or lane plus concrete ROADMAP row/link. Call out vague deferrals as insufficient. Align INVARIANTS §P5 (b) with the template without duplicating the checklist. Made-with: Cursor * docs(audit): W-C1 follow-up harvest table Single control surface for cleanup-lane harvest of #900/#901/#920/#897/#824/#825 per dispatch from tidy-dove-734 (#941). No ctrl#263 in repo; this docs/audit artifact is the agreed fallback. Rows: source PR, gap, file/invariant, owner lane, dissolution trigger, acceptance check, tracking authority, disposition. * docs(audit): mark #920 citation follow-up closed * docs(audit): close #897 #824 #825 harvest rows * docs(audit): cite closure evidence for harvest rows * WIP: Cleanup * docs(std.unicode): clarify UAX 11 coverage * docs: link cleanup harvest from roadmap * docs(std.unicode): refresh bootstrap spans * docs(std.unicode): refresh full bootstrap spans * docs(std.unicode): refresh no-parse bootstrap spans * docs(audit): stabilize harvest code references --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Pre-spawn implementation work has progressed materially while #1078 was in flight; managers spawning today would otherwise dispatch against work that's already landed. Refresh per-manager status tables to reflect current main: - **Substrate:** ValueBody::Map landed (#1017 + #1068 tightening); NominalOpacity fail-closed field-projection enforcement (#937); B4.8 Phase-2 site dissolution landed (#1069); B4.2 first-consumer wiring landed; T-Cost-Dimension fail-closed precedent (#1003). - **Grounding:** Rust IntegerRangeFact mirror dissolved (#1005); Python primitives.dag landed (#1080); Go primitives tranche 1 + additional (ac765ce + #1046); T-Ground-Engine Phase 2 slice 1 (c0cc8b2) noted as pre-cascade footprint queued for cleanup wave per design-emission-model.md option (c). - **Impossible-Bugs:** all 3 main implementations LANDED pre-spawn (nested-optional flatten #890 + #962 follow-ups; Int/Int totality- by-omission first slice #969; unenumerated effects lens landing #971). Day-1 work is class-close completion + sibling totalization dispatch (indexing/quotient/remainder), not initial implementation. - **Pure Bootstrap:** kernel_algebra_profile substrate met via #1017 + #1068 (consumer plumbing now the remaining R2 work, dispatchable Day-1); T-PB-Runtime ExecuteCommand typed-outcome hardening (#1049) + T-PB-B boundary coverage (#1082) advanced PB-Runtime foundation for R3 lens_apply.rs retirement gate. - **Modeling:** Secret<T> producer side substantially advanced (#900 carrier + #937 fail-closed enforcement); tokenizer charclass scanner-order retype landed pre-cascade (242c65d); SourceFiltering canonical authority precedent (#1004). - **Release:** initial closure-ledger snapshot now reflects all pre-spawn landings (Impossible-Bugs/Substrate/Ground/PB-Runtime). Evaluator brief unchanged — new lane added 2026-04-28; nothing landed yet (gated on PR-A through PR-E design lock cadence). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Per gpt-5-5-pro meta-review on PR #1126: dissolves the recurring "non-live authority consumed as live" pattern that surfaced 5+ times during PR #1078 + #1126 review loops (codex tooling false-positives naming non-existent files / sections; cursor-flagged single-authority drift on Goal numbering + R3 continuation count). v1 covers 4 of gpt-5-5-pro's 5 questions: - **Q1 — cited file existence** — extracts markdown links from each brief, resolves relative paths, fails closed if any cited file doesn't exist on disk. - **Q2 — cited section anchor existence** — for `path#anchor` links, verifies the anchor matches a slugified heading in the target file. - **Q4 — `LANDED via #N` reachability** — two-stage check: (a) fast `git log --grep="(#N)"` for normal merge subjects, (b) fall back to `gh pr view` for squash-merges that drop the suffix (caught a real case for PR #900). Verifies merge SHA is `git merge-base --is-ancestor HEAD`. - **Q5 — cross-brief projection consistency** — extracts manager/lane counts and verifies all briefs that mention a projection agree both cross-brief AND with canonical values from r2-structure.md / r3-structure.md (7 standing managers, 6 other managers, 10 R3 lanes, 7 of 10 Evaluator-gated). Catches drift like "5 R2-archiving managers" vs "all 6 other managers". Q3 (controlled status vocabulary) deferred to v2 — too subjective for a mechanical check; tracked in script header as next narrowing. **Self-test** (`scripts/test-check-manager-brief-authority.sh`): 7 contract assertions — negative cases for each of Q1/Q2/Q4/Q5 (×2) + fail-closed-on-missing-brief + positive case. Mirrors the `test-check-release-doc-authority.sh` pattern. **Wiring:** - Makefile: `manager-brief-authority-check` + `-test` targets; `verify` runs the check. - CI workflow: both check + self-test wired as named steps; check receives `GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}` for the gh API fallback in Q4. **SIGPIPE under pipefail caveat documented inline:** `grep -q .` on a piped `git log` causes pipefail to report failure (grep exits early, git log gets SIGPIPE 141). Workaround: capture output and test `-z`/`-n`. Pinned in Q4 implementation comment. Closes the convergence move gpt-5-5-pro proposed; future review loops that hit the same "non-live authority" class get caught at CI rather than reviewer-by-reviewer prose iteration. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Per gpt-5-5-pro APPROVE_WITH_COMMENTS on PR #1126 (sha:91b5274f → 6dafaec): Q4 silently missed title-case "Landed via #N" claims. **Finding 1 (Q4 case sensitivity):** live briefs use three case forms of "landed via #N": - UPPERCASE — emphasized status-table claims (most common) - lowercase — inline prose ("landed via #900", "landed via #937", ...) - title-case — sentence-leading headings (r2-release-manager.md:113 "Landed via #1078:") The pre-fix regex `(LANDED|landed) via` missed the title-case form, silently passing any future unique `Landed via #N` claim. Fix: `grep -oEi 'landed via #[0-9]+'` (case-insensitive flag). **Finding 2 (Q4 self-test gap):** Q4 negative fixture used UPPERCASE "LANDED via #88888888"; positive fixture had no landed-PR claim at all. Title-case wasn't covered. Fixes: - Added `test_negative_q4_unreachable_pr_titlecase` using "Landed via #88888887" — verifies case-insensitive Q4 catches title-case. - Updated `write_clean_briefs` clean fixture to include "Substrate landed via #999" (lowercase, matching real brief format). Q4 positive path is now non-vacuous: tmp git repo seeds "(#999)" merge subject so this resolves cleanly. **Finding 3 (Q2 prose deferral note)**: STALE — Q2-prose was implemented in 97affdb (2 commits before this review). The reviewer cited line numbers from before the implementation; current code at `scripts/check-manager-brief-authority.sh:121` says "Two forms covered" not "v2 candidate". No action needed. Self-test now: 8 contract assertions (6 negative + 1 positive + 1 fail-closed-on-missing-brief). