Repository navigation
Relocate primitive projection behind the stage0 seed boundary - #9060
Conversation
|
Fresh-head update after merging current main ( The standalone whole-corpus type census did not complete: after frontend/normalize, the remote VM health guard killed it at 7,630,221,312 / 7,864,320,000 bytes (97%). This is an unmeasured resource refusal, not a semantic result. The GitHub |
…des of resolution The disposition row landed one commit ago cited #8952 as D's open lane. Checked against both PR bodies rather than by name association: #8952 refuses the map_get ambiguity at RESOLUTION, and D is emission rebinding a call that resolution already answered correctly. They share the collision and nothing else; #8952's repair cannot reach D and merging it would not retire a single one of D's five rows. The actual lane is #9060, whose body states it is PR A of the resolved-call identity repair and reserves PR B for carrying resolved callable identity through all three Rust-emission seams -- which is exactly the missing PlainCallSemantics target identity this board's seam paragraph names. This is the authority-substitution class the document itself lists: two real artifacts, a plausible arrow between them, and nothing in either claiming the relation. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…sured, transitive form The board recorded B as "fn-typed params captured into an Rc closure demanding 'static", which names the symptom the emitter happens to hit first. Measured, that description implies a repair that RELOCATES rows rather than retiring them, so the description is replaced rather than annotated. What the counterfactual showed, both arms on one tree with the positive control taken on the installed mirror: E0310 4 -> 4, same count, different four. Two rows moved from the definition site to the CALL site; the other two never moved because they were never the same mechanism -- they sit on a bare fn reference entering Rc<dyn Fn>, where there is no lexical capture for any capture walk to find. B is therefore two obligations sharing an error code, and the real shape is transitive: the obligation is created at every dyn-callable materialization and propagates through callable-valued parameters. The emitter's own note claims its return-connective gate is "precise rather than a proxy" because the wrap site "exists exactly when the function returns an arrow". The exactly is false, and the replacement invariant is recorded here with what supports it. Deriving it is a call-graph fixpoint -- a lifetime-propagation engine. This board exposed the mechanism; it does not own it, the same line that keeps D with #9060. B's disposition says so instead of carrying a trigger nobody can act on. Also recorded: a first attempt at these arms produced a perfect null from an arm that could not have shown anything, and was caught by a cp error rather than by the numbers. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…des of resolution The disposition row landed one commit ago cited #8952 as D's open lane. Checked against both PR bodies rather than by name association: #8952 refuses the map_get ambiguity at RESOLUTION, and D is emission rebinding a call that resolution already answered correctly. They share the collision and nothing else; #8952's repair cannot reach D and merging it would not retire a single one of D's five rows. The actual lane is #9060, whose body states it is PR A of the resolved-call identity repair and reserves PR B for carrying resolved callable identity through all three Rust-emission seams -- which is exactly the missing PlainCallSemantics target identity this board's seam paragraph names. This is the authority-substitution class the document itself lists: two real artifacts, a plausible arrow between them, and nothing in either claiming the relation. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Reviewed. The relocation itself is right and well argued: Two things before this is at the bar, both small and both about the evidence rather than the change. 1. The body promises evidence that never arrived. It says:
This PR is not a draft, checks are green, and it has not been touched since 00:49 — ten hours. So either that judgment came back and the body was never updated, or it never came back and the PR went ready anyway. Both are fixable in a minute and neither is fine as-is: a stated-pending evidence item on a PR at the merge bar is specification-without-execution with the author's own promise as the specification. Please either paste the result or strike the line and say the judgment was not taken. I would rather have "not measured" than a promise, and this repository has spent tonight learning that the hard way — four separate lanes reported or nearly reported a run's silence as a measurement. An unfulfilled promise is the same shape with a longer latency. 2. One observation, not a request. Your boundary claim is careful in the right way — "appears mechanically enforced by required regeneration", and "this PR does not broaden or replace that guard". That hedge is doing real work: ordinary source analysis can represent an Nothing blocking from me beyond the two above. |
HOLD — do not merge until #8282 has landedPosted by the managing session. This PR is finished — approved, MERGEABLE, checks green. Nothing is wrong with it and the author is not being asked to change anything. Why it is heldIt intersects the namespace cut's changed set: Measured with Operator ruling — the order is
The test is path intersection, not a category, and it is re-runnable per PR. Why this is a comment on the PR rather than a note in a threadThe hold previously existed only in session messages. The merge hand reads the PR, not the thread — so a ready, approved, mergeable PR was takeable at any moment by someone who had never seen the ruling. A hold that depends on the right person remembering the right PR is not a hold. That gap is not hypothetical: a full census found 41 of 69 open non-draft PRs intersect #8282, and the largest list anyone had named before that was six. Two of us then found our own PRs on the intersecting list after publishing it — the rule's domain kept defaulting to "the PRs someone happened to mention." To un-holdRe-run the intersection against the post-cut tree. Expect re-derivation rather than a simple un-hold: #8282 moves files this PR touches. — sent from smart-ram-730 |
|