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…#1126) * WIP: Gunbc PM * WIP: Gunbc PM * WIP: Gunbc PM * WIP: Gunbc PM * docs(briefs): refresh 6 R2 manager briefs post-#1078 merge Aligns all 6 existing R2 manager briefs with #1078's locked design decisions and structural cascade: - Substrate Manager: adds T-Substrate-Lens-Primitive sub-lane (Q6+Q7+Q8 locks) + PR-PreF Interval<D> consolidation + R3 T-CostLens-Composition continuation (Director cascade Item 3); references INVARIANTS §P1 substrate-fact-introduction procedure + Q3 Cost<Unit> primitives. - Grounding Manager: engine-reframe to 11 lanes (5 substrate-completion lanes replace prior single Engine: Coercion-Fold + LanguageSpec + Lifetime-Analyzer + Diagnostic + CrossTarget-Meta); consumes PR-F through PR-J cadence; PR #989 footprint queued for cleanup wave. - Modeling Manager: int-lit item now consumes PR-PreF Interval<D> via Q1 lock; references INVARIANTS procedure for substrate-gap signaling. - Pure Bootstrap Manager: adds R3 continuation lanes (T-LensProducer- Retirement XL with 3 internal sub-gates per Director cascade Item 8; T-FixedPoint; T-Tier3-Dissolution; 3 distributed bridge retirements per Director cascade Item 4 — distribute work, centralize ledger). - Impossible-Bugs Manager: archives at R2 close per Director cascade; post-R2 emergent classes route to Substrate Manager continuation. - Release Manager: 6→7 manager count; closure ledger spans all 6 other managers + sub-gate progress for T-LensProducer-Retirement; structural- acceptance-per-lane-close discipline (demo IS structural gate); thesis-claim mapping landed via #1078, refresh authority lives here; v2 release-doc-authority guardrail follow-up added as next narrow PR. All 6 briefs now include: structural acceptance .dag TestClaim gates, locked-design-decisions-consumed section, INVARIANTS §P1 procedure references, and option-(c)-hybrid timing notes where R1-close-relevant. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: Gunbc PM * docs(briefs): R2 manager-brief status refresh against landed PRs Pre-spawn implementation work has progressed materially while #1078 was in flight; managers spawning today would otherwise dispatch against work that's already landed. Refresh per-manager status tables to reflect current main: - **Substrate:** ValueBody::Map landed (#1017 + #1068 tightening); NominalOpacity fail-closed field-projection enforcement (#937); B4.8 Phase-2 site dissolution landed (#1069); B4.2 first-consumer wiring landed; T-Cost-Dimension fail-closed precedent (#1003). - **Grounding:** Rust IntegerRangeFact mirror dissolved (#1005); Python primitives.dag landed (#1080); Go primitives tranche 1 + additional (ac765ce + #1046); T-Ground-Engine Phase 2 slice 1 (c0cc8b2) noted as pre-cascade footprint queued for cleanup wave per design-emission-model.md option (c). - **Impossible-Bugs:** all 3 main implementations LANDED pre-spawn (nested-optional flatten #890 + #962 follow-ups; Int/Int totality- by-omission first slice #969; unenumerated effects lens landing #971). Day-1 work is class-close completion + sibling totalization dispatch (indexing/quotient/remainder), not initial implementation. - **Pure Bootstrap:** kernel_algebra_profile substrate met via #1017 + #1068 (consumer plumbing now the remaining R2 work, dispatchable Day-1); T-PB-Runtime ExecuteCommand typed-outcome hardening (#1049) + T-PB-B boundary coverage (#1082) advanced PB-Runtime foundation for R3 lens_apply.rs retirement gate. - **Modeling:** Secret<T> producer side substantially advanced (#900 carrier + #937 fail-closed enforcement); tokenizer charclass scanner-order retype landed pre-cascade (242c65d); SourceFiltering canonical authority precedent (#1004). - **Release:** initial closure-ledger snapshot now reflects all pre-spawn landings (Impossible-Bugs/Substrate/Ground/PB-Runtime). Evaluator brief unchanged — new lane added 2026-04-28; nothing landed yet (gated on PR-A through PR-E design lock cadence). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: Gunbc PM * docs(briefs): align Substrate Produces + Release R2-close acceptance Per gpt-5-5-pro REQUEST_CHANGES on PR #1126 (sha:a9285fce). Two valid findings on coordination-contract internal consistency: 1. **Substrate Produces list omitted ValueBody::Map → PB signal.** The deliverables table at line 94 named ValueBody::Map as an R2 unblocker for PB's kernel_algebra_profile mirror dissolution, but the cross-program "Produces" section listed 5 signals and did not include this one. Same dependency represented in two places with different authority. Fix: add ValueBody::Map carrier read-path/API + arrow-body evaluation as the 6th produced signal targeted at PB Manager; update count from 5 to 6 (also in Reporting-cadence line 150). Remove the "Adjacent territory" note about kernel_algebra_profile being a future sub-lane — substrate already landed via #1017+#1068. 2. **Release R2-close acceptance gate excluded PB from close criterion.** The brief's "Consumes" section correctly named all 6 other managers including PB, but the r2_close_signal_to_director_authored gate at line 103 used "5 R2-archiving managers" (Substrate-prereq / Modeling / Grounding / Impossible-Bugs / Evaluator) — could fire the R2-close signal while PB's R2-scope lanes (Tier 3 mirror dissolutions + kernel_algebra_profile consumer plumbing) are still open. Fix: gate becomes "all 6 other managers' R2-scope lanes complete" with explicit lane-set listed per manager. Distinguish R2-scope completion from manager-archives (Modeling/Impossible-Bugs archive; Substrate/PB continue into R3 with R3-scoped lanes — those don't gate R2 close). Both are P2 single-authority alignments; no scope change. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: Gunbc PM * feat(scripts): manager-brief authority consumer + self-test Per gpt-5-5-pro meta-review on PR #1126: dissolves the recurring "non-live authority consumed as live" pattern that surfaced 5+ times during PR #1078 + #1126 review loops (codex tooling false-positives naming non-existent files / sections; cursor-flagged single-authority drift on Goal numbering + R3 continuation count). v1 covers 4 of gpt-5-5-pro's 5 questions: - **Q1 — cited file existence** — extracts markdown links from each brief, resolves relative paths, fails closed if any cited file doesn't exist on disk. - **Q2 — cited section anchor existence** — for `path#anchor` links, verifies the anchor matches a slugified heading in the target file. - **Q4 — `LANDED via #N` reachability** — two-stage check: (a) fast `git log --grep="(#N)"` for normal merge subjects, (b) fall back to `gh pr view` for squash-merges that drop the suffix (caught a real case for PR #900). Verifies merge SHA is `git merge-base --is-ancestor HEAD`. - **Q5 — cross-brief projection consistency** — extracts manager/lane counts and verifies all briefs that mention a projection agree both cross-brief AND with canonical values from r2-structure.md / r3-structure.md (7 standing managers, 6 other managers, 10 R3 lanes, 7 of 10 Evaluator-gated). Catches drift like "5 R2-archiving managers" vs "all 6 other managers". Q3 (controlled status vocabulary) deferred to v2 — too subjective for a mechanical check; tracked in script header as next narrowing. **Self-test** (`scripts/test-check-manager-brief-authority.sh`): 7 contract assertions — negative cases for each of Q1/Q2/Q4/Q5 (×2) + fail-closed-on-missing-brief + positive case. Mirrors the `test-check-release-doc-authority.sh` pattern. **Wiring:** - Makefile: `manager-brief-authority-check` + `-test` targets; `verify` runs the check. - CI workflow: both check + self-test wired as named steps; check receives `GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}` for the gh API fallback in Q4. **SIGPIPE under pipefail caveat documented inline:** `grep -q .` on a piped `git log` causes pipefail to report failure (grep exits early, git log gets SIGPIPE 141). Workaround: capture output and test `-z`/`-n`. Pinned in Q4 implementation comment. Closes the convergence move gpt-5-5-pro proposed; future review loops that hit the same "non-live authority" class get caught at CI rather than reviewer-by-reviewer prose iteration. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(scripts): manager-brief Q4 — gh-first for CI shallow-clone compat CI failed on the first run of the checker because the workflow uses fetch-depth=1 (shallow clone), so the Q4 fall-back stage's git-log --grep="(#N)" can't see merge history. The two-stage check worked locally because git log had full history; in CI it found nothing on either stage. Restructure Q4 to gh-first: - **Stage 1 (primary):** gh pr view N --json state — returns MERGED for actually-merged PRs regardless of clone depth or squash-merge subject variance. CI passes GH_TOKEN automatically. - **Stage 2 (fallback):** git log --grep — kept for offline dev / auth-blocked environments. In CI with fetch-depth=1 this stage finds nothing; that's why Stage 1 is primary. Reasoning: "is this PR actually merged" is what we want to verify; gh state=MERGED answers it directly. The previous git-log+ancestor check was defense-in-depth, but actually fragile in shallow clones which is the CI default. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(scripts): manager-brief check — set -e + return interaction Per claude-opus-4-7 review on PR #1126: three non-blocking findings addressed. 1. **set -e + return non-zero**: the per-brief driver loop used `check_q1_file_existence "$brief"; rc=$?` — under set -euo pipefail, a function returning non-zero is treated as a failed command and exits the script before the accumulator runs. Result was "stop at first failing brief," not "report all violations in one pass" as intended. Fix: use `|| rc=$?` form (with explicit `rc=0` reset). This keeps set -e from firing on expected-non-zero returns while still capturing the count. 2. **Q2 doc/code mismatch**: header comment promised both `path#anchor` markdown form AND `§"section name"` prose form. Implementation only handled markdown. Trim the comment to match the code; track prose-form in v2 follow-up alongside Q3 status-vocabulary as next narrowing. 3. **Q5 pattern overlap (exploratory)**: claude-opus-4-7 flagged that "standing managers" might substring-match "standing R2 managers". Empirical check shows it doesn't (POSIX regex requires the exact "standing managers" sequence; "R2 " breaks the match). Documented inline; no pattern change needed. 8-bit return-code truncation noted by reviewer is theoretical at current scale (briefs typically have <10 violations) and is now moot since the global `violations` accumulator is plain bash arithmetic; only the per-function `return` is uint8-bounded. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(scripts): manager-brief Q4 — explicit --repo for CI gh detection CI failed Q4 even after gh-first restructure: actions/checkout@v4's shallow clone exposes the remote in a form 'gh pr view' doesn't always auto-detect, so the stage-1 gh call returned empty (no error message in v1 because stderr was redirected to /dev/null) and the stage-2 git-log fallback also failed (shallow clone has no merge history). Three fixes in this commit: 1. **Derive REPO_SLUG from `git config remote.origin.url`** at script start. Falls back to "gunb-ai/gunbc" if origin isn't readable (self-test runs in tmpdir with no remote). 2. **Pass `--repo "$REPO_SLUG"` explicitly to `gh pr view`** so it doesn't have to infer from the cwd's git remote. 3. **Capture gh stderr** to a temp file and surface it in the violation diagnostic. If gh is auth-failing or rate-limited, the violation message now shows why instead of looking like "PR doesn't exist." Both checker + self-test still pass locally. CI should now succeed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(ci): grant pull-requests:read for manager-brief authority check The check uses `gh pr view --json state` to verify "LANDED via #N" claims map to MERGED PRs. Default GITHUB_TOKEN scopes only include contents:read; pull-request access fails with: GraphQL: Resource not accessible by integration (repository.pullRequest) Surfaced when the script's stderr-capture fix (ea33aeb) made the actual error message visible — diagnostic improvement paid off immediately. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: Gunbc PM * fix(scripts): manager-brief checker — markdown-bold + heading-strip + Q3 trigger Per gpt-5-5-pro REQUEST_CHANGES on PR #1126 (sha:ea33aeb9). Three findings — one BLOCKING (Q5 was ceremonial on its load-bearing projection), one secondary (heading-strip glob bug), one coverage gap. 1. **Q5 markdown-bold mismatch (BLOCKING).** Live briefs use `Names this manager one of **7** standing R2 managers` — markdown emphasis around the count. The pre-fix regex `[0-9]+ standing R2 managers` required a bare leading digit, so it matched zero claims on every brief. Counts_seen stayed empty → "0 counts seen → silent OK" branch fired → check passed ceremonially. A future drift to `**6** standing R2 managers` would have been invisible. Fix: regex now optionally accepts `**` before and after the digit: `\*?\*?[0-9]+\*?\*? standing R2 managers`. Extraction strips asterisks (`tr -d '*'`) before parsing. Verified on live briefs: $ grep -oE '\*?\*?[0-9]+\*?\*? standing R2 managers' docs/briefs/r2-*-manager.md docs/briefs/r2-evaluator-manager.md:**7** standing R2 managers docs/briefs/r2-grounding-manager.md:**7** standing R2 managers docs/briefs/r2-impossible-bugs-manager.md:**7** standing R2 managers docs/briefs/r2-modeling-manager.md:**7** standing R2 managers docs/briefs/r2-pure-bootstrap-manager.md:**7** standing R2 managers docs/briefs/r2-release-manager.md:**7** standing R2 managers docs/briefs/r2-substrate-manager.md:**7** standing R2 managers Now actually catches all 7 briefs' projections. 2. **Heading-strip glob bug (Q2 secondary).** `${heading##\#* }` is a Bash glob that strips through the LAST space, so "## Goal 7 — Evaluator XL" becomes "XL" instead of "Goal 7 — Evaluator XL". Multi-word heading anchors silently false-fail. Fix: introduced `strip_heading_marker()` helper using sed regex `^#{1,6}[[:space:]]+` for accurate prefix-only stripping. 3. **Self-test fixture format mismatch (coverage gap).** Self-test used bare-digit form ("7 standing R2 managers"); live briefs use markdown-bold ("**7** standing R2 managers"). Fixture proved Q5 for a format the live docs don't use, masking finding 1. Fix: updated all clean + drift fixtures in self-test to use markdown-bold form. Verifies Q5 catches the actual format. 4. **Q3 dissolution trigger (per debt-tracking discipline).** Previous "v2; the next narrowing opportunity" was a future bucket without a checkable trigger. Replaced with concrete trigger: "first reviewer-flagged status-string drift class that Q1/Q2/Q4/Q5 don't catch." Until that surfaces, status vocabulary is captured indirectly via Q5 count-projection consistency. Local checker + self-test still pass after fixes; Q5 now actually fires on live brief content rather than silently passing ceremonial. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(scripts+briefs): manager-brief Q2 prose-form check + align 7 citations Per gpt-5-5-pro BLOCKING on PR #1126 (sha:91b5274fc): Q2 explicitly excluded prose §"section name" citations, but live briefs use those for load-bearing INVARIANTS / r2-structure / design authority claims. The exclusion left 12 real authority drifts uncheckable. **Implements Q2-prose** (in addition to Q2-markdown-anchor): For each `§"quoted section"` or `§AnchorToken` in a brief: 1. Compute the prefix BEFORE this citation (running prefix; the bug in v0 was using before-first-§ for every iteration, so subsequent citations on the same line resolved against the first link's target instead of their own). 2. Find the most recent markdown link `[text](path)` in the prefix — that's the cited file. Fall back to bare `<NAME>.md` token via `resolve_authority_file()` (tries `$ROOT/`, `$ROOT/docs/`, `$ROOT/docs/thesis/`, `$ROOT/docs/briefs/`). 3. `grep -F` for the section text in the cited file. Permissive substring match (vs Q2-markdown's slug match) — accepts paraphrased section names while still catching the load-bearing "section deleted" failure mode. **Caught 12 real drifts on first run** — all now fixed: - r2-evaluator-manager.md: §"Goal 7 — Evaluator XL" + §"Evaluator Manager (added 2026-04-28 as Goal 7)" → §"Evaluator Manager (added 2026-04-28 amendment)" (matches r2-structure.md:159 actual heading) - r2-grounding-manager.md: §"Tier 1 — Structural correctness — Grounding completeness" → §"Tier 1 — Structural correctness" (matches THESIS.md:168 actual prose) - r2-impossible-bugs-manager.md (×2): §"R2 manager continuation" → §"Manager structure" (matches r3-structure.md:103 actual heading) - r2-impossible-bugs-manager.md: §Q1-Q3 + §Q6 → §Q1, §Q2, §Q3 + §Q6 (range citation didn't match anything literal; expand to discrete) - r2-release-manager.md (×2): §"R2 manager continuation" → §"Manager structure" - r2-release-manager.md (×2): §v2-guardrail-requirement-3 → §"v2 guardrail requirements" (matches r2-structure.md:490 body) - r2-substrate-manager.md: §"R3 lane structure" → §"Lane structure" (matches r3-structure.md:86 actual heading) Local checker + self-test still pass after fixes. Reinforces gpt-5-5-pro's earlier meta-observation: a checker that names a discipline but doesn't enforce it on the live format is documented cheating. Q2-prose closes that gap; the briefs' authority citations now have to match section text that actually exists. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * chore(scripts): manager-brief — mktemp gh-stderr + Q1 false-pos trigger Per claude-opus-4-7 APPROVE-with-exploratory-observations on PR #1126 (sha:91b5274f). Two non-blocking cleanups landed. 1. **gh-stderr capture: $$ → mktemp.** Previous form used `/tmp/gh-stderr-$$` which is fine in CI but a crashed run on a shared dev box could leak the file. `mktemp` gives a unique path + paired cleanup in scope. 2. **Q1 false-positive trigger documented.** Q1 currently treats every `](path)` as a filesystem reference. Markdown reference- style link definitions and code-block examples containing `](foo)` would false-positive. No briefs use either form today; added DISSOLUTION TRIGGER comment naming the condition that would force context-aware extraction (skip fenced code blocks + reference definitions). The third observation (squash-merge for the WIP: Gunbc PM commits) is a merge-time decision; PR-level chore. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: Gunbc PM * fix(scripts): manager-brief Q4 case-insensitive + title-case test Per gpt-5-5-pro APPROVE_WITH_COMMENTS on PR #1126 (sha:91b5274f → 6dafaec): Q4 silently missed title-case "Landed via #N" claims. **Finding 1 (Q4 case sensitivity):** live briefs use three case forms of "landed via #N": - UPPERCASE — emphasized status-table claims (most common) - lowercase — inline prose ("landed via #900", "landed via #937", ...) - title-case — sentence-leading headings (r2-release-manager.md:113 "Landed via #1078:") The pre-fix regex `(LANDED|landed) via` missed the title-case form, silently passing any future unique `Landed via #N` claim. Fix: `grep -oEi 'landed via #[0-9]+'` (case-insensitive flag). **Finding 2 (Q4 self-test gap):** Q4 negative fixture used UPPERCASE "LANDED via #88888888"; positive fixture had no landed-PR claim at all. Title-case wasn't covered. Fixes: - Added `test_negative_q4_unreachable_pr_titlecase` using "Landed via #88888887" — verifies case-insensitive Q4 catches title-case. - Updated `write_clean_briefs` clean fixture to include "Substrate landed via #999" (lowercase, matching real brief format). Q4 positive path is now non-vacuous: tmp git repo seeds "(#999)" merge subject so this resolves cleanly. **Finding 3 (Q2 prose deferral note)**: STALE — Q2-prose was implemented in 97affdb (2 commits before this review). The reviewer cited line numbers from before the implementation; current code at `scripts/check-manager-brief-authority.sh:121` says "Two forms covered" not "v2 candidate". No action needed. Self-test now: 8 contract assertions (6 negative + 1 positive + 1 fail-closed-on-missing-brief). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * chore(briefs): strip trailing whitespace at r2-evaluator-manager.md:46 Per codex review on PR #1126 (sha:3ba4f2c1): `git diff --check origin/main...HEAD` flagged trailing whitespace inside the PR-A-through-PR-E dependency-graph ASCII art. Removed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…1156) * WIP: Gunbc PM * WIP: Gunbc PM * WIP: Gunbc PM * WIP: Gunbc PM * docs(briefs): refresh 6 R2 manager briefs post-#1078 merge Aligns all 6 existing R2 manager briefs with #1078's locked design decisions and structural cascade: - Substrate Manager: adds T-Substrate-Lens-Primitive sub-lane (Q6+Q7+Q8 locks) + PR-PreF Interval<D> consolidation + R3 T-CostLens-Composition continuation (Director cascade Item 3); references INVARIANTS §P1 substrate-fact-introduction procedure + Q3 Cost<Unit> primitives. - Grounding Manager: engine-reframe to 11 lanes (5 substrate-completion lanes replace prior single Engine: Coercion-Fold + LanguageSpec + Lifetime-Analyzer + Diagnostic + CrossTarget-Meta); consumes PR-F through PR-J cadence; PR #989 footprint queued for cleanup wave. - Modeling Manager: int-lit item now consumes PR-PreF Interval<D> via Q1 lock; references INVARIANTS procedure for substrate-gap signaling. - Pure Bootstrap Manager: adds R3 continuation lanes (T-LensProducer- Retirement XL with 3 internal sub-gates per Director cascade Item 8; T-FixedPoint; T-Tier3-Dissolution; 3 distributed bridge retirements per Director cascade Item 4 — distribute work, centralize ledger). - Impossible-Bugs Manager: archives at R2 close per Director cascade; post-R2 emergent classes route to Substrate Manager continuation. - Release Manager: 6→7 manager count; closure ledger spans all 6 other managers + sub-gate progress for T-LensProducer-Retirement; structural- acceptance-per-lane-close discipline (demo IS structural gate); thesis-claim mapping landed via #1078, refresh authority lives here; v2 release-doc-authority guardrail follow-up added as next narrow PR. All 6 briefs now include: structural acceptance .dag TestClaim gates, locked-design-decisions-consumed section, INVARIANTS §P1 procedure references, and option-(c)-hybrid timing notes where R1-close-relevant. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: Gunbc PM * docs(briefs): R2 manager-brief status refresh against landed PRs Pre-spawn implementation work has progressed materially while #1078 was in flight; managers spawning today would otherwise dispatch against work that's already landed. Refresh per-manager status tables to reflect current main: - **Substrate:** ValueBody::Map landed (#1017 + #1068 tightening); NominalOpacity fail-closed field-projection enforcement (#937); B4.8 Phase-2 site dissolution landed (#1069); B4.2 first-consumer wiring landed; T-Cost-Dimension fail-closed precedent (#1003). - **Grounding:** Rust IntegerRangeFact mirror dissolved (#1005); Python primitives.dag landed (#1080); Go primitives tranche 1 + additional (ac765ce + #1046); T-Ground-Engine Phase 2 slice 1 (c0cc8b2) noted as pre-cascade footprint queued for cleanup wave per design-emission-model.md option (c). - **Impossible-Bugs:** all 3 main implementations LANDED pre-spawn (nested-optional flatten #890 + #962 follow-ups; Int/Int totality- by-omission first slice #969; unenumerated effects lens landing #971). Day-1 work is class-close completion + sibling totalization dispatch (indexing/quotient/remainder), not initial implementation. - **Pure Bootstrap:** kernel_algebra_profile substrate met via #1017 + #1068 (consumer plumbing now the remaining R2 work, dispatchable Day-1); T-PB-Runtime ExecuteCommand typed-outcome hardening (#1049) + T-PB-B boundary coverage (#1082) advanced PB-Runtime foundation for R3 lens_apply.rs retirement gate. - **Modeling:** Secret<T> producer side substantially advanced (#900 carrier + #937 fail-closed enforcement); tokenizer charclass scanner-order retype landed pre-cascade (242c65d); SourceFiltering canonical authority precedent (#1004). - **Release:** initial closure-ledger snapshot now reflects all pre-spawn landings (Impossible-Bugs/Substrate/Ground/PB-Runtime). Evaluator brief unchanged — new lane added 2026-04-28; nothing landed yet (gated on PR-A through PR-E design lock cadence). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: Gunbc PM * docs(briefs): align Substrate Produces + Release R2-close acceptance Per gpt-5-5-pro REQUEST_CHANGES on PR #1126 (sha:a9285fce). Two valid findings on coordination-contract internal consistency: 1. **Substrate Produces list omitted ValueBody::Map → PB signal.** The deliverables table at line 94 named ValueBody::Map as an R2 unblocker for PB's kernel_algebra_profile mirror dissolution, but the cross-program "Produces" section listed 5 signals and did not include this one. Same dependency represented in two places with different authority. Fix: add ValueBody::Map carrier read-path/API + arrow-body evaluation as the 6th produced signal targeted at PB Manager; update count from 5 to 6 (also in Reporting-cadence line 150). Remove the "Adjacent territory" note about kernel_algebra_profile being a future sub-lane — substrate already landed via #1017+#1068. 2. **Release R2-close acceptance gate excluded PB from close criterion.** The brief's "Consumes" section correctly named all 6 other managers including PB, but the r2_close_signal_to_director_authored gate at line 103 used "5 R2-archiving managers" (Substrate-prereq / Modeling / Grounding / Impossible-Bugs / Evaluator) — could fire the R2-close signal while PB's R2-scope lanes (Tier 3 mirror dissolutions + kernel_algebra_profile consumer plumbing) are still open. Fix: gate becomes "all 6 other managers' R2-scope lanes complete" with explicit lane-set listed per manager. Distinguish R2-scope completion from manager-archives (Modeling/Impossible-Bugs archive; Substrate/PB continue into R3 with R3-scoped lanes — those don't gate R2 close). Both are P2 single-authority alignments; no scope change. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: Gunbc PM * feat(scripts): manager-brief authority consumer + self-test Per gpt-5-5-pro meta-review on PR #1126: dissolves the recurring "non-live authority consumed as live" pattern that surfaced 5+ times during PR #1078 + #1126 review loops (codex tooling false-positives naming non-existent files / sections; cursor-flagged single-authority drift on Goal numbering + R3 continuation count). v1 covers 4 of gpt-5-5-pro's 5 questions: - **Q1 — cited file existence** — extracts markdown links from each brief, resolves relative paths, fails closed if any cited file doesn't exist on disk. - **Q2 — cited section anchor existence** — for `path#anchor` links, verifies the anchor matches a slugified heading in the target file. - **Q4 — `LANDED via #N` reachability** — two-stage check: (a) fast `git log --grep="(#N)"` for normal merge subjects, (b) fall back to `gh pr view` for squash-merges that drop the suffix (caught a real case for PR #900). Verifies merge SHA is `git merge-base --is-ancestor HEAD`. - **Q5 — cross-brief projection consistency** — extracts manager/lane counts and verifies all briefs that mention a projection agree both cross-brief AND with canonical values from r2-structure.md / r3-structure.md (7 standing managers, 6 other managers, 10 R3 lanes, 7 of 10 Evaluator-gated). Catches drift like "5 R2-archiving managers" vs "all 6 other managers". Q3 (controlled status vocabulary) deferred to v2 — too subjective for a mechanical check; tracked in script header as next narrowing. **Self-test** (`scripts/test-check-manager-brief-authority.sh`): 7 contract assertions — negative cases for each of Q1/Q2/Q4/Q5 (×2) + fail-closed-on-missing-brief + positive case. Mirrors the `test-check-release-doc-authority.sh` pattern. **Wiring:** - Makefile: `manager-brief-authority-check` + `-test` targets; `verify` runs the check. - CI workflow: both check + self-test wired as named steps; check receives `GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}` for the gh API fallback in Q4. **SIGPIPE under pipefail caveat documented inline:** `grep -q .` on a piped `git log` causes pipefail to report failure (grep exits early, git log gets SIGPIPE 141). Workaround: capture output and test `-z`/`-n`. Pinned in Q4 implementation comment. Closes the convergence move gpt-5-5-pro proposed; future review loops that hit the same "non-live authority" class get caught at CI rather than reviewer-by-reviewer prose iteration. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(scripts): manager-brief Q4 — gh-first for CI shallow-clone compat CI failed on the first run of the checker because the workflow uses fetch-depth=1 (shallow clone), so the Q4 fall-back stage's git-log --grep="(#N)" can't see merge history. The two-stage check worked locally because git log had full history; in CI it found nothing on either stage. Restructure Q4 to gh-first: - **Stage 1 (primary):** gh pr view N --json state — returns MERGED for actually-merged PRs regardless of clone depth or squash-merge subject variance. CI passes GH_TOKEN automatically. - **Stage 2 (fallback):** git log --grep — kept for offline dev / auth-blocked environments. In CI with fetch-depth=1 this stage finds nothing; that's why Stage 1 is primary. Reasoning: "is this PR actually merged" is what we want to verify; gh state=MERGED answers it directly. The previous git-log+ancestor check was defense-in-depth, but actually fragile in shallow clones which is the CI default. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(scripts): manager-brief check — set -e + return interaction Per claude-opus-4-7 review on PR #1126: three non-blocking findings addressed. 1. **set -e + return non-zero**: the per-brief driver loop used `check_q1_file_existence "$brief"; rc=$?` — under set -euo pipefail, a function returning non-zero is treated as a failed command and exits the script before the accumulator runs. Result was "stop at first failing brief," not "report all violations in one pass" as intended. Fix: use `|| rc=$?