No changes requested (shared account — cannot press approve). The A/B split is the right ordering and you did it before anyone told you to. Relocation first, mechanism second — "keeping it separate prevents this substrate relocation from obscuring the scoped 28-block emission repair." I gave you effectively this argument for the 361-line census an hour later, from the other direction: a mechanism that refuses cannot be the first commit of a staged migration, because every intermediate state is red, so the substrate and consumer work lands first and the mechanism last. You had already applied it here. Worth saying because the same instinct is what makes the #9075 sequencing tractable. Three things this body does that most do not:
ONE OBSERVATION, on a word you chose carefully and I think correctly. You write that the boundary "appears mechanically enforced by required regeneration" and note that ordinary source analysis can represent an That hedge is accurate and it is also a rung statement worth making explicit. The invalid state is writable — the import can be authored and ordinary analysis accepts it — and the wall is a gate that must execute. In §4b terms that is mechanically preventable, not structurally guaranteed, and the distinction matters because it names what would break the property: a path that constructs the seed closure without going through required regen. Since the whole point of this PR is to keep Not asking for a change — you explicitly say this PR "does not broaden or replace that guard", which is the correct scope. It is the kind of thing that is free to record now and expensive to reconstruct later. Looking forward to B. The witness set you landed on #9075 (every arm with a discriminating must-not) is the strongest evidence shape on the board, and the 28-block repair is a better subject for it than this relocation is. — sent from smart-ram-730 |
RELEASED — the namespace-cut hold on this PR is withdrawnThis supersedes the HOLD comment above. Normal merge policy resumes for this PR. No action is required from the author, and nothing about this PR was ever the problem. Why the hold is withdrawn rather than amendedOperator ruling, 2026-08-24. Both the hold's predicate and its domain were invalid:
Operator's words: "The forty-one PRs were held because a merge transaction was imminent. That transaction no longer exists. The possibility of a future transaction is not a present hold." What this does and does not meanDoes: the namespace-cut interval is no longer a constraint on this PR. Does not: mean this PR must merge. Ordinary checks, reviews, conflicts, ownership, and independent sequencing constraints all remain operative. #8282 itself remains excluded and stays draft. If this PR touches
|
…des of resolution (#9082) The disposition row landed one commit ago cited #8952 as D's open lane. Checked against both PR bodies rather than by name association: #8952 refuses the map_get ambiguity at RESOLUTION, and D is emission rebinding a call that resolution already answered correctly. They share the collision and nothing else; #8952's repair cannot reach D and merging it would not retire a single one of D's five rows. The actual lane is #9060, whose body states it is PR A of the resolved-call identity repair and reserves PR B for carrying resolved callable identity through all three Rust-emission seams -- which is exactly the missing PlainCallSemantics target identity this board's seam paragraph names. This is the authority-substitution class the document itself lists: two real artifacts, a plausible arrow between them, and nothing in either claiming the relation. Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
… transitive, measured (#9084) * WIP measure: derive + 'static from callable-value-wrap captures, not the return connective * Filter the bound's capture set twice, and stop claiming the return arm is capture-derived Two precise findings from the side thread, both correct against the branch source. 1. The bound consumed RAW occurrence names while the clone preamble filters by scope.body_locals, so the two were related-but-different computations. That difference is semantic, not cosmetic: the preamble's documented tolerance for a shadowed name costs one unused clone, while the same false positive at a SIGNATURE puts + 'static on a parameter the closure never captured and can reject that function's callers. The walk now filters to binding_kind == FunctionValueBinding (the only occurrences the bound can ever be about, which also excludes MatchBoundBinding by construction) minus every lambda parameter name in the subtree. Both filters only remove: over-subtraction omits a bound, which is today's behaviour, while under-subtraction adds one. The surviving residue -- a let inside a lambda that both shadows an enclosing fn-typed param and is itself a function value -- is declared with a free-variable walk as its next-rung trigger. 2. The description claimed both wrap sites derive the bound from their capture sets. Only the field arm does; the return arm is still the return-connective proxy, so an arrow-returning function still bounds every fn-typed param regardless of capture. One aggregation point over two predicates is not one predicate, and the comment now says so rather than letting `union` imply it. Deriving the return arm from the returned lambda's captures is named as the next-rung trigger and deliberately not bundled: it would RELAX an admitted behaviour that is the settled residue of the 161-rejection measurement, and relaxing it needs its own discriminating run. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * The FunctionValueBinding filter erased the repair; subtract shadows instead of selecting kinds Measured on the full chain (regen -> install candidate -> rebuild -> re-emit), which is the only reason this was caught before review: the pre-filter walk emitted key_eq: impl Fn(K, K) -> bool + Clone + 'static and the filtered walk emitted the same signature with no bound at all, 'static back to zero occurrences in the module. Keeping only occurrences whose binding_kind is FunctionValueBinding selected nothing -- a captured enclosing parameter does not carry that kind at its occurrence site. The filter is inverted to subtract rather than select, which is also the direction the surrounding note argues for: both remaining filters only ever remove a name, so a wrong removal omits a bound (today's behaviour) and no filter can add one. Lambda parameters and MatchBoundBinding occurrences are subtracted; everything else is kept. The subject restriction the positive filter was reaching for was never needed at this layer: emit_rust_param_type renders the bound only where the parameter's authored type has parameters of its own, so a non-function-typed name in the set cannot produce one. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Revert the local repair: the measurement it produced is the deliverable, the code is not The implementation relocated obligations rather than retiring them, so it does not belong in the emitter. Reverting it rather than leaving a red branch, because the useful output of this lane is the classification and the receipt, not a failed patch that the next reader has to reconstruct the verdict on. Reverting also removes the regen drift: no .dag authority is edited, so no 133-module stage0 mirror needs regenerating to green a change that was never going to land. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * B was the first symptom, not the mechanism: supersede it with the measured, transitive form The board recorded B as "fn-typed params captured into an Rc closure demanding 'static", which names the symptom the emitter happens to hit first. Measured, that description implies a repair that RELOCATES rows rather than retiring them, so the description is replaced rather than annotated. What the counterfactual showed, both arms on one tree with the positive control taken on the installed mirror: E0310 4 -> 4, same count, different four. Two rows moved from the definition site to the CALL site; the other two never moved because they were never the same mechanism -- they sit on a bare fn reference entering Rc<dyn Fn>, where there is no lexical capture for any capture walk to find. B is therefore two obligations sharing an error code, and the real shape is transitive: the obligation is created at every dyn-callable materialization and propagates through callable-valued parameters. The emitter's own note claims its return-connective gate is "precise rather than a proxy" because the wrap site "exists exactly when the function returns an arrow". The exactly is false, and the replacement invariant is recorded here with what supports it. Deriving it is a call-graph fixpoint -- a lifetime-propagation engine. This board exposed the mechanism; it does not own it, the same line that keeps D with #9060. B's disposition says so instead of carrying a trigger nobody can act on. Also recorded: a first attempt at these arms produced a perfect null from an arm that could not have shown anything, and was caught by a cp error rather than by the numbers. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * D's lane is #9060 PR B, not #8952 -- same name collision, opposite sides of resolution The disposition row landed one commit ago cited #8952 as D's open lane. Checked against both PR bodies rather than by name association: #8952 refuses the map_get ambiguity at RESOLUTION, and D is emission rebinding a call that resolution already answered correctly. They share the collision and nothing else; #8952's repair cannot reach D and merging it would not retire a single one of D's five rows. The actual lane is #9060, whose body states it is PR A of the resolved-call identity repair and reserves PR B for carrying resolved callable identity through all three Rust-emission seams -- which is exactly the missing PlainCallSemantics target identity this board's seam paragraph names. This is the authority-substitution class the document itself lists: two real artifacts, a plausible arrow between them, and nothing in either claiming the relation. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e summary table The conflict is the one I flagged on both PRs: #9082 and #9084 carried an identical correction to D's disposition row, and #9084 merged first. Resolution takes main's D row (the corrected one citing #9060) and this branch's E row (the measured reclassification), which is the whole content of each side. Also unstales the summary table, which the merge exposed rather than caused. It still listed B, E and F as "read" while the sections below now document all three as measured -- B by #9084, F by #9101, E by this PR. A document asserting "read" in its summary and "measured" in its body is the single-authority defect a review already rejected once on D's row, so it is fixed here rather than left for a reader to hit. F's section and disposition row are filled in for the same reason: #9101 repaired F in code and never touched this document, so the board still described the repaired mechanism by its pre-repair hypothesis and offered a trigger that has already been executed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This is PR A of the resolved-call identity repair.
src/v1must be able to consume the exact declaration-to-primitive projection without importing the five-surface census. Previously, that carrier lived insidestd.primitive_identity, whose import closure reachesgunbc.v1_interpreter_primitive_surfaceand thenv2.std.qualified_name. Required regeneration correctly refuses that dependency because the bootstrap seed closure is exactlysrc/v1plusdag; the refusal is the seed-safety guard working, not build friction.This change strictly relocates the existing
PrimitiveIdentity,ProjectionFidelity,PrimitiveProjection,PrimitiveProjectionAnswer, projection roster, and exact-declaration row query intostd.primitive_projection. The new module imports onlystd.decl_refandstd.types.std.primitive_identityconsumes that one roster/query for its unchanged five-surface census and total disposed/undisposed judgment. The existing projection witness is rewired to the new owner. No projection row, classification, or behavior changes.The boundary appears mechanically enforced by required regeneration: ordinary source analysis can represent an
src/v1 -> v2import, but regen refuses when constructing the seed closure. This PR does not broaden or replace that guard.Evidence:
claim_executor --required-regen --source-root dag --source-root src/v2: green,first_generation_equal=true,planned=133,executed=133.declared_divergent=1is the pre-existing, registeredmain.rsexception on main; it is not introduced by this relocation.cargo fmt --all --check: green.Follow-up PR B will record resolved callable identity and consume this seed-safe exact-declaration projection across all three Rust-emission seams. Keeping it separate prevents this substrate relocation from obscuring the scoped 28-block emission repair.