` form (with explicit `rc=0` reset). This keeps set -e from firing on expected-non-zero returns while still capturing the count. 2. **Q2 doc/code mismatch**: header comment promised both `path#anchor` markdown form AND `§"section name"` prose form. Implementation only handled markdown. Trim the comment to match the code; track prose-form in v2 follow-up alongside Q3 status-vocabulary as next narrowing. 3. **Q5 pattern overlap (exploratory)**: claude-opus-4-7 flagged that "standing managers" might substring-match "standing R2 managers". Empirical check shows it doesn't (POSIX regex requires the exact "standing managers" sequence; "R2 " breaks the match). Documented inline; no pattern change needed. 8-bit return-code truncation noted by reviewer is theoretical at current scale (briefs typically have <10 violations) and is now moot since the global `violations` accumulator is plain bash arithmetic; only the per-function `return` is uint8-bounded. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(scripts): manager-brief Q4 — explicit --repo for CI gh detection CI failed Q4 even after gh-first restructure: actions/checkout@v4's shallow clone exposes the remote in a form 'gh pr view' doesn't always auto-detect, so the stage-1 gh call returned empty (no error message in v1 because stderr was redirected to /dev/null) and the stage-2 git-log fallback also failed (shallow clone has no merge history). Three fixes in this commit: 1. **Derive REPO_SLUG from `git config remote.origin.url`** at script start. Falls back to "gunb-ai/gunbc" if origin isn't readable (self-test runs in tmpdir with no remote). 2. **Pass `--repo "$REPO_SLUG"` explicitly to `gh pr view`** so it doesn't have to infer from the cwd's git remote. 3. **Capture gh stderr** to a temp file and surface it in the violation diagnostic. If gh is auth-failing or rate-limited, the violation message now shows why instead of looking like "PR doesn't exist." Both checker + self-test still pass locally. CI should now succeed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(ci): grant pull-requests:read for manager-brief authority check The check uses `gh pr view --json state` to verify "LANDED via #N" claims map to MERGED PRs. Default GITHUB_TOKEN scopes only include contents:read; pull-request access fails with: GraphQL: Resource not accessible by integration (repository.pullRequest) Surfaced when the script's stderr-capture fix (ea33aeb) made the actual error message visible — diagnostic improvement paid off immediately. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: Gunbc PM * fix(scripts): manager-brief checker — markdown-bold + heading-strip + Q3 trigger Per gpt-5-5-pro REQUEST_CHANGES on PR #1126 (sha:ea33aeb9). Three findings — one BLOCKING (Q5 was ceremonial on its load-bearing projection), one secondary (heading-strip glob bug), one coverage gap. 1. **Q5 markdown-bold mismatch (BLOCKING).** Live briefs use `Names this manager one of **7** standing R2 managers` — markdown emphasis around the count. The pre-fix regex `[0-9]+ standing R2 managers` required a bare leading digit, so it matched zero claims on every brief. Counts_seen stayed empty → "0 counts seen → silent OK" branch fired → check passed ceremonially. A future drift to `**6** standing R2 managers` would have been invisible. Fix: regex now optionally accepts `**` before and after the digit: `\*?\*?[0-9]+\*?\*? standing R2 managers`. Extraction strips asterisks (`tr -d '*'`) before parsing. Verified on live briefs: $ grep -oE '\*?\*?[0-9]+\*?\*? standing R2 managers' docs/briefs/r2-*-manager.md docs/briefs/r2-evaluator-manager.md:**7** standing R2 managers docs/briefs/r2-grounding-manager.md:**7** standing R2 managers docs/briefs/r2-impossible-bugs-manager.md:**7** standing R2 managers docs/briefs/r2-modeling-manager.md:**7** standing R2 managers docs/briefs/r2-pure-bootstrap-manager.md:**7** standing R2 managers docs/briefs/r2-release-manager.md:**7** standing R2 managers docs/briefs/r2-substrate-manager.md:**7** standing R2 managers Now actually catches all 7 briefs' projections. 2. **Heading-strip glob bug (Q2 secondary).** `${heading##\#* }` is a Bash glob that strips through the LAST space, so "## Goal 7 — Evaluator XL" becomes "XL" instead of "Goal 7 — Evaluator XL". Multi-word heading anchors silently false-fail. Fix: introduced `strip_heading_marker()` helper using sed regex `^#{1,6}[[:space:]]+` for accurate prefix-only stripping. 3. **Self-test fixture format mismatch (coverage gap).** Self-test used bare-digit form ("7 standing R2 managers"); live briefs use markdown-bold ("**7** standing R2 managers"). Fixture proved Q5 for a format the live docs don't use, masking finding 1. Fix: updated all clean + drift fixtures in self-test to use markdown-bold form. Verifies Q5 catches the actual format. 4. **Q3 dissolution trigger (per debt-tracking discipline).** Previous "v2; the next narrowing opportunity" was a future bucket without a checkable trigger. Replaced with concrete trigger: "first reviewer-flagged status-string drift class that Q1/Q2/Q4/Q5 don't catch." Until that surfaces, status vocabulary is captured indirectly via Q5 count-projection consistency. Local checker + self-test still pass after fixes; Q5 now actually fires on live brief content rather than silently passing ceremonial. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(scripts+briefs): manager-brief Q2 prose-form check + align 7 citations Per gpt-5-5-pro BLOCKING on PR #1126 (sha:91b5274fc): Q2 explicitly excluded prose §"section name" citations, but live briefs use those for load-bearing INVARIANTS / r2-structure / design authority claims. The exclusion left 12 real authority drifts uncheckable. **Implements Q2-prose** (in addition to Q2-markdown-anchor): For each `§"quoted section"` or `§AnchorToken` in a brief: 1. Compute the prefix BEFORE this citation (running prefix; the bug in v0 was using before-first-§ for every iteration, so subsequent citations on the same line resolved against the first link's target instead of their own). 2. Find the most recent markdown link `[text](path)` in the prefix — that's the cited file. Fall back to bare `<NAME>.md` token via `resolve_authority_file()` (tries `$ROOT/`, `$ROOT/docs/`, `$ROOT/docs/thesis/`, `$ROOT/docs/briefs/`). 3. `grep -F` for the section text in the cited file. Permissive substring match (vs Q2-markdown's slug match) — accepts paraphrased section names while still catching the load-bearing "section deleted" failure mode. **Caught 12 real drifts on first run** — all now fixed: - r2-evaluator-manager.md: §"Goal 7 — Evaluator XL" + §"Evaluator Manager (added 2026-04-28 as Goal 7)" → §"Evaluator Manager (added 2026-04-28 amendment)" (matches r2-structure.md:159 actual heading) - r2-grounding-manager.md: §"Tier 1 — Structural correctness — Grounding completeness" → §"Tier 1 — Structural correctness" (matches THESIS.md:168 actual prose) - r2-impossible-bugs-manager.md (×2): §"R2 manager continuation" → §"Manager structure" (matches r3-structure.md:103 actual heading) - r2-impossible-bugs-manager.md: §Q1-Q3 + §Q6 → §Q1, §Q2, §Q3 + §Q6 (range citation didn't match anything literal; expand to discrete) - r2-release-manager.md (×2): §"R2 manager continuation" → §"Manager structure" - r2-release-manager.md (×2): §v2-guardrail-requirement-3 → §"v2 guardrail requirements" (matches r2-structure.md:490 body) - r2-substrate-manager.md: §"R3 lane structure" → §"Lane structure" (matches r3-structure.md:86 actual heading) Local checker + self-test still pass after fixes. Reinforces gpt-5-5-pro's earlier meta-observation: a checker that names a discipline but doesn't enforce it on the live format is documented cheating. Q2-prose closes that gap; the briefs' authority citations now have to match section text that actually exists. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * chore(scripts): manager-brief — mktemp gh-stderr + Q1 false-pos trigger Per claude-opus-4-7 APPROVE-with-exploratory-observations on PR #1126 (sha:91b5274f). Two non-blocking cleanups landed. 1. **gh-stderr capture: $$ → mktemp.** Previous form used `/tmp/gh-stderr-$$` which is fine in CI but a crashed run on a shared dev box could leak the file. `mktemp` gives a unique path + paired cleanup in scope. 2. **Q1 false-positive trigger documented.** Q1 currently treats every `](path)` as a filesystem reference. Markdown reference- style link definitions and code-block examples containing `](foo)` would false-positive. No briefs use either form today; added DISSOLUTION TRIGGER comment naming the condition that would force context-aware extraction (skip fenced code blocks + reference definitions). The third observation (squash-merge for the WIP: Gunbc PM commits) is a merge-time decision; PR-level chore. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: Gunbc PM * fix(scripts): manager-brief Q4 case-insensitive + title-case test Per gpt-5-5-pro APPROVE_WITH_COMMENTS on PR #1126 (sha:91b5274f → 6dafaec): Q4 silently missed title-case "Landed via #N" claims. **Finding 1 (Q4 case sensitivity):** live briefs use three case forms of "landed via #N": - UPPERCASE — emphasized status-table claims (most common) - lowercase — inline prose ("landed via #900", "landed via #937", ...) - title-case — sentence-leading headings (r2-release-manager.md:113 "Landed via #1078:") The pre-fix regex `(LANDED|landed) via` missed the title-case form, silently passing any future unique `Landed via #N` claim. Fix: `grep -oEi 'landed via #[0-9]+'` (case-insensitive flag). **Finding 2 (Q4 self-test gap):** Q4 negative fixture used UPPERCASE "LANDED via #88888888"; positive fixture had no landed-PR claim at all. Title-case wasn't covered. Fixes: - Added `test_negative_q4_unreachable_pr_titlecase` using "Landed via #88888887" — verifies case-insensitive Q4 catches title-case. - Updated `write_clean_briefs` clean fixture to include "Substrate landed via #999" (lowercase, matching real brief format). Q4 positive path is now non-vacuous: tmp git repo seeds "(#999)" merge subject so this resolves cleanly. **Finding 3 (Q2 prose deferral note)**: STALE — Q2-prose was implemented in 97affdb (2 commits before this review). The reviewer cited line numbers from before the implementation; current code at `scripts/check-manager-brief-authority.sh:121` says "Two forms covered" not "v2 candidate". No action needed. Self-test now: 8 contract assertions (6 negative + 1 positive + 1 fail-closed-on-missing-brief). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * chore(briefs): strip trailing whitespace at r2-evaluator-manager.md:46 Per codex review on PR #1126 (sha:3ba4f2c1): `git diff --check origin/main...HEAD` flagged trailing whitespace inside the PR-A-through-PR-E dependency-graph ASCII art. Removed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(scripts): manager-brief Q2-prose digit-leading + negative test Per gpt-5-5-pro REQUEST_CHANGES on PR #1126 (sha:b9f7a1c1): Q2-prose extractor required §-followed-by-letter, silently skipping the digit-leading citation forms used in the same diff. Live brief usage caught: §4 — r2-evaluator/grounding/impossible-bugs/modeling/pure-bootstrap §6a — r2-modeling-manager.md (cite of design-substrate-carrier-port-program §6a) §0.7 — r2-pure-bootstrap-manager.md (cite of debt-paydown-synthesis §0.7) §5 — r2-release-manager.md All previously skipped → "Q2 (prose §) resolved" was vacuously true on those lines. Fix: regex `§[A-Za-z][A-Za-z0-9._-]*[A-Za-z0-9]|§[A-Za-z]` → `§[A-Za-z0-9][A-Za-z0-9._-]*[A-Za-z0-9]|§[A-Za-z0-9]` (extends [A-Za-z]-leading to [A-Za-z0-9]-leading; quoted form unchanged). Documented limitation: short digit-only tokens like §4 resolve permissively because grep -F "4" matches anywhere; multi-character tokens like §6a are discriminating. Self-test gap (also flagged): added `test_negative_q2_missing_prose_numeric_section` using §99zzz (digit-leading, multi-char so substring match doesn't trivially pass). Verifies regex extraction triggers Q2-prose violation on digit-leading citation drift. Self-test now: 9 contract assertions (7 negative + 1 positive + 1 fail-closed-on-missing-brief). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): consume Tier 1 design locks 1+2+3 from #1129 Director landed Items 1+2+3 design locks together via #1129 (`e1afabe47`): - Item 1 (Q1 asymmetric bound algebra) — `docs/design-emission-model.md` §"Q1 — `BoundDeclaration` substrate type" - Item 2 (reflection completeness) — NEW `docs/design-reflection-completeness.md` - Item 3 (Q6.5 two-layer diagnostic-kind) — `docs/design-lens-framework.md` §"Q6.5 — Two-layer authority for diagnostic kinds" Per agreed PM role on inbox #828: as each design-lock doc lands, PM consumes the lock into worker brief updates (statuses move from PENDING/gated → LIVE; cited authority anchors verified by the manager-brief authority checker). Mostly mechanical. Brief updates: - **Substrate** (3 sites): T-Substrate-Lens-Primitive flips from "gated on PR-K" to "Q6/Q6.5/Q7/Q8 LANDED via #1129; ready to dispatch"; "Diagnostic-kind extensibility (Q6 lock)" replaced with the locked Q6.5 two-layer authority cite (Layer 1 closed sum Substrate-owned; Layer 2 lens-instance via inhabitance; additive widening of `Diagnostic.kind` named). - **Evaluator** (5 sites): "Lens application gated on PR-C" → cites the landed reflection-completeness doc; PR-C row in cadence table flips to LANDED; Q6 disposition becomes Q6+Q6.5 with explicit cite to design-lens-framework.md §Q6.5; "Reflection completeness lives in PR-C" → "lives in design-reflection-completeness.md (LANDED via #1129)"; PR-C worker brief in pending list crossed out as superseded. - **Modeling** (1 site): status header now cites Q1 lock landing with explicit anchor; int-lit item already references Interval<D> via PR-PreF. - **Grounding** (2 sites): T-Ground-Diagnostic lane and Substrate- Manager-cross-program-dependency cite Q6.5 — clarifies lane is Layer-1 consumer (not Layer-2 author), no cross-manager handoff. - **Pure Bootstrap** (1 site): Q6 disposition becomes Q6+Q6.5 + reflection-completeness cite added (load-bearing for R3-T- LensProducer-Retirement per design-reflection-completeness.md §"Cascade and gates" §7.3). - **Impossible-Bugs** (1 site): Q6 cite becomes Q6+Q6.5; classes consume Layer 1, not author Layer 2. Verified: `bash scripts/check-manager-brief-authority.sh` passes all 7 briefs (Q1/Q2-md/Q2-prose/Q4/Q5); 9 contract assertions in self-test still pass. Note: one brief edit required restructuring (modeling-manager.md:3) because the original cite put §"section" inside the markdown link's display text, while the heuristic finds the rightmost `](path)` BEFORE the §. Moved cite outside the link to align: `[file.md](path) §"section"`. Same pattern as other landed cites; the checker enforces it structurally. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * chore(scripts): manager-brief — concrete dissolution trigger for short-digit § limitation Per codex APPROVE_WITH_COMMENTS on PR #1156 (sha:00540f36): the short digit-only § resolve-permissively limitation was documented and bounded but lacked a concrete dissolution trigger. Updated to match Q3 dissolution-trigger discipline: trigger fires on first reviewer-flagged stale `§N` (single-digit) citation that survives the substring check because the digit appears elsewhere in the target file. At that point the check tightens to require structural context — match `§N` only if the target has a heading `## N`, `### N`, etc. or numbered-list item at column 0. Until that surfaces, multi-character disambiguation is the load-bearing discriminator (and live briefs predominantly use multi-char forms — §P1, §Q6, §Q6.5, §"Lane structure" — so single-digit `§4` citations are uncommon). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(design): consume Q6.5 lock in worked examples + r2-structure Q6 row Per Director (zesty-bear-812) endorsement on inbox #828: fold the design-doc Q6.5-consumption edits originally drafted in PR #1137 (jolly-ram-908) into the canonical consumption PR. Single-sourced consumption story; #1137 ends up as a clean no-op redirect. 8 lens-framework worked-example reframes + 1 r2-structure Q6 row update. All consume the Q6.5 two-layer authority disposition landed via #1129: **design-lens-framework.md (8 sites):** - §"Lens<TenantFlow>" `validate(dag, set)`: "new CompilerDiagnosticKind variant" → "lens-local diagnostic-kind declaration" - §"Lens<IFC>" `validate(dag, label)`: same reframe for IFCDowngradeViolation - §"D5 Failure modes": "appropriate CompilerDiagnosticKind variant (lens instances may extend CompilerDiagnosticKind...)" → "appropriate lens-local diagnostic-kind declaration" - §Q6 alternative (d): "pushes structural failure data into Diagnostic.kind (which is CompilerDiagnosticKind sum type — already extends per-instance per feedback_state_space_vs_behavioral_invariants)" → "pushes structural failure data into lens-local Diagnostic.kind declarations" - §Q6 anti-bridge claim renaming `no_string_parsing_in_witness_consumers` description: "Diagnostic.kind extensions" → "lens-local Diagnostic.kind declarations" - §Q6 Recommendation (d): "encode into Diagnostic.kind sum-type variants. Lens instances ... extend CompilerDiagnosticKind with their own variants" → "encode into lens-local Diagnostic.kind declarations. Lens instances ... declare their own kinds beside the lens instance" - §Q6 DECISION line: "(c)/(d) hybrid — Witness<C> stays as-is; rich structural validation failures encode into Diagnostic.kind extensions via the lens-framework's structural inhabitance" → same with "lens-local Diagnostic.kind declarations"; date stamp augmented with "refined 2026-04-29" - §Q6 Director's framing #1: "CapabilityViolation as a CompilerDiagnosticKind variant is uniform" → "CapabilityViolation as a lens-local diagnostic-kind declaration is uniform" **r2-structure.md (1 site):** §"Q1-Q8 disposition" Q6 row updated to match design-lens-framework's locked language: "encode into Diagnostic.kind extensions via lens-framework's structural inhabitance" → "encode into lens-local Diagnostic.kind declarations via lens-framework structural inhabitance, not into the closed compiler-core CompilerDiagnosticKind sum". These edits are *editorial* — the Q6.5 lock at design-lens-framework.md §"Q6.5 — Two-layer authority for diagnostic kinds" remains the canonical authority; this just aligns the worked examples + r2- structure summary row with that canonical phrasing so future readers don't see the older "extends CompilerDiagnosticKind" framing in worked examples and assume it survived. Verified: manager-brief authority check passes (7 briefs / 0 violations); 9 contract assertions in self-test pass; release-doc authority check passes. Per inbox #828 + #1130 coordination: jolly-ram-908 confirmed PR #1137 will close as redundant once #1156 lands (the brief edits were already absorbed by my prior consumption pass; these design-doc edits are the residual that's now folded in). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: Gunbc PM --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
T-Substrate
NominalOpacity— carrier-only stagingBrief:
docs/briefs/r2-substrate-nominal-opaque-for-secret-subset.mdManager dispatch: issue #869.
Scope (re-scoped per manager directives at #869)
This PR lands only the substrate carrier for nominal opacity, with a target
TypeRealizationso the field is observable from generated code. It does not ship a fail-closed walker, a typedDiagnosticvariant, or aSecret<T>consumer.It is not a Shape B / consumer-proof / Modeling-readiness PR, and it does not signal #858 readiness.
What lands here
src/v3/std/substrate.dag:type NominalOpacity { permitted_accessors: List<DeclarationRef> }, plus optional fieldnominal_opacity: NominalOpacity?onDeclaration.src/v3/compiler/src/dag.rs: Rust mirror —pub struct NominalOpacity { pub permitted_accessors: Vec<DeclarationId> }andpub nominal_opacity: Option<NominalOpacity>onDeclaration.src/v3/spec/rust.dagandsrc/v3/spec/go.dag: targetTypeRealizationforNominalOpacityso the carrier is reflected through code generation (rust_nominal_opacity/go_nominal_opacity).Declaration { ... }constructor sites updated withnominal_opacity: None; bootstrap regenerated viaregen_bootstrap --features bootstrap-regen-fresh;regen_v3fixed-point verified.What is explicitly out of scope (named follow-up)
A separate PR will land the dissolution of this staging by adding, together:
nominal_opacityand refuses to descend through opaque declarations outsidepermitted_accessors.Diagnostickind for nominal-opacity violations, declared via the.dagdiagnostic-kind authority (not hand-added to the Rust enum) with regen-driven Rust/Go consumer proof.stdSecret<T>marking — graduatedsl/std/types.dagtype Secret = Stringto use this carrier and populatepermitted_accessorswithredact,compare_in_constant_time, etc.The dissolution trigger is: walker/descent +
Secret<T>+ diagnostic-kind authority + carry-forward policy land in one coherent PR. Until then, the carrier is dormant data.Pre-flight authority audit (still accurate)
opacitymatches inINVARIANTS.md/SELF_HOSTING.mdare the emission-layer "Layer opacity" lens — different concept.TypeConnectivestays at 6 variants. No 7th proposed.phantom_params: List<PhantomParameter>— a sibling field onDeclarationcarrying typedDeclarationIdedges to a secondary substrate concept.nominal_opacitymirrors that shape.inhabits: DeclarationId?is occupied by algebra-law inhabitance; not overloaded.DeclarationRefsentinel reused for the permitted-accessor list; no new sentinel.specialization_parent,refinementnot in.dag) declared, not widened.DeclarationRef↔DeclarationIdmirror convention.dagDeclarationRefrealizes as RustDeclarationId. Follows existing precedent (type_realization,operator_realization, everyaccessor/realization/languagefield onSubstrateAccessorBinding).Gates
fmt/ci/v3— refreshed against the latest commit (bcd479357) which re-emits bootstrap after theorigin/mainmerge to pick up theDeclarationHasRefinementTestPredicatevariant added on main.self_host_ratchet/ DB-8 — must be observed clean on reviewer host before merge.Cross-program note
r2-modeling-secret-graduation-worker.md. Awaits the dissolution PR above.Secret<T>-leakage proof depends on the dissolution PR, not this carrier alone.